A mid-market organisation with two hundred employees and three high-risk AI systems carries substantially the same regulatory obligations as a far larger firm, but the delivery models available to it were designed for enterprises. That mismatch, rather than the regulation itself, is where most of the cost sits.
The consulting model is built for enterprises
Large consulting firms charge what their cost structure demands. A multi-framework compliance engagement is generally staffed across several grades and billed by time, with workshops, travel, and interim reporting adding overhead on top. That structure was designed for organisations with thousands of employees, large system estates, and compliance budgets to match. For those organisations it makes sense.
For a mid-market financial services firm with a two-person compliance function and a handful of AI systems, the same structure is disproportionate. The firm pays for a delivery model it does not need in order to get a programme it does.
What makes this harder is that the obligations scale down far less than the organisation does. Each of the frameworks makes some allowance for size, and none of those allowances removes the substance of the work. DORA applies a proportionality principle throughout and permits a simplified ICT risk management framework under Article 16 for certain smaller entities, but the entity still needs a framework, a register of information, and an incident reporting capability. The EU AI Act provides support measures for SMEs under Article 62 and a simplified form of technical documentation for small firms, but the classification, risk management, and human oversight obligations attaching to a high-risk system do not change with headcount. NIS2 does use size thresholds, with large entities in its Annex I sectors treated as essential and medium entities generally treated as important, but both categories carry cybersecurity risk management and reporting duties, and sector-specific rules pull some smaller entities in regardless of size.
The obligations therefore compress only modestly as an organisation gets smaller, while the resources available to meet them compress a great deal. The delivery model is the variable with real room to move.
Enterprise GRC platforms are built for large compliance teams
The usual alternative is an enterprise governance, risk, and compliance platform. Licensing is only part of the commitment. Implementation, configuration, training, and the internal staff required to run the platform all sit on top of it, so the cost of ownership in year one can run well ahead of the licence figure.
For mid-market organisations the operational problem is usually worse than the financial one. These platforms are designed around a staffed compliance function managing a large control estate across multiple business units. A two-person team cannot configure, populate, and maintain that while also doing its day job, so the platform sits underused, the team reverts to spreadsheets, and the investment produces very little.
Where AI changes the delivery model
The tasks that consume the most hours in a traditional engagement are drafting policies, mapping obligations across frameworks, producing risk registers, generating documentation, and building board reports. Those are precisely the tasks that AI handles fastest, because they are high in volume and structured in form.
AI handles that volume. Expert oversight handles the judgement, which means reviewing for accuracy, interpreting supervisory expectations, validating against the specific facts of your organisation, and taking professional accountability for what is signed off. Neither half works alone. A regulator asking who approved a control will not accept a model as the answer.
What Morclear charges
A CORA™ Gap Assessment is €999 and takes two weeks. It covers obligation mapping across the frameworks in scope, a scored maturity report, and a prioritised remediation roadmap. A full Programme Build starts from €15,000* and runs eight to twelve weeks. Ongoing Managed Compliance starts from €2,000 per month*. Individual CORA™ modules are €1,500 to €3,500 and take one to two weeks.
Every engagement is scoped and priced in writing before work begins, so the fee is known in advance.
*Fees confirmed after a free scoping call.
Where the timeline actually stands
Following Regulation (EU) 2026/1744, the EU AI Act timeline is no longer a single date. The Article 5 prohibitions have been enforceable since February 2025. The Article 50 transparency obligations became applicable on 2 August 2026 and were not deferred. Systems already on the market before that date come into scope for content marking on 2 December 2026. Annex III standalone high-risk systems apply from 2 December 2027, and Annex I embedded high-risk systems from 2 August 2028.
The practical effect is that some obligations are live now and others sit more than a year out, which is a harder position to manage than a single deadline. Organisations that treat the deferral as a pause tend to discover that the parts already in force were the parts that applied to them.
On penalties, the EU AI Act provides for fines of up to €35 million or 7% of total worldwide annual turnover for the prohibited practices in Article 5, up to €15 million or 3% for breaches of most other obligations including those on high-risk systems, and up to €7.5 million or 1.5% for supplying incorrect or misleading information to authorities. Under GDPR the upper tier is €20 million or 4%.
The right model for mid-market
Mid-market organisations need the same rigour as enterprise programmes on a cost and timeline that matches their reality. AI-powered delivery with expert oversight is how that becomes possible, not because anything is left out but because the structural inefficiencies that make hourly consulting expensive are removed from the process.
A sensible sequence is to run the free AI Act assessment to understand exposure, commission a gap assessment to map obligations against your own systems, and then decide with full visibility whether to build internally from the roadmap, engage Morclear for the implementation, or move into continuous managed compliance through CORA™. Each step is priced before it starts and each one is optional.
Primary Regulatory Sources
Morclear resources are independently produced. They do not constitute legal, regulatory, financial, or professional advice.