The EU AI Act
Risk classification, documentation of models and data sources, and human oversight designed into any decision that affects a person.
Industry Insights
Article details
In short: European software budgets in 2026 are being set less by ambition than by deadlines. The AI Act, DORA, NIS2 and the European Accessibility Act each turn something that used to be optional into something a board has to fund, and they all land on the same engineering surfaces: data handling, logging, resilience and accessibility. Build for them once and they stop being separate projects.
Most articles about European technology spend lead with a market-size forecast. We are going to skip that, because the forecast is not what is moving budgets in the engagements we actually see. Deadlines are. Four pieces of EU legislation have moved from consultation into force over the last two years, and each one converts something a team used to defer into something with a date attached. That is a very different kind of budget pressure, and it lands almost entirely on engineering.
These are not the only rules in play, but they are the ones that come up in almost every scoping conversation we have with a European team, regardless of sector.
Risk classification, documentation of models and data sources, and human oversight designed into any decision that affects a person.
Operational resilience for financial entities and their critical ICT providers: tested recovery, incident reporting, and third-party risk you can evidence.
Baseline security obligations across a far wider set of sectors than its predecessor, with management accountability attached.
Accessibility as a market-access condition for a broad class of consumer-facing digital products, not a best-effort target.
Why they land together
Read separately they look like four compliance programmes. Read as engineering requirements they converge on the same four surfaces: how you handle data, what you log, how you recover, and who can use the product. Teams that treat them as one architecture problem spend a fraction of what teams running four parallel workstreams spend.
| Driver | What it asks for in practice | Where it hits first |
|---|---|---|
| EU AI Act | A record of what each model does, what it was trained or grounded on, and where a human can intervene | Any LLM feature shipped without an evaluation harness |
| DORA | Tested backup and recovery, incident timelines you can reconstruct, and a register of critical providers | Financial products with untested restore paths |
| NIS2 | Access control, patching discipline, logging and a real incident response process | Long-lived credentials and unmonitored infrastructure |
| Accessibility Act | Keyboard operability, contrast, semantics and assistive-technology support in the shipped product | Component libraries built for looks rather than semantics |
The teams that struggle are rarely the ones with weak engineers. They are the ones whose systems cannot answer questions. A supervisor asks what happened during an outage eighteen months ago, and the logs rolled over. An auditor asks which model version made a decision, and nobody recorded it. The work is not hard; it is just impossible to do retroactively, which is why it arrives as an emergency rather than a sprint.
Build it once
Structured logging, tested restore, model and decision records, and an accessible component layer cover most of what all four regimes ask for. None of them is a large piece of work on its own. All four at once, under a deadline, is.
We come in at the point where a team knows something has to change but not what to do first. The engagement opens with a production readiness audit that maps your obligations against what the system can currently evidence, and produces a prioritised risk register rather than a proposal. From there we fix the constraints that matter, verify them against the baseline, and hand over documentation your own team can operate.
The teams that win in 2026 are not the ones with the best compliance slide. They are the ones whose systems can answer the question when it is asked.— DevzAura Engineering
Start with a production readiness audit. You get a prioritised risk register and an action plan you can act on with us or without us.
Want this reviewed on your codebase?
Bring the specifics. We will tell you what actually applies to your stack and what does not.
Need help with Custom Software Development?
Explore Custom Software DevelopmentKeep Reading
11 min read
In 2026, expect to budget roughly $15k for a simple internal tool, €28k to €75k for an MVP, $80k to $200k for a SaaS platform, and $200k or more for an enterprise build. The real number tracks scope, integrations, engineer seniority, and compliance, not whichever Europe vendor gives you the vaguest quote.
12 min read
Building fintech in the EU or UK regime is not a feature you bolt on at the end. It is an architecture decision you make on day one. Get data residency, encryption, auditability, and KYC and AML right early, and compliance becomes a moat instead of a blocker.
FAQ
Book a free consultation with our engineers.