Sofpact field note

AI in the CEE Mid-Market: Sequence Adoption to the Team You Have

Editorial three-step adoption staircase from one workflow to evidence to an operating model under EU rules

On 2 August 2026, every EU member state must have at least one AI regulatory sandbox operational at national level. Access is free of charge for small and medium-sized enterprises, including start-ups. In most of Central and Eastern Europe, the mid-market organisations this was designed for do not know it exists.

That gap is the shape of the whole problem. The obligations of EU AI regulation apply the same way to a 300-person manufacturer in Plovdiv as to a bank in Frankfurt. The resources available to meet them do not scale down in proportion. The organisations that will handle this well are not the ones that spend the most; they are the ones that sequence the work to the team they actually have.

What applies regardless of size

There is no small-company exemption from the substance of the European Commission: AI Act. Prohibited practices are prohibited for everyone. Classification rules do not soften below a headcount threshold. If a mid-market firm deploys an AI system for recruitment screening or creditworthiness assessment, it is in the same Annex III territory as a much larger one.

The same is true of everything the AI Act sits on top of. Data protection obligations apply now. Sectoral supervision applies now. Employment and consumer law apply now. A common failure in the mid-market is to treat AI governance as a future project attached to a 2027 date while running systems today that already process personal data without an adequate basis.

What does change with size is proportionality in how obligations are met — and the support available to meet them.

The support that exists and is underused

The AI Act contains specific measures for smaller organisations that are, in practice, barely taken up in the region.

  • Regulatory sandboxes. AI Act Service Desk: Article 57 — AI regulatory sandboxes requires member states to ensure at least one national sandbox is operational by 2 August 2026. It may be established jointly with other member states, which matters for smaller markets.
  • Priority and free access. AI Act Service Desk: Article 62 — measures for providers and deployers, in particular SMEs provides SMEs and start-ups with priority sandbox access, free of charge, alongside tailored training, dedicated communication channels and facilitated participation in standardisation.
  • Reduced fees. Conformity assessment fees are to be reduced for SMEs.
  • Standardised templates. The AI Office is tasked with providing standardised documentation templates and a single information platform — which removes a real cost for firms without in-house legal capacity.

The measures in support of innovation apply from 2 August 2026. For a mid-market firm with one plausible high-risk use case and no compliance function, a free national sandbox is the single most valuable thing on this list, and it is worth contacting the national competent authority directly rather than waiting for an announcement.

Sequence for the team you have

The standard enterprise sequence — strategy, operating model, platform, portfolio — assumes people whose full-time job is this. A mid-market organisation typically has an IT lead with an existing workload, an operations manager who understands the process, and a sponsor who needs a result this year. The sequence has to fit that.

  1. One workflow. Choose a single recurring process where the current cost is visible and the output is easy to check. Resist the portfolio exercise; it consumes the credibility you need for the second project.
  2. Evidence in context. Prove it in your own environment, with your own data and your own people, against a baseline recorded beforehand. Evidence from a vendor’s reference customer is not evidence about your operation.
  3. Operating model. Only once something works does it make sense to define ownership, monitoring, change control and the route by which the next use case is chosen.

The inventory step belongs at the start regardless. Most mid-market firms are already running AI they have not catalogued, because it arrived inside procured software — the CRM, the recruitment platform, the customer service tool. You cannot classify what you have not listed, and the list is usually longer than the leadership team expects.

Language is a technical constraint, not a preference

Model performance is not uniform across languages, and the gap matters most for exactly the operational tasks a mid-market firm wants to automate. A system that handles English customer correspondence well may perform noticeably worse in Bulgarian, Romanian, Hungarian or Slovak — on entity extraction, on domain terminology, on the handling of inflected forms, and on distinguishing formal from informal register in customer-facing text.

The practical consequence is that vendor benchmarks do not transfer. A published accuracy figure derived from English-language evaluation says very little about performance on your correspondence, and a demonstration conducted in English says less still. Any evaluation set has to be built in the language of the work, with your own terminology, abbreviations and document conventions.

This also affects the build-or-buy decision. Where a task depends heavily on local-language nuance, a smaller specialist provider with genuine regional data may outperform a larger international one, and is often more willing to negotiate the contract terms that matter. Where the task is language-light — classification of structured records, anomaly detection, forecasting — the international vendor is usually the better bet.

Capability is the binding constraint

The scarce resource in the regional mid-market is rarely budget for software. It is people who can judge whether an output is correct and are senior enough to say no. AI specialists command salaries that look reasonable against Western European benchmarks and unreasonable against local pay structures, which makes a dedicated hire hard to justify for a single use case.

Three routes work better than a premature hire. Develop an existing subject-matter expert — the person who already knows what a correct output looks like is easier to teach evaluation than a technologist is to teach the domain. Bring in external capability on a defined mandate with an explicit handover, so the knowledge stays after the engagement. Or join a sandbox or standardisation process where the learning is subsidised. What does not work is delegating judgement to the vendor whose system is being judged.

The vendor asymmetry

A mid-market buyer negotiating with a large software provider has limited leverage over contract terms, model changes and data handling. This is a structural disadvantage rather than a negotiating failure, and it should shape which risks the organisation is willing to take.

Concentrate the limited leverage where it matters: notice of model changes, the ability to reproduce a prior decision, clarity on whether your data trains the provider’s models, data location, and an exit path that returns your data in a usable form. Accept standard terms elsewhere. A firm that cannot obtain these commitments for a high-consequence use case should consider whether that use case belongs with that vendor at all.

For organisations processing personal data in Bulgaria, the Commission for Personal Data Protection: national data protection authority is the supervisory point of contact, and its published guidance is the appropriate reference alongside EU-level material.

What this cannot do

Sequencing does not substitute for capability. If nobody in the organisation can evaluate whether a model output is correct, no amount of staging will produce a safe deployment — that capability has to be bought, borrowed or built before the first use case, not after it. Nor does the sandbox route remove obligations; it provides supervised space to develop, not a waiver.

Stop when the first workflow has no owner who can change the process, when the baseline cannot be measured, when the data required is not lawfully available for the new purpose, or when the only evidence of value comes from the vendor selling the system. A mid-market organisation gets fewer attempts than a large one. The first project should be the one most likely to work, not the one most likely to impress.

Further reading: AI Act Service Desk: Article 57 — regulatory sandboxes; AI Act Service Desk: Article 62 — measures for SMEs; European Commission: European approach to artificial intelligence; European Commission: AI Act; NIST: AI Risk Management Framework.

See how embedded leadership builds AI capability inside a mid-market operating model.