
The EU AI Act Is a Tax on Europe's Smallest Builders
Brussels is celebrating. Builders should be worried.
Here is the situation as of today, June 18, 2026. Only 35% of Swedish companies are using generative AI. Thirty-five percent. In the United States, companies are racing to meet a possible August 2026 EU AI Act compliance deadline, which means they built first and are lawyering second. Swedish companies are doing the opposite. They are lawyering first and barely building at all.
Meanwhile, Brussels is patting itself on the back for "timeline relief" and "targeted simplification" of the EU AI Act. Bruegel, the EU's own policy think tank, is openly publishing pieces titled "how to fix European Union artificial intelligence regulation". Let that sink in. The Act isn't even fully in force yet, and the people closest to it already admit it's broken.
I run HEIMLANDR.IO, an AI development company in Europe, based in Jönköping, Sweden. We build AI agents, SaaS products, and blockchain systems. I'm writing this because I watch the gap between what Europe regulates and what Europe builds grow wider every quarter. And nobody with a platform seems willing to say the obvious thing: the EU AI Act is not a safety framework. It is a compliance tax. And it falls hardest on the smallest builders in the smallest markets.
The 35% number tells you everything
When I talk to founders and CTOs in Sweden about AI adoption, there's a pattern. The large enterprises, the Ericssons and H&Ms, have compliance teams. They can absorb the cost of interpreting a regulation that changes shape every few months. They have legal departments in Brussels. They will be fine.
The ten-person software development company in Sweden? The two founders in Gothenburg trying to build an AI-powered health screening tool? They are looking at the EU AI Act's risk classification system and doing math. Not the math of "can we build something useful." The math of "can we afford to find out if what we're building is classified as high-risk, and if so, can we afford the conformity assessment, the documentation requirements, the post-market monitoring, and the liability exposure." Most of them are answering no. Not because they can't build. Because they can't afford to find out whether they're allowed to.
That is why only 35% of Swedish companies are using generative AI. It is not a technology problem. It is a confidence problem. And the regulation is making it worse, not better.
The opacity is the feature
A new free tool just had to be launched in Sweden, reported by Dagens Infrastruktur, specifically to help Swedish companies understand EU cybersecurity requirements. Think about that for a second. The regulatory environment has become so opaque that someone had to build a separate product just to make the rules interpretable for the people who are supposed to follow them.
This is not an accident. Regulatory complexity benefits incumbents. It benefits large consultancies. It benefits the compliance-industrial complex that has sprung up around GDPR and is now salivating over the AI Act. Every new prohibition, like the recently added AI nudifier ban with "unclear enforcement," adds another layer of ambiguity. Ambiguity costs money to resolve. Money that a Series A founder in Jönköping does not have.
The irony is painful. The people the EU AI Act claims to protect, European citizens, end up getting served by American and Chinese AI systems built without these constraints, while European builders sit on the sidelines trying to decode 400 pages of regulatory text.
Sweden vs. the world: a tech company in Jönköping looks outward
Let me give you the view from where I sit.
San Francisco doesn't care about the EU AI Act. Not really. American companies are building foundation models, deploying agents at scale, and treating EU compliance as a market-access checkbox. They build the product. Then they hire a European law firm to figure out how to sell it in the EU. The order matters. Product first. Compliance second.
Shenzhen doesn't care at all. Chinese AI companies are deploying systems at a pace that makes Silicon Valley look cautious. They have a domestic market of 1.4 billion people and zero interest in EU regulatory philosophy.
And then there's Sweden. We have world-class engineers. We have a history of building global tech companies out of small cities. Spotify came from Stockholm. Minecraft came from a one-person operation. The Nordic model produces high-trust, high-quality, well-educated builders. And right now, those builders are spending their energy on compliance interpretation instead of product development.
If you want to hire an AI developer in Sweden today, the first question isn't "what can you build." It's "do you understand the regulatory requirements for what we want to build." That is backwards. And it is a competitive disadvantage that compounds every month.
The United States has the Inflation Reduction Act pulling AI investment domestically. China has state-backed AI infrastructure programs. Europe has the AI Act. One of these is not like the others.
What the EU actually exports
There's a phrase I keep coming back to: Europe is a regulation exporter, not a technology exporter. GDPR was the template. The EU defined the rules, and the rest of the world partially adopted them. Brussels called this the "Brussels Effect" and celebrated it. But the Brussels Effect has a dark side. You can export rules to places that build things. Or you can build things yourself. Europe chose door number one.
The AI Act follows the same playbook. Europe will define what responsible AI looks like. American and Chinese companies will spend 0.1% of their revenue on EU compliance and keep shipping. European companies will spend 10-30% of their early-stage capital on the same compliance and ship slower, ship less, or not ship at all.
This is not a theoretical concern. I see it in conversations with founders every week. We build AI solutions at HEIMLANDR, and the number of projects where the first discussion is about regulatory classification instead of user value is growing. That ratio should alarm everyone who cares about European competitiveness.
Where this goes: AGI implications and the regulatory gap
Now let me talk about the next two to five years, because this is where the situation goes from bad to genuinely dangerous for European tech.
We are on a trajectory toward increasingly general AI systems. Whether you call it AGI or something else, the capability curve is steep. The systems being built in 2026 are qualitatively different from what existed in 2023. By 2028, we will likely see AI agents that can autonomously handle complex multi-step workflows, make decisions with minimal human oversight, and operate across domains.
The EU AI Act was written for a world of narrow, classifiable AI applications. A chatbot. A hiring algorithm. A medical imaging tool. You can put those in risk categories. You can write conformity assessments for them. The Act's entire architecture assumes you can draw a box around an AI system and evaluate it.
General-purpose AI systems don't fit in boxes. An AI agent that can write code, analyze data, communicate with customers, and make operational decisions doesn't have a single risk category. It has all of them or none of them, depending on how it's used at any given moment. The regulation is not equipped for this. And the gap between what the Act covers and what AI systems actually do will widen every year.
What happens then? One of two things. Either the EU tries to expand the Act to cover general-purpose systems, which creates even more compliance burden and even more ambiguity. Or the EU effectively cedes the general-purpose AI space to non-European companies, which means the most powerful AI infrastructure in the world gets built and controlled elsewhere.
Both outcomes are bad for European builders. Both are preventable. Neither is being prevented.
For founders in Sweden and across Europe, the practical implication is this: build for global markets from day one. Do not architect your product around EU compliance as the primary constraint. Build something valuable. Make it work. Then handle compliance as a deployment concern, not a design constraint. The Americans figured this out years ago.
What to look at
If you're a CTO or founder trying to stay ahead of this, here are tools and resources worth your time right now:
CISO Assistant (open source GRC platform)
intuitem/ciso-assistant-community on GitHub. Over 4,100 stars. This is a one-stop GRC platform that supports 150+ frameworks including GDPR, NIS2, DORA, ISO 27001, and SOC 2 with automatic control mapping. If you have to deal with compliance, at least don't do it manually. This tool lets you map your controls across multiple frameworks simultaneously, which is exactly what you need when the EU keeps stacking regulations.
Prowler (cloud security automation)
prowler-cloud/prowler. Over 14,000 stars. The most widely used open-source cloud security platform. If you're building AI systems and deploying to cloud infrastructure, Prowler automates security checks and compliance verification across AWS, Azure, and GCP. The less time you spend on manual security audits, the more time you spend building.
Comp (AI-native compliance platform)
trycompai/comp. An open-source alternative to Vanta and Drata. If you're a startup that needs SOC 2 or GDPR compliance but doesn't want to pay enterprise prices for it, this is worth evaluating. The irony of using AI to handle AI compliance is not lost on me, but pragmatism beats philosophical purity.
Baserow (open source no-code platform)
baserow/baserow. Over 5,000 stars. GDPR and SOC 2 compliant, self-hostable. If you need to build internal tools, automations, or lightweight applications without spinning up a full dev team, Baserow lets you move fast while keeping data sovereignty, which matters more than ever when the regulatory ground keeps shifting.
What builders should actually do
I'll make this concrete.
If you're a founder: Do not let compliance paralysis stop you from building. The regulation will change. Your product's value to users will not. Build the MVP. Validate the market. Handle regulatory classification when you have revenue, not before.
If you're a CTO: Automate compliance wherever possible. Use open-source GRC tools. Don't hire a compliance team before you hire your fifth engineer. And build your architecture so you can deploy to different regulatory environments without rewriting your core product.
If you're a policymaker reading this: Talk to builders. Not to lobbying groups, not to large enterprise compliance departments, not to think tanks. Talk to the two-person team in Jönköping that wants to build an AI product and can't figure out if they're allowed to. That's where the damage is happening.
The real question
I keep coming back to a simple test. In 2030, will the most important AI systems in the world have been built in Europe, or will they have been built elsewhere and sold to Europe? Right now, everything points to the second outcome. The EU AI Act is accelerating that trajectory, not reversing it.
Sweden has the talent. The Nordics have the culture of trust, transparency, and technical excellence that should make us ideal builders of responsible AI. But we are channeling those strengths into interpreting regulations instead of shipping products. We are producing compliance documentation instead of code. We are exporting regulatory frameworks instead of technology.
I am not against regulation. I am against regulation that makes it harder for a small team in Sweden to compete with a well-funded team in San Francisco. I am against regulation that claims to protect European citizens but actually protects European incumbents. I am against a regulatory philosophy that treats every new technology as a threat to be contained rather than a capability to be directed.
From Jönköping, I can see the future being built. It's just being built somewhere else. That should bother all of us enough to do something about it.
Fredrik Brunnberg is the CEO of HEIMLANDR.IO, building AI and software solutions from Jönköping, Sweden. This is the daily HEIMLANDR briefing. If you found this valuable, share it with someone who builds things.
VD & Skribent
VD för HEIMLANDR.IO. Punk rock-teknik från Jönköping, Sverige. Bygger AI-system, blockchain-infrastruktur och skriver om vart branschen faktiskt är på väg — inget ekokammare, ingen hype.