The European Commission estimates roughly 50,000 companies will be caught by the Corporate Sustainability Reporting Directive (CSRD) once all applicability waves are in force. Each one must produce a structured sustainability report against the European Sustainability Reporting Standards (ESRS). Each report currently takes 6–18 months of consultant-assisted work to produce.
That is the CSRD wave alone. Add the AI Act documentation obligations (every in-scope AI system deployed in the EU needs model cards, risk assessments, human-oversight procedures), NIS2 incident reports (160,000+ EU entities in-scope), the GDPR ROPA maintenance obligation, and DORA for financial services. Each layer of regulation adds a new report type. Each applies to a different but overlapping set of companies.
The Big 4 capacity wall
Deloitte, EY, PwC, and KPMG are the default suppliers for this work. They are good at it. They are also capacity-constrained in a way regulation doesn’t care about.
A CSRD report engagement for a mid-sized EU company costs roughly €100k–€500k in Big 4 fees and takes two to three consultants six to eighteen months. Scaling linearly to 50,000 companies would require a workforce that does not exist and cannot be hired fast enough. Capacity is the constraint, not talent or willingness.
The result: mid-cap companies are in the queue. Some will miss deadlines. Some will file thin reports that regulators will flag. Some will pay premium rates to boutiques filling in the capacity gap. None of this is a satisfactory outcome for either the companies or the regulators.
Why services-as-software fits this wave
The standards are published. ESRS is explicit. AI Act Annex templates are specified. NIS2 reporting taxonomies are defined. GDPR Article 30 is clear about what a ROPA must contain. This is rubric-bound work, not freeform consulting.
The underlying facts overlap. A company’s CSRD climate disclosure, AI Act model documentation, NIS2 risk-management policy, and GDPR ROPA all draw from the same underlying operational truth — what data you hold, which systems process it, what your controls are, how you manage incidents, what your supply chain looks like. A single source of operational truth can drive all four outputs.
The reports compound. CSRD year 2 builds on year 1. AI Act documentation needs updating as models change. NIS2 requires continuous incident reporting. A system that owns the source-of-truth memory and regenerates reports against updated data structurally outperforms a consulting engagement that builds the report once and walks away.
What ComplyAI does
ComplyAI ingests operational data — ERP sustainability data, AI-system inventory, security-incident logs, data-flow maps — and maps it to the relevant regulatory rubric. Section-specialised drafting agents produce each disclosure. A cross-framework consistency agent ensures the company’s CSRD, AI Act, and NIS2 outputs don’t contradict each other.
Before filing, a reviewer-simulation agent scores each section against the published framework for completeness and alignment. Gaps are flagged. The human reviewer — a sustainability lead internally, or a consultant at a firm using ComplyAI as an engine — concentrates on the sections that need judgment, not on the mechanical drafting.
Two buyer profiles, one engine
For the in-house team: replace the €100k–€500k annual Big 4 engagement with an internal sustainability lead plus the ComplyAI licence. Own your sustainability narrative. Iterate on it as frameworks evolve.
For the compliance consultancy: scale your practice without the linear headcount cost. Serve 5x more clients per associate. Keep the professional judgment, offload the drafting.
"CSRD is not a reporting exercise. It is a recurring, mandatory, structured-document workload at a scale the existing consulting market cannot absorb. The wave is the product."
A word on Greyfork
Blackflake’s sister brand Greyfork handles technical security compliance — pen testing, ISO 27001 control implementation, NIS2 technical measures. ComplyAI handles regulatory document drafting — the written artefacts the regulation requires. Different shape of work, different buyer (CFO/GC vs CISO), complementary positioning within the group.
ComplyAI is planned for Q3–Q4 2026. Frameworks at launch: CSRD (ESRS), AI Act, NIS2, GDPR ROPA. Register interest: enterprise@blackflake.com with the frameworks that apply to you.
— Blackflake Editorial · Blackflake 15 August 2026 · Łódź, Poland