09 · Risks & Roadmap
Tax Labs · Strategic Design & Analysis
Confidential · Aug 2026 · v0.1

Risks & Roadmap

The hardest thing to build here is also the strongest thing to own: the legal-and-technical connectivity surface — the right to act for thousands of taxpayers, bound to machine credentials, across ~10–27 divergent national tax authorities. It is registry plumbing, not a form. This section is honest about what can go wrong, argues why the same difficulty compounds into a moat, and lays out a thin-slice roadmap from POC to scale with a concrete first-90-days plan.

9.1 Risk board

Every material risk, ranked by severity, each paired with a concrete mitigation (→ in indigo). Regulatory and technical accuracy risks are the ones that can kill a claim; execution risk is the one that kills the company.

RegulatoryAuthorization, licensing & data law — the perimeter that must never be crossed accidentally.
Right to act, per taxpayer × per country. Acting for thousands means holding, renewing and revoking a power-of-attorney (colaboración social / REGAPO in ES, Vollmacht in DE, delega in IT) bound to a machine credential — different in every state, verified at request time. Get it wrong and every downstream filing is void. hi → Build a country-agnostic authorization object + credential vault + QES-bound onboarding + lifecycle automation (renew/revoke/audit) once; each country ships as an adapter, not a rebuild.
PSD2 AISP/PISP licensing. Reading accounts (AISP) and moving recovered funds (PISP) are regulated activities requiring authorization + eIDAS QWAC/QSealC certificates; PISP needs full payment-institution authorization. hi → Ride a licensed aggregator as agent/distributor (Tink · TrueLayer · GoCardless) — stay outside the licensed perimeter until scale justifies our own AISP. Defer any money-movement build.
GDPR + EU AI Act (HITL). Tax data is sensitive personal data; every LLM/OCR call is processing needing an Art. 28 DPA + SCCs. If any vertical scores creditworthiness it becomes Annex III high-risk, triggering Art. 14 human-oversight duties (live 2 Aug 2026). md → EU-hosted inference (Claude on Bedrock Frankfurt / Azure EU) + zero-data-retention + DPAs with every sub-processor; make HITL + confidence scoring + audit trail a built-in control, not a bolt-on.
DORA operational-resilience creep. Not in scope as pure tax-tech — but the moment we become an AISP/PISP or serve a regulated financial-entity customer, DORA's ICT-risk, incident-reporting & resilience-testing duties flow down. md → Keep the licensed perimeter with the aggregator; contractually push DORA obligations to them; only assume DORA cost as a deliberate, financed decision at scale.
E-filing per-country variance. No single EU rail: AEAT SOAP+cert (ES), ERiC SDK/DLL not REST (DE), PDP routing (FR), Entratel delega + new API (IT), Digipoort/SBR (NL), KSeF token (PL) — each with its own schema churn (SII 4-day, VeriFactu, ViDA DRR). hi → Normalize behind one internal filing API; version adapters; monitor schema releases (ERiC/SII) as an operations discipline; ride Peppol AP providers (Storecove-style) before pursuing own AP status.
ExecutionCan we actually build and run a multi-tenant, multi-country platform with the right people?
Multi-tenant complexity. One platform, many operators, strict data isolation, shared regulatory adapters — a hard system to get right, and unforgiving if it leaks or mixes tenants. → Thin-slice: one vertical end-to-end on the platform first, then generalize the tenancy model. Never fan out before the single tenant is production-clean.
Per-country rules maintenance. Deadlines, thresholds, schemas and mandates change constantly (ViDA staging, VeriFactu, KSeF go-live). Rules rot silently. → Treat regulatory content as a first-class, versioned, RAG-grounded asset with owned monitoring; amortize the maintenance cost across every vertical and customer.
Hiring domain + tech experts. The rare people who understand both EU tax law and distributed systems are scarce and expensive. → Sell the CTO-as-a-service mission to attract them; pair a tax-domain lead with each engineering pod; encode expertise into the platform so it doesn't walk out the door.
MarketWill operators adopt, and can incumbents crush the wedge?
Customers resist equity. The equity component of the CTO-as-a-service model asks founders to give up ownership they may not want to part with. → Offer a menu — usage-only, licensing, or equity blend — and reserve equity for cases where we genuinely replace a technical co-founder. Let value, not dogma, set the split.
Incumbents move down-market. Eurowag, VAT IT, Sovos or an AP provider could add platform-style APIs and target the same operators. → Own the empty recovery × infrastructure quadrant fast; the authorization moat + data network effect are years of hard-won plumbing an obligation-focused incumbent has no reason to have built.
Slow operator adoption. A B2B2X infra sale is deliberate and technical; the pipeline can be slow to convert. → Land a marquee reference vertical (transport / fuel VAT), publish "Powered by Reclaim" proof, and let the ingredient brand pull the next operators in.
TechnicalWhere correctness is existential — a wrong field voids a claim.
Extraction accuracy — a wrong VAT number kills a claim. The 8th-Directive refund portal requires an invoice image above per-item thresholds (€1,000, but €250 for fuel — so nearly every fuel claim is captured), and a single mis-read VAT number, date or amount can void the refund. hi → Confidence scoring + HITL review before filing; VIES validation of every VAT number; deterministic cross-checks against structured e-invoice feeds; never auto-file below a confidence gate.
Tenant isolation vs. shared-intelligence pool. The data network effect needs pooled cross-vertical data; GDPR + competitive trust need airtight per-tenant isolation. These pull in opposite directions. → Physical isolation for raw tenant data; aggregate/anonymize into the shared model layer only; contract the pooled-intelligence use explicitly; make the boundary auditable.
So what

Two families of risk dominate. The regulatory/authorization surface is hard but buildable once and then owned — it becomes the moat. Extraction accuracy is existential and mitigated structurally by HITL, VIES validation and confidence gates. Everything else is de-risked by the same discipline: thin-slice one vertical end-to-end before fanning out.

9.2 Moats — why this is defensible

Four reinforcing moats. None is a single feature; each is an accumulation that a per-vertical startup cannot justify building and an obligation-focused incumbent has no reason to.

Data network effect

Fraud signals, recovery-success prediction and cross-country benchmarks compound across every vertical and customer — intelligence no single operator could accumulate alone. Each new tenant makes the model better for all. md

Connectivity depth

Hard-won tax-authority integrations (AEAT SOAP+cert, ERiC, SdI/delega, KSeF, Digipoort, PDP) plus licensed banking rails. Normalizing ~10–27 divergent national systems behind one API is multi-year work no vertical can amortize solo. hi

Switching cost — the backbone

Once an operator files on our authorization registry, credential vault and filing rails, we are the load-bearing infrastructure. Ripping it out means rebuilding the very thing they came to us to avoid. md

Expertise

Equal parts platform and domain — people who understand both EU tax law and distributed systems, encoded into RAG-grounded rules and advisory. The CTO-as-a-service layer competitors would have to hire against. lo

9.3 Regulation — moat and tailwind

The same complexity that makes the connectivity surface a moat also throws off a decade of mandated new feeds. Regulation is not a headwind to survive — it is the demand engine and the barrier to entry, at once.

The moat

There is no single EU rail. Each state has its own auth model, filing channel, e-invoicing regime and eID. The authorization-at-scale problem — holding a legally-binding, QES-bound power-of-attorney per taxpayer per country, bound to a machine credential and kept reconciled with the authority's own register — is registry infrastructure, not a form. It is the single biggest reason a per-vertical startup cannot self-build, and the strongest lock-in Tax Labs holds. hi

The tailwind

Three regulatory waves converge in the 2026–2030 window and all cut in our favour: ViDA harmonizes e-invoicing (EN 16931, intra-EU DRR from 1 Jul 2030); PSD2 → PSD3/PSR matures open banking into standardized, mandatory data interfaces; eIDAS 2.0 / EUDI Wallet standardizes cross-border identity and QES. Every new mandate is a new machine-readable feed and a new integration we pre-build once and resell many times. hi

Country connectivity — the surface to own

CountryTax-authority channelAuthorization primitiveLive mandate signal
Spain ref.AEAT SOAP web services + cert; Modelo 360 refundColaboración social (censo) + REGAPO apoderamientoSII (2017) · VeriFactu 2026
GermanyELSTER via ERiC — SDK/DLL, not RESTVollmacht + org cert (Vollmachtsdatenbank)B2B receipt mandatory 1 Jan 2025
FranceDGFiP + PDP routing → PPF hubMandate to a registered PDP + DGFiP delegationB2B (large/mid) 1 Sep 2026
ItalySdI clearance (FatturaPA) + new API (Prov. 200918/2026)Delega to intermediary (Entratel), verified at requestSdI live since 2019
NetherlandsDigipoort / SBR (XBRL), PKIoverheid certIntermediary credential + client authorizationB2G mandatory · Peppol strong
PolandKSeF API (FA_VAT XML), token/cert authKSeF token/authorization per NIPKSeF phase 1 — 1 Feb 2026
PortugalAT — SAF-T (PT) upload or WebserviceCertified software under taxpayer NIF + ATCUDSAF-T · QR live

Source: evidence/regulatory-tech.md §1, §3, §7. Confidence: hi for ES/IT/DE/FR mechanisms & dates; md on per-country delegation minutiae outside ES/IT/DE. This is the surface Tax Labs normalizes behind one API — and the reason it can.

So what

Regulation is simultaneously the barrier to entry (nobody wants to build this; we do it once) and the growth engine (every mandate through 2035 hands us a new feed to pre-integrate and resell). The harder recovery gets to do alone, the more valuable the shared platform becomes.

9.4 Phased roadmap

Thin-slice first: one vertical end-to-end on the platform → prove multi-tenancy → fan out verticals and countries. Sequence de-risks the platform before it scales. Click each phase to expand.

Phase 1 · POC — one vertical, end-to-end~0–3 months

Prove the full path on a single reference vertical (transport / fuel VAT) for one country (Spain / AEAT): ingest invoice → extract → VIES-validate → confidence-score → HITL review → file Modelo 360 through a real colaboración-social / apoderamiento authorization.

  • One AEAT filing adapter (SOAP + certificate); one authorization object bound to a QES-signed PoA.
  • OCR + LLM extraction on EU-hosted inference (Bedrock Frankfurt), ZDR, confidence gate wired in.
  • Banking read via a licensed aggregator (agent model) — no money movement yet.
Gate A real refund claim filed and accepted for a real end-taxpayer, with an audit trail. No thin slice ⇒ no MVP.
Phase 2 · MVP — the multi-tenant platform~3–9 months

Generalize the working slice into a real multi-tenant platform with hardened isolation, the country-agnostic authorization model, and a clean filing API — onboard a first paying operator.

  • Tenant isolation (raw data physically separate; aggregate-only into the shared model layer).
  • Credential vault + authorization lifecycle (renew/revoke/registry-sync) as a first-class service.
  • Second country adapter (Italy delega + new API, or Germany ERiC) proves the adapter pattern.
  • RAG-grounded, versioned regulatory rules with owned schema-change monitoring.
Gate Two tenants, two countries, live filings, isolation audited — the platform, not a bespoke build.
Phase 3 · Scale — fan out verticals & countries~9–24 months

With the platform proven, fan out: more verticals (SME VAT, corporate travel, import duty), more countries (FR PDP, NL Digipoort, PL KSeF), and turn on the data network effect and optional money-movement rails.

  • Country adapters as a repeatable playbook; pursue own Peppol AP status as volume justifies.
  • Cross-vertical intelligence flywheel live (fraud, success prediction, benchmarks).
  • Pre-build ViDA / VeriFactu / KSeF feeds ahead of mandate dates; consider own AISP if economics warrant.
  • "Powered by Reclaim" ingredient brand drives operator pull.
Gate Multiple verticals across multiple countries on one backbone; the moat is compounding.

Roadmap at a glance

Timeline →
Q1Q2–Q3Q3–Q4Y2
POC · 1 vertical E2E
POC — fuel VAT · AEAT
MVP · multi-tenant
MVP platform · 2nd country
Authorization core
auth object · vault · lifecycle
Scale · fan out
verticals + countries · network effect
Regulatory feeds
pre-build ViDA · KSeF · VeriFactu

Indigo = POC · navy = MVP/platform · emerald = scale. Bars are directional sequencing, not committed dates.

So what

The roadmap is a de-risking sequence, not a feature list. Prove one vertical end-to-end, then earn multi-tenancy, then fan out. Each phase converts a risk from §9.1 into a shipped, audited capability — and each country adapter is amortized across every vertical that follows.

9.5 The first 90 days

Concrete opening moves — the shortest path to a real refund filed for a real taxpayer.

  1. Lock the reference vertical & countryCommit to transport / fuel VAT via Spain (AEAT · Modelo 360) — the deepest-documented rail and the direct endpoint for the flagship vertical. Sign a design-partner operator.
  2. Secure the right to actRegister for colaboración social (censo de colaboradores) or set up REGAPO apoderamiento; procure the FNMT/qualified certificate; stand up a minimal credential vault to hold it.
  3. Stand up EU-hosted inferenceDeploy the OCR + LLM extraction pipeline on Bedrock Frankfurt (Claude, EU residency, zero-data-retention); sign DPAs + SCCs with every sub-processor. GDPR-clean from day one.
  4. Wire the accuracy controlsImplement confidence scoring, VIES VAT-number validation, and the HITL review gate — nothing auto-files below the confidence threshold. This is the AI-Act-ready posture, not a bolt-on.
  5. Build the one AEAT filing adapterSOAP + client-certificate presentation of Modelo 360, wrapped behind the first version of the internal filing API and a country-agnostic authorization object.
  6. Integrate a licensed banking aggregatorConsume Tink / TrueLayer / GoCardless as agent for read-only account access — reconcile VAT-paid — with no money movement and no license of our own yet.
  7. File a real claim, end-to-endIngest → extract → validate → score → HITL → file → track a genuine refund for a real end-taxpayer, with a full audit trail. This is the POC gate.
  8. Hire the first domain + tech pairRecruit one EU-tax-domain lead and one platform engineer; begin encoding regulatory rules as versioned, RAG-grounded content with owned schema-change monitoring.
So what

Ninety days should end with one thing that nothing else on this page can substitute for: a real tax refund, filed and accepted, for a real taxpayer, on the platform. Everything after — multi-tenancy, more countries, the network effect — is generalization of a slice that already works.

Sources: AEAT — Colaboración social · EC — VAT refunds (Dir. 2008/9/EC) · Sovos — ViDA timeline · TrueLayer — PSD2 agents & the data chain · EU AI Act — Art. 14 (human oversight) · DORA — in effect (Jan 2025) · ELSTER / ERiC (erica) · EU e-invoicing mandate matrix · evidence/regulatory-tech.md (internal), Aug 2026 — the primary source for this section.
Previous← 8 · Go-to-Market
Tax Labs · Confidential09 · Risks & Roadmap