09 · Risks & Roadmap
Tax Labs · Strategic Design & Analysis
Confidential · Aug 2026 · v0.1
Risks & Roadmap
The hardest thing to build here is also the strongest thing to own: the legal-and-technical
connectivity surface — the right to act for thousands of taxpayers, bound to machine credentials,
across ~10–27 divergent national tax authorities. It is registry plumbing, not a form. This section is honest about
what can go wrong, argues why the same difficulty compounds into a moat, and lays out a thin-slice roadmap from POC to
scale with a concrete first-90-days plan.
9.1 Risk board
Every material risk, ranked by severity, each paired with a concrete mitigation
(→ in indigo). Regulatory and technical accuracy risks are the ones that can kill a claim; execution risk is the one that kills the company.
RegulatoryAuthorization, licensing & data law — the perimeter that must never be crossed accidentally.
Right to act, per taxpayer × per country. Acting for thousands means holding, renewing and revoking a power-of-attorney (colaboración social / REGAPO in ES, Vollmacht in DE, delega in IT) bound to a machine credential — different in every state, verified at request time. Get it wrong and every downstream filing is void. hi
→ Build a country-agnostic authorization object + credential vault + QES-bound onboarding + lifecycle automation (renew/revoke/audit) once; each country ships as an adapter, not a rebuild.
PSD2 AISP/PISP licensing. Reading accounts (AISP) and moving recovered funds (PISP) are regulated activities requiring authorization + eIDAS QWAC/QSealC certificates; PISP needs full payment-institution authorization. hi
→ Ride a licensed aggregator as agent/distributor (Tink · TrueLayer · GoCardless) — stay outside the licensed perimeter until scale justifies our own AISP. Defer any money-movement build.
GDPR + EU AI Act (HITL). Tax data is sensitive personal data; every LLM/OCR call is processing needing an Art. 28 DPA + SCCs. If any vertical scores creditworthiness it becomes Annex III high-risk, triggering Art. 14 human-oversight duties (live 2 Aug 2026). md
→ EU-hosted inference (Claude on Bedrock Frankfurt / Azure EU) + zero-data-retention + DPAs with every sub-processor; make HITL + confidence scoring + audit trail a built-in control, not a bolt-on.
DORA operational-resilience creep. Not in scope as pure tax-tech — but the moment we become an AISP/PISP or serve a regulated financial-entity customer, DORA's ICT-risk, incident-reporting & resilience-testing duties flow down. md
→ Keep the licensed perimeter with the aggregator; contractually push DORA obligations to them; only assume DORA cost as a deliberate, financed decision at scale.
E-filing per-country variance. No single EU rail: AEAT SOAP+cert (ES), ERiC SDK/DLL not REST (DE), PDP routing (FR), Entratel delega + new API (IT), Digipoort/SBR (NL), KSeF token (PL) — each with its own schema churn (SII 4-day, VeriFactu, ViDA DRR). hi
→ Normalize behind one internal filing API; version adapters; monitor schema releases (ERiC/SII) as an operations discipline; ride Peppol AP providers (Storecove-style) before pursuing own AP status.
ExecutionCan we actually build and run a multi-tenant, multi-country platform with the right people?
Multi-tenant complexity. One platform, many operators, strict data isolation, shared regulatory adapters — a hard system to get right, and unforgiving if it leaks or mixes tenants.
→ Thin-slice: one vertical end-to-end on the platform first, then generalize the tenancy model. Never fan out before the single tenant is production-clean.
Per-country rules maintenance. Deadlines, thresholds, schemas and mandates change constantly (ViDA staging, VeriFactu, KSeF go-live). Rules rot silently.
→ Treat regulatory content as a first-class, versioned, RAG-grounded asset with owned monitoring; amortize the maintenance cost across every vertical and customer.
Hiring domain + tech experts. The rare people who understand both EU tax law and distributed systems are scarce and expensive.
→ Sell the CTO-as-a-service mission to attract them; pair a tax-domain lead with each engineering pod; encode expertise into the platform so it doesn't walk out the door.
MarketWill operators adopt, and can incumbents crush the wedge?
Customers resist equity. The equity component of the CTO-as-a-service model asks founders to give up ownership they may not want to part with.
→ Offer a menu — usage-only, licensing, or equity blend — and reserve equity for cases where we genuinely replace a technical co-founder. Let value, not dogma, set the split.
Incumbents move down-market. Eurowag, VAT IT, Sovos or an AP provider could add platform-style APIs and target the same operators.
→ Own the empty recovery × infrastructure quadrant fast; the authorization moat + data network effect are years of hard-won plumbing an obligation-focused incumbent has no reason to have built.
Slow operator adoption. A B2B2X infra sale is deliberate and technical; the pipeline can be slow to convert.
→ Land a marquee reference vertical (transport / fuel VAT), publish "Powered by Reclaim" proof, and let the ingredient brand pull the next operators in.
TechnicalWhere correctness is existential — a wrong field voids a claim.
Extraction accuracy — a wrong VAT number kills a claim. The 8th-Directive refund portal requires an invoice image above per-item thresholds (€1,000, but €250 for fuel — so nearly every fuel claim is captured), and a single mis-read VAT number, date or amount can void the refund. hi
→ Confidence scoring + HITL review before filing; VIES validation of every VAT number; deterministic cross-checks against structured e-invoice feeds; never auto-file below a confidence gate.
Tenant isolation vs. shared-intelligence pool. The data network effect needs pooled cross-vertical data; GDPR + competitive trust need airtight per-tenant isolation. These pull in opposite directions.
→ Physical isolation for raw tenant data; aggregate/anonymize into the shared model layer only; contract the pooled-intelligence use explicitly; make the boundary auditable.
So what
Two families of risk dominate. The regulatory/authorization surface is hard but buildable once and then owned — it becomes the moat. Extraction accuracy is existential and mitigated structurally by HITL, VIES validation and confidence gates. Everything else is de-risked by the same discipline: thin-slice one vertical end-to-end before fanning out.
9.2 Moats — why this is defensible
Four reinforcing moats. None is a single feature; each is an accumulation that a per-vertical startup cannot justify building and an obligation-focused incumbent has no reason to.
Data network effect
Fraud signals, recovery-success prediction and cross-country benchmarks compound across every vertical and customer — intelligence no single operator could accumulate alone. Each new tenant makes the model better for all. md
Connectivity depth
Hard-won tax-authority integrations (AEAT SOAP+cert, ERiC, SdI/delega, KSeF, Digipoort, PDP) plus licensed banking rails. Normalizing ~10–27 divergent national systems behind one API is multi-year work no vertical can amortize solo. hi
Switching cost — the backbone
Once an operator files on our authorization registry, credential vault and filing rails, we are the load-bearing infrastructure. Ripping it out means rebuilding the very thing they came to us to avoid. md
Expertise
Equal parts platform and domain — people who understand both EU tax law and distributed systems, encoded into RAG-grounded rules and advisory. The CTO-as-a-service layer competitors would have to hire against. lo
9.3 Regulation — moat and tailwind
The same complexity that makes the connectivity surface a moat also throws off a decade of mandated new feeds. Regulation is not a headwind to survive — it is the demand engine and the barrier to entry, at once.
The moat
There is no single EU rail. Each state has its own auth model, filing channel, e-invoicing regime and eID. The
authorization-at-scale problem — holding a legally-binding, QES-bound power-of-attorney per taxpayer per country, bound to a
machine credential and kept reconciled with the authority's own register — is registry infrastructure, not a form. It is the single
biggest reason a per-vertical startup cannot self-build, and the strongest lock-in Tax Labs holds. hi
The tailwind
Three regulatory waves converge in the 2026–2030 window and all cut in our favour: ViDA harmonizes e-invoicing (EN 16931,
intra-EU DRR from 1 Jul 2030); PSD2 → PSD3/PSR matures open banking into standardized, mandatory data interfaces;
eIDAS 2.0 / EUDI Wallet standardizes cross-border identity and QES. Every new mandate is a new machine-readable feed and a
new integration we pre-build once and resell many times. hi
Country connectivity — the surface to own
| Country | Tax-authority channel | Authorization primitive | Live mandate signal |
| Spain ref. | AEAT SOAP web services + cert; Modelo 360 refund | Colaboración social (censo) + REGAPO apoderamiento | SII (2017) · VeriFactu 2026 |
| Germany | ELSTER via ERiC — SDK/DLL, not REST | Vollmacht + org cert (Vollmachtsdatenbank) | B2B receipt mandatory 1 Jan 2025 |
| France | DGFiP + PDP routing → PPF hub | Mandate to a registered PDP + DGFiP delegation | B2B (large/mid) 1 Sep 2026 |
| Italy | SdI clearance (FatturaPA) + new API (Prov. 200918/2026) | Delega to intermediary (Entratel), verified at request | SdI live since 2019 |
| Netherlands | Digipoort / SBR (XBRL), PKIoverheid cert | Intermediary credential + client authorization | B2G mandatory · Peppol strong |
| Poland | KSeF API (FA_VAT XML), token/cert auth | KSeF token/authorization per NIP | KSeF phase 1 — 1 Feb 2026 |
| Portugal | AT — SAF-T (PT) upload or Webservice | Certified software under taxpayer NIF + ATCUD | SAF-T · QR live |
Source: evidence/regulatory-tech.md §1, §3, §7. Confidence: hi for ES/IT/DE/FR mechanisms & dates; md on per-country delegation minutiae outside ES/IT/DE. This is the surface Tax Labs normalizes behind one API — and the reason it can.
So what
Regulation is simultaneously the barrier to entry (nobody wants to build this; we do it once) and the growth engine
(every mandate through 2035 hands us a new feed to pre-integrate and resell). The harder recovery gets to do alone, the more valuable the shared platform becomes.
9.4 Phased roadmap
Thin-slice first: one vertical end-to-end on the platform → prove multi-tenancy →
fan out verticals and countries. Sequence de-risks the platform before it scales. Click each phase to expand.
Phase 1 · POC — one vertical, end-to-end~0–3 months
Prove the full path on a single reference vertical (transport / fuel VAT) for one country (Spain / AEAT):
ingest invoice → extract → VIES-validate → confidence-score → HITL review → file Modelo 360 through a real colaboración-social / apoderamiento authorization.
- One AEAT filing adapter (SOAP + certificate); one authorization object bound to a QES-signed PoA.
- OCR + LLM extraction on EU-hosted inference (Bedrock Frankfurt), ZDR, confidence gate wired in.
- Banking read via a licensed aggregator (agent model) — no money movement yet.
Gate A real refund claim filed and accepted for a real end-taxpayer, with an audit trail. No thin slice ⇒ no MVP.
Phase 2 · MVP — the multi-tenant platform~3–9 months
Generalize the working slice into a real multi-tenant platform with hardened isolation, the
country-agnostic authorization model, and a clean filing API — onboard a first paying operator.
- Tenant isolation (raw data physically separate; aggregate-only into the shared model layer).
- Credential vault + authorization lifecycle (renew/revoke/registry-sync) as a first-class service.
- Second country adapter (Italy delega + new API, or Germany ERiC) proves the adapter pattern.
- RAG-grounded, versioned regulatory rules with owned schema-change monitoring.
Gate Two tenants, two countries, live filings, isolation audited — the platform, not a bespoke build.
Phase 3 · Scale — fan out verticals & countries~9–24 months
With the platform proven, fan out: more verticals (SME VAT, corporate travel, import duty),
more countries (FR PDP, NL Digipoort, PL KSeF), and turn on the data network effect and optional money-movement rails.
- Country adapters as a repeatable playbook; pursue own Peppol AP status as volume justifies.
- Cross-vertical intelligence flywheel live (fraud, success prediction, benchmarks).
- Pre-build ViDA / VeriFactu / KSeF feeds ahead of mandate dates; consider own AISP if economics warrant.
- "Powered by Reclaim" ingredient brand drives operator pull.
Gate Multiple verticals across multiple countries on one backbone; the moat is compounding.
Roadmap at a glance
Timeline →
Q1Q2–Q3Q3–Q4Y2
POC · 1 vertical E2E
POC — fuel VAT · AEAT
MVP · multi-tenant
MVP platform · 2nd country
Authorization core
auth object · vault · lifecycle
Scale · fan out
verticals + countries · network effect
Regulatory feeds
pre-build ViDA · KSeF · VeriFactu
Indigo = POC · navy = MVP/platform · emerald = scale. Bars are directional sequencing, not committed dates.
So what
The roadmap is a de-risking sequence, not a feature list. Prove one vertical end-to-end, then earn multi-tenancy, then fan out.
Each phase converts a risk from §9.1 into a shipped, audited capability — and each country adapter is amortized across every vertical that follows.
9.5 The first 90 days
Concrete opening moves — the shortest path to a real refund filed for a real taxpayer.
- Lock the reference vertical & countryCommit to transport / fuel VAT via Spain (AEAT · Modelo 360) — the deepest-documented rail and the direct endpoint for the flagship vertical. Sign a design-partner operator.
- Secure the right to actRegister for colaboración social (censo de colaboradores) or set up REGAPO apoderamiento; procure the FNMT/qualified certificate; stand up a minimal credential vault to hold it.
- Stand up EU-hosted inferenceDeploy the OCR + LLM extraction pipeline on Bedrock Frankfurt (Claude, EU residency, zero-data-retention); sign DPAs + SCCs with every sub-processor. GDPR-clean from day one.
- Wire the accuracy controlsImplement confidence scoring, VIES VAT-number validation, and the HITL review gate — nothing auto-files below the confidence threshold. This is the AI-Act-ready posture, not a bolt-on.
- Build the one AEAT filing adapterSOAP + client-certificate presentation of Modelo 360, wrapped behind the first version of the internal filing API and a country-agnostic authorization object.
- Integrate a licensed banking aggregatorConsume Tink / TrueLayer / GoCardless as agent for read-only account access — reconcile VAT-paid — with no money movement and no license of our own yet.
- File a real claim, end-to-endIngest → extract → validate → score → HITL → file → track a genuine refund for a real end-taxpayer, with a full audit trail. This is the POC gate.
- Hire the first domain + tech pairRecruit one EU-tax-domain lead and one platform engineer; begin encoding regulatory rules as versioned, RAG-grounded content with owned schema-change monitoring.
So what
Ninety days should end with one thing that nothing else on this page can substitute for: a real tax refund, filed and accepted, for a
real taxpayer, on the platform. Everything after — multi-tenancy, more countries, the network effect — is generalization of a slice that already works.