High risk-systems will need to be registered in a centralized EU database, and also, include post-market monitoring systems. This is a lot of work. So a likely outcome is for large companies to hire specialized firms, or develop in-house teams, to produce such documentation. /15

This reminds me of one of the negative outcomes of GDPR, where institutions migrate to Microsoft services because they provide GDPR certification, instead of overwhelmingly superior Free and Open Source alternatives (w.r.t data protection and everything else).

Microsoft does not really implement any sort of meaningful data protection; they just have the lawyer power to claim compliance. Choosing a Free alternative means that the institution needs to cover the liability itself... The end result is negative for data protection.

