The budget-friendly ways to get EU AI Act compliance
- The largest avoidable cost is over-classification. Treating a system as high risk when it is not can add tens of thousands in documentation you did not owe.
- Do the inventory yourself. It costs nothing but time and it is the input every proposal needs.
- Build once against ISO/IEC 42001 and map to the Act, rather than writing separate documentation for each regime.
- Reuse GDPR work. Data protection impact assessments and records of processing cover real ground.
- Do not economise on classification or on human oversight. Those are the two places where saving money creates exposure.
Where the money goes
The cheapest route to EU AI Act compliance is an accurate classification. Most overspend in this area is not paying too much per document; it is writing documentation for systems that never needed it, or discovering late that a system did.
A realistic first-year total for a company with a handful of systems and one or two high-risk ones is £15,000 to £50,000. The decisions below move you towards the lower end without weakening the position.
| Line | Typical cost | Avoidable? |
|---|---|---|
| Inventory | £0 if done internally, £5,000 to £15,000 with help | Largely, by doing it yourself |
| Classification | £5,000 to £15,000 | No. This is where the saving is created |
| Gap assessment | £5,000 to £20,000 | Partly, by scoping to systems that matter |
| Annex IV technical file, per high-risk system | £8,000 to £25,000 | Only by not having systems that need one |
| Control and process build | £10,000 to £30,000 | Partly, by reusing existing work |
| Legal opinion on borderline systems | £3,000 to £12,000 | Only where the position is genuinely clear |
| Ongoing monitoring | Retainer or internal time | No. The duty is continuous |
1. Do the inventory yourself
The single largest free saving. Finding every AI system your organisation provides or uses is work only your people can do properly, because they know what is running.
List every system, what it does, who owns it, what data it uses, whether it affects decisions about people, which markets it reaches, and whether it carries your name. Include AI features inside software you already buy, which is where most omissions sit.
An accurate inventory turns every subsequent quote from an estimate into a price.
2. Classify accurately, in both directions
Over-classification is the expensive mistake nobody warns about. Treating a system as high risk when it is not commits you to a technical file, a risk management system, logging, registration and conformity assessment you did not owe.
Under-classification is the exposure. It surfaces when a customer, an investor or an authority asks, and by then the timeline is not yours.
This is the one workstream where paying for judgement saves money rather than costing it. Record the reasoning as well as the conclusion, because a position you cannot explain is one you will pay to redo.
3. Build once, against ISO/IEC 42001
ISO/IEC 42001 is the management system standard for AI, and its structure maps closely onto what the Act's high-risk duties require: policy, roles, risk assessment, impact assessment, controls, internal audit, management review.
Building the management system once and mapping it to the Act turns the documentation requirement into a mapping exercise rather than a writing exercise. It also produces something you can show buyers, which the Act's self-assessed file does not. See our ISO/IEC 42001 service page.
4. Reuse your GDPR work
Data protection impact assessments, records of processing, lawful basis analysis and your data inventory all cover ground the Act asks about. A fundamental rights impact assessment and a data protection impact assessment share a great deal of their content where the system processes personal data.
Map the existing documents across rather than starting a parallel set. The saving is real and it also prevents the two sets drifting apart, which is a cost that arrives later.
5. Push data governance questions to your suppliers early
Article 10 asks how training, validation and testing data was assembled and examined. For a bought model, those answers sit with the vendor.
Ask now, in writing, and check what your contract entitles you to. Discovering at technical file stage that your supplier will not answer is expensive, because you then have to document the limitation and reflect it in your risk assessment under time pressure.
6. Sequence by date, not by system
Not everything is due at once, and treating it as though it were is a way of spending early.
Article 50 transparency obligations took effect on 2 August 2026, so anything customer-facing that interacts with people or generates content needs attention now. Article 50(2) reaches systems already on the market on 2 December 2026, alongside the new prohibitions on AI generating non-consensual intimate imagery and child sexual abuse material. High-risk obligations arrive on 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for AI embedded in Annex I regulated products.
Do the live obligations first, then the classification, then the technical files in date order.
7. Price per system, not per programme
Ask suppliers to itemise by system, with high-risk systems priced separately. That is how the work actually scales, it makes proposals comparable, and it lets you stage the spend across financial years.
A single programme number quoted before anyone has seen your inventory is an estimate that will move.
8. Decide who owns it internally
The most expensive arrangement is the implicit one, where AI governance belongs to everybody and nobody. Tasks wait, the dates do not, and the final stretch gets bought at premium rates.
Naming an internal owner with protected hours costs nothing and is the highest-return decision available.
What not to economise on
Classification. Getting it wrong is expensive in both directions, and it is the input to everything else.
Human oversight. Designing it as a sentence rather than a capability leaves you exposed on the requirement most likely to matter when something goes wrong.
Monitoring. Post-market monitoring is a continuing duty. A position that lapses has to be rebuilt, which costs more than maintaining it.
What to do next
Do the inventory this month. It is free, it is the input everything else needs, and it usually surfaces systems nobody had recorded.
Our free AI impact assessment gives an immediate first view, and our readiness and gap assessment produces the full position for a fixed fee.
References
FAQ
What is the cheapest way to comply with the EU AI Act?
An accurate classification, an inventory done in-house, documentation built once against ISO/IEC 42001, and GDPR work reused rather than duplicated.
Can we wait until 2027?
No. Article 50 transparency duties are live now, new prohibitions arrive on 2 December 2026, and classification takes weeks to months.
Is ISO/IEC 42001 worth the extra cost?
For any organisation that will hold high-risk systems, usually yes. It builds the substance the Act assumes and produces a certificate you can show buyers.
How much does a technical file cost?
Commonly £8,000 to £25,000 per high-risk system, which is why accurate classification is the largest saving available.
Should we buy a compliance platform?
Only after classification. A platform organises decisions; it does not make them, and buying one first tends to produce an organised list of unanswered questions.
About Hael
Hael is an advisory firm specialising in AI governance and security compliance. Every engagement has a named practitioner and an agreed scope, timetable and fee, and we price by system rather than by programme. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.
This guide is general information and is not legal advice on your particular circumstances.