Hael
Book a meeting
EU AI Act · Cost

The budget-friendly ways to get EU AI Act compliance

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 8 min read
Key takeaways
  • The largest avoidable cost is over-classification. Treating a system as high risk when it is not can add tens of thousands in documentation you did not owe.
  • Do the inventory yourself. It costs nothing but time and it is the input every proposal needs.
  • Build once against ISO/IEC 42001 and map to the Act, rather than writing separate documentation for each regime.
  • Reuse GDPR work. Data protection impact assessments and records of processing cover real ground.
  • Do not economise on classification or on human oversight. Those are the two places where saving money creates exposure.

Where the money goes

The cheapest route to EU AI Act compliance is an accurate classification. Most overspend in this area is not paying too much per document; it is writing documentation for systems that never needed it, or discovering late that a system did.

A realistic first-year total for a company with a handful of systems and one or two high-risk ones is £15,000 to £50,000. The decisions below move you towards the lower end without weakening the position.

LineTypical costAvoidable?
Inventory£0 if done internally, £5,000 to £15,000 with helpLargely, by doing it yourself
Classification£5,000 to £15,000No. This is where the saving is created
Gap assessment£5,000 to £20,000Partly, by scoping to systems that matter
Annex IV technical file, per high-risk system£8,000 to £25,000Only by not having systems that need one
Control and process build£10,000 to £30,000Partly, by reusing existing work
Legal opinion on borderline systems£3,000 to £12,000Only where the position is genuinely clear
Ongoing monitoringRetainer or internal timeNo. The duty is continuous

1. Do the inventory yourself

The single largest free saving. Finding every AI system your organisation provides or uses is work only your people can do properly, because they know what is running.

List every system, what it does, who owns it, what data it uses, whether it affects decisions about people, which markets it reaches, and whether it carries your name. Include AI features inside software you already buy, which is where most omissions sit.

An accurate inventory turns every subsequent quote from an estimate into a price.

2. Classify accurately, in both directions

Over-classification is the expensive mistake nobody warns about. Treating a system as high risk when it is not commits you to a technical file, a risk management system, logging, registration and conformity assessment you did not owe.

Under-classification is the exposure. It surfaces when a customer, an investor or an authority asks, and by then the timeline is not yours.

This is the one workstream where paying for judgement saves money rather than costing it. Record the reasoning as well as the conclusion, because a position you cannot explain is one you will pay to redo.

3. Build once, against ISO/IEC 42001

ISO/IEC 42001 is the management system standard for AI, and its structure maps closely onto what the Act's high-risk duties require: policy, roles, risk assessment, impact assessment, controls, internal audit, management review.

Building the management system once and mapping it to the Act turns the documentation requirement into a mapping exercise rather than a writing exercise. It also produces something you can show buyers, which the Act's self-assessed file does not. See our ISO/IEC 42001 service page.

4. Reuse your GDPR work

Data protection impact assessments, records of processing, lawful basis analysis and your data inventory all cover ground the Act asks about. A fundamental rights impact assessment and a data protection impact assessment share a great deal of their content where the system processes personal data.

Map the existing documents across rather than starting a parallel set. The saving is real and it also prevents the two sets drifting apart, which is a cost that arrives later.

5. Push data governance questions to your suppliers early

Article 10 asks how training, validation and testing data was assembled and examined. For a bought model, those answers sit with the vendor.

Ask now, in writing, and check what your contract entitles you to. Discovering at technical file stage that your supplier will not answer is expensive, because you then have to document the limitation and reflect it in your risk assessment under time pressure.

6. Sequence by date, not by system

Not everything is due at once, and treating it as though it were is a way of spending early.

Article 50 transparency obligations took effect on 2 August 2026, so anything customer-facing that interacts with people or generates content needs attention now. Article 50(2) reaches systems already on the market on 2 December 2026, alongside the new prohibitions on AI generating non-consensual intimate imagery and child sexual abuse material. High-risk obligations arrive on 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for AI embedded in Annex I regulated products.

Do the live obligations first, then the classification, then the technical files in date order.

7. Price per system, not per programme

Ask suppliers to itemise by system, with high-risk systems priced separately. That is how the work actually scales, it makes proposals comparable, and it lets you stage the spend across financial years.

A single programme number quoted before anyone has seen your inventory is an estimate that will move.

8. Decide who owns it internally

The most expensive arrangement is the implicit one, where AI governance belongs to everybody and nobody. Tasks wait, the dates do not, and the final stretch gets bought at premium rates.

Naming an internal owner with protected hours costs nothing and is the highest-return decision available.

What not to economise on

Classification. Getting it wrong is expensive in both directions, and it is the input to everything else.

Human oversight. Designing it as a sentence rather than a capability leaves you exposed on the requirement most likely to matter when something goes wrong.

Monitoring. Post-market monitoring is a continuing duty. A position that lapses has to be rebuilt, which costs more than maintaining it.

What to do next

Do the inventory this month. It is free, it is the input everything else needs, and it usually surfaces systems nobody had recorded.

Our free AI impact assessment gives an immediate first view, and our readiness and gap assessment produces the full position for a fixed fee.

References

FAQ

What is the cheapest way to comply with the EU AI Act?

An accurate classification, an inventory done in-house, documentation built once against ISO/IEC 42001, and GDPR work reused rather than duplicated.

Can we wait until 2027?

No. Article 50 transparency duties are live now, new prohibitions arrive on 2 December 2026, and classification takes weeks to months.

Is ISO/IEC 42001 worth the extra cost?

For any organisation that will hold high-risk systems, usually yes. It builds the substance the Act assumes and produces a certificate you can show buyers.

How much does a technical file cost?

Commonly £8,000 to £25,000 per high-risk system, which is why accurate classification is the largest saving available.

Should we buy a compliance platform?

Only after classification. A platform organises decisions; it does not make them, and buying one first tends to produce an organised list of unanswered questions.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance. Every engagement has a named practitioner and an agreed scope, timetable and fee, and we price by system rather than by programme. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.

This guide is general information and is not legal advice on your particular circumstances.

Free check

See where you stand on EU AI Act, free.

Answer a short set of questions and see what EU AI Act expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether EU AI Act applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to EU AI Act.

Or speak to us about your deadline. Book a meeting.