EU AI Act Compliance Consultants
- Consultants come from three backgrounds: legal and regulatory, AI and data science, and management systems. A programme needs all three capabilities.
- The Act is young, so nobody has fifteen years of AI Act experience. Judge on adjacent regulatory experience and on written work.
- Ask to see a redacted Annex IV technical file. It is the fastest way to assess capability.
- Day rates commonly run £700 to £1,600. Fixed fees per phase are usually better for a first engagement.
- The strongest signal is a consultant who tells you when a classification is genuinely arguable rather than asserting certainty.
Where they come from
EU AI Act compliance consultants help organisations find their AI systems, classify them, meet the duties that classification attaches, and hold documentation that would survive scrutiny.
This guide is about the people rather than the services. Where they come from, what to look for, and how to test capability in a market where nobody can point to a long track record because the regulation is new.
Legal and regulatory. Practitioners from regulatory practice or supervisory bodies. Their strength is classification judgement and knowing what a supervisor accepts as sufficient, which is the skill the Act's self-assessed model depends on most. Their limit tends to be technical depth on how models are built and monitored. This is our own background, described on the about page.
AI and data science. Practitioners who have built and operated machine learning systems. Their strength is understanding what the technical requirements actually mean in a real pipeline, particularly data governance, accuracy, robustness and logging. Their limit tends to be writing to a regulatory standard, which is a distinct discipline.
Management systems. Practitioners from ISO implementation and internal audit. Their strength is building a system that runs and produces evidence repeatedly, which maps closely to what the Act's quality management and post-market monitoring duties require. Their limit tends to be the legal classification call.
None is inherently better. A programme needs all three capabilities, and the question is whether the firm brings them or expects you to.
Judging experience in a young field
The Act entered into force in August 2024 and its largest obligations do not apply until December 2027. Nobody has a decade of AI Act delivery, and a firm claiming otherwise is describing something else.
Three things transfer meaningfully.
Adjacent regulatory experience. Having taken organisations through authorisation, supervision or examination under any regime teaches what evidence a supervisor accepts. That judgement is the scarce ingredient and it is framework-independent.
ISO/IEC 42001 delivery. The standard builds the AI management system the Act's high-risk duties assume. Practitioners who have implemented it have done most of the substantive work under a different label.
Model documentation. Anyone who has written model risk documentation for a financial regulator, or medical device technical files, has produced something structurally close to an Annex IV file.
What to look for
They ask what your systems actually do before discussing tiers. Classification cannot be done from a product name.
They check whether you have become a provider without noticing, by putting your name on a third-party system, modifying it substantially, or using it for an unintended purpose. This is the single most common misclassification and a consultant who does not raise it is not looking properly.
They record reasoning, not just conclusions. A classification register with a decision and no basis is not defensible when someone asks a year later.
They tell you when something is genuinely arguable. If your estate is anything beyond simple and your adviser has never said "this one is borderline, and here is the position I would take and why", the analysis is thinner than it appears.
They design human oversight around a named person with the time and the authority to intervene, rather than as a sentence in a policy.
They know what did not change. The deferral moved the high-risk dates. It did not move Article 50, and it expanded the prohibited practices list rather than relaxing it.
The single best test
Ask to see a redacted Annex IV technical file the firm has written.
It takes ten minutes to assess and it tells you almost everything: whether they write to a supervisory standard, whether the document describes a real system or a template, whether the data governance section engages with actual pipelines, and whether human oversight is described as something a person does or as an aspiration.
A firm that has never produced one is selling advice rather than delivery, which is fine if that is what you are buying.
How they charge
| Model | Typical range |
|---|---|
| Fixed fee, inventory and classification | £5,000 to £15,000 |
| Fixed fee, full readiness and build | £15,000 to £50,000 |
| Annex IV technical file, per high-risk system | £8,000 to £25,000 |
| Day rate | £700 to £1,600 |
| Retainer for ongoing monitoring | Scope dependent |
Per-phase fixed fees usually work better than a single programme number, because the build cannot be priced sensibly until classification is complete. A firm quoting one figure before seeing your inventory is estimating blind.
What no consultant can do
Certify you. For most systems the Act is self-assessed, and where third-party conformity assessment applies it comes from a notified body, not from your adviser.
Make a prohibited use compliant. There is no compliant version.
Operate your human oversight. The Act requires a competent person with authority to intervene, and that person works for you.
Guarantee an outcome. Anyone offering a guarantee under a self-assessed regime is describing a commercial promise rather than a regulatory one.
What to do next
Work out which of the three capabilities you are short of before shortlisting. If your data science team is strong but nobody writes for regulators, you need the regulatory skill set. If your legal position is clear but nothing is built, you need delivery.
Our free AI impact assessment gives a first view, and the EU AI Act service page sets out how we run the programme.
References
FAQ
What qualifications should an EU AI Act consultant have?
There is no required licence. Adjacent regulatory experience, ISO/IEC 42001 delivery and model documentation experience all transfer. Written work matters more than certificates.
How do I test a consultant's capability?
Ask to see a redacted Annex IV technical file they have written, and ask how they would classify one of your borderline systems and why.
How much does an EU AI Act consultant cost?
Day rates commonly £700 to £1,600. Fixed fees for a first programme commonly £15,000 to £50,000, with technical files at £8,000 to £25,000 each.
Can a consultant certify us?
No. Most systems are self-assessed. Where third-party conformity assessment applies, it comes from a notified body.
Do we need a lawyer as well?
For a genuinely borderline classification, or where provider and deployer duties need allocating contractually, a written legal position is worth having alongside the delivery work.
About Hael
Hael is an advisory firm specialising in AI governance and security compliance, built on fifteen years of regulatory practice advising firms through authorisation, supervision and examination. Every engagement has a named practitioner and an agreed scope, timetable and fee. We are not a certification body and we take no commission from certification bodies or platform vendors. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.
This guide is general information and is not legal advice on your particular circumstances.