EU AI Act Compliance Services
- Four routes: in-house, law firm, technology platform, or specialist consultancy. Each covers a different part of the problem.
- Law firms are strongest on classification and weakest on building the evidence. Platforms are the reverse.
- The Annex IV technical file is the deliverable that separates advice from delivery. Ask who writes it.
- Cost is driven by system count and how many are high risk, not by company size.
- Whichever route you take, post-market monitoring continues for the life of the system, so decide who owns that before you start.
The four routes
EU AI Act compliance services are bought in four broad ways, and they are not substitutes for one another. Each covers a different part of a problem that runs from a legal classification question at one end to a maintained technical record at the other.
Unlike SOC 2 or ISO certification, no external body issues you a result for most systems. You self-assess, document, and hold the file. That makes the quality of the documentation the entire product, and it changes what you should be buying.
| Route | What it covers well | What it leaves to you | Typical cost |
|---|---|---|---|
| In-house | Knowledge of your own systems, which nobody else has | Regulatory judgement on classification, and writing to a supervisory standard | Internal time only |
| Law firm | Classification, legal opinion, contractual allocation of duties between provider and deployer | Building the technical file, designing controls, running the programme | £400 to £900 an hour |
| Technology platform | Inventory, tracking, workflow, keeping a register current | Deciding classifications, writing documentation, designing human oversight | £8,000 to £40,000 a year |
| Specialist consultancy | The whole programme, from inventory to technical file to monitoring | Operating the controls, which stays with your people | £15,000 to £50,000 |
Where each route runs out
In-house works when someone in your organisation has written for a regulator before. The knowledge gap is rarely about AI. It is about what a supervisory authority accepts as sufficient, which is learned by having been examined rather than by reading the regulation.
A law firm gives you a defensible classification and, where the position is genuinely borderline, a written opinion that is worth having. What it does not usually give you is the Annex IV technical file, the risk management process, or the person chasing your engineers for evidence. Those are engineering and project management tasks billed at legal rates if a firm takes them on at all.
A platform gives you a register, a workflow and a place to keep things current, which is genuinely useful once the underlying decisions are made. It cannot make the classification decision, and it cannot write documentation that describes your specific system. Buying a platform before you have classified your estate tends to produce an organised list of unanswered questions.
A specialist consultancy covers the span, and the variation between firms is mostly in the last workstream. Some deliver a classification register and stop. Some write the technical files and run the programme through to a maintained position. Those are very different products at similar headline prices.
The question that separates any proposal
Ask who writes the Annex IV technical file.
It is the heaviest single deliverable for any high-risk system, it has to describe your actual system rather than a template, and it has to stay current as the system changes. A firm that will write it is selling delivery. A firm that will tell you what should be in it is selling advice. Both are legitimate. They are not the same amount of work for you.
What the Act obliges regardless of route
These do not move whichever supplier you choose.
An inventory of every AI system you provide or use, including AI features inside purchased software.
A classification per system, with the reasoning recorded, covering both your role as provider or deployer and the risk tier.
For high-risk systems: risk management, data governance, technical documentation, automatic logging, instructions for deployers, human oversight, accuracy and robustness, quality management, conformity assessment, EU database registration, and post-market monitoring.
For systems caught by Article 50: disclosure that people are dealing with AI, machine-readable marking of synthetic content, deep fake disclosure, and notice where emotion recognition or biometric categorisation is used. These obligations took effect on 2 August 2026, with Article 50(2) reaching systems already on the market on 2 December 2026.
How to choose
Answer three questions honestly.
Is your classification genuinely uncertain? If several systems sit on the Annex III boundary, a written legal position is worth buying, then have someone else build from it.
Does anyone internal write to a regulatory standard? If yes, buy advice. If no, buy delivery, because the difference between a technical file that satisfies a supervisor and one that does not is not visible until it is tested.
Do your models change often? If so, the monitoring arrangement matters more than the build, and you should choose a route that includes it rather than treating it as an extra.
Our own approach is set out on the EU AI Act service page, and how we scope, build and assure is on the about page.
What to do next
Build a first-pass inventory before requesting proposals. Cost scales with system count and high-risk count, so no supplier can quote sensibly without it, and the exercise usually surfaces systems the leadership team did not know about.
Our free AI impact assessment gives an immediate first view, and our readiness and gap assessment produces the full position for a fixed fee.
References
FAQ
What are EU AI Act compliance services?
The work of inventorying your AI systems, classifying each, assessing the gap, building the documentation and controls, and monitoring for the life of the system.
Do we need a law firm or a consultancy?
A law firm for a genuinely borderline classification or a written opinion. A consultancy to build the technical file and run the programme. Many organisations use both, sequentially.
Will a compliance platform make us AI Act compliant?
It will keep a register current and organise the workflow. It cannot make classification decisions or write documentation describing your specific system.
How much do EU AI Act compliance services cost?
Commonly £15,000 to £50,000 for a first programme, with individual technical files at £8,000 to £25,000. Cost scales with system count, not headcount.
Which obligations are live right now?
Prohibited practices, AI literacy, general purpose AI model duties, and the Article 50 transparency obligations since 2 August 2026.
About Hael
Hael is an advisory firm specialising in AI governance and security compliance. We do the work, hold the deadline and stand behind the evidence, across the EU AI Act, ISO/IEC 42001, SOC 2 and ISO 27001. We are not a certification body and we take no commission from certification bodies or platform vendors. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.
This guide is general information and is not legal advice on your particular circumstances.