Hael
Book a meeting
EU AI Act · Services

EU AI Act vCISO Services

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 7 min read
Key takeaways
  • Under the AI Act the fractional role is broader than security. It covers classification decisions, oversight design, documentation upkeep and incident reporting.
  • Retainers commonly run £3,000 to £15,000 a month, with most mid-market arrangements between £4,000 and £9,000.
  • The Act has no completion point, which is the strongest argument for an ongoing arrangement rather than a project.
  • Ask what is excluded. Technical file writing, legal opinions and engineering implementation frequently sit outside the retainer.
  • The person needs authority as well as expertise. Human oversight and incident escalation both depend on someone being able to stop a system.

What the role covers under the Act

A virtual CISO, sometimes called a fractional CISO or a fractional AI officer, is senior governance leadership engaged part time. Under the EU AI Act that role is wider than information security, because the Act's duties reach into model documentation, data provenance, human oversight and incident reporting rather than only into access control and infrastructure.

In practice the person owns the AI governance function: the classification register, the technical documentation, the oversight design, the monitoring cadence, and the escalation path when something goes wrong.

AreaWhat the person owns
Classification registerThe decision for each system on provider or deployer status and risk tier, with the reasoning recorded and revisited when systems change
Technical documentationKeeping each Annex IV file current as systems are retrained or repurposed
Human oversightDesigning oversight that a named competent person can actually perform, with the time and authority to intervene
Risk managementRunning the Article 9 process as a continuing cycle rather than a one-off assessment
Data governanceHolding the evidence on training, validation and testing data, and pursuing suppliers where models were bought
Post-market monitoringCollecting performance data after deployment and feeding it back into risk management
Incident readinessKnowing what counts as a serious incident, who reports it, to which authority, and within what window
Board and buyer reportingExplaining the AI governance position to leadership, customers and investors

Why the Act suits an ongoing arrangement

Most compliance frameworks have a finish line. The AI Act does not.

Post-market monitoring runs for the life of every high-risk system. Technical documentation has to describe the system as it currently is, so every material retraining or change of purpose triggers work. New systems arrive through ordinary business growth and need classifying. Serious incidents must be reported within defined windows, which requires someone who already knows the process rather than someone learning it during the incident.

A project engagement produces a good position on the day it ends. Something has to hold it afterwards, and that is the case for a retainer rather than a marketing argument for one.

What it costs

ModelTypical range
Monthly retainer, small company, one or two systems£3,000 to £5,000
Monthly retainer, mid-market, several systems including high risk£4,000 to £9,000
Monthly retainer, complex estate with board reporting and multiple regimes£9,000 to £15,000
Day rate£700 to £1,600
Fixed-fee project, readiness and build£15,000 to £50,000

A full-time head of AI governance or CISO in the UK generally costs £120,000 to £220,000 fully loaded. A retainer at £6,000 a month is £72,000 a year. The comparison is not exact, since a full-time officer is present daily and manages people, but for organisations below a few hundred staff the fractional model usually reflects the real need.

What sits outside the retainer

Ask for exclusions in writing, because this is where proposals differ most.

Annex IV technical file writing is often priced separately at £8,000 to £25,000 per high-risk system, because it is a substantial piece of authorship rather than an oversight task.

Legal opinions on genuinely borderline classifications usually come from a law firm at separate cost.

Engineering implementation, meaning the hours to configure logging, build data lineage or change a pipeline, may or may not be inside the fee. This is the largest source of surprise cost.

Hour caps and overage rates matter. A retainer with a strict cap and a high overage rate becomes expensive in the month an incident happens, which is the month you most need it.

Authority matters as much as expertise

Two of the Act's requirements only work if the person has standing.

Human oversight requires a competent person who can decide not to use a system's output and can intervene or stop it. If the fractional officer designs that oversight but the named overseer cannot override without a committee, the requirement is met on paper only.

Serious incident reporting requires someone able to escalate quickly and, where necessary, take a system out of service. An adviser without that authority can recommend it and then wait.

Agree at the outset what the person can decide alone, what they escalate, and to whom. It takes one conversation and it is the difference between a governance function and a reporting line.

Fractional officer, project consultant, or a hire?

Best suited to
Fractional retainerSystems in production, models retrained regularly, multiple regimes, and no internal owner with capacity
Project consultantA defined outcome, such as classifying the estate and producing the first technical files, with an internal owner taking it on afterwards
Full-time hireA large or high-risk estate, or a regulated firm where the supervisor expects a named accountable individual on the payroll

Many organisations get the best result from a fixed-fee project to build the position, followed by a smaller ongoing arrangement to hold it. That is how our readiness and gap assessment and continuous governance and assurance services are designed to fit together.

What to do next

Decide whether your need is a build or a standing function. Organisations that buy a retainer when they needed a project overspend, and those that buy a project when they needed a retainer lose the position within a year.

Our free AI impact assessment gives a first view, and the EU AI Act service page sets out how we work.

References

FAQ

What does a vCISO do for the EU AI Act?

Owns the classification register, the technical documentation, the human oversight design, the monitoring cadence and the incident escalation path.

How much does a fractional AI governance officer cost?

Commonly £3,000 to £15,000 a month, with most mid-market arrangements between £4,000 and £9,000.

Is technical file writing included?

Often not. Ask explicitly, and expect £8,000 to £25,000 per high-risk system where it is priced separately.

Do we need one if we already have a CISO?

Possibly not, if the CISO has capacity and the AI-specific knowledge. The gap is usually model documentation and data provenance rather than security.

When should we hire full time?

Once the estate is large or high risk enough to need daily attention, or where a regulator expects a named accountable individual employed by the firm.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance. We take companies through the EU AI Act, ISO/IEC 42001, SOC 2 and ISO 27001, and maintain the position afterwards through our continuous assurance service. Every engagement has a named practitioner and an agreed scope, timetable and fee. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on FCA authorisation and compliance since 2013.

This guide is general information and is not legal advice on your particular circumstances.

Free check

See where you stand on EU AI Act, free.

Answer a short set of questions and see what EU AI Act expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether EU AI Act applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to EU AI Act.

Or speak to us about your deadline. Book a meeting.