EU AI Act compliance cost: what it actually costs in 2026
How much does EU AI Act compliance cost?
For most small and mid-sized companies in 2026, far less than the internet says — because most of them are not building high-risk AI systems, and the obligations that landed on 2 August 2026 are transparency duties, not quality-management systems. The European Commission's own estimate for the expensive case — a genuinely high-risk system — was €6,000 to €7,000 in compliance costs on an average high-risk AI system costing around €170,000, plus €3,000 to €7,500 in verification costs. The five- and six-figure numbers circulating online describe a company building its first high-risk product with no existing quality system at all. That is a real scenario. It is not the median one.
The rest of this guide separates the cost pictures — because "EU AI Act compliance cost" is not one number, and anyone quoting you one without asking what you build is guessing.
What did the European Commission actually estimate?
The figures come from the explanatory memorandum accompanying the Commission's original AI Act proposal, COM(2021) 206 final:
| Cost item | Commission estimate | Applies to |
|---|---|---|
| Compliance with the high-risk requirements | €6,000–€7,000 per system | Providers of high-risk AI systems |
| Verification / conformity assessment | €3,000–€7,500 | Suppliers of high-risk AI |
| Reference system value | ~€170,000 by 2025 | An "average" high-risk AI system |
Two honest caveats, because a cost guide that hides its own weaknesses is worth nothing. First, these are 2021 estimates expressed in 2025 prices — they predate the final text, the GPAI chapter and the 2026 Omnibus amendments. Second, they are marginal costs: what the Act adds on top of building the system, not the total cost of building it.

Where does the "€400,000 for a small business" figure come from?
This is the most-repeated number in the entire debate, and the researchers whose work it came from say it is wrong.
The chain: the Commission commissioned a supporting study from CEPS (the Centre for European Policy Studies), with ICF and Wavestone. A think-tank paper then reported that "a small business can expect total compliance costs of up to €400,000 for one high-risk AI product requiring a quality management system." Headlines followed — including that Europe's proposed AI law could cost its economy $36 billion.
CEPS published a public correction. Their actual estimate was that setting up an entirely new Quality Management System could cost €193,000–€330,000, with roughly €71,400 in annual maintenance. The €400,000 figure appears to be those two numbers added together.

Their correction also makes three points that matter more than the arithmetic:
- The QMS cost is only fully incurred if the company has no quality management system in the first place. Once it exists, later products cost far less.
- A QMS is required only for providers of high-risk AI systems — not for every company using AI.
- The 17%-of-development-cost figure that produced the "€30 billion" headline applies only to companies meeting none of the requirements as business-as-usual practice. Most companies already do some of them.
EU AI Act compliance cost is not a price tag on using AI. It is the marginal cost of proving that one specific high-risk system does what you say it does — and it collapses toward zero for every system that is not high-risk.
Am I even in the expensive category?
Probably not, and this is the single biggest cost variable. The Commission expected high-risk systems to be 5–15% of all AI systems; the CEPS study modelled 10%. The Act does not classify whole sectors as high-risk — only specific applications inside them, listed in Annex III. Using AI in education is not high-risk; using AI to score students or gate admission is.
So before you budget anything, answer one question: are you a provider of a system on Annex III, a provider of a GPAI model, or neither? If neither, your 2026 obligations are transparency obligations, and the cost conversation changes completely. Our guide to what actually applies from August 2026 walks through that split in detail.
What does compliance cost if my system is not high-risk?
For most SaaS companies shipping AI features to EU users, the obligations that became enforceable on 2 August 2026 are the Article 50 transparency duties: tell people when they are interacting with an AI system, label synthetic content and deepfakes, and mark machine-generated output in a machine-readable way.
Costed honestly, that is:
- Engineering: a disclosure string in the chat UI, a label on generated media, and content-provenance marking. Days, not quarters, for most teams.
- Legal review: one targeted opinion on whether your features fall inside Annex III. Low four figures if scoped tightly.
- Documentation: an AI inventory — what models you use, where, on whose data. The prerequisite for everything else and the highest-return artifact you can produce.
- Ongoing: review when you ship a new AI feature. A checklist item, not a headcount.
The honest number here is measured in internal hours plus one legal review — not in the six figures being quoted at you.
Has the Digital Omnibus changed the cost picture?
Yes, and mostly by moving the expensive part further out. Post-Omnibus:
- Article 50 transparency and GPAI-adjacent obligations landed 2 August 2026 and are enforceable now.
- High-risk (Annex III) obligations moved to 2 December 2027; high-risk systems embedded in regulated products moved to 2 August 2028.
- The SME simplified regime was extended to companies up to 750 employees / €150M revenue, widening the population that gets lighter documentation requirements.
For a company that would eventually be high-risk, this is not a cost reduction — it is a cash-flow reprieve. The QMS still has to exist. It just does not have to exist this year.
What is the cost of doing nothing?
Enforcement powers for the AI Office and national competent authorities apply from 2 August 2026. Penalty ceilings under the Act: up to €35M or 7% of total worldwide annual turnover for prohibited practices, and up to €15M or 3% for other breaches including GPAI model obligations — whichever is higher in each case.
Those are ceilings, not expected fines, and no public AI Act fine has been issued as of this writing. The more probable near-term cost is commercial: an enterprise buyer's AI questionnaire arrives, you cannot answer it, and the deal slows. That cost never appears in any impact assessment.
What is the cheapest defensible first step?
Build the inventory before you buy anything. You cannot cost an obligation you have not scoped, and every framework — the AI Act, ISO 42001, NIST AI RMF — starts in the same place: a list of the AI systems you actually operate, what they touch, and who owns them. Companies that skip it either overbuy a compliance programme they do not need or discover an Annex III system in year two.
Then map what you already do. If you hold ISO 27001, or run SOC 2 controls, a meaningful share of the AI Act's documentation, logging and risk-management expectations is already being produced somewhere in your organisation — it is just not filed under "AI Act." That overlap is the difference between a €300,000 programme and a €30,000 one. A free readiness self-assessment will show you which of it you already have.
FAQ
How much does EU AI Act compliance cost for a small business?
It depends entirely on whether you provide a high-risk AI system. If you do not — the case for most SMBs — your 2026 obligations are Article 50 transparency duties, costed in internal engineering hours plus one scoped legal review. If you do, the European Commission's own estimate was €6,000–€7,000 in compliance costs per system plus €3,000–€7,500 in verification, on top of any quality-management system you do not already have.
Is the €400,000 EU AI Act compliance cost figure real?
No. CEPS, whose study the figure was drawn from, published a correction stating that their actual estimates were €193,000–€330,000 to set up an entirely new Quality Management System, plus about €71,400 in annual maintenance — and that the €400,000 number appears to be those two added together. It also applies only to a provider of a high-risk AI system with no existing QMS.
What percentage of AI systems are high-risk under the EU AI Act?
The European Commission expected 5–15% of all AI systems to fall in the high-risk category; the supporting CEPS study modelled 10%. The Act classifies specific applications listed in Annex III, not entire sectors.
Did the Digital Omnibus reduce EU AI Act compliance costs?
It deferred them. High-risk (Annex III) obligations moved to 2 December 2027 and embedded high-risk systems to 2 August 2028, while Article 50 transparency and GPAI obligations still took effect on 2 August 2026. The SME simplified regime was extended to companies up to 750 employees / €150M revenue.
What are the penalties for EU AI Act non-compliance?
Up to €35 million or 7% of total worldwide annual turnover for prohibited practices, and up to €15 million or 3% for other breaches including GPAI model obligations — whichever is higher. These are ceilings set in the Act, not typical outcomes.