✨ New — try Standpoint free for 14 days: full access to all 15 frameworks. A card is required, but you won’t be charged. Start your free trial →
Standpointby AI Service Pro
Security Intelligence / EU AI Act
Guide

EU AI Act compliance cost: what it actually costs in 2026

M
Mohammad
Founder, AI Service Pro · 9 min read

How much does EU AI Act compliance cost?

For most small and mid-sized companies in 2026, far less than the internet says — because most of them are not building high-risk AI systems, and the obligations that landed on 2 August 2026 are transparency duties, not quality-management systems. The European Commission's own estimate for the expensive case — a genuinely high-risk system — was €6,000 to €7,000 in compliance costs on an average high-risk AI system costing around €170,000, plus €3,000 to €7,500 in verification costs. The five- and six-figure numbers circulating online describe a company building its first high-risk product with no existing quality system at all. That is a real scenario. It is not the median one.

The rest of this guide separates the cost pictures — because "EU AI Act compliance cost" is not one number, and anyone quoting you one without asking what you build is guessing.

What did the European Commission actually estimate?

The figures come from the explanatory memorandum accompanying the Commission's original AI Act proposal, COM(2021) 206 final:

Cost itemCommission estimateApplies to
Compliance with the high-risk requirements€6,000–€7,000 per systemProviders of high-risk AI systems
Verification / conformity assessment€3,000–€7,500Suppliers of high-risk AI
Reference system value~€170,000 by 2025An "average" high-risk AI system

Two honest caveats, because a cost guide that hides its own weaknesses is worth nothing. First, these are 2021 estimates expressed in 2025 prices — they predate the final text, the GPAI chapter and the 2026 Omnibus amendments. Second, they are marginal costs: what the Act adds on top of building the system, not the total cost of building it.

Bar chart comparing EU AI Act cost estimates: €6,000–€7,000 compliance per high-risk AI system and €3,000–€7,500 verification against €193,000–€330,000 to set up a first Quality Management System, drawn to true linear scale.
Per-system compliance and a first quality-management system are two different questions. Bars are drawn to true linear scale — the per-system cost really is that small beside a first QMS build. Sources: European Commission COM(2021) 206; CEPS (2021).

Where does the "€400,000 for a small business" figure come from?

This is the most-repeated number in the entire debate, and the researchers whose work it came from say it is wrong.

The chain: the Commission commissioned a supporting study from CEPS (the Centre for European Policy Studies), with ICF and Wavestone. A think-tank paper then reported that "a small business can expect total compliance costs of up to €400,000 for one high-risk AI product requiring a quality management system." Headlines followed — including that Europe's proposed AI law could cost its economy $36 billion.

CEPS published a public correction. Their actual estimate was that setting up an entirely new Quality Management System could cost €193,000–€330,000, with roughly €71,400 in annual maintenance. The €400,000 figure appears to be those two numbers added together.

Diagram showing the €400,000 EU AI Act figure broken into its two components: €330,000 to set up a new Quality Management System plus €71,400 in annual maintenance.
The anatomy of the misquote: a one-off upper bound and a recurring annual cost, summed into a single headline number. Source: CEPS, “Clarifying the costs for the EU’s AI Act” (2021).

Their correction also makes three points that matter more than the arithmetic:

  • The QMS cost is only fully incurred if the company has no quality management system in the first place. Once it exists, later products cost far less.
  • A QMS is required only for providers of high-risk AI systems — not for every company using AI.
  • The 17%-of-development-cost figure that produced the "€30 billion" headline applies only to companies meeting none of the requirements as business-as-usual practice. Most companies already do some of them.

EU AI Act compliance cost is not a price tag on using AI. It is the marginal cost of proving that one specific high-risk system does what you say it does — and it collapses toward zero for every system that is not high-risk.

Am I even in the expensive category?

Probably not, and this is the single biggest cost variable. The Commission expected high-risk systems to be 5–15% of all AI systems; the CEPS study modelled 10%. The Act does not classify whole sectors as high-risk — only specific applications inside them, listed in Annex III. Using AI in education is not high-risk; using AI to score students or gate admission is.

So before you budget anything, answer one question: are you a provider of a system on Annex III, a provider of a GPAI model, or neither? If neither, your 2026 obligations are transparency obligations, and the cost conversation changes completely. Our guide to what actually applies from August 2026 walks through that split in detail.

What does compliance cost if my system is not high-risk?

For most SaaS companies shipping AI features to EU users, the obligations that became enforceable on 2 August 2026 are the Article 50 transparency duties: tell people when they are interacting with an AI system, label synthetic content and deepfakes, and mark machine-generated output in a machine-readable way.

Costed honestly, that is:

  • Engineering: a disclosure string in the chat UI, a label on generated media, and content-provenance marking. Days, not quarters, for most teams.
  • Legal review: one targeted opinion on whether your features fall inside Annex III. Low four figures if scoped tightly.
  • Documentation: an AI inventory — what models you use, where, on whose data. The prerequisite for everything else and the highest-return artifact you can produce.
  • Ongoing: review when you ship a new AI feature. A checklist item, not a headcount.

The honest number here is measured in internal hours plus one legal review — not in the six figures being quoted at you.

Has the Digital Omnibus changed the cost picture?

Yes, and mostly by moving the expensive part further out. Post-Omnibus:

  • Article 50 transparency and GPAI-adjacent obligations landed 2 August 2026 and are enforceable now.
  • High-risk (Annex III) obligations moved to 2 December 2027; high-risk systems embedded in regulated products moved to 2 August 2028.
  • The SME simplified regime was extended to companies up to 750 employees / €150M revenue, widening the population that gets lighter documentation requirements.

For a company that would eventually be high-risk, this is not a cost reduction — it is a cash-flow reprieve. The QMS still has to exist. It just does not have to exist this year.

What is the cost of doing nothing?

Enforcement powers for the AI Office and national competent authorities apply from 2 August 2026. Penalty ceilings under the Act: up to €35M or 7% of total worldwide annual turnover for prohibited practices, and up to €15M or 3% for other breaches including GPAI model obligations — whichever is higher in each case.

Those are ceilings, not expected fines, and no public AI Act fine has been issued as of this writing. The more probable near-term cost is commercial: an enterprise buyer's AI questionnaire arrives, you cannot answer it, and the deal slows. That cost never appears in any impact assessment.

What is the cheapest defensible first step?

Build the inventory before you buy anything. You cannot cost an obligation you have not scoped, and every framework — the AI Act, ISO 42001, NIST AI RMF — starts in the same place: a list of the AI systems you actually operate, what they touch, and who owns them. Companies that skip it either overbuy a compliance programme they do not need or discover an Annex III system in year two.

Then map what you already do. If you hold ISO 27001, or run SOC 2 controls, a meaningful share of the AI Act's documentation, logging and risk-management expectations is already being produced somewhere in your organisation — it is just not filed under "AI Act." That overlap is the difference between a €300,000 programme and a €30,000 one. A free readiness self-assessment will show you which of it you already have.

FAQ

How much does EU AI Act compliance cost for a small business?

It depends entirely on whether you provide a high-risk AI system. If you do not — the case for most SMBs — your 2026 obligations are Article 50 transparency duties, costed in internal engineering hours plus one scoped legal review. If you do, the European Commission's own estimate was €6,000–€7,000 in compliance costs per system plus €3,000–€7,500 in verification, on top of any quality-management system you do not already have.

Is the €400,000 EU AI Act compliance cost figure real?

No. CEPS, whose study the figure was drawn from, published a correction stating that their actual estimates were €193,000–€330,000 to set up an entirely new Quality Management System, plus about €71,400 in annual maintenance — and that the €400,000 number appears to be those two added together. It also applies only to a provider of a high-risk AI system with no existing QMS.

What percentage of AI systems are high-risk under the EU AI Act?

The European Commission expected 5–15% of all AI systems to fall in the high-risk category; the supporting CEPS study modelled 10%. The Act classifies specific applications listed in Annex III, not entire sectors.

Did the Digital Omnibus reduce EU AI Act compliance costs?

It deferred them. High-risk (Annex III) obligations moved to 2 December 2027 and embedded high-risk systems to 2 August 2028, while Article 50 transparency and GPAI obligations still took effect on 2 August 2026. The SME simplified regime was extended to companies up to 750 employees / €150M revenue.

What are the penalties for EU AI Act non-compliance?

Up to €35 million or 7% of total worldwide annual turnover for prohibited practices, and up to €15 million or 3% for other breaches including GPAI model obligations — whichever is higher. These are ceilings set in the Act, not typical outcomes.

See where you stand — free
2-minute check · no card · runs in your browser
Run your free check →
Newsletter
Practical AI-governance & security tips, monthly

No fluff, no fear-selling. Unsubscribe anytime.

// Keep reading