Back
Christof Jori

7 min read · 26 May 2026
Last reviewed

Next
Made on your device, with no Instagram connection. We copy the post link for Instagram’s Link sticker.

EU AI Act Compliance Cost for a Startup: Scope Before Budget

There is no statutory fee schedule or dependable universal price for EU AI Act compliance. Team size alone does not determine the work. A startup's cost depends on what the system is intended to do, whether the company is a provider, deployer, importer or distributor, which duties apply, and how much usable evidence already exists.

This guide is a planning framework from the engineering side, not a legal opinion or a market-rate survey. It helps founders identify the workstreams that should be estimated before they request legal, assurance or implementation quotes.

Already comparing suppliers? Use the 45-question EU AI vendor security questionnaire to request evidence, score hard stops and turn accepted gaps into contract terms before you sign.

Shipping AI into the EU?

 Book Free Consultation

What should you classify before estimating cost?

The Act does not define a general four-tier price ladder called prohibited, high-risk, limited-risk and minimal-risk. Use a decision sequence instead:

  1. Check scope and role. Record the intended purpose, affected people, market, supply chain and whether you are acting as provider, deployer, importer or distributor. A company can hold more than one role.
  2. Check prohibited practices. Article 5 contains specific prohibitions and exceptions. Do not reduce that legal test to labels such as "social scoring" or "emotion recognition" without checking the exact purpose, actor and context.
  3. Check the high-risk routes. Article 6(1) covers certain safety components or products under Annex I legislation that require third-party conformity assessment. Article 6(2) covers Annex III use cases, subject to the Article 6(3) exception and its documentation rules. Profiling of natural persons within an Annex III use case remains high-risk.
  4. Check other AI Act duties. These can include AI literacy, transparency under Article 50, or general-purpose AI model obligations. They are not a formal "limited-risk" class.
  5. Map other law separately. GDPR, consumer, employment, product-safety and sector rules can apply even when an AI system is not high-risk under the AI Act.

Architecture is not the classification. A RAG assistant, recommendation feature or AI agent must be assessed by its intended purpose and actual function.

Which AI Act dates matter as of September 2026?

Article 4 AI-literacy duties and most prohibited-practice rules have applied since 2 February 2025. Most Article 50 transparency duties apply from 2 August 2026. A narrow grace period gives providers of certain pre-existing systems that generate synthetic content until 2 December 2026 to meet Article 50(2).

Regulation (EU) 2026/1744 changed the high-risk schedule. Chapter III Sections 1 to 3 apply from 2 December 2027 for Article 6(2) and Annex III systems, and from 2 August 2028 for Article 6(1) and Annex I product-route systems. Those later dates are not a reason to wait: classification, contracts, data lineage, testing and technical records often require lead time.

How do you build a defensible compliance budget?

Estimate named deliverables against evidence gaps. Do not start with a generic startup size or a percentage of engineering spend.

WorkstreamQuestions that drive effortTypical evidence output
Scope and classificationWhat is the intended purpose, who is affected, which operator roles apply, and does Article 5, Article 6, Annex I, Annex III or Chapter V apply?Versioned classification memo and obligation map
Governance and contractsWho owns each duty, what evidence must suppliers provide, and what happens when the model, data or intended purpose changes?Responsibility matrix, vendor terms and change-control rules
Technical documentationWhich provider duties apply, what records already exist, and can documentation stay aligned with releases?Traceable system description, design records, test evidence and instructions
Risk, data and testingWhich foreseeable risks and affected groups matter, what datasets are used, and which accuracy, robustness and cybersecurity claims need evidence?Risk register, data records, evaluation plan and release criteria
Transparency and human oversightWhat must users know, what decisions can humans review, and can operators understand limits and intervene?Notices, interface controls, operating instructions and escalation paths
OperationsDo post-market monitoring or incident duties apply, what signals are available, and who owns investigation and reporting?Monitoring plan, logs, incident process and retained decisions
Assessment and registrationWhich conformity route applies, is a notified body involved, and what EU database registration is required?Assessment file, declaration, registration record and release approval

Ask each supplier to state assumptions, exclusions, deliverables, responsible roles and acceptance criteria. A low quote that excludes product changes, dataset work or ongoing operations is not comparable with an implementation quote that includes them.

What belongs in high-risk technical documentation?

Annex IV describes the information required for high-risk provider documentation. It is not usefully reduced to a fixed number of documents or engineering hours. Scope depends on the system, its versions, development methods, data, monitoring, standards used and applicable conformity route. Keep records versioned with the product so that claims can be traced to tests and releases.

What does data governance require?

Article 10 applies to training, validation and testing datasets used for high-risk AI systems. It requires governance and management practices appropriate to the intended purpose. The law calls for datasets that are relevant, sufficiently representative and, to the best extent possible, free of errors and complete in view of the intended purpose. It does not promise perfect data or prescribe a universal quarterly bias audit. Define checks and review frequency from the actual risks, data changes and performance evidence.

When is a third-party conformity assessment involved?

Not every Annex III system automatically requires a notified body. Article 43 sets different routes. Certain Annex III biometric systems can involve a notified body under the conditions in that Article, while other Annex III systems generally use the internal-control procedure. AI covered through the Annex I product route follows the applicable product legislation and conformity process. Confirm the route for the exact system before budgeting external assessment fees or lead time.

Christof Jori

"Compliance is an evidence system. Scope the duties, owners and proof before estimating the work."

Who owns monitoring and incident reporting?

Article 72 requires providers of high-risk systems to establish and document a proportionate post-market monitoring system. Article 73 places serious-incident reporting duties on providers of high-risk systems, with role-specific cooperation elsewhere in the Act. Deployer duties are set out separately, including use according to instructions, appropriate human oversight and monitoring where applicable. Avoid assigning every provider duty to every startup simply because it uses AI.

What does AI-literacy work look like?

Article 4 requires providers and deployers to take measures, to their best extent, to ensure sufficient AI literacy for staff and others operating AI on their behalf. The measures should reflect technical knowledge, experience, education, training, context and affected people. The Act does not mandate a half-day workshop, a specific handbook length or annual refresh. Choose training, guidance and practice exercises that fit the roles and risks, then retain evidence that the measures occurred.

How should ongoing cost be estimated?

Do not apply a universal percentage to the first-year project. Recurring work can include evidence maintenance, supplier review, model or data change assessment, monitoring, incident exercises, training and reassessment after changes. Estimate each activity by trigger, frequency, owner and expected volume. A stable internal tool and a frequently changing high-risk product will have very different operating profiles.

How do RAG and AI agents affect the analysis?

They do not create an automatic category. An internal knowledge assistant may still raise transparency, data-protection, confidentiality or employment-law issues. An agent used in recruitment is not automatically high-risk merely because it sends messages or calls tools; examine whether its intended purpose falls within the Annex III employment use cases, whether it materially influences a decision, and whether the Article 6(3) exception can apply. Record that reasoning rather than relying on the architecture label.

Final thoughts

A defensible EU AI Act budget begins with the use case, operator role, applicable date and evidence gap. Convert that map into named legal, governance, documentation, testing, transparency, training, monitoring and assessment deliverables. Generic EUR bands hide the assumptions that determine the real effort.

Revisit the scope when the intended purpose, model, dataset, supplier, affected group or product integration changes. Treat the result as a maintained engineering and governance system, not a one-time paperwork package.

Primary legal sources used in this guide

Legal applicability depends on the system, role and use case. This planning framework is not legal advice.

Production AI help

Building an AI product and worried about inference cost, architecture, or production readiness? Wavect helps founders turn AI prototypes into reliable production systems.

Explore the service path:

Inbox, without the noise

Follow the work that matters to you

Get a short email when we publish something new. Follow the whole blog or only the problems you care about.

What would you like to receive?
Choose your topics

Free, double opt-in, no tracking pixels.

Back
Christof Jori

7 min read · 26 May 2026
Last reviewed

Next

Get the next Business and regulation field note

One concise email when we publish. No tracking pixels, and no inbox filler.

Free, double opt-in, no tracking pixels.