โ Last verified: 2026-07-23ยท Source: Regulation (EU) 2024/1689, Articles 8โ27, 50โ55, 99, 113ยท report a change โ
Everyone publishes the obligations. Nobody prices them. Pick your role and risk tier and this builds a first-year budget from the actual workstreams the Regulation requires, then puts it next to the fine you are insuring against.
Tier is everything. The distance between a limited-risk transparency duty and an Annex III high-risk conformity programme is roughly two orders of magnitude. Confirm your classification before you budget โ that single decision moves the number more than every other input on this page combined.
โ
first-year programme cost
โongoing per year
โper system, year one
โmax fine exposure
Where the hours go
First-system effort by obligation workstream, plus the recurring annual duty each one leaves behind. Additional systems are charged at the reuse discount you set above, because a quality management system written once serves the whole portfolio.
Workstream
Article
Hours (1st system)
Year-one cost
Recurring / yr
What each tier costs on your inputs
The same organisation, the same rate, the same number of systems โ priced at every tier. This is the table to look at before you accept someone's casual classification of your product.
Tier
Year one
Ongoing / yr
3-year total
Fine band
โ ๏ธ Planning estimate, not legal advice. Hour ranges are modelled from the obligation set in Regulation (EU) 2024/1689 (Arts. 9โ15 risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy/robustness/cybersecurity; Art. 17 quality management system; Arts. 43โ48 conformity assessment and CE marking; Art. 72 post-market monitoring; Arts. 53โ55 GPAI). Actual effort varies widely with system complexity, existing ISO 42001 or ISO 27001 coverage, and whether a notified body is involved. Article 113 application dates and ongoing simplification amendments should be confirmed for your tier before you commit a budget. ยท Report an error โ
Why nobody will give you a number
Search for the cost of EU AI Act compliance and you get two kinds of answer: consultancies quoting six-figure ranges with no method, and law firms explaining the obligations without ever converting them into hours. Neither helps you write a budget line. The obligations are, however, unusually enumerable โ the Regulation lists them by article, and each one maps to a recognisable engineering or governance workstream. A risk management system under Article 9 is a documented, iterative process with owners and review cycles. Data governance under Article 10 is provenance, representativeness and bias examination on your training, validation and test sets. Article 11 technical documentation is a specified deliverable with an annex telling you what goes in it. Article 17's quality management system is the single largest line for most organisations and the one that scales best across a portfolio, which is why the reuse percentage above moves the total so much.
The tier decision dominates everything else
Run the tier comparison table and the shape is immediately obvious: limited-risk transparency duties are a rounding error, Annex III high-risk is a real programme, and Annex I high-risk adds a notified body whose fees you do not control. General-purpose model providers sit in their own regime under Article 53 โ model documentation, a copyright policy, and a sufficiently detailed public summary of training content โ with a second, much heavier layer at Article 55 for models presenting systemic risk, where adversarial evaluation and serious-incident reporting become continuous obligations rather than one-off deliverables. Most disputes about compliance cost are actually disputes about classification wearing a budget costume. Settle the tier first.
Compliance cost versus the thing it insures against
Article 99 caps penalties as the higher of a fixed amount or a share of worldwide turnover: 35 million euro or 7% for prohibited practices, 15 million or 3% for most other breaches including the high-risk requirements, and 7.5 million or 1% for supplying incorrect information. The percentage limb only overtakes the fixed limb above roughly 500 million euro of turnover, so for a mid-sized company the fixed ceiling is what matters and the ratio of exposure to programme cost is usually somewhere between 50ร and 200ร. That ratio is the argument, and it is worth putting in front of a finance team in exactly those terms. Once you have the programme scoped, price the systems it governs with the AI guardrails stack cost calculator and the LLM observability cost calculator โ logging and monitoring obligations under Articles 12 and 72 are met with infrastructure you also have to pay for.
Price your EU AI Act obligations by risk tier. Enter your role, tier and number of AI systems to get first-year cost, ongoing annual cost, a workstream-by-workstream breakdown, and your fine exposure under Article 99.
Frequently asked questions
How much does EU AI Act compliance actually cost?
It depends almost entirely on which risk tier your system lands in, and the gap between tiers is enormous. A limited-risk system needing only transparency disclosures is a few tens of thousands of euros of internal work. An Annex III high-risk system carries a risk management system, data governance, technical documentation, logging, human oversight design, accuracy and robustness testing, and a quality management system โ well over 1,400 hours of first-year work before any external legal or conformity-assessment spend. A general-purpose model provider crossing the systemic-risk threshold adds adversarial evaluation and incident-reporting obligations on top. The single most valuable thing you can do is confirm your tier, because guessing one tier too high wastes six figures and guessing one too low is what the fines are for.
When do the EU AI Act obligations actually apply?
The Act's Article 113 timetable staggers entry into application: the prohibitions and AI-literacy duties applied from 2 February 2025, the general-purpose AI model obligations from 2 August 2025, the bulk of the framework including Annex III high-risk obligations from 2 August 2026, and high-risk systems embedded in products already covered by EU product-safety legislation under Annex I from 2 August 2027. Simplification and delay amendments have been actively debated, so confirm the current position for your tier before you budget against a fixed date โ but plan on the published timetable rather than on a delay arriving.
What are the fines and how do they compare to the cost of complying?
Article 99 sets three bands, each expressed as the higher of a fixed amount or a percentage of worldwide annual turnover: up to 35 million euro or 7% for deploying a prohibited practice, up to 15 million euro or 3% for breaching most other obligations including the high-risk requirements, and up to 7.5 million euro or 1% for supplying incorrect or misleading information to authorities. Because the percentage limb bites for anyone above roughly 500 million euro of turnover, large firms face exposure that dwarfs any compliance budget, while for a small company the fixed ceiling is the binding number. This calculator puts your exposure next to your programme cost so the ratio is explicit.