Enterprise consultants charge €50K–€200K for EU AI Act compliance. Here is what it actually costs an SME — and why you need about 10% of what they are quoting. Start with the 7-step compliance checklist to map the actual work before estimating your budget.

Not sure which of your AI systems is high-risk? Run a free Attestia scan first →

The Cost Myth: Why Enterprise Pricing Does Not Apply to SMEs

If you have been quoted €50,000 or more for EU AI Act compliance, you have been quoted an enterprise price for an enterprise scope. The figure is not fabricated — it is what a large organisation with 50+ AI systems, a multinational footprint, complex supply chains, and dedicated legal and procurement teams genuinely costs to bring into compliance. That organisation might use 200 staff hours of legal review, engage specialist notified bodies, run parallel workstreams across jurisdictions, and need ongoing retainers to maintain compliance as the regulatory guidance evolves.

You are not that organisation.

Most SMEs have three to twelve AI-enabled tools in active use. Of those, two to five might be in Annex III domains. Of those, most are likely to fall into the limited or minimal risk categories — or into the deployer obligations category, where your compliance requirements are significantly lighter than a provider's. The compliance surface area for a typical SME is a fraction of what enterprise consultancies price for. The largest chunk of that work is Annex IV technical documentation — which SMEs can produce themselves with the right template.

The other factor driving enterprise quotes is margin. Compliance consulting is billed at €200–€500 per hour. A firm that quotes you 200 hours of work is building in review cycles, partner oversight, junior staff hours, and contingency. An SME that builds the same compliance posture using automated tooling, focused consulting on genuinely ambiguous questions, and internal ownership of the documentation process gets the same outcome for a fraction of the price.

Real Cost Breakdown by Company Size

Here is what EU AI Act compliance actually costs for SMEs, broken down by the number of AI systems in your organisation. These figures assume you are primarily a deployer (using AI tools built by others), which applies to the vast majority of SMEs.

1–5 AI Systems: €2,000–€5,000 Total

This is the most common SME scenario — a company using a handful of AI-powered tools: an applicant tracking system with AI scoring, a CRM with predictive lead ranking, a customer service chatbot, maybe a risk assessment tool.

What this covers:

Total for year one: €2,000–€5,000 including tooling, minimal consulting, and training. Year two onwards: primarily the tooling subscription plus any re-assessment when you add new AI systems.

5–20 AI Systems: €5,000–€15,000

A mid-size SME with a broader AI footprint — multiple departments each using AI tools, potentially some custom-developed internal tooling, and more complex supply chain relationships with AI providers.

What this covers:

Total for year one: €5,000–€12,000. The upper end applies if you have multiple genuinely high-risk systems requiring detailed documentation or if vendor relationships require legal negotiation.

20–50 AI Systems: €15,000–€40,000

At this scale, you likely have AI embedded across core business functions — automated decision-making in finance, AI-assisted HR processes, customer-facing AI tools, and possibly some custom-built internal systems. This is also the point at which the compliance programme starts to resemble a function rather than a project.

What this covers:

Total for year one: €18,000–€40,000. This is the range where it becomes worth considering whether a dedicated compliance role saves money compared to ongoing consulting fees — typically it does, from about 25 AI systems onwards.

Hidden Costs Most SMEs Miss

The figures above cover the visible compliance spend. The costs below are the ones that surprise organisations mid-project.

Employee Training (Article 4 Requirement)

Article 4 of the EU AI Act requires operators to ensure staff who work with AI systems have sufficient AI literacy for their role. This is not optional, it is not limited to technical staff, and it is not satisfiable with a single all-hands presentation.

The training obligation is role-specific. An HR manager using an AI CV screening tool needs to understand what the system does, what its limitations are, what discriminatory patterns to watch for, and how to exercise genuine oversight. A credit officer using an AI risk scoring system needs to understand the model's confidence intervals and known failure modes. This is different from general "AI awareness" training.

Practical cost: For a 50-person company with 20 staff using AI-enabled tools in relevant roles, budget €500–€2,000 for developing role-specific training content and €500–€1,000 for delivery and record-keeping. Add €200–€500 annually for refreshers as systems or obligations change. Total annual training cost for a mid-size SME: €1,000–€3,000.

Documentation Maintenance (Ongoing, Not One-Time)

Technical documentation is not a project deliverable — it is a living record that must be updated when systems change, when performance data reveals new information, when vendors update their products, or when regulatory guidance evolves.

Most SMEs budget for creating documentation but not for maintaining it. A system documented in Q1 2026 and not reviewed since will not pass an audit in Q4 2026 if the system's vendor released a major update in Q2, if your use case changed, or if new European Commission guidance affected your risk classification.

Budget 10–20% of your initial documentation cost annually for maintenance. For a company with €3,000 of initial documentation spend, that is €300–€600 per year — manageable if structured, expensive if it creates a backlog that requires consultant time to clear.

Post-Market Monitoring Infrastructure

High-risk AI deployers are required to monitor system performance in production and report serious incidents to the relevant national authority. This requires infrastructure — not necessarily sophisticated infrastructure, but something.

At minimum: a process for logging AI-assisted decisions and their outcomes, a mechanism for reviewing whether outcomes are consistent with expected performance, and a process for users and affected individuals to raise concerns. This does not require specialist software. It can be as simple as a structured spreadsheet review process. But it takes time — budget two to four hours per month per high-risk system for ongoing monitoring, or €500–€1,500 annually in internal resource cost per system.

Audit Preparation Time

If a national market surveillance authority investigates your organisation — triggered by a complaint, an incident, or a sector-wide review — you need to be able to produce documentation quickly. The hidden cost here is not the audit itself (which may never occur) but the ongoing readiness that makes an audit survivable: organised documentation, current records, trained staff who can speak to oversight processes.

Companies that build compliance correctly from the start have minimal audit preparation costs — their documentation is organised, current, and accessible. Companies that have treated compliance as a one-time project discover that audit preparation can require 40–100 hours of scrambling to recreate or update records. At consultant rates, that is €8,000–€20,000 in unbudgeted spend, plus the distraction cost to the organisation.

The Cost of Non-Compliance

The compliance costs above need to be weighed against the cost of non-compliance. These are not theoretical risks — enforcement mechanisms are active, national authorities are building investigation capacity, and the first significant fines under the Act are expected in the 2026–2027 enforcement window.

Fines: Up to €35 Million or 7% of Global Turnover

The Act establishes three tiers of fines:

For an SME with €5 million in annual revenue, a 3% fine is €150,000 — many multiples of the compliance investment required to avoid it. Even a €7.5 million cap on the lowest tier is existential for most SMEs. Enforcement actions against SMEs are not exempt from these scales.

Market Access Restrictions

Non-compliant AI systems can be required to be withdrawn from service. For SMEs using AI tools in core business processes — hiring, credit assessment, safety monitoring — forced withdrawal means operational disruption while you rebuild compliant processes. This cost is uncapped and can exceed the fine itself.

Additionally, as enterprise customers increasingly require AI compliance attestations from their supply chains, being unable to provide evidence of compliance becomes a commercial liability. B2B procurement questionnaires now routinely ask about AI compliance status. SMEs that cannot answer affirmatively risk losing contracts.

Reputational Damage in B2B Procurement

Regulatory investigations are public. Fines are published. In B2B markets — particularly financial services, healthcare, public sector procurement, and HR technology — an enforcement action under the EU AI Act signals systemic governance failure. The reputational damage in enterprise procurement contexts can exceed the direct regulatory cost.

How to Minimise Costs

Start with Risk Classification (Free)

Before spending anything, classify your AI systems. Many systems you are concerned about will turn out to be limited or minimal risk — not subject to the full high-risk compliance requirements. Every hour you spend documenting a limited-risk system is an hour not spent on a high-risk one.

Attestia's scanner is free to start. Describe your AI tools, receive a risk classification with Annex III domain analysis, and understand which systems actually require compliance investment. The scanner takes 20–40 minutes and directly reduces wasted spend by narrowing your compliance scope accurately.

Prioritise High-Risk Systems First

Even within your high-risk AI inventory, not all systems carry equal risk. Prioritise documentation for systems with the highest decision stakes: tools that affect employment outcomes, credit access, safety monitoring, or critical infrastructure. Start with the system that would generate the most serious regulatory and reputational exposure if investigated. Get that fully compliant before moving to lower-stakes systems.

Use Automated Tools vs. Manual Consulting

The cost differential between automated compliance tooling and consultant-led compliance work is substantial. At €149/month, Attestia provides ongoing classification, documentation scaffolding, monitoring alerts, and compliance tracking. An equivalent function delivered through consulting engagements runs €2,000–€5,000 per quarter for ongoing support.

Use consulting time for what automated tools cannot do: reviewing genuinely ambiguous classification decisions, advising on novel use cases, drafting contractual requirements for non-compliant vendors, and providing legal sign-off on risk classification rationale. Use tooling for everything else.

Build Internal Ownership Early

The most expensive compliance programmes are ones where external consultants own the work and internal staff do not. When the consultant engagement ends, the documentation becomes stale, the monitoring lapses, and the next regulatory update requires starting over. Internal ownership — even a part-time designated compliance lead — dramatically reduces ongoing costs by eliminating the re-onboarding cost every time external support is needed.

Attestia vs. Enterprise Compliance Costs

Compliance approachYear 1 costOngoingBest for
Full enterprise consulting €50,000–€200,000 €20,000–€50,000/yr Large enterprises with 50+ AI systems
Mid-market consulting €15,000–€50,000 €8,000–€20,000/yr Mid-size companies with complex supply chains
Attestia + targeted consulting €2,000–€8,000 €2,000–€4,000/yr SMEs with 1–20 AI systems
Attestia only (DIY) €1,800 €1,800/yr SMEs with straightforward risk profiles

Attestia starts at €149/month. That is under €1,800 annually for continuous risk classification, Annex IV documentation templates, monitoring infrastructure, and compliance tracking — the core tooling layer that replaces the most expensive parts of a consulting engagement.

Start your free AI compliance scan — understand your risk in 20 minutes →

The August 2026 Deadline

August 2, 2026 is when enforcement begins for high-risk AI systems under Annex III. That is 77 days from now. The good news is that an SME with a straightforward AI profile — five to ten tools, one or two genuinely high-risk — can get to a defensible compliance posture in that timeframe if they start this week.

The work breaks down simply: classify your systems (week one), document your high-risk systems (weeks two through four), train your staff (week five), establish monitoring (week six), review and finalise (weeks seven through eight). Eight weeks, manageable investment, defensible compliance posture before the deadline.

The expensive path is starting in July, when consultants' calendars are full, prices spike, and rushed work produces the paper compliance that fails audits. Start now. The cost curve runs in your favour.


This article provides general educational information about the EU AI Act and does not constitute legal advice. Costs are indicative estimates based on current market data and will vary depending on your specific AI systems, organisational structure, and jurisdiction. For advice specific to your situation, consult a qualified legal professional.