When estimating what compliance costs, the factor that weighs most is each system's classification. It's worth looking at the two columns side by side, because the distance between them surprises almost everyone — in both directions.
Left column: minimal risk
For the vast majority of systems a company uses — writing assistants, demand forecasting, route optimisation, summarisation, AI-assisted office tools — the Regulation asks for two things, and both reach any organisation regardless of classification.
Article 4 — AI literacy. Take measures to support the development of AI literacy among staff who operate or use the systems, "taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in". It's an obligation of means, not of result, and the article itself has said so since the Digital Omnibus rewrote it.
Article 5 — not engaging in prohibited practices. It isn't a task you complete: it's a line you don't cross. It's resolved by knowing what your systems do.
And little else under the AI Act. If the system interacts with people or generates content, the Article 50 transparency regime, whose main obligation falls on the provider, also comes into play.
What is added, and isn't from the AI Act: if it processes personal data, the GDPR applies just as it would to any other processing. The minimal-risk classification doesn't reduce any of that.
Right column: high risk
Here the whole of Article 26 opens up. These are obligations of the deployer, distinct from the provider's, and none of them is resolved by signing a document.
26(1) — use the system "in accordance with the instructions for use", with appropriate technical and organisational measures.
26(2) — assign human oversight to natural persons "who have the necessary competence, training and authority". The third word is the one that decides whether the appointment means anything.
26(4) — that input data be "relevant and sufficiently representative", to the extent you exercise control over it.
26(5) — monitor operation and inform the provider when appropriate.
26(6) — keep the logs the system generates automatically, to the extent they're under your control.
26(7) — if you're an employer, inform workers' representatives and the affected workers.
And on top of that, when one of the Article 27 triggers applies, a fundamental rights impact assessment. Plus the DPIA under Article 35 GDPR if the processing activates it, which follows its own logic.
Why the difference is one of nature, not degree
Read the right column looking for what's done once and what's done continuously.
Almost everything is continuous. Monitoring operation, keeping records, keeping oversight assigned to someone who's still there and still holds authority, checking that actual use still matches the instructions. This isn't a project with a delivery date: it's a function that's maintained for as long as the system is in use.
The left column, by contrast, is substantially a state: knowing what you have, who uses it, and having adopted proportionate measures.
That's the real reason classification dominates cost. It isn't that a high-risk system has more boxes to tick: it's that it introduces recurring work where there was none before.
What isn't in the right column, and gets attributed to it anyway
It's worth saying, because it inflates budgets by mistake.
The quality management system of Article 17, the documentation retention of Article 18, the technical documentation of Annex IV, the post-market monitoring of Article 72 and the serious-incident reporting of Article 73 are the provider's obligations. Attributing them to the deployer is the most expensive mistake in the whole Regulation, because each one is an entire body of work that isn't yours to do.
And the date, which changes the order of things
The Annex III high-risk regime applies from 2 December 2027, and the date circulating in a good many guides is August 2026. The Annex I regime applies from 2 August 2028.
That means the right column isn't enforceable today, and saying otherwise means using a deadline that doesn't exist. The left column is, and has been since 2 February 2025.
So the sensible order is the reverse of what's usually proposed: first what already binds everyone and is cheap, then what will bind a few and is expensive. And in between, the one task that decides which of the two columns applies to you — knowing what systems you have.
Content in accordance with Articles 4, 5, 26, 27 and 50 and Annexes I and III of Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744 (Official Journal of the EU, 24 July 2026), and Article 35 of Regulation (EU) 2016/679.
This article is for informational purposes only and does not constitute legal advice.