By Rafael Luque Ocaña

How much does it cost to comply with the AI Act? The right question is what determines the cost

It isn't determined by company size or turnover. Three things determine it: how many AI systems you have, what each one's classification requires, and how much of that is already documented.

It's the first question anyone asks, and it doesn't have an answer in the form of a figure. Not because nobody wants to give one, but because the question isn't well posed: it asks for a number for something that's the product of three very unequal factors.

What can be answered — and is more useful — is what determines it. With that, every organisation can work out its own.

Factor 1 — how many systems, not how much company

Cost doesn't scale with headcount or turnover. It scales with the number of distinct AI systems the organisation uses.

A two-hundred-person company with three tools can have less work than a twenty-person one with fifteen, because each system is an independent unit of analysis: it has to be identified, understood, classified, and matched to what applies to it.

And this is where the first, systematic estimation error shows up: almost nobody knows how many they have. The count that's done off the top of the head counts the AI that was deliberately bought. It doesn't count the AI features built into tools that were already there — like the software used to hire and evaluate people — nor the ones someone uses on their own without going through anyone.

So the first factor isn't estimated: it's counted. And counting is the part of the job that can't be skipped, because the other two factors are calculated on top of it.

Factor 2 — what each classification requires, which is the most unequal part

This is the factor that blows the total up or brings it down, and the one that's almost never explained well.

A minimal-risk system requires little: that the people who use it have the literacy measures under Article 4, and that its use doesn't fall under any prohibited practice in Article 5. Documenting it properly is a matter of knowing what it is, who uses it, and for what.

A high-risk system requires the whole of Article 26: using it in accordance with its instructions, with technical and organisational measures; assigning oversight to people with the competence and authority for it; monitoring its operation; keeping the records it generates; informing the workers exposed to it. And, if any of the situations in Article 27 apply, an additional impact assessment.

The difference between the two columns isn't one of degree: it's one of kind. That's why the number that matters isn't "how many systems do I have" but "how many of them are high-risk" — and for most organisations, the answer is lower than feared and sits somewhere other than where people look.

Factor 3 — how much of this already exists

The third factor is the one nobody counts, and it's usually the one that cuts the most.

An organisation with reasonably solid GDPR practice already has a record of processing activities, a lawful basis for each one, contracts with processors and, where it applied, impact assessments already done. A good part of what the AI Act asks for on those same systems builds on that material, rather than duplicating it.

The reverse also holds: an organisation starting from zero on data protection isn't doing one job for the AI Act. It's doing two, and the second one was already required before the first.

What does NOT determine the cost

Worth saying, because these are the three variables that come up most in conversations, and none of them drives it.

The sector, except for how it changes the classification. Belonging to a regulated one doesn't in itself raise the cost: it raises the cost if your systems fall under high risk through that route.

Urgency. The high-risk regime under Annex III applies from 2 December 2027, and the date circulating in plenty of guides is wrong. Working against a deadline that doesn't exist doesn't change the work: it changes the price someone is willing to pay to have it done fast.

Size, except for its correlation with factor 1. More people usually means more tools, but that's a correlation, not a cause.

How to estimate it without anyone giving you a number

Four steps, in this order, and the first two are free.

Count the systems — including the ones that administer people and the ones someone uses on their own.

Separate the ones that decide something about people from the ones that only produce or assist. That's the cut that approximates the classification before doing it formally.

Look at what you already have documented on those systems through the GDPR route.

And only then ask about the cost, with those three data points in hand. Any quote requested before that point is being calculated on an inventory that doesn't exist — yours or someone else's.

What's in force in the meantime, whatever the outcome turns out to be, is Article 4 on AI literacy, in force since 2 February 2025rewritten by the Digital Omnibus without ceasing to be an obligation — and Article 5. Neither depends on any inventory, and they're the floor of any calculation.

Content in line with Articles 4, 5, 26 and 27 and Annex III of Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744 (Official Journal of the EU, 24 July 2026).

This article is for informational purposes only and does not constitute legal advice.

Get analysis like this in your inbox

Alethexis regulatory and product news. No noise.

I agree to receive communications from Alethexis: content about AI and regulation, and product news. I can unsubscribe at any time.

Controller: ALETHEXIS, S.L. (CIF B88758057). Purpose: to send you the Alethexis newsletter (content about AI and regulation, and product news). Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. Retention: until you unsubscribe or after 24 months of inactivity. Rights of access, rectification, erasure, objection, restriction and portability: [email protected]. You may lodge a complaint with the Spanish Data Protection Authority (AEPD, www.aepd.es). More information in the privacy policy.