Back
Christof Jori

7 min read · 26 May 2026

Next

Real EU AI Act Compliance Cost for a 5-Person Startup (€30 to €80k Breakdown)

Concrete planning ranges for a 5-person startup deploying an AI system in the EU: a chatbot or RAG assistant subject mainly to transparency duties can land around €15k to €30k in first-year compliance work. A high-risk system such as hiring or credit scoring can land around €40k to €90k+, depending on classification, documentation and operating controls. Third-party assessment is not automatic for every Annex III system. Minimal-risk systems can carry little direct AI Act cost, although GDPR and sector rules may still apply.

I am writing this from the engineering side. We have done the technical documentation and risk-management workstreams for clients who needed to ship AI features into the EU. Numbers below are ranges from Wavect's engagement history plus published auditor fee schedules. Talk to a lawyer for legal certainty. Talk to me for the implementation reality.

Already comparing suppliers rather than estimating your own compliance budget? Use the 45-question EU AI vendor security questionnaire to request evidence, score hard stops and turn accepted gaps into contract terms before you sign.

Shipping AI into the EU?

 Book Free Consultation

What does the EU AI Act actually classify your system as?

Before any number makes sense, classify your system. The Act defines four tiers:

  • Prohibited. Social scoring, real-time biometric ID in public, manipulative dark-pattern AI, emotion recognition at work or school. Cost of compliance: do not build it.
  • High-risk. Annex III list: hiring decisions, credit scoring, education scoring, law enforcement, critical infrastructure, medical devices, biometrics. Full conformity regime applies.
  • Limited-risk. Chatbots, generative content, emotion or biometric categorization where allowed. Transparency obligations, lighter documentation.
  • Minimal-risk. Spam filters, recommendation engines for media, basic ML in games. No specific obligations beyond GDPR.

Most early-stage SaaS startups land in limited-risk or minimal-risk. The big cost jump happens at high-risk.

How much does EU AI Act compliance cost line-by-line?

Budget table for a 5-person startup. The first column assumes a customer-facing chatbot or RAG product with transparency duties. The high-risk column assumes a hiring or credit-scoring system and treats external assurance as optional unless the applicable procedure requires a notified body.

Line itemLimited-risk (EUR)High-risk (EUR)
Initial legal review and risk classification3,000 to 6,0006,000 to 12,000
Technical documentation (Annex IV)4,000 to 8,00010,000 to 18,000
Data governance and dataset documentation2,000 to 5,0008,000 to 15,000
Risk management system setup1,500 to 3,0005,000 to 10,000
Conformity assessment (third-party where required)n/a (self-declaration)0 to 20,000
Post-market monitoring tooling and process2,000 to 4,0005,000 to 10,000
Internal training and SOP rollout1,500 to 3,0003,000 to 6,000
Transparency and user-facing labelling1,000 to 2,0001,500 to 3,000
First-year total15,000 to 31,00046,500 to 94,000

What does the legal review actually deliver?

A lawyer specializing in EU tech law writes a memo classifying your system under the Act, mapping the obligations, and flagging GDPR overlaps. Expect 8 to 20 hours of senior lawyer time at €300 to €600/hour in DACH. Cheap lawyers will quote €1,500 and produce a templated document that does not survive an enforcement query. Pay for the senior.

What goes into the technical documentation?

Annex IV of the Act lists 9 categories of required documentation: general description, design specifications, monitoring and control, validation and testing, post-market monitoring plan, and so on. We typically produce this as a versioned document in the client repo, kept in sync with the codebase. The first version takes 40 to 80 engineering hours plus 10 to 20 hours of senior review. Maintenance after that is roughly 4 to 8 hours per release.

What does data governance actually require?

For high-risk systems the Act demands datasets that are relevant, representative, free of errors, and complete. In practice this means: documented data sources, documented preprocessing, documented quality checks, documented bias evaluation. We bake this into the SDLC using model cards and dataset cards, plus a quarterly bias audit on production data. The setup cost is in the table; the ongoing cost is engineering time we treat as part of the feature budget.

When do you need a third-party conformity assessment?

Not every Annex III system needs a notified body. Under Article 43, most stand-alone Annex III systems follow the internal-control procedure. Biometric systems in point 1 of Annex III can require notified-body involvement in defined cases, while AI embedded in regulated products follows the relevant sectoral conformity route. Confirm the route for the specific system before adding third-party fees or lead time to the budget.

Christof Jori

"Compliance is architecture, not paperwork. Build it into the SDLC and the audit becomes a sign-off."

What about post-market monitoring?

The Act requires ongoing monitoring of system performance and incident reporting. For most startups this means: logging structured model inputs and outputs with privacy controls, an alerting pipeline for drift and anomalies, a documented incident-response process, and a serious-incident notification path to the national authority. We typically wire this through the same observability stack the team already uses (Sentry, Grafana, Datadog) plus a small custom layer. One-time setup as in the table, ongoing cost is operational.

What does internal training cover?

Everyone who designs, builds, or operates the AI system needs to understand its obligations and limits. For a 5-person team we usually run a half-day workshop plus a 10 to 20-page handbook tailored to the product, then refresh annually. Cheap, high-leverage. Skip it and the first regulator query exposes the gap.

What is the ongoing annual cost after year one?

Roughly 30 to 50 percent of the first-year cost as recurring cost. So a limited-risk system runs €5k to €15k per year ongoing, a high-risk system €15k to €35k per year. Plus reassessment fees if you make substantial changes to the system, which is broadly defined and tends to apply more often than founders expect.

What if you build with AI agents or RAG?

The classification still depends on the use case, not the architecture. A RAG assistant for internal knowledge search is usually minimal or limited-risk. A multi-step AI agent that takes actions on behalf of users (booking, purchasing, sending communications) needs to be classified by what those actions affect. An agent triggering hiring decisions is high-risk regardless of how cleverly the prompt is written. We discuss this with every client during scoping under our AI service.

Final thoughts

For a transparency-focused system, a practical planning range is roughly €15k to €30k. A high-risk system can require €40k to €90k or more in the first year, but the route depends on the use case and whether the applicable conformity procedure is internal or requires a notified body. Classify first, then price the actual controls.

The trap most founders fall into is treating compliance as a Q4 paperwork exercise. By Q4 your architecture choices have already locked in much of the compliance cost. Treat it as architecture from day one and the work becomes easier to evidence, operate and maintain.

Production AI help

Building an AI product and worried about inference cost, architecture, or production readiness? Wavect helps founders turn AI prototypes into reliable production systems.

Explore the service path:

Inbox, without the noise

Follow the work that matters to you

Get a short email when we publish something new. Follow the whole blog or only the problems you care about.

What would you like to receive?
Choose your topics

Free, double opt-in, no tracking pixels.

Back
Christof Jori

7 min read · 26 May 2026

Next