You want a number. A license price, an advisory rate, an internal business case that fits on one page. That number does not exist without a few answers first, and most software vendors and advisers do not volunteer them. This article is not a quote. It explains where the money goes in each route, what each route does not solve, and the one question to ask every provider before you sign.
The biggest cost is almost never the license or the hourly rate
Software costs a subscription. An adviser costs an hourly rate or a fixed project fee. Doing it in-house costs salary you are already paying. On paper that looks easy to compare. In practice, the cost line all three routes share, and the one that rarely appears in any quote, is internal time: finding every AI system running in the organization (from the HR screening tool to the chatbot customer service bought without asking IT), finding the owner of each one, and querying suppliers about training data, test results and technical documentation.
You do that inventory yourself, have someone do it for you, or have a tool help you fill it in. But the facts have to come from inside the organization. No license and no adviser can extract them without someone internally answering "which systems do we use, who owns them, and what does this system actually do." Budget for that before choosing any of the three routes, or you are comparing three ways of hiding the same problem.
Route 1: buying governance software or a compliance platform
What you buy. A system to register AI systems, track risk classifications, manage tasks and deadlines, and centralize documentation. License costs are usually structured as a price per user or per registered system, plus an implementation fee and annual maintenance. Do the math: ten systems and five users is a very different license than a hundred systems and a twenty-person compliance team.
What it doesn't solve. An empty database. Software does not fill itself. Someone has to enter every system, answer the classification question (is this system prohibited under Article 5, high-risk under Annex III, or neither1), and upload the evidence. Without an owner doing that work, you get an expensive dashboard with three completed rows. This is the most common trap of this route: the platform gets bought to "automate the problem away," while the problem lives in the people who have to feed it.
Internal effort. High up front. Someone has to configure the system, enter every AI system, assign owners and train them to keep it current. Ongoing: someone has to maintain the platform every time a new system appears or a supplier changes.
Timeline. The timelines in this article come from projects we run ourselves, not from market research; treat them as orders of magnitude, not as a promise. The software itself is live within days. A register that reflects reality takes weeks to months, depending on how many systems and suppliers you have.
When this is the wrong route. When nobody in the organization owns filling it in and keeping it current. If you do not yet know which systems you have, buying a platform before you have inventoried anything is spending money on an empty box.
Route 2: an external adviser or implementation partner
What you buy. Expertise and speed. An adviser knows the regulation, has done prior classifications, and structures the project so you do not have to work out yourself what an FRIA is or when Article 26(5) applies. Advisory engagements are usually priced fixed per phase (scan, classification, gap analysis, implementation) or hourly.
As a concrete benchmark: Embed AI publishes fixed prices for deployers within confirmed scope, excluding VAT. A guided AI governance scan at 2,950 euros, deductible once against a follow-up engagement that starts within sixty days. An AI Act Readiness Sprint at a fixed 9,900 euros, covering register, classification, gap analysis, ownership and a 30-60-90 day roadmap. An AI Act Compliance Bundle at a fixed 21,900 euros, adding supplier evidence, Article 4 evidence, policy and implementation. Providers (organizations that place their own AI system on the market) fall outside these fixed prices and get a custom quote, because their obligations are substantially heavier. These are not market averages, they are a single example of how a fixed engagement is structured; other firms price differently, and you should ask about this structure on every quote you receive.
What it doesn't solve. Ownership after the engagement ends. The classic risk of this route is the report that sits in a drawer: an adviser delivers a gap analysis and a roadmap, and nobody inside the organization feels responsible for actually executing it. An advisory report is not compliance. It is a route map. If nobody follows it, nothing changes.
Internal effort. Lower than doing it yourself, but not zero. An adviser can supply the method and the legal interpretation, but the factual input (which systems, which suppliers, which data) still has to come from internal staff. Budget for an internal project lead who makes time to answer questions and supply documents.
Timeline. A scan is done in days to a few weeks. A bounded readiness phase takes a few weeks. A full project that also collects supplier evidence and implements policy runs longer, and the deciding factor is almost always how quickly suppliers respond, not how fast the adviser works.
When this is the wrong route. When all you want is a report without anyone internally taking ownership afterward. An adviser can classify and advise, but cannot enforce the policy inside your organization once the engagement is over.
Route 3: doing it in-house with your own people
What you buy. Nothing, in cash terms. You allocate compliance, legal or IT staff time they would otherwise spend on something else. The direct cost is hidden in payroll, not in an invoice.
What it doesn't solve. The first classification question. Most in-house projects stall the moment someone has to determine whether a system falls under Annex III, whether the organization is a provider or a deployer in the chain, and what evidence a regulator would want to see. Without a reference framework (the regulation text, guidance, precedent), that question is easy to get wrong in either direction: classifying too strictly wastes implementation effort, classifying too loosely leaves a real obligation unaddressed.
Internal effort. Total. This is the route where internal hours are not shared with a vendor or adviser. Budget weeks of work for a single qualified person, or months if the task is added on top of a regular role.
Timeline. The longest of the three routes, usually because the work competes with existing responsibilities and rarely gets the priority it needs.
When this is the wrong route. If the organization is a provider (places its own AI system on the market or puts it into service under its own name), or if the applications sit in HR, credit, healthcare, education, essential services or government decision-making. Those profiles require a heavier evidence layer and precise classification, where a wrong internal call can be expensive.
Comparison at a glance
| | Software / platform | External adviser | In-house | |---|---|---|---| | Cost structure | License per user/system + implementation + maintenance | Fixed per phase or hourly | Payroll cost, no direct invoice | | What you buy | Registration and tracking system | Expertise, speed, structure | Nothing, your own people's time | | Biggest risk | Empty register | Report in a drawer | Stalling on classification | | Internal effort | High (data entry and upkeep) | Medium (supplying input) | Total | | Timeline | Weeks to months for a register that reflects reality | Weeks to roughly 12 weeks for a full engagement | Usually the longest | | Best fit | Already classified, wants structure and tracking | Needs speed and legal certainty | Small, low-risk profile, time available |
What actually drives the bill
Four factors push the cost of every route up or down, regardless of which one you choose.
Your role in the chain. A deployer (you use an AI system someone else built) carries a substantially lighter obligation set than a provider (you place an AI system on the market or put it into service under your own name). Providers carry conformity assessment, technical documentation and quality management; that is a different order of work than a deployer who mainly needs to know what it is using and how.
The number of AI systems and suppliers. Every route scales with this number. Ten systems from three suppliers is a different project than sixty systems scattered across departments nobody has tracked centrally. Querying suppliers (training data, test results, technical documentation) is often the slowest step, because you depend on their response time.
The risk profile of the applications. Systems in HR, credit scoring, healthcare, education, essential services or government decision-making trigger a classification duty and a heavier evidence layer sooner1. For some of those applications (public authorities, private entities providing public services, creditworthiness assessments, life and health insurance assessments) a fundamental rights impact assessment is added, which can partly reuse an existing DPIA1. Those obligations become enforceable on the Annex III timeline, from December 2, 20271, but preparing for them (knowing which systems are affected) costs time now, regardless of when enforcement starts.
The difference between knowing where you stand and a file someone else can read. A spreadsheet you understand is not the same as a file a procurement officer in a tender or a regulator can read through: substantiated, sourced, with clear ownership and version control. Building the second version takes more time in every route, because it is not just gathering facts, it is making them presentable.
Certainty you cannot buy yet
One cost that gets forgotten is rework. The European standards that will let you demonstrate conformity with the high-risk requirements are still being developed by CEN-CENELEC under standardisation request M/6135. A harmonised standard only delivers a presumption of conformity once it is cited in the Official Journal. So when a supplier tells you today that its product makes you "compliant", you are buying a promise the standard itself cannot yet keep. That is not an argument for sitting still, it is an argument for spending on what stays necessary either way: knowing which systems you have, who owns them, and what the supplier can actually demonstrate.
What's free: Article 4 and Article 5
Not everything needs a budget. The obligations under Article 4 (AI literacy) and Article 5 (prohibited practices) have applied since February 2, 20251, and mostly require behavior and documentation, not software or an adviser. Article 4 was rewritten as of July 27, 2026 into a measures obligation2: the organization takes measures that support AI literacy, it does not guarantee any individual skill level3. In practice that means: an internal policy on what AI use is allowed, an overview of who uses which systems, and a few hours of training, documented. Article 5 prohibits practices such as social scoring and certain forms of manipulative influence4; checking that you are not exposed there is a conversation and a short review, not an implementation project. This is the cheapest step every organization can take now, independent of whichever route you choose for the rest.
A decision rule by organization type
A small organization with a handful of AI applications, all bought off the shelf and low risk, usually gets by with doing it in-house plus the free steps under Articles 4 and 5, and only brings in software or advice once a tender or a specific high-risk application appears. A mid-size organization with ten to thirty systems scattered across departments usually gets the most value from an advisory engagement for the first inventory and classification, followed by software to maintain it afterward. An organization that places its own AI systems on the market, or that operates in HR, credit, healthcare, education, essential services or government decision-making, should not rely on doing it in-house for the classification question; the cost of getting that call wrong outweighs the cost of getting help.
Ask every quote, from every vendor, this one question: does scope include inventory, classification, ownership, supplier evidence and implementation, or are you only buying part of that and having to add the rest internally? A quote that does not make that explicit is one where you discover the real bill later.
Frequently asked questions
What does EU AI Act compliance cost on average?
There is no average, and any number you get without questions first is a guess. The bill is driven by your role in the chain, the number of AI systems and suppliers, and the risk profile of your use cases. As a reference point: at Embed AI a guided governance scan costs EUR 2,950, a Readiness Sprint EUR 9,900 fixed and the Compliance Bundle EUR 21,900 fixed, excluding VAT, for deployers within a confirmed scope.
Is software cheaper than an adviser?
On the invoice, often yes. In total cost, frequently not. Software does not fill itself: someone has to enter every system, answer the classification question and collect the evidence. Count the internal hours before you compare the two, otherwise you are comparing a licence with a complete project.
Can we do this ourselves?
For an organisation with a handful of known systems, a low risk class and someone who genuinely gets time for it: yes. Where in-house work stalls, it is almost always on the classification question or on suppliers who do not answer. If you work in HR, credit, healthcare, education, essential services or public decision-making, the cost of getting the classification wrong is higher than the cost of help.
What has to happen now and what can wait?
Article 5 (prohibited practices) and Article 4 (measures for AI literacy) have applied since 2 February 2025, and Article 50 (transparency) since 2 August 2026. The high-risk duties in Annex III become enforceable on 2 December 2027. Waiting to take inventory is still unwise: this year's procurement decisions determine what can still be fixed in 2027.
What should I ask of every quote?
This: are inventory, classification, ownership, supplier evidence and implementation in scope, or am I buying only part of that? A quote that does not make this explicit leaves the rest for you to discover internally later.

