What This Costs, Both Ways
What an engagement with us costs, and what the regulations say on the other side. Regulatory penalty is the headline number, but it's rarely the one that bites first โ deals stall and evidence gets rebuilt by hand long before a regulator calls.
Engagement Scoping Calculator
This shows our actual pricing, not a risk score. We're not going to invent a dollar figure for your exposure โ nobody can calculate that from three inputs, and a number that looks precise is worse than no number at all.
Single-phase engagement. Fixed price agreed in writing before any work begins.
Framework applicability depends on your role in the value chain โ provider, deployer, importer or distributor โ and on your system's risk classification. That's determined during an assessment with your counsel, not by a slider. This is orientation only.
The Penalty Tiers, As Written
Maximum administrative fines under the EU AI Act. In each tier the higher of the two figures applies; reduced caps apply to SMEs and startups.
Prohibited AI practices โ manipulative systems, exploitation of vulnerabilities, social scoring, unauthorised biometric identification.
Breach of high-risk system obligations โ risk management, data governance, record-keeping, transparency, human oversight.
Supplying incorrect, incomplete or misleading information to notified bodies or national authorities.
For comparison, GDPR caps at โฌ20M or 4% of global annual turnover. The AI Act's top tier was deliberately set above it โ and the two regimes apply in parallel, not instead of one another.
Where The Deadlines Actually Sit
The 2026 revisions moved several dates. Reflecting the timeline as it currently stands.
General-purpose AI obligations
Transparency and documentation duties for GPAI model providers began applying.
Article 50 transparency duties
Users must be told when they're interacting with an AI system. This date was not moved by the revisions.
Synthetic content marking & Art. 5 prohibitions
Machine-readable marking of AI-generated or manipulated output, and the prohibited-practices regime, take effect on this track.
Annex III high-risk systems
Stand-alone high-risk obligations โ pushed back from August 2026 to give standards bodies time to publish. The requirements themselves were not reduced.
Annex I product-regulated high-risk
AI embedded in products already covered by EU product-safety law โ postponed from August 2027.
Summarised for orientation, not legal advice. Applicability depends on your role in the value chain and your system's risk classification โ confirm with counsel.
The Costs That Land First
Deal cycles stretch
Enterprise security review is where AI features go to wait. Without evidence of output controls, an AI questionnaire adds weeks to a cycle that was already long โ and it lands at the worst moment, right before signature.
Evidence gets rebuilt by hand
Reconstructing what a model returned, to whom, under which prompt version, from application logs that were never designed for it. This is engineering time, not compliance time โ and it recurs every audit cycle.
Features ship disabled
The most common outcome isn't a fine โ it's an AI feature that ships behind a flag for two quarters because nobody can sign off on what it might output to a regulated customer.
Retrofit costs compound
Adding governance to one pipeline is a config change. Adding it to eleven, after they've each grown their own prompt conventions and logging, is a project with a headcount attached.
Get a real number, not a slider
Fifteen minutes against your actual pipeline inventory gives you something you can take to a board.