Skip to main content
Compliance2 min read

AI Act, GDPR, sovereignty: the real cost of AI compliance in 2026

The AI Act framework comes into full application in 2026. Here are the 3 real cost centres that IT and legal directions still underestimate, and how we cost them in scoping missions.

By Laurent Falise — CEO, ProofPilot
Legal compliance office: stack of cream folders tied with a burgundy ribbon, open binder with highlighted passages and brass lamp

The European AI Act came into force in August 2024. Its main obligations apply progressively between 2025 and 2027. Legal directions are preparing for it. IT directions, however, often discover during the project the real operational cost, which goes well beyond the purely legal scope.

Cost centre 1: mapping AI systems in place

Before qualifying a system (unacceptable, high, limited, minimal risk), you need to know what you have in production. Yet most large companies don't have an up-to-date inventory. Models have been deployed by business units, sometimes via third-party SaaS, with no central visibility. Count 4 to 12 weeks of mapping for an organisation of 1,000 people.

Cost centre 2: technical documentation and traceability

For systems qualified as high risk, the AI Act requires detailed technical documentation: datasets used, training methodology, performance metrics, usage logs. This requires an MLOps toolchain that few organisations have. For a high-risk system, instrumentation cost is significant from the first year.

  1. Model registry with versioned metadata
  2. Timestamped inference logs kept 6 years minimum
  3. Continuous bias and drift evaluation pipeline
  4. Documented human supervision procedure

Cost centre 3: data sovereignty and model choice

For sensitive data (health, HR, financial, industrial secret), using mainstream US models becomes legally risky, or simply contractually banned by large clients. The fix: intelligent routing to hosted European models (Mistral, Pléiade, Azure EU deployments) for sensitive flows, global models for the rest. Infrastructure overhead varies depending on the mix.

« The cost of AI compliance is not a potential fine. It's a recurring opex line that has to be in the TCO of every project from scoping. »

How to cost it in scoping

Our method: for each contemplated use case, we produce a 1-page compliance fiche (AI Act risk class, data involved, recommended model, estimated annual overhead). It's attached to the business case at go/no-go. Which avoids nasty surprises 6 months later when the DPO blocks the deployment.

The AI Act is not a brake. It's a reading grid that forces organisations to stop launching AI projects blind. Done well, compliance becomes a commercial asset, especially with large clients who now require an AI governance attestation in their RFPs.

By
Laurent Falise
CEO, ProofPilot
Share on

Got an AI project to scope?

30 minutes on a call to challenge your use case and quantify ROI.