AI Act, GDPR, sovereignty: the real cost of AI compliance in 2026
The AI Act framework comes into full application in 2026. Here are the 3 real cost centres that IT and legal directions still underestimate, and how we cost them in scoping missions.

The European AI Act came into force in August 2024. Its main obligations apply progressively between 2025 and 2027. Legal directions are preparing for it. IT directions, however, often discover during the project the real operational cost, which goes well beyond the purely legal scope.
Cost centre 1: mapping AI systems in place
Before qualifying a system (unacceptable, high, limited, minimal risk), you need to know what you have in production. Yet most large companies don't have an up-to-date inventory. Models have been deployed by business units, sometimes via third-party SaaS, with no central visibility. Count 4 to 12 weeks of mapping for an organisation of 1,000 people.
Cost centre 2: technical documentation and traceability
For systems qualified as high risk, the AI Act requires detailed technical documentation: datasets used, training methodology, performance metrics, usage logs. This requires an MLOps toolchain that few organisations have. For a high-risk system, instrumentation cost is significant from the first year.
- Model registry with versioned metadata
- Timestamped inference logs kept 6 years minimum
- Continuous bias and drift evaluation pipeline
- Documented human supervision procedure
Cost centre 3: data sovereignty and model choice
For sensitive data (health, HR, financial, industrial secret), using mainstream US models becomes legally risky, or simply contractually banned by large clients. The fix: intelligent routing to hosted European models (Mistral, Pléiade, Azure EU deployments) for sensitive flows, global models for the rest. Infrastructure overhead varies depending on the mix.
« The cost of AI compliance is not a potential fine. It's a recurring opex line that has to be in the TCO of every project from scoping. »
How to cost it in scoping
Our method: for each contemplated use case, we produce a 1-page compliance fiche (AI Act risk class, data involved, recommended model, estimated annual overhead). It's attached to the business case at go/no-go. Which avoids nasty surprises 6 months later when the DPO blocks the deployment.
The AI Act is not a brake. It's a reading grid that forces organisations to stop launching AI projects blind. Done well, compliance becomes a commercial asset, especially with large clients who now require an AI governance attestation in their RFPs.


