The Orphan Line Item
The EU AI Act's high-risk AI obligations became enforceable in August 2026 with no harmonised standards published and almost no notified bodies designated — the infrastructure the regulation assumed would exist. What arrives instead is a bill finance did not forecast: third-party conformity assessment at €50,000–150,000 per system, months-long queues for notified-body slots, and recurring annual costs at 20–40% of initial spend. The compliance deadline has moved; the invoice has not.
The EU AI Act entered into force in August 2024. High-risk AI obligations become fully applicable on 2 August 2026, with enforcement powers live. The enforcement powers of the AI Office and national competent authorities apply from 2 August 2026. The penalty structure matches GDPR in structure but exceeds it in scale: non-compliance with prohibited AI practices can result in fines up to €35 million or 7% of a company's annual turnover, while other violations can result in fines up to €15 million or 3% of annual turnover.
What has not materialised is the infrastructure the Act assumed would exist by now.
No harmonised standards have been published in the Official Journal. No notified bodies are formally designated in the NANDO database for AI Act assessments. As of March 2026, the designation process is ongoing. Very few bodies have been fully designated specifically for AI Act conformity assessment. Notified bodies are the third-party organisations that member states designate to assess whether high-risk AI systems comply with the Act before they can be placed on the EU market. Without them, companies building systems for biometric identification, critical infrastructure or employment decisions cannot complete the conformity assessment required by law. Experience shows that a conformity assessment takes 3-6 months, and delays in conformity assessments can increase time-to-market by 3-6 months.
The person who discovers this gap is not the chief legal officer or the compliance lead. It is the finance owner who opens a vendor proposal in June and learns that the consultancy scoped €150,000 for third-party assessment, the notified body will charge another €50,000, the timeline assumes a nine-month queue, and none of it was forecast because the legal team believed self-assessment would suffice.
The presumption that will not arrive
If your system complies with a harmonised standard covering a specific requirement, you are presumed to meet that requirement. This simplifies enforcement: the standard is the benchmark, and compliance with it is a defensible position. That presumption saves money. A self-assessment following a published standard is documentation work that a compliance officer and an engineer can complete internally. Self-assessment runs EUR 20,000-50,000 in internal effort depending on system complexity and existing documentation.
The alternative is to demonstrate compliance directly against the regulation text, with no standard to follow and no safe harbour. Third-party assessment runs EUR 50,000-150,000 or more, including notified body fees, remediation cycles, and the time cost of external coordination. Certain categories of high-risk AI, such as remote biometric identification systems, cannot use self-assessment at all under Article 43 of the regulation. They must go through a notified body. There is no self-assessment shortcut for biometrics until standards are finalized, published in the Official Journal, and applied by the provider. That sequence will not complete before August 2026.
The standards were meant to be ready. CEN and CENELEC, the European standardisation bodies, began work in 2024. The Commission cited concerns that neither industry nor the harmonized standards bodies would be ready in time, and that the conformity-assessment infrastructure the Act assumes would exist had not yet matured. The Commission recognises that the infrastructure is not ready — harmonised standards are not published, notified bodies are not designated in sufficient numbers, and many member states have not established their competent authorities.
The companies that need certification do not control the standards process, the notified-body accreditation pipeline, or the timeline. What they control is their budget, and the conversation that happens when the CFO sees a six-figure line item appear that legal said would be handled internally.
Who carries the designation lag
Each Member State should have designated and empowered national competent authorities until 2 August 2025. Notifying authorities in turn designate notified bodies. Notified bodies must be established under a member state's national law and have legal personality. They must meet certain organizational, quality management, resource, and cybersecurity requirements. They must be independent of the providers they assess and of competitors. They need staff who understand AI risk management, domain expertise in the sector they are assessing, and accreditation from a national body.
That takes time. The notified body ecosystem for the AI Act is not ready. The designation process commenced on 2 August 2025. Initial designation of sufficient notified bodies is still ongoing as of September 2025. While some bodies already have designation for related areas (like medical devices), specific AI Act designation takes time.
The bodies that do exist are rebuilding assessment procedures from adjacent fields. A notified body approved for medical devices under the Medical Device Regulation or machinery under the Machinery Regulation can assess the product layer, but AI-specific obligations around data governance, bias monitoring, transparency and post-market surveillance are new territory. Existing notified bodies under product legislation (MDR, Machinery Regulation, etc.) can assess AI components within their existing scope, but AI-specific designation takes time.
The lag creates a queue. If five notified bodies are designated across the EU by August 2026, and several hundred companies need third-party assessment before placing high-risk systems on the market, the arithmetic is unforgiving. Capacity is limited. Timelines are uncertain. A company that files an assessment request in July 2026 may receive a start date in 2027.
The cost of the queue is not just the assessment fee. It is revenue deferred, launches postponed, procurement cycles lost to competitors who finished assessment earlier or who are not subject to the regulation because they deployed before the deadline. Delays in conformity assessments can increase time-to-market by 3-6 months. For a SaaS company selling into enterprise accounts, a six-month delay is two quarterly sales cycles where the product cannot be legally sold into the EU.
The certification ladder nobody priced
ISO 42001 is the international standard for AI management systems, published in December 2023. It is voluntary. The EU AI Act is mandatory. The two are not the same, but companies are buying both. For B2B organizations selling AI into enterprises or regulated sectors, ISO 42001 certification is quickly becoming a baseline expectation, similar to what ISO 27001 and SOC 2 are for security.
Most organizations spend between €15,000 and €200,000 in total to achieve ISO 42001 certification. Small companies with one or two AI systems in scope typically land between €15,000 and €40,000, mid-size organizations between €40,000 and €90,000, and large enterprises at €90,000 to €200,000 or more. Organizations with 50 to 200 employees invest between €85,000 and €150,000 for their first ISO 42001 certification. That is initial certification. Annual surveillance audits cost €3,500-9,000, and a full recertification audit occurs at year three. Total cost over three years for a mid-sized company: €250,000-350,000.
The EU AI Act conformity assessment is separate. Organisations combining this with a management-system approach should first get the difference between ISO 42001 certification and AI Act conformity straight: certifying the wrong thing means paying twice. ISO 42001 demonstrates that you have a management system for AI governance. EU AI Act conformity assessment demonstrates that a specific high-risk AI system meets the requirements in Chapter III of Regulation 2024/1689. They use different documentation, different assessors, and deliver different certificates.
A company that decides in early 2025 to pursue both will spend the ISO 42001 budget, complete that certification by mid-2026, and then discover that the EU AI Act assessment still requires technical documentation the ISO process did not produce, a post-market monitoring plan with different obligations, and a notified body that may or may not accept the ISO certificate as evidence of anything useful.
Conformity assessments for high-risk AI systems cost between €5,000 and €50,000 per system. Documentation preparation accounts for up to 40% of total assessment costs. Large enterprise or provider of high-risk AI: €100,000 to €500,000 or more, spread over the run-up to 2 December 2027. Focus: conformity assessment, quality management system, technical documentation, ongoing monitoring.
Finance sees the ISO invoice in Q2, the AI Act assessment quote in Q3, and the compliance-tool subscription renewal in Q4. Three separate vendors, three separate deliverables, cumulative cost trending toward half a million euros for a portfolio of four high-risk systems. None of it shows up in a product P&L because compliance does not ship features. It sits in an overhead cost centre, attributed to "AI governance", a line that did not exist in the 2024 budget.
The extension that moved the bill, not the amount
On 29 June 2026, the Council of the European Union gave final approval to the Digital Omnibus simplification package, formally pushing back the compliance deadline for stand-alone high-risk AI systems under Annex III from 2 August 2026 to 2 December 2027. High-risk AI systems embedded in regulated products receive a parallel 12-month extension, moving their deadline from 2 August 2027 to 2 August 2028.
The deferral provides 16 additional months to complete conformity assessments. It does not reduce the assessment cost, the notified-body fee, the documentation burden, or the recurring surveillance cost. Both categories retain their full substantive obligations; only the compliance clock has moved. The Article 50 transparency obligations requiring disclosure of AI interactions remain in force on their original 2 August 2026 schedule. Only the narrower watermarking requirement for systems already deployed receives a four-month grace period to 2 December 2026.
What the extension does is spread the spending. A company that would have paid €180,000 in H2 2026 to meet the August deadline can now phase that across 2027. Cash flow improves. The total invoice does not.
The deeper problem is recurring cost. Expect 20-40% of the initial investment per year for register maintenance, retraining and monitoring. A high-risk system that costs €120,000 to certify in 2027 will require €24,000-48,000 per year in post-market monitoring, documentation updates, and eventual recertification. Multiply that by the number of systems in the portfolio, add the ISO 42001 surveillance audits, and add the GRC platform subscription that automates evidence collection.
Large enterprises may spend $1 million annually on AI Act compliance programs. That is operational cost, every year, for as long as the systems remain on the market. It does not deliver new models, faster inference, or better accuracy. It delivers the legal right to continue selling what you already built.
The sovereignty backstop nobody wants to explain
The United States issued an AI Diffusion Framework on 15 January 2025. BIS revises the Export Administration Regulations' controls on advanced computing integrated circuits and adds a new control on artificial intelligence model weights for certain advanced closed-weight dual-use AI models. The new interim final rule imposes new global licensing requirements, controls for closed AI model weights, and updated data center validated end-user authorizations. The interim final rule was effective 13 January 2025, with compliance generally effective 15 May 2025.
Since October 2022, the United States has devoted significant resources to restricting China's access to AI and advanced semiconductor technologies. On 2 December 2024, it released two rules that added 140 companies to the Entity List, expanded the scope of the Foreign Direct Product Rule, and restricted new technology areas such as high-bandwidth memory.
European companies deploying AI on US-controlled cloud infrastructure or using US foundation models now face a second compliance layer. Regional deployment from a US provider does not equal sovereignty. The US CLOUD Act still applies to US-headquartered companies regardless of data center location. If personal data of EU residents is used to train a model on infrastructure located outside the EEA, the training run itself is a transfer. The legal mechanism must cover that specific processing activity.
The global sovereign cloud market is projected to grow to $195.35 billion in 2026, with Europe leading the charge. AWS European Sovereign Cloud launched in January 2026 as a German-incorporated entity, physically and logically separate from other AWS regions, with EU-resident leadership and 90 initial services. Microsoft Azure Sovereign uses a multi-layered approach including public cloud controls, private deployments, and partner clouds. EU Data Boundary ensures customer data stays in EU.
Finance sees sovereign cloud pricing that runs 30-50% higher than standard regions, model API calls restricted to EU endpoints where the latest versions lag US availability by weeks or months, and contracts that require separate DPAs, export-control attestations, and architectural reviews before a single GPU hour is billed.
The AI Act conformity assessment assumes you can document where training data was processed, which jurisdiction governed the compute, and which legal entity controlled the model weights. If the answer involves three subsidiaries, two cloud providers, and a foundation model licensed under terms that forbid disclosing the training location, the documentation does not close. The notified body flags it. You pay for another remediation cycle.
The contract this piece will not end on
I would not bet the EU simplifies this. The Digital Omnibus moved one deadline. It did not merge ISO 42001 and AI Act conformity, fund notified-body designation, publish the harmonised standards, or exempt SMEs from third-party assessment. The architecture remains: separate certifications, overlapping timelines, vendor-driven cost, and compliance as a permanent line in the P&L.
The finance owner writing the 2027 budget knows three things. The external assessment cost will recur at 20-40% of the initial spend. The number of systems in scope will grow as product teams ship new features. And the regulatory floor will rise, because the EU, the US, and China are all tightening rules on the same 18-month cycle.
What makes it defensible is not the absolute euro amount. It is whether the revenue those systems generate exceeds the cost to keep them compliant. A high-risk recruitment AI that adds €2 million in annual contract value and costs €180,000 to certify, then €50,000 per year to maintain, clears the bar. A pilot system serving 400 users that requires the same certification does not.
The CFO's question in December 2027 will be the same one finance asked in manufacturing when ISO 9001 rolled out, in SaaS when SOC 2 became table stakes, and in privacy when GDPR landed: which systems justify the ticket price, and which ones do we turn off because compliance costs more than the line brings in?
That calculation is not a regulatory problem. It is a portfolio problem. The regulation set the floor. The market will decide which AI systems can carry the weight.
Tarry Singh is the founder and CEO of Real AI (realai.eu), an enterprise AI advisory and deployment firm working with global enterprises on production agent systems, model risk, and AI sovereignty strategy. He also leads Earthscan (earthscan.io) for Energy AI, and is a founding contributor to the EU-funded HCAIM and PANORAIMA programmes for responsible AI education across European universities. He writes at tarrysingh.com.