AI + Cost

What does an EU AI Act readiness assessment cost?

Huceptron InsightsBy the Huceptron senior partners·5 min read

Most firms will not publish a price for this, which is itself informative. The honest answer is that it depends on how many AI systems you run and whether any of them are high-risk - and that you can usually tell which band you are in before anyone quotes you.

What actually drives the price

The number of systems. The inventory is the bulk of the first pass, and it scales with how many tools are in use rather than how big the company is. A thirty-person firm running fifteen AI tools is more work than a three-hundred-person firm running four.

Whether anything is high-risk. This is the step change. A company with nothing in Annex III needs a review. A company running AI in recruitment or credit decisions needs a programme, because the Act requires a risk management system, data governance, technical documentation, logging and human oversight for each such system.

Whether you are a provider. If you build and place AI on the market under your own name, conformity assessment obligations attach that deployers simply do not carry.

How much already exists. A firm with ISO 27001, a data protection function and a risk register is starting halfway up. One starting from nothing is paying for the foundations too.

What you should get for the money

Insist on artefacts, not a report. A readiness assessment that produces only a document is a questionnaire with a covering letter.

The deliverables that matter: a system inventory you can maintain yourself; a risk classification of each system against the Act with the reasoning shown; a gap analysis against the obligations that actually apply to you, not all of them; an evidence pack - the documents you would hand a regulator or a procurement team; and a prioritised remediation plan with dates and owners.

And one thing most providers will not give you: a plain statement of where you do not need help. If everything in the report needs remediation, read it twice.

What we charge

We publish our prices, which is unusual in this market and deliberate.

The AI audit using recognised frameworks - ISACA AAIA, ISO/IEC 42001, NIST AI RMF 1.0 and the EU AI Act - is EUR 3,500 for a working week. It produces the inventory, risk classification against the Act, control and evidence gaps, an evidence pack and a prioritised remediation plan.

The TCM readiness assessment and programme blueprint is EUR 3,500 per working week, sized by company. This is the broader transformation review, of which AI governance is one dimension of forty-two.

For a company that simply wants to know whether it has a problem, a one-hour consultation is EUR 400, refunded in full if you do not find it useful. Most companies should start there rather than with a week of anybody's time.

Buying an assessment in the UK, the United States or Australia

There is no licence to audit AI anywhere in the world. That is worth saying plainly, because a great deal of marketing implies otherwise.

United Kingdom. The government is building a profession rather than regulating one. DSIT published a trusted third-party AI assurance roadmap in September 2025; an AI Assurance Stakeholder Consortium led by BCS has been running since June 2026 and is working on a code of ethics, a skills framework and certification pathways, none of them published yet; a Centre for AI Measurement was announced at the National Physical Laboratory in January 2026. The one scheme that looked as though it would become a procurement gate, AI Management Essentials, was cancelled in February 2026. So today, in the UK, nothing about an assurance provider is verified by anyone.

United States. No scheme at all, with one exception that is worth knowing because it is the only statutory independence test on the market. New York City requires the bias auditor of an automated employment decision tool to be genuinely independent: no employment relationship with the employer, no involvement in building or distributing the tool, and no financial interest in either. That is a reasonable standard to hold any assessor to, whatever your jurisdiction.

Australia. No scheme either. Certification bodies are accredited by JAS-ANZ for ISO/IEC 42001, which tells you something about a certifier and nothing about an advisor.

What to ask instead of asking for a credential. Ask what register the assessment starts from and who fills it in. Ask for the mapping: every finding tied to a named article, section or rule, not to a theme. Ask which gaps will be named as out of scope and why. Ask who signs. And ask the New York City question - does the firm have a financial interest in the remediation it is about to recommend.

Our own answer: the week is fixed price, the register and the mapping come with it, and we deliver it in Ireland, the United Kingdom, the United States and Australia through our representation in those countries.

What you can do yourself for nothing

Genuinely: build the inventory. It is an afternoon, it needs no procurement, and it answers the first question anyone will ask you. If the inventory comes back short and boring, you may well not need us at all - and we would rather tell you that early than discover it in week two.

Where we earn the fee is the judgement calls: whether a borderline system is Annex III, what evidence will actually satisfy your sectoral regulator, and what can safely be left until 2027.

One week. Then you know.
The AI audit week - what applies to you, where the gaps are, and what to do first
See what the week covers →