European businesses are racing to meet the first enforcement deadline of the European Union’s Artificial Intelligence Act, with compliance costs projected to reach between €4 billion and €6 billion across the bloc, according to a new analysis published Tuesday by the Centre for European Policy Studies.
The regulation, which entered into force in 2025, begins its phased implementation this summer with prohibitions on unacceptable-risk AI practices — including social scoring, real-time biometric surveillance in public spaces, and manipulative AI systems. Companies found in breach face fines of up to €35 million or 7% of global annual turnover, whichever is higher.
“We are seeing a scramble unlike anything since GDPR,” said Dr. Elena Vasquez, director of AI governance at consultancy Forvis Mazars. “Firms that dismissed this as a Brussels abstraction are now confronting the reality that their existing AI deployments — from recruitment screening tools to credit-scoring algorithms — may require fundamental redesign or abandonment.”
The Act adopts a risk-based tiered framework. High-risk AI systems used in critical infrastructure, education, employment, and law enforcement must comply with stringent transparency, documentation, and human oversight requirements. General-purpose AI models, including large language models, face separate obligations around training data disclosure and systemic risk assessment.
CEPS estimates that approximately 40% of European enterprises currently use at least one AI system that will fall into the high-risk category. The financial services sector is expected to shoulder the heaviest compliance burden, accounting for roughly a third of total projected costs, followed by healthcare and insurance.
“The cost is significant, but so is the opportunity cost of non-compliance,” said Marcus Lindström, senior policy fellow at the Digital Europe Institute. “The EU market represents 450 million consumers. For any global technology firm, walking away isn’t a realistic option. What we’re witnessing is the emergence of a new compliance industry — law firms, consultancies, and software vendors are building entire practices around AI Act readiness.”
Small and medium-sized enterprises face particular challenges, with limited resources to conduct the required conformity assessments. The European Commission has pledged €200 million in support through its Digital Europe Programme, but industry groups warn this falls well short of what is needed.
Looking ahead, the next major milestone arrives in mid-2027, when obligations for high-risk AI systems come fully into force. With Japan, Canada, and several U.S. states developing their own AI governance frameworks, the EU’s approach is increasingly viewed as a bellwether for global regulatory trends. “Compliance isn’t just a cost centre,” Vasquez added. “Firms that get this right will have a structural advantage when similar frameworks emerge in other jurisdictions.”