Try all features for free — 3 credits included on sign-upTry for free
Skip to main content
Regulation · AI Strategy

Investing in AI without risking a €35 million fine.

Since 2 August 2026, the AI Act has strictly regulated AI investments for European businesses. A constraint? Rather, an opportunity to structure projects that are both high-performing and compliant, while avoiding the pitfalls of prohibited practices and misclassified systems.

Jérémy Pierre
Jérémy Pierre
AI Act Compliance Expert
8 August 2026 7 min read
Investing in AI for Business: Balancing Performance and Compliance
Key takeaways · 4 figures to remember
7%
of AI projects in businesses exceed their initial budget
€35M
maximum fine for non-compliance with the AI Act
62%
of executives cite compliance as a barrier to AI adoption
2027
deadline for high-risk AI systems under Annex III
01 - Regulation

Why the AI Act changes everything for your AI investments

The entry into force of the AI Act on 1 August 2024 marked a turning point for European businesses. From now on, every AI investment must be assessed against two criteria: return on investment and regulatory risk level.

Regulation (EU) 2024/1689 introduces a classification of AI systems into four categories: prohibited, high-risk, limited-risk and minimal-risk. This classification determines the applicable obligations, as well as the cost and complexity of compliance. For example, a credit scoring system classified as high-risk will require exhaustive technical documentation, robustness testing and post-deployment monitoring, which can account for up to 30% of the project's initial budget.

According to several studies, nearly 60% of AI projects in businesses fail to meet their initial objectives, often due to poor assessment of technical and regulatory constraints. The AI Act now requires executives to integrate these parameters from the design phase, which can paradoxically improve project success rates.

"The AI Act is not a barrier to innovation, but a framework for innovating responsibly and sustainably. Businesses that anticipate it gain a competitive advantage."

Transparency obligations, applicable since 2 August 2026 for generative AI systems, add an additional layer of complexity. Businesses must now inform users when content is generated by AI, which can impact user experience and require technical adjustments.

02 - Strategy

The 3 pillars of smart and legal AI investment

To balance performance and compliance, businesses must structure their AI investments around three pillars: system classification, risk assessment and proactive documentation.

1. Classify your AI systems from the outset

The first step is to determine the risk category of each AI project. This classification determines the applicable obligations and the level of investment required for compliance. The AI Office provides practical guidance to help businesses classify their systems, but legal analysis is often necessary for borderline cases.

2. Assess regulatory and operational risks

Each AI project must undergo a risk assessment covering both regulatory aspects (AI Act compliance, GDPR) and operational aspects (bias, robustness, impact on users). This assessment must be documented and updated regularly. Businesses can rely on existing frameworks such as the AI Risk Management Framework from the European Commission.

3. Document proactively to save time

The technical documentation required by the AI Act (Annex IV) can represent a significant cost if done retrospectively. By integrating this documentation from the development phase, businesses can reduce these costs by 40 to 60%, according to a Capgemini study. This approach also helps better anticipate testing and validation needs.

Reference
Article 9 AI Act - Risk assessment
Obligation
Documentation of risk assessments for high-risk AI systems
03 - Methodology

Classifying your AI projects: the risk/ROI matrix

To prioritise their AI investments, businesses can use a matrix that crosses the level of regulatory risk with the expected return on investment. This approach helps identify high-potential projects while controlling compliance costs.

Risk level High ROI Medium ROI Low ROI
High-risk Top priority (e.g., medical diagnosis) Case-by-case evaluation (e.g., credit scoring) Avoid (e.g., emotional surveillance)
Limited-risk Major opportunity (e.g., customer chatbots) Pilot projects (e.g., productivity tools) Abandon (e.g., cosmetic AI features)
Minimal-risk Safe investment (e.g., spam filters) Develop in-house (e.g., reporting tools) Not a priority (e.g., AI for email decoration)

This matrix helps avoid two common pitfalls: investing in high-risk projects with no guaranteed return, or neglecting low-risk opportunities with high potential. For example, a fraud detection tool in the banking sector may be classified as high-risk, but its high ROI justifies the compliance investment.

For high-risk systems, businesses must allocate a specific budget for compliance, which can represent up to 25% of the total project cost. This budget covers technical documentation, robustness testing, team training and post-deployment monitoring.

04 - Sectors

Sector-specific case studies: where to invest first?

Healthcare: AI diagnostics under close scrutiny

In the healthcare sector, AI systems used for diagnosis or treatment are classified as high-risk. Investments must therefore be accompanied by exhaustive technical documentation and rigorous clinical testing. However, the ROI can be very high, with estimated savings of 20-30% on diagnostic costs.

Example: A French hospital invested in an AI system for medical imaging analysis. By integrating compliance from the development phase, the institution reduced compliance costs by 40% and obtained CE certification more quickly.

Banking and insurance: credit scoring under the AI Act

Credit scoring systems are also classified as high-risk. Banks must document their algorithms, prove the absence of discriminatory bias and implement mechanisms for customer redress. These requirements may seem onerous, but they also offer an opportunity for differentiation.

Example: A European bank used its AI Act compliance as a commercial argument, highlighting the transparency and fairness of its scoring system. Result: a 15% increase in market share among young professionals.

Retail: generative AI for personalising the customer experience

In retail, generative AI systems (chatbots, personalised recommendations) are classified as limited-risk. Transparency obligations apply, but compliance costs remain manageable. The ROI can be very high, with estimated gains of 10-20% on average basket size.

Example: A major retailer deployed an AI chatbot to advise online customers. By clearly informing users about AI usage and allowing human intervention, the company improved its conversion rate by 12% while remaining compliant with the AI Act.

Reference
Annex III AI Act - High-risk AI systems
Obligation
Technical documentation and testing for high-risk AI systems
05 - Financing

Financing compliance without breaking the bank

AI Act compliance represents an additional cost for AI projects, but several levers can help control this budget without sacrificing performance.

1. Integrate compliance from the outset

The cost of compliance can be reduced by 40 to 60% if integrated from the project design phase. This approach, known as Privacy by Design or Compliance by Design, helps avoid delays and additional costs linked to late modifications.

2. Pool costs with sector-specific consortia

Several sectors have created consortia to pool compliance costs. For example, in healthcare, hospitals and startups collaborate to develop common testing and documentation frameworks. This approach reduces costs while improving system quality.

3. Use public and EU funding

The European Union and Member States offer funding to support businesses in their transition to compliant AI. For example, the Digital Europe Programme funds AI R&D projects, with a focus on regulatory compliance. SMEs can also benefit from national grants for compliance.

4. Outsource compliance to experts

For businesses without in-house resources, outsourcing compliance to specialised firms can be a cost-effective solution. These experts can help classify systems, draft technical documentation and train teams, while avoiding costly mistakes.

Are your AI projects compliant?

Identify your AI Act obligations in 3 minutes with our free assessment. Prioritise your investments based on risk and ROI.

06 - FAQ

Frequently asked questions

Everything you need to know to invest in AI with confidence.

The AI Act classifies AI systems into four categories: prohibited, high-risk, limited-risk and minimal-risk. High-risk systems are listed in Annex III of Regulation (EU) 2024/1689. They cover sensitive areas such as healthcare, banking, insurance, education and critical infrastructure.

To determine if your project is classified as high-risk, you can use the practical guide from the AI Office or conduct a compliance assessment. If in doubt, legal analysis is recommended.

The costs of non-compliance go far beyond fines, which can reach €35 million or 7% of global turnover. They also include:

  • Remediation costs, which can be 2 to 5 times higher than those of proactive compliance.
  • Revenue losses due to service interruptions or loss of customer trust.
  • Legal costs and defence fees in case of litigation.
  • Reputational costs, which can impact the company's valuation.

According to a PwC study, businesses compliant with the AI Act gain a competitive advantage, with faster growth and greater resilience in times of crisis.

To convince your management to invest in AI, highlight three key arguments:

  1. Expected ROI: Present case studies from your sector, with concrete figures on productivity gains, cost savings or revenue increases.
  2. Compliance as a performance driver: Show how integrating compliance from the outset can reduce costs and speed up deployment.
  3. The risks of not investing: Emphasise the costs of non-compliance and missed opportunities compared to more agile competitors.

Use a risk/ROI matrix to prioritise projects and demonstrate how each investment aligns with the company's overall strategy.

The AI Act requires detailed technical documentation for high-risk AI systems, covering:

  • The system description and its objectives.
  • The data used for training and testing.
  • Robustness and cybersecurity measures.
  • Post-deployment monitoring procedures.

Several tools can help structure this documentation:

  • Model Cards: To describe model performance and limitations.
  • Datasheets for Datasets: To document the datasets used.
  • AI FactSheets: An IBM standard for comprehensive AI system documentation.
  • AI governance tools: Such as IBM Watson OpenScale or Fiddler AI, which allow real-time monitoring of model performance and compliance.

For SMEs, ready-to-use templates are available on the AI Office website.

Team training is a cornerstone of AI Act compliance. It should cover three levels:

  1. Awareness: For all employees, with modules on AI Act principles, non-compliance risks and best practices.
  2. Technical training: For technical teams (data scientists, engineers), with modules on technical documentation, robustness testing and bias management.
  3. In-depth training: For compliance officers and legal teams, with modules on text interpretation, incident management and interactions with authorities.

Several resources are available:

The CNIL also provides guides and tools to help businesses train their teams.

Jérémy Pierre
Jérémy Pierre
Founder aiacto.eu · AI Act Compliance Expert

Supports providers and deployers of AI in their regulatory compliance.

Share this article