The regulatory line item your AI consultant should already have priced in

Two professionals in a meeting room across a table reviewing a document together
TL;DR

Regulated SMEs running AI need EU AI Act, UK GDPR DPIA, and sector-specific compliance work in the engagement budget. The EU Commission's own impact assessment puts regulatory overhead at 17% of total AI spending. If your consultant's proposal omits this line, the cost will surface anyway.

Key takeaways

- Five regulatory frameworks affect UK SME AI engagements: EU AI Act, UK GDPR (ICO), SRA, FCA, CQC - High-risk EU AI Act QMS work costs €193,000 to €330,000 one-time + €71,400 annual per CEPS / EU Commission - The EU Commission's own impact assessment puts regulatory overhead at 17% of total AI spending - Penalty exposure: EU AI Act €30 to €35 million or 6 to 7% turnover; UK GDPR £20 million or 4% - If a proposal lacks a regulatory line in a regulated sector, ask the consultant to add it explicitly

You are a managing partner at a 30-person law firm. The proposal in front of you is for an AI document review pilot. The fee is £18,000. There is no line about SRA guidance, no mention of DPIA work, no reference to data residency or audit trail. You ask the consultant about EU AI Act exposure. There is a pause.

The pause is the point. The proposal looks complete because the consultant has scoped what they want to do, not what your sector requires the engagement to include. In regulated sectors, that gap is real cost waiting to surface, and it surfaces whether the consultant priced for it or not.

Why is regulatory work real cost rather than a checkbox?

Regulatory compliance for AI in regulated sectors is not optional and not free. Each framework requires specific deliverables: a Data Protection Impact Assessment, an AI risk classification, audit trail design, model documentation, human oversight protocols, and ongoing monitoring. Each deliverable takes hours to produce and review, and the hours have to come from somewhere. If the consultant has not priced them, they will either come from your team’s time, your legal counsel’s bill, or a frantic round of remediation work after the regulator visits.

The EU Commission’s own impact assessment for the EU AI Act puts regulatory overhead at 17% of total AI spending. That is a real number, derived from compliance modelling, and it applies to any UK firm serving EU clients.

The five frameworks that touch UK SME AI engagements

Five regulatory frameworks routinely affect UK SME AI engagements. EU AI Act. UK GDPR via the ICO. SRA for legal firms. FCA for financial services. CQC for healthcare. Most regulated SMEs intersect at least two of these in any given AI engagement, and each one carries a cost line that should appear somewhere in the proposal or the pre-engagement scoping conversation.

The EU AI Act is the largest in absolute terms. Any UK firm serving EU clients falls under its extra-territorial reach. High-risk AI systems require a Quality Management System, conformity assessment, technical documentation, and post-market monitoring. The CEPS analysis derived from the EU Commission impact assessment puts QMS setup at €193,000 to €330,000 one-time plus €71,400 annual maintenance for high-risk systems. Most SME AI use cases fall short of the high-risk classification, but transparency obligations, prohibited-use checks, and AI literacy requirements still apply.

UK GDPR via the ICO is the second framework. Any AI processing of personal data triggers Data Protection Impact Assessment requirements, lawful basis review, and bias and fairness audits. ICO penalties under the higher tier reach £20 million or 4% of worldwide turnover. The DPIA work itself runs £2,500 to £10,000 depending on system complexity, and it has to be done before the AI is deployed, not after.

The SRA is the third for legal firms. The February 2026 SRA guidance covers bias in AI-assisted legal advice, conflicts of interest in AI use, disclosure to clients, and supervision of AI-generated work. The cost is in policy work, training, and updated client engagement letters, typically £5,000 to £15,000 across an SME firm.

The FCA is the fourth for financial services. AI in algorithmic trading, automated decision-making in consumer finance, and model risk management all fall under existing FCA guidance, with AI-specific updates issued through 2024 to 2026. Compliance work for an SME financial services firm typically runs £10,000 to £30,000 depending on use case.

The CQC and NHS information governance is the fifth for healthcare. CQC GP Mythbuster 109 covers AI in GP services. NHS information governance guidance covers DPIA and lawful basis specifically for AI. Costs run £5,000 to £20,000 for an SME clinic, and the standards continue to tighten.

What “priced in” actually looks like

A proposal that has priced in regulatory work names the relevant frameworks, scopes specific deliverables, and either includes the work in the fee or flags it as a separate workstream with an estimated cost band. It does not say “we follow industry best practice.” It says specifically what the engagement will produce and what it will not.

The deliverables are concrete. A DPIA document. An AI risk classification with reasoning. Audit trail design for the deployed AI system. Model documentation that meets EU AI Act technical-documentation standards. A staff AI literacy plan. A handover to a named internal compliance owner who will run the ongoing monitoring after the consultant leaves.

A consultant who has done this before will name these deliverables on the second call without prompting. A consultant who has not done this before will either skip the regulatory section entirely or use vague language that signals they do not know what to deliver.

How to surface a missing regulatory line at proposal stage

You can surface a missing regulatory line without making the conversation adversarial. Three questions tell you what you need to know, and they apply across every regulated sector.

Ask whether the proposal includes a DPIA for the AI processing involved. The DPIA is the simplest test, because UK GDPR requires one for AI systems that process personal data, and a consultant who does not name it has not engaged with the regulatory side at all.

Ask which of your sector regulators’ AI guidance documents the engagement is built against. The SRA, FCA, CQC, and NHS each have specific AI guidance, and a consultant working in a regulated sector should be able to name the document and the specific clauses they are designing for. A consultant who cannot name the guidance is either operating from generic frameworks or has not read the sector-specific work.

Ask what the proposal assumes about EU client exposure. Most UK SMEs in professional services have at least some EU clients, which brings the engagement under the EU AI Act’s extra-territorial reach. A consultant who has thought about this will give you a clear answer about whether the engagement is scoped for EU compliance or not. A consultant who has not thought about it will say “we can look at that later” or “it probably doesn’t apply.” Either answer means the cost will surface later, when it is more expensive to fix.

The 17% rule

The EU Commission’s impact assessment puts regulatory overhead at 17% of total AI spending. That is the figure to use in budget planning until UK-specific data emerges, and as of 2026 the UK does not have a published AI consulting compliance cost survey. For a £25,000 AI engagement, 17% is £4,250 of compliance work that should be priced somewhere. For a £60,000 engagement, it is £10,200.

The number serves as a planning anchor rather than a definitive answer. Some sectors run higher (financial services and healthcare typically 20 to 25%), some run lower (lighter-touch professional services 10 to 15%). The point is that the line exists, the line has cost, and the buyer who has not priced it is going to pay it later, usually under more pressure.

If you would like to talk about how regulatory cost should be priced into an AI engagement in your sector, book a conversation.

Sources

  • EU Commission impact assessment for the EU AI Act: regulatory overhead at 17% of total AI spending for affected systems. Source.
  • CEPS (Centre for European Policy Studies) analysis derived from EU Commission impact assessment: QMS setup €193,000-€330,000 one-time plus €71,400 annual maintenance for high-risk AI systems. Source.
  • ICO penalties under UK GDPR higher tier: up to £20 million or 4% of worldwide turnover for serious AI processing breaches. Source.
  • SRA February 2026 AI guidance: bias in AI-assisted legal advice, conflicts of interest, disclosure to clients, and supervision of AI-generated work. Source.
  • FCA AI guidance updates 2024-2026: algorithmic trading, automated decision-making in consumer finance, model risk management. Source.
  • CQC GP Mythbuster 109: AI in GP services regulatory expectations. Source.
  • NHS information governance: DPIA and lawful basis requirements specifically for AI in healthcare settings. Source.

Frequently asked questions

What regulatory work should a UK SME budget for in an AI engagement?

Five frameworks typically apply. EU AI Act for any firm serving EU clients (extra-territorial). UK GDPR DPIA work via the ICO. SRA guidance for legal firms. FCA guidance for financial services. CQC guidance for healthcare. Each carries cost. The EU Commission's impact assessment puts the aggregate at 17% of total AI spending; in regulated UK sectors a 15 to 25% uplift on consulting cost is the realistic working figure.

How much does EU AI Act compliance actually cost an SME?

The CEPS / EU Commission impact assessment puts high-risk AI Quality Management System setup at €193,000 to €330,000 one-time plus €71,400 annual maintenance for high-risk systems specifically. The European Parliament's 2026 inquiry put entity-wide compliance for high-risk AI at €320,000 to €600,000. Most SME AI use cases fall short of the high-risk classification, but DPIA, transparency, and audit logging requirements still carry cost in the £5,000 to £20,000 range.

What are the penalties for AI compliance failure in the UK?

EU AI Act penalties run €30 to €35 million or 6 to 7% of worldwide annual turnover (whichever higher) for prohibited or high-risk AI non-compliance. UK GDPR enforcement under the higher tier reaches £20 million or 4% of turnover. Sector-specific regulators (SRA, FCA, CQC) add disciplinary risk that affects practising certificates and operating permissions, not just fines.

What should I do if a consultant's proposal does not include regulatory work?

Ask explicitly whether their proposal accounts for EU AI Act exposure, UK GDPR DPIA work, and your sector regulator's guidance. A good consultant will respond with specifics. A consultant who pauses, deflects, or claims regulation does not apply to your sector is either uninformed or hoping you do not press. In a regulated sector, that pause is the answer.

This post is general information and education only, not legal, regulatory, financial, or other professional advice. Regulations evolve, fee benchmarks shift, and every situation is different, so please take qualified professional advice before acting on anything you read here. See the Terms of Use for the full position.

Ready to talk it through?

Book a free 30 minute conversation. No pitch, no pressure, just a useful chat about where AI fits in your business.

Book a conversation

Related reading

If any of this sounds familiar, let's talk.

The next step is a conversation. No pitch, no pressure. Just an honest discussion about where you are and whether I can help.

Book a conversation