Photo: Unsplash
The Compliance Gold Rush Nobody Advertised
Every major regulatory intervention creates two industries: the one being regulated, and the one that grows up around regulating it. The latter is almost always more profitable in the short term and almost never the one the regulation’s architects were thinking about.
The Sarbanes-Oxley Act of 2002, passed in the wake of Enron and WorldCom, was designed to improve corporate financial governance. It did, in the limited sense that audit quality improved and executive fraud became marginally harder. It also generated roughly $35 billion in annual compliance spending in the US alone by 2005, much of it flowing to the Big Four accounting firms that SOX nominally strengthened oversight of. The regulation created a compliance economy that was larger than many of the industries it governed.
The EU AI Act is following this trajectory with extraordinary speed. We are barely eight months into serious enforcement, and the compliance industry it has created is already operating at a scale that would surprise anyone who thought the regulation was primarily about AI companies.
The Numbers, Quickly
PwC’s dedicated EU AI Act advisory practice launched in October 2024. By the first half of 2026, it had generated revenues that the firm described in an earnings context as “materially significant.” Deloitte stood up an AI Act compliance team of over 200 people across its European offices — a team that didn’t exist two years ago. KPMG’s AI assurance practice has published four versions of its “EU AI Act Readiness Framework,” each one updated as new guidance emerges from the EU AI Office and each one necessitating a fresh client engagement to implement.
Law firms have been even more aggressive. Linklaters, Freshfields, and CMS all rank EU AI Act practice as among their fastest-growing practice areas in 2025 and 2026. Individual partner billing rates in this space are running at €800 to €1,200 per hour at the top end. A mid-market company seeking legal guidance on whether its AI system is high-risk can expect to spend €30,000 to €80,000 just to get a credible opinion. That opinion will contain so many caveats that the company will then need to spend more to operationalize it.
Notified Bodies — the private certification organizations authorized to conduct conformity assessments for high-risk AI — are perhaps the most interesting participants in this ecosystem. There are currently 28 EU-designated Notified Bodies with some AI competence, and demand exceeds their capacity by an estimated factor of four to six. TÜV SÜD, the German testing and certification organization, has been among the most aggressive in expanding AI certification capacity. They’ve hired over 50 dedicated AI auditors since 2024. Their CEO publicly stated in April 2026 that they expected AI Act certification to become one of the company’s top three revenue streams within five years.
TÜV SÜD’s AI certification revenue for 2025 was approximately €35 million. If their projection is correct, we’re talking about a company generating €150 to €200 million annually from AI certification within a few years. From a standing start.
The Anatomy of a Compliance Engagement
Understanding why this industry generates so much revenue requires understanding what an EU AI Act compliance engagement actually involves for a company with a high-risk AI system.
The engagement typically begins with a scoping exercise: is the system actually high-risk under the Act? This sounds simple. It rarely is. The system might span multiple application domains. It might be used in ways the original developer didn’t anticipate. The distinction between “influencing” and “determining” a human decision requires legal judgment. This phase costs €15,000 to €50,000 and takes four to eight weeks.
If the system is high-risk, the company then needs to prepare a technical conformity assessment. This requires documentation of the system’s development process, training data governance, risk management methodology, accuracy and robustness testing, and post-market monitoring plan. Assembling this documentation from scratch for a system that wasn’t built with these requirements in mind takes significant engineering and legal effort. €50,000 to €150,000 is common. For complex systems, €300,000 is not unusual.
The Notified Body then reviews this documentation. The review itself costs €30,000 to €100,000 and takes six to nine months in the current backlogged environment. The Notified Body may request modifications or additional documentation, triggering another round of work and billing on both sides. If the system passes, the company receives a certificate valid for three years, after which the process begins again.
For an ongoing compliance posture — post-market monitoring, responding to regulatory changes, updating documentation as the system evolves — companies typically engage either an internal compliance team or an external retainer. External retainers for this function are running €5,000 to €15,000 per month at the low end.
The total cost for a medium-complexity high-risk AI system, from initial scoping to certificate issuance, sits somewhere between €150,000 and €600,000. This is for a single system. A company with five AI products in high-risk domains is looking at seven figures in compliance costs before they’ve served a single additional customer.
The Software Layer
Beyond the professional services world, a software ecosystem has emerged to sell tools that make AI compliance more manageable. This is perhaps the most interesting development in the compliance economy, because it’s creating a new product category that didn’t exist two years ago.
Companies like Holistic AI (London), Certa (US but EU-focused), and a cluster of European startups with names like Complai, RegulatAI, and AI Governance Platform offer software that helps organizations document their AI systems, assess risk classification, manage the evidence required for conformity assessments, and track regulatory changes. Prices range from €500 per month for small organizations to €50,000 per year for enterprise platforms.
The irony here is exquisite: the EU AI Act, designed to govern AI systems, has generated a market for AI-powered compliance software. Holistic AI’s own platform uses machine learning to help classify AI systems and generate documentation. There is no obvious reason why an AI system used to assess compliance with AI regulation is not itself a high-risk AI system under the regulation it’s designed to help navigate. When I asked Holistic AI’s communications team about this directly in August 2026, the response was a careful statement that their platform was “decision support” rather than a determination system.
Readers familiar with Part 2 of this series will recognize the move.
The Knowledge Asymmetry Problem
The compliance industry boom creates a knowledge asymmetry that compounds the market concentration effects discussed earlier. Companies that can afford deep compliance engagement — including both the professional services and the software tools — develop sophisticated understanding of what the regulation actually requires in practice. They build institutional knowledge. They develop relationships with specific Notified Body staff. They understand the unwritten interpretive norms that are emerging alongside the written rules.
Companies that can’t afford sustained compliance engagement remain in the dark. They know the regulation is there. They know they might be subject to it. They don’t know exactly what compliance looks like for their specific product, and they can’t afford to find out. This isn’t a stable equilibrium.
The companies with sophisticated compliance knowledge are mostly large, well-resourced enterprises — both European incumbents and major US players. The companies in the dark are mostly smaller, earlier-stage, and often more innovative. The regulation is not creating a more level playing field for AI development. It’s entrenching the players who were already strongest.
This pattern isn’t unique to AI. When the Basel III capital requirements for banks were introduced after the 2008 financial crisis, the compliance burden fell disproportionately on smaller and mid-size banks. The large banks had compliance departments; the small banks had to hire them. JPMorgan Chase and Goldman Sachs hired armies of compliance staff and absorbed the cost easily. Community banks and regional lenders faced existential compliance pressure. The regulation designed to make banking safer may have accelerated consolidation in ways that made the overall system more, not less, brittle.
The compliance gold rush around the EU AI Act will eventually moderate. As the regulation matures, as Notified Bodies expand capacity, as the software tools become commoditized, as case law accumulates — the knowledge asymmetry will narrow. This is what happened with GDPR. Data protection compliance is still expensive, but it’s dramatically less opaque and expensive than it was in 2018.
The question is how much of the European AI startup ecosystem survives the interval. The gold rush is profitable for the miners. It’s not necessarily good for the territory they’re mining.
The Standard-Setting Power Grab
There’s a long-term implication of the compliance industry boom that the immediate revenue numbers obscure: whoever writes the standards wins.
The EU AI Act delegates significant norm-setting authority to technical standards bodies — specifically CEN (the European Committee for Standardization) and CENELEC — to develop harmonized technical standards that AI systems can comply with to demonstrate conformity with the Act’s essential requirements. These standards don’t exist yet in complete form. CEN-CENELEC’s AI working groups are producing them, with publication expected through 2027 and 2028.
The process of developing these standards is, structurally, controlled by whoever has the most sophisticated representation. Large companies — the ones with resources to send technical experts to standard-setting meetings in Brussels and Berlin — have disproportionate influence over how the standards are written. The compliance consultants advising those companies have secondary influence. Small companies and civil society have less. The standards that emerge will reflect the institutional knowledge and preferences of their most active participants.
This is the endgame of the compliance economy that the EU AI Act has created. The immediate revenue flows to consultants and auditors. The durable structural benefit flows to the companies that shape the standards their competitors must meet. In ten years, when harmonized AI standards define what European AI compliance looks like in concrete technical terms, the companies that helped write those standards will face a much lighter compliance burden than those who didn’t — because the standards will be written around what they already do.
This is not conspiracy. It’s how standard-setting has always worked. ISO standards, ASTM standards, IEEE standards — all shaped heavily by the companies with the most at stake and the most capacity to participate. The AI Act’s compliance economy is not just generating legal fees today. It’s generating the regulatory infrastructure that will define European AI market entry conditions for decades. Whoever invests most heavily in that infrastructure now will collect the returns when the standards crystallize.
The compliance gold rush, in this light, is not just profitable. It’s politically rational.
One email a month: the upcoming live event + free recording access for subscribers. No spam, unsubscribe anytime.
