The decision that sets the budget
Almost every question about the cost of AI Act compliance reduces to one determination: is this system high-risk?
On one side, a provider faces a risk management system, data governance requirements, technical documentation, logging capability, transparency toward deployers, human oversight design, accuracy and robustness requirements, a quality management system, conformity assessment, a declaration of conformity, CE marking, registration, and post-market monitoring.
On the other side, for a minimal-risk system, the Act imposes no product requirements at all.
There is no gradual slope between those positions. It is a threshold, and the entire apparatus switches on when it is crossed.
That makes classification the highest-leverage analysis in the whole regime, and it explains a pathology worth naming early: the incentive to classify downward is enormous, and the reasoning gets shaped by the answer people want. The defence against it is that the assessment must be documented and, in the derogation case, produced to authorities on request. A conclusion you would not want a sceptical reader to see is a conclusion to revisit.

