A client sits across from you and cannot say how many AI systems their company runs. You start a list: the CV screener in HR, the support chatbot, the scoring model someone in finance built over a weekend. Most of it is ordinary software. One of them may sit in the high-risk tier of the EU AI Act, and nobody in the building has classified it. You can see the worry on their face.
That worry is a market. And maybe you are the person in your own company who already understands this stuff, while your title and pay say otherwise. Compliance work tends to reward people who are early and precise, and companies are hunting for them right now.
The window is real. Regulation is fresh, the dates keep moving, and most firms have no one in-house who can classify their systems with confidence. The consultants who build a name in this stretch become the ones clients call for years. Tools to automate the inventory are coming, so the easy listing work will shrink and the judgment work will go to people who already have a track record.
The numbers: retainers on this work start around $800 a month. You can begin with nothing but your own time, a properly equipped practice runs to about $2,500, and most people take 3 to 9 months before it pays for itself.
Your first step tonight is smaller than any of that. Check the current high-risk deadline before you quote anyone. Saying August 2026 is now wrong, and a client who knows the date moved will discount everything else you say.
Those numbers are why your phone will ring. A penalty scaled to global turnover is a board-level problem, and boards buy advice about board-level problems.
One framing point before the detail, because it decides whether you come across as offering help or spreading fear. Enforcement of a new regime is slow, and most companies will never meet a regulator, so the coming fines are a weak reason to hire you. The strong reason is that a large number of organisations currently cannot describe what AI they use, in which parts of their business, making which decisions about which people. That is a management problem first and a legal one second, and customers and procurement teams are surfacing it faster than supervisory authorities. If you can answer that question, you are useful whether a fine ever arrives or not, and that is what separates a lasting consulting practice from a compliance scare that fades.
Get this right, because most published guidance has it wrong, and being the person who knows the current position is a big part of the value you sell.
The row in bold is the one that matters. High-risk obligations were widely expected to apply from 2 August 2026, and a great deal of consulting material, training and internal planning was built on that date. They were extended to 2 December 2027 following the political agreement on the AI Omnibus proposal.
Two things follow, and they pull in opposite directions in a way that is useful for you to understand.
Organisations that planned around August 2026 now have breathing room they may not know about, which is a conversation worth having with them.
And clients will treat a deadline that has already moved once as a deadline that might move again, which changes how you sell. Selling on urgency alone is now weaker. Selling on the obligations that are already live is stronger, because those are staying put. Which of your likely clients built a plan around the old August date?
This is where your immediate work is, and it gets far less attention than the high-risk regime that keeps being deferred.
Read the emphasised one again. Emotion recognition in the workplace is banned outright. Any organisation running sentiment analysis on employees, monitoring engagement through webcam analysis, or buying an HR tool with an emotion-inference feature is in the prohibited tier, at the 7% penalty level, today. Many have no idea, because in their minds they bought a product and never deployed a system.
The commercial reading for you: the deferred high-risk regime is the headline, and the live obligations are the revenue. An organisation using an HR screening tool with emotion inference, running an undisclosed customer chatbot and giving staff no AI training has three current exposures whatever happens in December 2027.
Almost every engagement you take will start with the same question: which of our systems fall into which tier? The Act defines four.
Employment tools is the one that reaches ordinary companies. Recruitment screening, CV ranking, promotion and task allocation systems, and performance monitoring all sit here. A mid-sized company with an applicant tracking system that scores candidates is operating a high-risk AI system whether or not anyone in the building thinks of it that way. Think of the last job you applied for: was your CV ranked by software before a person saw it?
Make a point of telling clients about that last tier early, because the common reaction to a first briefing is that everything is now regulated and nothing can be used. Most of what a typical organisation runs falls here with no obligations attached. Saying so plainly earns you credibility for the cases where you do have to insist, and it sets you apart from consultants whose commercial interest lies in making everything sound covered. A short list of genuine problems inside a long inventory of unregulated systems is a far more usable finding than a blanket warning, and clients act on it.
Classification is the product because it is genuinely hard, it decides everything downstream, and getting it wrong is expensive in both directions. Classify too broadly and you saddle a client with obligations they do not have. Classify too narrowly and they are exposed at 7 or 3% of global turnover.
You now know what the rules cover and when they bite. Turning that into something a company will put on a purchase order is a separate step.
Six services, roughly in order of how easy they are to start with.
A seventh exists if you have the right background, and it pays best: acting as the named person responsible for AI governance on a fractional basis. Smaller organisations that need the function but cannot justify a full-time hire will engage you for a day or two a month to own it. That gives you a longer relationship, a higher fee and a deeper understanding of the client than any project, and it is where you naturally end up after doing the first six well for the same client. Which of these six could you deliver next month with what you already know?
Be specific here, because the obvious targets are the wrong ones for you as a new consultant.
Mid-sized organisations with regulatory exposure are the sweet spot: large enough to have real AI deployment and real penalty exposure, too small for an in-house AI governance function. Financial services, healthcare, recruitment, education and anything selling into the public sector all feel this first.
Any organisation using AI in hiring. Employment tools are explicitly high-risk, and almost every mid-sized company now screens candidates with something. This is your single most reliable door.
Companies selling AI products into the EU, wherever they are based. The Act reaches by market and ignores geography, and a great many non-EU vendors have obligations they have never looked at.
Companies whose customers are asking. Procurement questionnaires now routinely ask about AI governance, and a supplier that cannot answer loses deals. That turns compliance from a cost into a revenue problem, which is a much easier sale for you.
Take that last one to heart. Selling "avoid a fine that may never come" is hard. Selling "answer this questionnaire so you stop losing tenders" is easy, and it is often the same work.
Pricing the Work
So the scope is clear. The next question is what a buyer will pay for it.
There is no published rate card for this, because the field is too new, so price from the shape of the engagement instead of from a market rate you cannot look up.
AI literacy training is the easiest to price because it looks like training generally: a session or a programme, priced per delivery or per cohort, with materials you build once and reuse. Your margin improves quickly after the first client, because the second delivery reuses preparation you have already done.
AI inventory and discovery is scoped by the size of the organisation and the number of systems and vendors. It is bounded work with a defined deliverable, which makes it easy to sell as a fixed fee and easy to finish without scope creep.
Risk classification should be priced per system instead of per hour, because your speed improves dramatically with experience and hourly billing punishes you for that. It is also your most defensible fee, since it carries the most judgment.
Framework and documentation work is a project, usually your largest single engagement, and it is where a fixed fee needs careful scoping. Writing policies is bounded; getting an organisation to agree to them can drag on for months.
Ongoing monitoring is the retainer and the goal. A monthly or quarterly fee covering inventory updates, regulatory change briefings, vendor reviews and classification of new systems. Price it against what it would cost the client to discover a problem late, and set your hours aside.
Two pricing principles specific to this field. Never price against the penalty, because quoting a fee as a fraction of a possible 7% fine reads as fear-selling and invites the client to gamble on enforcement instead. And put the retainer in from the start, in your first proposal, because turning a finished project into ongoing work later is much harder than including it from the beginning.
Training materials built once and reused get more profitable with every client. If a literacy session delivered to a few cohorts a quarter leaves you a margin after costs, it could pay your parents' phone and internet for the year while the retainer income stays yours. Put ongoing monitoring in your very first proposal.
Imagine a few retainers arriving each month from clients who rely on you to keep them out of trouble. That is a salary you set yourself, with no annual review where someone else decides what your knowledge is worth. It could fund the school fees, or the move closer to family you keep postponing.
Getting Credible Without a Law Degree
That is the money side settled. What follows decides whether anyone lets you near their systems in the first place.
There is no licence for this and no protected title, which cuts both ways: nothing stops you starting, and nothing stops anyone else either.
Read the Regulation itself. Skip the summaries and the courses and go to the text. It is long, it is the primary source, and more of the people selling advice on it have skipped reading it than you would hope. Knowing where an obligation actually sits, and being able to point to it, is what will set you apart.
Track the amendments obsessively. The high-risk deferral to December 2027 is the clearest example. Anyone whose knowledge is a year old is now wrong about a central date. Being reliably current is a service in itself.
Learn one existing framework properly. ISO/IEC 42001 for AI management systems, or an established AI risk management framework. These give you a structure to sell instead of an opinion, and structures are easier for clients to buy.
Come from a neighbouring discipline. Data protection and privacy work, information security, internal audit, quality management and regulatory compliance all transfer heavily. If you have done GDPR work, you already understand records of processing, risk assessments, vendor obligations and supervisory authorities, and the AI Act reuses that shape. What in your own work history already looks like this?
Publish what you read. A clear written explanation of one narrow question, such as whether a particular category of HR tool is high-risk, does more for your credibility than any certificate. The field is new enough that useful public writing is scarce.
Start with the live obligations. Delivering AI literacy training and building an AI inventory need competence more than authority, and both give you a client relationship that grows into classification work later.
Why This Regulation Exists, and Why the Dates Slip
Understanding the politics explains the deferrals and helps you predict what happens next, which is much of what your client is paying you for.
The EU has regulated technology this way before. Data protection law set the template: a regulation with reach beyond its borders, obligations scaled to risk, penalties expressed as a percentage of global turnover, and a long transition period. It also showed the approach works commercially, because companies build to the strictest regime and apply it everywhere instead of running two systems.
The AI Act follows that template on purpose, with one significant difference. Data protection regulated a practice that already existed and was well understood. The AI Act regulates a technology that was changing faster than the legislative process could keep up with. Drafting began before general purpose models transformed the field, which is why the general purpose AI obligations read like a layer added to a structure built for something else.
That mismatch is where the deferrals come from. The high-risk regime needs conformity assessments, technical documentation and harmonised standards, and the standards were not ready in time. Deferring the high-risk obligations to December 2027 was a practical answer to that gap, and the policy itself stands.
Three predictions follow, and they are the ones worth sharing with your clients.
The direction is stable even though the dates are not. Nothing in the political agreement reverses the risk-tier structure or the penalty levels. Organisations that treat a deferral as a cancellation will do the work later under more pressure.
The deadlines tied to standards that do not yet exist are the ones most likely to move again. Obligations that need nothing external, such as AI literacy and the prohibitions, arrived on schedule and stayed.
And the template will be copied. Other jurisdictions are legislating, and the risk-tier approach is the most likely thing they borrow, which is why building your practice around a framework, instead of a single statute, is the choice that lasts.
Rookie Mistakes
Quoting the superseded high-risk date. Saying August 2026 for high-risk obligations is now wrong, and a client who knows it moved will discount everything else you say.
Selling on fear of fines alone. The penalties are real, and clients have heard the number many times. Your stronger sale is the procurement questionnaire they cannot answer, or the prohibited practice they are running today without realising.
Ignoring what is already in force. The deferred regime grabs the attention while AI literacy obligations, prohibited practices and transparency requirements are live now. That is where you can start an engagement immediately.
Treating classification as a formality. It decides every obligation downstream, and it is genuinely hard in edge cases. Over-classifying wastes your client's money and under-classifying exposes them at 7% of turnover.
Forgetting that most clients deploy and few provide. Their exposure arrives through tools they bought, and their leverage is contractual. Advice written for model developers will not fit them.
Giving legal advice you are not qualified to give. There is a real line between explaining what a regulation requires and advising on legal exposure. Know where yours is, say so plainly, and build a relationship with a lawyer you can refer to. That protects your client and you. If a client asked you tomorrow whether they would be fined, which lawyer would you call?
Selling a one-off project. Systems change, vendors add features, dates move and obligations phase in. A governance position is a state you maintain over time, and the retainer is better for the client and better for you.
Gotchas Worth Knowing
The dates may move again. They already have. Build that expectation into your engagements openly instead of being surprised by it, and treat monitoring as part of the service.
Reach beyond the EU surprises people. The Act applies based on the EU market, wherever a company is incorporated. Plenty of non-EU businesses have obligations and no awareness of them, which gives you an opportunity and a duty to explain carefully.
National implementation adds a layer. Member States designate authorities and set parts of enforcement, so the practical picture varies by country on top of the Regulation itself.
Other regimes overlap. Data protection law, sector-specific regulation, product safety rules and employment law all touch AI deployment. Your client's AI governance problem is rarely an AI Act problem alone, and pretending otherwise produces incomplete advice.
Your own liability needs thought. Advising on compliance with a regime carrying 7% penalties means thinking about professional indemnity cover and being explicit in your engagement terms about scope and limits.
Certification falls short of a shield. An ISO management system certificate shows process maturity. It does not establish compliance with the Regulation, and presenting it as though it does is a serious misrepresentation.
The market is noisy. New regulation attracts consultants faster than it attracts competence. You can stand out simply by having read the text and staying current, precisely because so many skip both.
The AI Inventory, in Practice
This is the deliverable you will produce most often, so it helps to describe it concretely. It is also the one clients most consistently underestimate.
Inventories are hard because almost nobody deployed AI on purpose. It arrived inside software already in use, added by vendors in an update, and often switched on by default. Ask "what AI do you use" and you get a list of two or three obvious things. To get the real list, you have to ask differently.
Go function by function. A general question gets a general answer. Recruitment and HR, customer support, sales and CRM, marketing, finance, security, operations. For each, ask what software the team uses and what that software decides, ranks, scores, predicts, generates or routes automatically.
Ask about features. Nobody bought "an AI system". They bought an applicant tracking system that happens to rank candidates, or a support desk that happens to route tickets, or a CRM that happens to score leads. The AI is a feature inside a purchase.
Check what the vendor added recently. Software evaluated two years ago may have shipped AI features since, switched on without anyone deciding. Release notes are a genuine discovery source for you.
Find the shadow usage. Staff using general assistants on work documents, browser extensions, personal accounts on free tiers. This is real deployment with real data exposure, and it appears on no procurement record. How many people in your own office paste work into a chatbot every week?
Capture the right fields for each system. What it does, who deployed it, which vendor, what data it touches, whether it makes or supports a decision about a person, whether a human reviews the output, and which tier it falls into. That last field is the classification, and everything else is there to support it.
Record the reasoning alongside the conclusion. A tier assignment with no explanation is worthless in six months when someone asks why, and worse than worthless if a regulator or a customer asks.
The output is a living document. Its value decays fast because vendors ship features all the time, which is exactly your argument for the monitoring retainer over a one-off deliverable.
The inventory you produce is often the first time a company has seen all its AI on one page. The finance director who forwards it to the board will call you back, and the colleagues who raised an eyebrow at your career change start asking how you won the work.
Who This Suits
I will be direct, because the barrier here is credibility more than skill, and that decides fit more than aptitude does.
It suits you if you come from a neighbouring compliance discipline. Data protection, information security, internal audit, quality management and regulatory affairs all transfer directly, and the AI Act deliberately reuses structures those professionals already know. With GDPR experience, you already hold most of the mental model.
It suits you if you read primary sources for pleasure. What sets people apart in this field is having actually read the Regulation and tracked its amendments while competitors work from summaries. If that sounds tedious to you, this will be a grind.
It suits you if you can explain complex things to non-specialists. Most of the job is telling a marketing director why their tool is a problem, in words that get action instead of defensiveness. AI literacy training, the easiest entry point, is pure teaching.
It suits you if you can live with uncertainty and say so. Parts of this regime are genuinely unsettled, and a consultant who gives confident answers to open questions is dangerous. Being comfortable saying "this is unclear, here is the range of interpretation, here is what I would do" is the professional stance.
It will frustrate you if you want a fast start. Credibility takes months of reading and writing before the first paid engagement, and no certificate shortcuts it.
It will wear on you if you are uneasy near legal boundaries. You will constantly work close to the line between explaining a regulation and advising on legal exposure, and you need to know where yours is and hold it.
It will disappoint you if you want to sell a product. This is judgment work sold as a relationship, and the deliverables decay and need maintaining, which is the business model itself. Be honest: does months of reading before your first invoice sound like a price you would pay?
Behind the Scenes: A First Engagement
The realistic version starts with confusion, and the brief comes later.
A mid-sized company gets a procurement questionnaire from a prospective customer asking how it governs AI. Nobody can answer it. Someone is told to sort it out, and they call you.
Your first session is discovery, and it is mostly list-building. What AI are you using? The first answer is one or two obvious tools. Then you ask about the recruitment platform, the customer support routing, the CRM's lead scoring, the marketing content generation, and whether anyone uses a general assistant on work documents. The list reaches a dozen systems, most of which arrived inside products the company already had.
Then comes the uncomfortable discovery, which happens more often than you would expect. Something in the inventory sits in the prohibited or high-risk tier and nobody knew. Often it is the recruitment tool, because employment is explicitly high-risk, and now and then it is an engagement or sentiment feature that touches the emotion recognition prohibition.
Then classification, done properly, with your reasoning written down for each system. This is the deliverable with value beyond the immediate question, because every future obligation attaches to it.
Then the gap analysis: for each system in a regulated tier, what is required and what exists. Usually very little exists, because nobody was asked to build it.
Then the awkward conversation about the recruitment tool, which the HR team likes and which someone will have to review with the vendor.
Then a plan, ordered by exposure instead of by ease, and your offer to maintain it, because the inventory will be out of date within a quarter.
The client's original question, the procurement questionnaire, gets answered somewhere in the middle and turns out to have been the least important part.
Finding Your First Clients
Credibility does nothing until someone knows you exist. Getting in front of that first buyer is its own piece of work.
Selling here is unusual, because the buyer often has no idea they have the problem until you describe it, and describing it well is the whole pitch.
Lead with the questionnaire. Companies increasingly get AI governance questions in procurement and vendor security reviews. A supplier who cannot answer loses deals. "I help you answer these so you stop losing tenders" is a commercial pitch. "I help you comply with the AI Act" is a cost pitch, and cost pitches lose to inertia.
Go after the recruitment angle in particular. Employment tools are explicitly high-risk, and nearly every mid-sized company screens candidates with software that scores or ranks. It is your most reliable single way in, because the exposure is everywhere and the client usually has no idea.
Approach the compliance-adjacent professionals who already have the relationships. Data protection officers, information security consultants, employment lawyers and accountants serving mid-sized businesses all have clients with this exposure and no way to serve it. Two or three referral relationships will bring you more than any marketing. Who in your contacts already advises a long list of small companies?
Write publicly on narrow questions. Skip the "what is the AI Act" articles, of which there are thousands. Write specific, useful pieces: whether a particular category of HR tool is high-risk, what the AI literacy obligation actually requires in practice, what changed with the December 2027 deferral. Narrow and current beats broad and generic, and this field is new enough that genuinely useful writing is scarce.
Offer the inventory as a paid first step. A free audit attracts people who want free things. A modestly priced, bounded inventory engagement attracts people who intend to act, and it produces the document every later engagement builds on.
Subcontract to larger firms. Consultancies and law firms have demand they cannot staff. The rate is lower because they hold the client, and in return you get volume, a range of situations to learn from, and no sales function to run while you learn.
Subcontracting to a law firm gives you volume while you learn, and direct clients follow. If your roster of monitoring retainers holds close to 12,000 a month, where this page's figures stop, for long enough to cover costs and bank a year of runway, leaving a salaried role becomes a real option. That takes many months, so let the firm's volume carry the early stretch.
Each month you wait, another firm signs with someone who started a little sooner and knows the regulation a little better than you do today. The cost is quiet, and it adds up. Tonight, write a one-page summary of the current timeline in plain language, and send it to one person who might need it. That page is your first proof.
Staying Current Is the Service
Clients keep paying because this regime keeps moving, and so do their systems. Staying current is the work itself.
Follow the primary sources. Use the Commission's own pages, official journal publications, and the guidance from the bodies responsible for implementation, and treat commentary as secondary. Commentary lags and repeats errors, as the persistence of the superseded August 2026 high-risk date shows.
Track the standards, because the standards drive the dates. The obligations most likely to move are the ones depending on harmonised standards that do not yet exist. Watching how the standards progress gives you a genuine early signal of whether a deadline will hold.
Watch national implementation. Member States designate authorities and shape parts of enforcement, so a multinational client's picture varies by country and changes as each state acts.
Keep a change log for each client. What changed in the regime, what changed in their systems, and what either means for their position. This is the document that justifies your retainer, and producing it monthly is far easier than rebuilding a year of changes.
Diary the phased dates. December 2026 for the additional prohibition, December 2027 for high-risk in sensitive areas, August 2028 for high-risk embedded in regulated products. Clients will not track these and will be grateful that you did.
The compounding advantage is real. If you track this continuously for two years, you know the current position and why it changed, which questions are genuinely unsettled and which are merely under-reported. Someone arriving later and reading the current text cannot copy that, and it is the closest thing to a moat this field offers you.
Where This Goes Next
These are directional judgements in a field where the regulatory timetable itself keeps moving, so treat the order of events as uncertain even where the direction is clear.
Deadlines keep moving and the obligations keep arriving. So far the pattern is deferral of the heaviest requirements under industry pressure while the underlying direction holds. Expect more of both, which makes staying current a lasting service for you and makes selling on a single date a weak strategy.
Procurement becomes the real enforcement mechanism, well before regulators. Large buyers asking suppliers about AI governance will change behaviour faster than any supervisory authority, because losing a contract is immediate and a fine is hypothetical. Position yourself around the questionnaire and let the regulator come second.
The work moves from classification to operation. Once organisations know what they have and what tier it sits in, demand shifts to running the controls: monitoring, documentation, incident handling, vendor reviews. That is retainer work, and it is worth more to you than the first mapping.
Other jurisdictions follow with different rules. As more regions legislate, multinational clients will need someone who can hold several regimes at once. That is harder and better paid, and it favours you if you built a framework-based approach over a single-regulation one.
Insurance and contracts start doing the enforcement. As underwriters begin asking about AI governance before quoting, and as commercial contracts start carrying AI compliance warranties, the pressure to have documentation comes from parties who check, ahead of regulators who might. That is a faster and more reliable driver than enforcement, and you can already see it in procurement.
Tooling arrives and takes the inventory work. Governance platforms that discover AI systems and generate documentation are being built, and they will absorb the mechanical part. What remains for you is classification judgment in edge cases, and persuading an organisation to change something it likes, which is the same split of labour visible in every other field on this site facing automation. When the tools do the listing, will your judgment be the part clients still pay for?
The people who will own this field in a few years are writing their first classification memos today. Each engagement adds to a portfolio of edge cases that newcomers cannot match. Start building yours now, while clients are still grateful to find anyone who knows the rules.