This is the second activity on this site with a statutory calendar behind it rather than a market trend. The first was accessibility auditing. The mechanism is the same: a law names a standard, sets dates, attaches penalties, and organisations discover they need someone who has actually read it.
Those numbers are why the phone rings. A penalty scaled to global turnover is a board-level problem, and boards buy advice about board-level problems.
One framing point before the detail, because it determines whether this reads as an opportunity or as fearmongering. The value here is not that organisations are about to be fined; enforcement of a new regime is slow and most companies will never meet a regulator. The value is that a large number of organisations are currently unable to describe what AI they use, in which parts of their business, making which decisions about which people. That is a management problem before it is a legal one, and it is being surfaced by customers and procurement teams faster than by supervisory authorities. Someone who can answer that question is useful whether or not a fine ever arrives, which is the difference between a durable consulting practice and a compliance scare that fades.
Get this right, because most published guidance has it wrong, and being the person who knows the current position is a substantial part of the value you sell.
The row in bold is the important one. High-risk obligations were widely expected to apply from 2 August 2026, and a great deal of consulting material, training and internal planning was built on that date. They were extended to 2 December 2027 following the political agreement on the AI Omnibus proposal.
Two things follow, and they pull in opposite directions in a way that is useful to understand.
Organisations that planned around August 2026 now have breathing room they may not know about, which is a conversation worth having with them.
And a deadline that has already moved once will be treated by clients as a deadline that might move again, which changes how you sell. Selling on urgency alone is now weaker; selling on the obligations that are already live is stronger, because those are not moving.
This is where the immediate work is, and it gets far less attention than the high-risk regime that keeps being deferred.
Read the emphasised one again. Emotion recognition in the workplace is banned, not regulated. Any organisation running sentiment analysis on employees, monitoring engagement through webcam analysis, or buying an HR tool with an emotion-inference feature is in the prohibited tier, at the 7 percent penalty level, today. Many do not know this because they bought a product rather than deploying a system.
The commercial reading: the deferred high-risk regime is the headline, and the live obligations are the revenue. An organisation using an HR screening tool with emotion inference, running an undisclosed customer chatbot and providing no AI training to staff has three current exposures regardless of what happens in December 2027.
Almost every engagement starts with the same question: which of our systems fall into which tier? The Act defines four.
Employment tools is the one that reaches ordinary companies. Recruitment screening, CV ranking, promotion and task allocation systems, and performance monitoring all sit here. A mid-sized company with an applicant tracking system that scores candidates is operating a high-risk AI system whether or not anyone in the building thinks of it that way.
That last tier is worth emphasising to clients early, because the common reaction to a first briefing is that everything is now regulated and nothing can be used. It is not, and most of what a typical organisation runs falls here with no obligations attached. Saying so plainly buys you credibility for the cases where you do have to insist, and it distinguishes you from consultants whose commercial interest lies in making everything sound covered. A short list of genuine problems in a long inventory of unregulated systems is a far more actionable finding than a blanket warning, and clients act on it.
Classification is the product because it is genuinely difficult, it determines everything downstream, and getting it wrong is expensive in both directions. Classify too broadly and you saddle a client with obligations they do not have. Classify too narrowly and they are exposed at 7 or 3 percent of global turnover.
Six, roughly in order of how easy they are to start with.
A seventh exists for anyone with the right background, and it pays best: acting as the named person responsible for AI governance on a fractional basis. Smaller organisations that need the function but cannot justify a full-time hire will engage someone for a day or two a month to own it. That is a longer relationship, a higher fee and a deeper understanding of the client than any project produces, and it is the natural destination for a consultant who has done the first six well for the same client.
Being specific matters, because the obvious targets are the wrong ones for a new consultant.
Any organisation using AI in hiring. Employment tools are explicitly high-risk, and almost every mid-sized company now screens candidates with something. This is the single most reliable door.
Companies selling AI products into the EU, regardless of where they are based. The Act reaches by market rather than by geography, and a great many non-EU vendors have obligations they have not examined.
Companies whose customers are asking. Procurement questionnaires now routinely ask about AI governance, and a supplier that cannot answer loses deals. That converts compliance from a cost into a revenue problem, which is a much easier sale.
The last one is worth internalising. Selling "avoid a fine that may never come" is hard. Selling "answer this questionnaire so you stop losing tenders" is easy, and it is frequently the same work.
Pricing the Work
There is no published rate card for this because the field is too new, so price from the shape of the engagement rather than from a market rate you cannot look up.
AI literacy training is the easiest to price because it resembles training generally: a session or a programme, priced per delivery or per cohort, with materials you build once and reuse. The margin improves rapidly after the first client because the second delivery costs you preparation time you have already spent.
AI inventory and discovery is scoped by the size of the organisation and the number of systems and vendors. It is bounded work with a defined deliverable, which makes it easy to sell as a fixed fee and easy to complete without scope creep.
Risk classification should be priced per system rather than per hour, because your speed improves dramatically with experience and hourly billing punishes that. It is also the most defensible fee, since it carries the most judgment.
Framework and documentation work is a project, typically the largest single engagement, and it is where a fixed fee needs careful scoping. Writing policies is bounded; getting an organisation to agree them is not.
Ongoing monitoring is the retainer and the goal. A monthly or quarterly fee covering inventory updates, regulatory change briefings, vendor reviews and new-system classification. Price it against the cost of the client discovering a problem late rather than against your hours.
Two pricing principles specific to this field. Never price against the penalty, because quoting a fee as a fraction of a possible 7 percent fine reads as fear-selling and invites the client to gamble on enforcement instead. And price the retainer from the start, in the first proposal, because converting a completed project into ongoing work later is much harder than including it from the beginning.
Getting Credible Without a Law Degree
There is no licence for this and no protected title, which cuts both ways: nothing stops you starting, and nothing stops anyone else either.
Read the Regulation itself. Not a summary, not a course, the text. It is long and it is the primary source, and the number of people selling advice on it who have not read it is higher than you would hope. Knowing where an obligation actually sits, and being able to point to it, is the credibility differentiator.
Track the amendments obsessively. The high-risk deferral to December 2027 is the clearest example. Anyone whose knowledge is a year old is now wrong about a central date. Being reliably current is a service in itself.
Learn one existing framework properly. ISO/IEC 42001 for AI management systems, or an established AI risk management framework. These give you a structure to sell rather than an opinion, and structures are easier for clients to buy.
Come from an adjacent discipline. Data protection and privacy work, information security, internal audit, quality management and regulatory compliance all transfer heavily. If you have done GDPR work, you already understand records of processing, risk assessments, vendor obligations and supervisory authorities, and the AI Act reuses that shape.
Publish your reading. A clear written explanation of one narrow question, such as whether a particular category of HR tool is high-risk, does more for credibility than any certificate. This field is new enough that useful public writing is scarce.
Start with the live obligations. Delivering AI literacy training and building an AI inventory requires competence rather than authority, and both produce a client relationship that extends into classification work later.
Why This Regulation Exists, and Why the Dates Slip
Understanding the politics explains the deferrals and helps you predict what happens next, which is much of what a client is paying for.
The EU has legislated technology this way before. Data protection law established the template: a regulation with extraterritorial reach, obligations scaled to risk, penalties expressed as a percentage of global turnover, and a long transition period. It also established that the approach works commercially, because companies build to the strictest regime and apply it everywhere rather than maintaining two systems.
The AI Act follows that template deliberately, with one significant difference. Data protection regulated a practice that already existed and was well understood. The AI Act regulates a technology that was changing faster than the legislative process could track. Drafting began before general purpose models transformed the field, which is why general purpose AI obligations read as a layer added to a structure designed for something else.
That mismatch is the source of the deferrals. The high-risk regime requires conformity assessments, technical documentation and harmonised standards, and the standards were not ready in time. Deferring high-risk obligations to December 2027 was a practical response to that gap rather than a retreat from the policy.
Three predictions follow, and they are the ones worth sharing with clients.
The direction is stable even though the dates are not. Nothing in the political agreement reverses the risk-tier structure or the penalty levels. Organisations that treat a deferral as cancellation will do the work later under more pressure.
Deadlines tied to standards that do not yet exist are the ones most likely to move again. Obligations that require nothing external, such as AI literacy and the prohibitions, moved on schedule and stayed.
And the template will be copied. Other jurisdictions are legislating, and the risk-tier approach is the most likely thing they borrow, which is why building your practice around a framework rather than a single statute is the more durable choice.
Rookie Mistakes
Quoting the superseded high-risk date. Saying August 2026 for high-risk obligations is now wrong, and a client who knows it moved will discount everything else you say.
Selling on fear of fines alone. The penalties are real and clients have heard the number repeatedly. The stronger sale is the procurement questionnaire they cannot answer, or the prohibited practice they are running today without realising.
Ignoring what is already in force. The deferred regime attracts the attention while AI literacy obligations, prohibited practices and transparency requirements are live now. That is where an engagement can start immediately.
Treating classification as a formality. It determines every obligation downstream and it is genuinely difficult in edge cases. Over-classifying wastes a client's money and under-classifying exposes them at 7 percent of turnover.
Forgetting that most clients are deployers, not providers. Their exposure arrives through purchased tools and their leverage is contractual. Advice written for model developers does not fit them.
Giving legal advice you are not qualified to give. There is a real line between explaining what a regulation requires and advising on legal exposure. Know where yours is, say so plainly, and build a relationship with a lawyer you can refer to. This protects the client and you.
Selling a one-off project. Systems change, vendors add features, dates move and obligations phase in. A governance position is a state to maintain, not a document to deliver, and the retainer is both better for the client and better for you.
Gotchas Worth Knowing
The dates may move again. They already have. Build that expectation into your engagements explicitly rather than being surprised by it, and treat monitoring as part of the service.
Extraterritorial reach surprises people. The Act applies based on the EU market rather than where a company is incorporated. Plenty of non-EU businesses have obligations and no awareness of them, which is an opportunity and a duty to explain carefully.
National implementation adds a layer. Member States designate authorities and set aspects of enforcement, so the practical picture varies by country on top of the Regulation itself.
Other regimes overlap. Data protection law, sector-specific regulation, product safety rules and employment law all interact with AI deployment. A client's AI governance problem is rarely only an AI Act problem, and pretending otherwise produces incomplete advice.
Your own liability needs thought. Advising on compliance with a regime carrying 7 percent penalties means considering professional indemnity cover and being explicit in your engagement terms about scope and limits.
Certification is not a shield. An ISO management system certificate demonstrates process maturity. It does not establish compliance with the Regulation, and presenting it as though it does is a serious misrepresentation.
The market has plenty of noise. New regulation attracts consultants faster than it attracts competence. Differentiating on having actually read the text, and on being current, is available precisely because so many are not.
The AI Inventory, in Practice
This is the deliverable you will produce most often, so it is worth describing concretely. It is also the one clients most consistently underestimate.
The reason inventories are hard is that almost nobody deployed AI deliberately. It arrived inside software already in use, added by vendors in an update, and often enabled by default. Asking "what AI do you use" produces a list of two or three obvious things. Getting the real list requires asking differently.
Go function by function rather than asking generally. Recruitment and HR, customer support, sales and CRM, marketing, finance, security, operations. For each, ask what software the team uses and what that software decides, ranks, scores, predicts, generates or routes automatically.
Ask about features, not products. Nobody bought "an AI system". They bought an applicant tracking system that happens to rank candidates, or a support desk that happens to route tickets, or a CRM that happens to score leads. The AI is a feature inside a purchase.
Check what the vendor added recently. Software you evaluated two years ago may have shipped AI features since, enabled without a decision on your side. Release notes are a genuine discovery source.
Find the shadow usage. Staff using general assistants on work documents, browser extensions, personal accounts on free tiers. This is real deployment with real data exposure and it appears on no procurement record.
Capture the right fields for each system. What it does, who deployed it, which vendor, what data it touches, whether it makes or supports a decision about a person, whether a human reviews the output, and which tier it falls into. That last field is the classification, and everything else exists to support it.
Record the reasoning, not just the conclusion. A tier assignment with no explanation is worthless in six months when someone asks why, and worse than worthless if a regulator or a customer asks.
The output is a living document. Its value decays quickly because vendors ship features continuously, which is exactly the argument for the monitoring retainer rather than a one-off deliverable.
Who This Suits
Direct, because the barrier here is credibility rather than skill and that determines fit more than aptitude does.
It suits people coming from an adjacent compliance discipline. Data protection, information security, internal audit, quality management and regulatory affairs all transfer directly, and the AI Act deliberately reuses structures those professionals already know. Someone with GDPR experience has most of the mental model already.
It suits people who read primary sources for pleasure. The differentiator in this field is having actually read the Regulation and tracked its amendments while competitors work from summaries. If that sounds tedious rather than interesting, this will be a grind.
It suits people who can explain complexity to non-specialists. Most of the job is telling a marketing director why their tool is a problem, in language that produces action rather than defensiveness. AI literacy training, the most accessible entry point, is pure teaching.
It suits people who can tolerate uncertainty and say so. Parts of this regime are genuinely unsettled, and a consultant who states confident answers to open questions is dangerous. Being comfortable saying "this is unclear, here is the range of interpretation, here is what I would do" is the professional posture.
It does not suit anyone wanting a fast start. Credibility takes months of reading and writing before the first paid engagement, and there is no certificate that shortcuts it.
It does not suit anyone uncomfortable near legal boundaries. You will constantly be near the line between explaining a regulation and advising on legal exposure, and you need to know where yours is and hold it.
It does not suit anyone who wants to sell a product. This is judgment work sold as a relationship, and the deliverables decay and need maintaining, which is the business model rather than a flaw in it.
Behind the Scenes: A First Engagement
The realistic version starts with confusion rather than a brief.
A mid-sized company gets a procurement questionnaire from a prospective customer asking how it governs AI. Nobody can answer it. Someone is told to sort it out, and they call you.
The first session is discovery, and it is mostly a list-building exercise. What AI are you using? The initial answer is one or two obvious tools. Then you ask about the recruitment platform, the customer support routing, the CRM's lead scoring, the marketing content generation, and whether anyone is using a general assistant on work documents. The list reaches a dozen systems, most of which arrived inside products the company already had.
Then the uncomfortable discovery, which happens more often than you would expect. Something in the inventory sits in the prohibited or high-risk tier and nobody knew. Frequently it is the recruitment tool, because employment is explicitly high-risk, and occasionally it is an engagement or sentiment feature that touches the emotion recognition prohibition.
Then classification, properly, with reasoning written down for each system. This is the deliverable that has value beyond the immediate question, because it is what every future obligation attaches to.
Then the gap analysis: for each system in a regulated tier, what is required and what exists. Usually very little exists, because nobody was asked to build it.
Then the awkward conversation about the recruitment tool, which the HR team likes and which someone will have to review with the vendor.
Then a plan, prioritised by exposure rather than by ease, and an offer to maintain it, because the inventory will be out of date within a quarter.
The client's original question, the procurement questionnaire, is answered somewhere in the middle and turns out to have been the least important part.
Finding the First Clients
The sales motion here is unusual because the buyer often does not know they have the problem until you describe it, and describing it well is the entire pitch.
Lead with the questionnaire, not the regulation. Companies increasingly receive AI governance questions in procurement and vendor security reviews. A supplier who cannot answer loses deals. "I help you answer these so you stop losing tenders" is a commercial pitch. "I help you comply with the AI Act" is a cost pitch, and cost pitches lose to inertia.
Target the recruitment angle specifically. Employment tools are explicitly high-risk, and nearly every mid-sized company screens candidates with software that scores or ranks. It is the most reliable single entry point because the exposure is universal and the client is usually unaware.
Approach the compliance-adjacent professionals who already have the relationships. Data protection officers, information security consultants, employment lawyers and accountants serving mid-sized businesses all have clients with this exposure and no capability to serve it. Two or three referral relationships produce more than any marketing.
Write publicly on narrow questions. Not "what is the AI Act" articles, of which there are thousands. Specific, useful pieces: whether a particular category of HR tool is high-risk, what the AI literacy obligation actually requires in practice, what changed with the December 2027 deferral. Narrow and current beats broad and generic, and this field is new enough that genuinely useful writing is scarce.
Offer the inventory as a paid first step, not a free audit. A free audit attracts people who want free things. A modestly priced, bounded inventory engagement attracts people who intend to act, and it produces the document every subsequent engagement builds on.
Subcontract to larger firms. Consultancies and law firms have demand they cannot staff. The rate is lower because they hold the client, and in exchange you get volume, exposure to varied situations, and no sales function to run while you are learning.
Staying Current, Which Is the Service
The reason clients keep paying is that this regime does not hold still, and neither do their systems. Currency is not preparation for the work, it is the work.
Follow the primary sources rather than commentary. The Commission's own pages, official journal publications, and the guidance issued by the bodies responsible for implementation. Commentary lags and repeats errors, as the persistence of the superseded August 2026 high-risk date demonstrates.
Track the standards, because the standards drive the dates. The obligations most likely to move are the ones depending on harmonised standards that do not yet exist. Watching standards progress is a genuine leading indicator of whether a deadline will hold.
Watch national implementation. Member States designate authorities and shape aspects of enforcement, so a multinational client's picture varies by country and changes as each state acts.
Maintain a change log for each client. What changed in the regime, what changed in their systems, and what either means for their position. This is the artefact that justifies the retainer, and producing it monthly is far easier than reconstructing a year of changes.
Diary the phased dates. December 2026 for the additional prohibition, December 2027 for high-risk in sensitive areas, August 2028 for high-risk embedded in regulated products. Clients will not track these and will be grateful that you did.
The compounding advantage is real. A consultant who has tracked this continuously for two years knows not only the current position but why it changed, which questions are genuinely unsettled and which are merely under-reported. That is not replicable by someone entering later and reading the current text, and it is the closest thing to a moat this field offers.
Where This Goes Next
These are directional judgements in a field where the regulatory timetable itself keeps moving, so treat the sequencing as uncertain even where the direction is not.
Deadlines keep moving and the obligations keep arriving. The pattern so far is deferral of the most burdensome requirements under industry pressure while the underlying direction holds. Expect more of both, which makes currency a durable service and makes selling on a single date a weak strategy.
Procurement becomes the real enforcement mechanism, well before regulators. Large buyers asking suppliers about AI governance will change behaviour faster than any supervisory authority, because losing a contract is immediate and a fine is hypothetical. Position around the questionnaire rather than the regulator.
The work moves from classification to operation. Once organisations know what they have and what tier it sits in, the demand shifts to running the controls: monitoring, documentation, incident handling, vendor reviews. That is retainer work and it is more valuable than the initial mapping.
Other jurisdictions follow with different rules. As more regions legislate, multinational clients will need someone who can hold several regimes at once. That is harder and better paid, and it favours consultants who built a framework-based approach rather than a single-regulation one.
Insurance and contracts start doing the enforcement. As underwriters begin asking about AI governance before quoting, and as commercial contracts start carrying AI compliance warranties, the pressure to have documentation arrives from parties who check rather than from regulators who might. That is a faster and more reliable driver than enforcement, and it is already visible in procurement.
Tooling arrives and takes the inventory work. Governance platforms that discover AI systems and generate documentation are being built, and they will absorb the mechanical part. What remains is classification judgment in edge cases, and persuading an organisation to change something it likes, which is the same division of labour visible in every other field on this site facing automation.