Skip to content
Masarat

What a new regulation actually asks of a mid-size firm, in numbers

Not the legal summary, which exists everywhere. The count of systems a 400-person insurer had to classify, how long each tier took, and which obligations turned out to be cheap.

Risk & legal · 17.07.26 · 9 min · by admin

Every regulation arrives with a thousand summaries and no numbers. This is the numbers version, from one readiness engagement at a 400-person insurer in scope for the EU AI Act, written so that a risk team elsewhere can budget rather than worry.

The inventory

61

systems that made an automated or assisted decision about a person

How it was measured 

The firm's own estimate before the inventory was 'about fifteen'. The rest were spreadsheets, vendor tools and a pricing model nobody had thought of as AI.

The inventory took three weeks and was the most valuable artefact of the engagement. Most of the sixty-one were out of scope or minimal-risk; knowing which was the whole job.

The tiers

  • 44 minimal risk, a register entry and an owner. Half a day each.
  • 13 limited risk: transparency obligations. Two days each, mostly writing the notice.
  • 4 high risk: the full set: risk management, data governance, logging, human oversight, conformity. Six to nine weeks each, and the whole budget.

What was cheap

Transparency. Logging, where the system already had audit trails. Human oversight, where a person already reviewed the output: the obligation was to write down what was already happening. Roughly 70% of the obligations were met by documenting existing service properly.

What was not

Data governance for the four high-risk systems. In every case the training data’s lineage lived in somebody’s head, and reconstructing it was the long pole. This is not a regulatory cost; it is a debt the regulation made visible.

The register is now maintained by two people who do not work for us. That was the test.

Ines Duarte, partner

Who wrote it, and what to read next.