Most governance budgets are built the way a certification budget is: scope the gap, fund the remediation, close the programme. The obligation never closes, so what actually arrives is a standing cost with a unit, priced per system and per year for as long as that system takes traffic. What decides its size is not the policy or the platform licence. It is whether the pipeline that runs the system also produces the record, or whether people rebuild that record by hand every time somebody asks.
Policy and committee, documentation and tooling licences show up in nearly every governance budget. The three below show up in almost none, and over a three-year horizon they usually cost more than the three that do.
A one-off platform cost plus a per-system figure to attach each system to it. In the worked example that is $180,000 and $11,000 a system, so fourteen systems come to $334,000 once. It is the only line here that gets cheaper per system as scope grows, and the only one whose price rises the longer it is deferred.
Loaded hours, charged per system per audit event. Sixty-two hours at $85 is $5,270, and three events a year, internal audit, customer review and surveillance, makes $15,810 per system. Finance rarely sees this line at all, since it hides inside the day jobs of a risk analyst and two engineers, which is how it grows unchallenged.
Per system, per year, and it only ever grows. Logs have to be kept for a defined period, and a schema designed after the fact means nothing can be queried cheaply when an assessor asks about a particular week. Cheap to switch on this quarter, expensive to reconstruct, and useless until it has been running a while.
Move it out of the capital plan and into the operating line, with a per-system, per-year unit that anyone can multiply. A budget with a completion date stops paying the moment the programme closes.
The crossover between the two evidence paths sits between one system and two, so the system count decides the answer. Most organisations find more systems in scope than they expected, not fewer.
A governance tool with nothing to ingest reports on an empty inventory. Provenance at ingestion, event logging and a model registry publish step come first, and all three are engineering work rather than procurement.
Article 99 ceilings are flat across the mid-market and land years out. Revenue waiting on an AI section nobody can answer lands this quarter, and in the worked example it is 1.6 times larger.
Nearly every cost line has a unit. Documentation, evidence assembly, retention and the per-system share of instrumentation all scale with the number of systems in scope, and they recur every year that system takes traffic. Only policy and committee time is genuinely fixed, and it is the smallest of the six.
Between one system and two. Above that, the fixed platform cost amortises across everything attached to it while hand assembly adds a full set of hours for every system and every review. From six systems to thirty the generated path falls 45 per cent per system; the assembled path falls only 26 per cent.
You can buy the schema back at two to three times the build-time cost. You cannot buy the history. A record of how a system behaved, who overrode it and what monitoring showed over eighteen months is produced by eighteen months of operation and by nothing else, so every quarter of delay is evidence permanently gone.
Once, as context, then move on. The tiers are the higher of 35 million euro or 7 per cent of worldwide turnover for prohibited practices, 15 million or 3 per cent for most operator duties, and 7.5 million or 1 per cent for misleading information. Below roughly 500 million euro of turnover the fixed sum governs, so exposure is flat rather than proportional.
The commercial one. In the worked example, 40 million dollars of new enterprise ACV a year with 12 per cent of deals carrying an AI governance section puts 4.8 million at stake; a ten per cent slip in close rate is 480,000, which is 1.6 times the regulatory expected value and arrives years earlier.
This one prices the standing cost of holding evidence, per system and per year, and compares generating it against assembling it. The Economics of AI Security prices the other side: which control family buys the most risk reduction per pound, and what the containment clock costs while an incident runs.
CFOs and CTOs who have to defend a governance line in a budget meeting. It assumes you accept that the duties exist and now need a unit, a model you can run on your own system count and loaded rate, and two numbers you can argue in a board room.
Drop your details and we'll send The Economics of AI Governance straight to your inbox - no spam, unsubscribe anytime.
Bring your system count and your loaded rate, and we will run both evidence paths against your numbers instead of ours. You leave with the model, the crossover point and a costed next quarter. SECTION 7 - FAQ - 5 to 8 questions
Run the numbers with us