✨ New — try Standpoint free for 14 days: full access to all 15 frameworks. A card is required, but you won’t be charged. Start your free trial →
Standpointby AI Service Pro
Security Intelligence / EU AI Act
Guide

The EU AI Act for startups: what's in force and how to prepare

M
Mohammad
Founder, AI Service Pro · 9 min read

Does it apply to a startup like mine?

Probably, if either of these is true: (1) you put an AI system or a general-purpose AI model on the EU market, or (2) the output of your AI system is used by people in the EU. The Act follows the use of the system, not where your company is registered. A US SaaS with EU customers is squarely in scope.

The good news: most startups are not building "high-risk" systems, and the heaviest obligations fall on a minority of use cases. The work is figuring out which bucket you're in and meeting the matching duties.

The four risk tiers (in plain terms)

  • Prohibited. A small set of uses are simply banned — things like social scoring, manipulative techniques that cause harm, and certain biometric practices. If you're here, the answer is "don't."
  • High-risk. AI used in sensitive areas (for example, employment decisions, access to essential services, certain safety components). These carry the real obligations: a risk-management system, data governance, technical documentation, logging, human oversight, accuracy and robustness, and a conformity assessment before going to market.
  • Limited risk (transparency). Chatbots, AI-generated content, and similar must tell people they're interacting with or seeing AI. This catches a lot of ordinary products — and it's usually light to satisfy.
  • Minimal risk. Most everyday AI features. No specific obligations beyond good practice.

Building on top of a model like GPT or Claude? You're likely a deployer or downstream provider, while the model maker is the general-purpose AI (GPAI) provider. The GPAI rules (technical documentation, a training-content summary, a copyright policy) mostly bind the model maker — but you still own the obligations for your system and how you use it.

What the deadlines mean for you

The Act phases in over time. Prohibited-practice bans came first (Feb 2025), the general-purpose AI obligations followed (Aug 2025), and the Article 50 transparency rules — labelling AI-generated content, disclosing chatbots and deepfakes — apply from August 2026. The heaviest tier, the standalone high-risk (Annex III) obligations, was deferred by the EU's Digital Omnibus from August 2026 to 2 December 2027 (embedded-product high-risk moved to August 2028).

So the honest 2026 takeaway for a startup isn't a high-risk deadline — it's that your buyers are already asking. The pressure most SMBs feel right now is a security questionnaire that asks "Is your organization aligned with the NIST AI RMF?" or "Are you ISO 42001 certified or pursuing certification?" — and a deal that stalls until you can answer. Enforcement and fines are real (up to the higher of €15M or 3% of global turnover for many breaches, more for prohibited uses), but the thing that costs you revenue first is the questionnaire, not the regulator. The cheapest time to get organized is before either asks.

A practical readiness path

  • Inventory your AI. List every AI feature and model you build or use, and what each does. You can't classify what you haven't written down.
  • Classify each system. Prohibited / high-risk / limited / minimal. Be honest about the high-risk triggers — they're about the use, not the cleverness of the model.
  • Map your obligations. For limited-risk, it's usually transparency notices. For high-risk, it's the full set (risk management, data governance, documentation, logging, human oversight, accuracy/robustness, conformity).
  • Stand up the basics. A short AI policy, an AI risk register you actually maintain, and clear human-oversight points for anything consequential cover most of the early gap.
  • Keep evidence as you go. Regulators and enterprise buyers both want to see that your process runs — dated records, owners, reviews — not just that a policy exists.

How Standpoint helps

Standpoint includes a free EU AI Act exposure diagnostic that classifies your system's risk tier in a few questions, plus the full EU AI Act framework mapped article by article — with the exact evidence to collect for each obligation, tailored to your stack. And because it crosswalks to NIST AI RMF, ISO 42001, SOC 2 and more, the work you do for the AI Act also moves your other frameworks forward.

Go deeper: the full EU AI Act guide hub — with a compliance checklist, a free readiness assessment, and a framework crosswalk.

This article is general information, not legal advice. For decisions about your specific obligations, consult qualified counsel and the official text of Regulation (EU) 2024/1689.

See where you stand — free
2-minute check · no card · runs in your browser
Run your free check →
Newsletter
Practical AI-governance & security tips, monthly

No fluff, no fear-selling. Unsubscribe anytime.

// Keep reading