DoAIRight
EU AI Act · practical guide for startups

EU AI Act compliance for startups — without the legalese

The EU AI Act is phasing in now, and it reaches beyond the EU — if your AI's output is used there, it can apply to you. Here's what actually matters: your risk tier, the timeline, what you must do, and the fastest way to get provably ready.

No credit card to start · one AI Management System maps to the EU AI Act, ISO 42001, NIST AI RMF, SOC 2 & ISO 27001

First, find your risk tier

The Act sorts AI into four tiers. Your obligations — and your workload — depend entirely on which one you're in.

Unacceptable risk

Banned outright (social scoring, manipulative or exploitative AI, most real-time biometric ID in public).

High risk

Allowed with strict duties: risk management, data governance, documentation, human oversight, accuracy & robustness, registration. Covers AI in areas like hiring, credit, education, critical infrastructure.

Limited risk

Transparency duties — tell people they're interacting with AI, and label AI-generated content (incl. deepfakes).

Minimal risk

No specific obligations, but voluntary codes of practice and good governance are encouraged.

The compliance timeline

Aug 2024
Entered into force

The EU AI Act became law; the clock started on a phased rollout.

Feb 2025
Prohibited practices banned

Unacceptable-risk uses (e.g. social scoring, most real-time biometric ID) are now illegal.

Aug 2025
General-purpose AI (GPAI) rules

Obligations for GPAI model providers and the governance bodies took effect.

Aug 2026
High-risk obligations begin

Most high-risk AI system requirements start applying — the big one for many companies.

Aug 2027
Remaining high-risk rules

High-risk AI embedded in regulated products phases in.

What to actually do

Determine your role — are you a provider (you build/put the AI on the market) or a deployer (you use it)? Duties differ.
Classify each AI system's risk tier, and document why.
Stand up AI governance: an AI policy, risk & impact assessments, data governance, human-oversight measures, and logging.
Keep technical documentation and a record you can show — that's what demonstrates compliance.
Review it on a cadence as your systems and the rules evolve.

Notice the pattern: most of this is a management system — exactly what ISO/IEC 42001 defines. Build it once and you satisfy the internal machinery the EU AI Act expects, with evidence you reuse across frameworks.

Get provably ready — in days

01

Assess

A free 5-minute readiness check shows exactly where you stand and what a regulator or customer would ask.

02

Generate

Stand up an ISO 42001-aligned AIMS in one click — policy, Statement of Applicability, AI risk & impact register — then tailor it.

03

Prove it

Produce the impact assessments, controls and audit pack that demonstrate EU AI Act readiness — reused for ISO 42001, NIST AI RMF, SOC 2 and ISO 27001.

EU AI Act FAQ

Does the EU AI Act apply to my startup?

If you build, provide, or use AI and your system's output is used in the EU — even if your company is based in the US, UK or elsewhere — the Act can apply to you. It's extraterritorial, like the GDPR. Your duties depend on your role (provider vs deployer) and your system's risk tier.

What are the EU AI Act risk categories?

Four tiers: unacceptable risk (banned), high risk (strict obligations), limited risk (transparency duties, e.g. disclosing AI and labelling deepfakes), and minimal risk (no specific obligations). Most startup software falls into limited or minimal risk, but AI used in hiring, credit, education, or critical services is often high risk.

When does the EU AI Act take effect?

It's phased. It entered into force in August 2024; prohibited practices applied from February 2025; general-purpose AI rules from August 2025; most high-risk obligations from August 2026; and remaining high-risk rules from August 2027.

What are the penalties for non-compliance?

Fines scale with severity — up to €35 million or 7% of global annual turnover for prohibited practices, and up to €15 million or 3% for most other breaches, whichever is higher.

Does ISO 42001 help with EU AI Act compliance?

Yes — substantially. ISO/IEC 42001, the AI Management System standard, operationalizes much of what the Act expects: AI risk and impact assessments, data governance, human oversight, documentation, and continual review. Building a 42001-aligned AIMS gives you the internal machinery to demonstrate EU AI Act readiness, and the same evidence maps to NIST AI RMF, SOC 2 and ISO 27001.

This page is general information, not legal advice. For decisions specific to your organization, consult qualified counsel.