EU AI Act compliance for startups — without the legalese
The EU AI Act is phasing in now, and it reaches beyond the EU — if your AI's output is used there, it can apply to you. Here's what actually matters: your risk tier, the timeline, what you must do, and the fastest way to get provably ready.
First, find your risk tier
The Act sorts AI into four tiers. Your obligations — and your workload — depend entirely on which one you're in.
Unacceptable risk
Banned outright (social scoring, manipulative or exploitative AI, most real-time biometric ID in public).
High risk
Allowed with strict duties: risk management, data governance, documentation, human oversight, accuracy & robustness, registration. Covers AI in areas like hiring, credit, education, critical infrastructure.
Limited risk
Transparency duties — tell people they're interacting with AI, and label AI-generated content (incl. deepfakes).
Minimal risk
No specific obligations, but voluntary codes of practice and good governance are encouraged.
The compliance timeline
The EU AI Act became law; the clock started on a phased rollout.
Unacceptable-risk uses (e.g. social scoring, most real-time biometric ID) are now illegal.
Obligations for GPAI model providers and the governance bodies took effect.
Most high-risk AI system requirements start applying — the big one for many companies.
High-risk AI embedded in regulated products phases in.
What to actually do
Notice the pattern: most of this is a management system — exactly what ISO/IEC 42001 defines. Build it once and you satisfy the internal machinery the EU AI Act expects, with evidence you reuse across frameworks.
Get provably ready — in days
Assess
A free 5-minute readiness check shows exactly where you stand and what a regulator or customer would ask.
Generate
Stand up an ISO 42001-aligned AIMS in one click — policy, Statement of Applicability, AI risk & impact register — then tailor it.
Prove it
Produce the impact assessments, controls and audit pack that demonstrate EU AI Act readiness — reused for ISO 42001, NIST AI RMF, SOC 2 and ISO 27001.
EU AI Act FAQ
Does the EU AI Act apply to my startup?
If you build, provide, or use AI and your system's output is used in the EU — even if your company is based in the US, UK or elsewhere — the Act can apply to you. It's extraterritorial, like the GDPR. Your duties depend on your role (provider vs deployer) and your system's risk tier.
What are the EU AI Act risk categories?
Four tiers: unacceptable risk (banned), high risk (strict obligations), limited risk (transparency duties, e.g. disclosing AI and labelling deepfakes), and minimal risk (no specific obligations). Most startup software falls into limited or minimal risk, but AI used in hiring, credit, education, or critical services is often high risk.
When does the EU AI Act take effect?
It's phased. It entered into force in August 2024; prohibited practices applied from February 2025; general-purpose AI rules from August 2025; most high-risk obligations from August 2026; and remaining high-risk rules from August 2027.
What are the penalties for non-compliance?
Fines scale with severity — up to €35 million or 7% of global annual turnover for prohibited practices, and up to €15 million or 3% for most other breaches, whichever is higher.
Does ISO 42001 help with EU AI Act compliance?
Yes — substantially. ISO/IEC 42001, the AI Management System standard, operationalizes much of what the Act expects: AI risk and impact assessments, data governance, human oversight, documentation, and continual review. Building a 42001-aligned AIMS gives you the internal machinery to demonstrate EU AI Act readiness, and the same evidence maps to NIST AI RMF, SOC 2 and ISO 27001.