EU AI Act: What Founders Need to Know (Without the Legal Jargon)
The EU AI Act is here. Here is what it means for founders: risk categories, compliance requirements, what investors will ask, and claims to avoid in your deck.

The EU AI Act is here. If you are building an AI product, it affects you.
This is the world's first comprehensive AI regulation. It came into force in 2024 and is being implemented in stages through 2027. Whether you are based in the EU or just selling to EU customers, you need to understand what it means for your startup.
But most explanations are written by lawyers for lawyers. This guide is written for founders. It covers what the EU AI Act actually requires, how to figure out if it applies to you, what investors will ask about it, and how to avoid compliance claims that could backfire.
Important: This is not legal advice. The EU AI Act is complex and still being interpreted. For specific guidance on your situation, consult a lawyer who specialises in AI regulation.
What Is the EU AI Act?
The EU AI Act is a regulation that creates rules for AI systems sold or used in the European Union. It takes a risk-based approach: the higher the risk your AI poses, the stricter the rules.
Key dates (phased application):
- 2 February 2025: Prohibitions on unacceptable-risk AI apply
- 2 August 2025: Rules for general-purpose AI models apply
- 2 August 2026: Most other provisions apply (including high-risk AI systems)
- 2 August 2027: Certain high-risk rules for specific sectors; some obligations also apply to existing GPAI models already on the market
Who it applies to:
- AI providers (companies that develop and place AI on the market)
- AI deployers (companies that use AI systems)
- Anyone placing AI on the EU market, regardless of where they are based
If you sell to EU customers, this applies to you even if you are based in the UK, US, or elsewhere.
Your Role Under the Act: Provider, Deployer, or Something Else?
The EU AI Act assigns different obligations depending on your role. Understanding your role is critical.
Provider: You develop an AI system and place it on the market or put it into service under your own name or trademark. Providers have the heaviest obligations (conformity assessments, documentation, registration for high-risk systems).
Deployer: You use an AI system in a professional capacity (but did not develop it). Deployers have lighter obligations but still must use systems according to instructions and monitor for risks.
Importer/Distributor: You bring AI systems into the EU market or make them available without being the provider or deployer. You have verification and documentation duties.
Where most startups fall:
- If you build your own AI models or systems: you are likely a provider
- If you use GPT, Claude, or similar via API with minimal modification: you are likely a deployer
- If you fine-tune significantly, brand it as your own product, or substantially modify a foundation model: your obligations may shift toward provider status
Why this matters: A deployer using OpenAI's API has fewer direct obligations than a provider building their own system. But if you fine-tune heavily, add your branding, and sell it as "your AI," regulators may treat you as a provider with corresponding obligations.
When in doubt, get legal advice on your specific setup.
TL;DR
- The EU AI Act uses a risk-based system: unacceptable, high, limited, and minimal risk
- Most startup AI products fall into limited or minimal risk (fewer requirements)
- High-risk AI (hiring, credit, healthcare decisions) has significant compliance obligations
- General-purpose AI models (like foundation models) have their own rules
- Penalties are serious: up to €35M or 7% of global revenue
- Investors will ask about your compliance posture. Have an answer
- Do not overclaim compliance in your pitch deck. It will be checked
The Risk Categories
The EU AI Act categorises AI systems by risk level. Your obligations depend on which category your product falls into.
Unacceptable Risk (Prohibited)
These AI applications are generally prohibited in the EU, though some have narrow exceptions under strict conditions:
- Social scoring by public authorities
- Real-time remote biometric identification in public spaces (narrow law enforcement exceptions exist)
- AI that manipulates people's behaviour to cause harm
- AI that exploits vulnerabilities of specific groups (age, disability) to cause harm
- Emotion recognition in workplaces and educational institutions (with limited exceptions)
- Untargeted scraping of facial images from the internet or CCTV to build recognition databases
- Biometric categorisation based on sensitive characteristics
For most startups: If your product falls into these categories, get legal advice immediately. Most are prohibited or heavily restricted.
High Risk
AI systems that pose significant risks to health, safety, or fundamental rights. These face the strictest requirements.
High-risk categories include:
- AI used in hiring, recruitment, or employment decisions
- AI used in credit scoring or loan decisions
- AI used in educational assessment or admissions
- AI used in healthcare diagnostics or treatment decisions
- AI used in law enforcement or criminal justice
- AI used in migration and border control
- AI used in critical infrastructure management
Requirements for high-risk AI:
- Risk management system throughout the AI lifecycle
- Data governance and documentation requirements
- Technical documentation and record-keeping
- Transparency and information to users
- Human oversight measures
- Accuracy, robustness, and cybersecurity requirements
- Conformity assessment before placing on market
- Registration in EU database
For startups in these areas: Compliance is real work. Budget for it. Get legal help early.
Limited Risk
AI systems with specific transparency obligations, but fewer requirements than high-risk.
Examples:
- Chatbots and conversational AI (must disclose they are AI)
- AI systems generating synthetic content (deepfakes, synthetic media)
- Emotion recognition systems (outside prohibited uses)
- Biometric categorisation systems (outside prohibited uses)
Requirements:
- Transparency: users must know they are interacting with AI (e.g., chatbots must disclose their nature)
- Disclosure for synthetic content: certain AI-generated content, particularly deepfakes and synthetic media that could be mistaken for real, must be disclosed as AI-generated
- Information provision: certain AI systems must inform users of their nature and capabilities
For most B2B SaaS startups: This is likely your category. The requirements are manageable.
Minimal Risk
AI systems that pose minimal or no risk. No specific requirements under the Act, though voluntary codes of conduct are encouraged.
Examples:
- AI-powered spam filters
- AI in video games
- Inventory management AI
- Most recommendation systems
For these products: No specific EU AI Act obligations, though other laws (GDPR, product safety) still apply.
General-Purpose AI Models
The EU AI Act has special rules for general-purpose AI (GPAI) models, including foundation models and large language models.
If you are building on top of GPT, Claude, or similar:
You are likely a "deployer" using a GPAI model, not a GPAI provider. The heavy GPAI-specific obligations fall on the model provider (OpenAI, Anthropic, etc.), not on you. See the section above on provider vs deployer roles.
However:
- If you fine-tune significantly, you may take on additional responsibilities
- You must still comply with rules for your specific use case (high-risk, limited risk, etc.)
- You cannot use a foundation model to circumvent your own obligations
If you are building a foundation model yourself:
You face additional requirements: technical documentation, transparency about training, compliance with copyright rules, and more. GPAI models with "systemic risk" (very large models) have even stricter obligations.
How to Figure Out If You Are High-Risk
This is the key question for most founders. Here is a practical checklist:
You are likely HIGH-RISK if your AI:
- Makes or significantly influences hiring decisions
- Scores or assesses candidates for jobs or education
- Makes or influences credit, loan, or insurance decisions
- Provides medical diagnoses or treatment recommendations
- Assesses risk in law enforcement contexts
- Makes decisions about migration or asylum
- Controls critical infrastructure (energy, water, transport)
You are likely LIMITED RISK if your AI:
- Interacts directly with users who might think it is human (chatbots)
- Generates content (text, images, audio) that could be mistaken for human-created
- Recognises emotions or categorises people biometrically
You are likely MINIMAL RISK if your AI:
- Works in the background without significant user interaction
- Does not make decisions about people
- Does not generate deceptive content
- Serves internal operational purposes
When in doubt: Consult a lawyer. The line between categories is not always clear, and the consequences of getting it wrong are significant.
What This Means for Fundraising
Investors are increasingly aware of AI regulation. Here is what they will ask and how to prepare:
Questions to expect
"Have you assessed your EU AI Act risk category?"
"What is your compliance roadmap?"
"Do you have legal counsel advising on AI regulation?"
"How does regulation affect your ability to sell in the EU?"
"What happens if the rules tighten?"
How to answer well
Know your risk category. "We have assessed our product as limited risk under the EU AI Act because we are a B2B chatbot that does not make consequential decisions about individuals."
Have a roadmap. "We have identified the transparency requirements that apply to us and are implementing disclosure mechanisms before the August 2025 deadline."
Show proportionate response. "We are monitoring regulatory developments and have allocated budget for compliance as we scale into EU markets."
Do not overclaim. "We are working toward compliance" is better than "we are fully compliant" if you cannot back it up.
Claims to avoid in your pitch deck
"Fully EU AI Act compliant" — Unless you have gone through conformity assessment (for high-risk) or have documentation to prove it, this claim will be challenged.
"AI-powered decision-making for HR/lending/healthcare" — These trigger high-risk classification. Make sure you can back up the compliance work.
"Our AI has no regulatory risk" — This suggests you have not done the analysis. Every AI product has some regulatory exposure.
Better framing:
- "We have assessed our product under the EU AI Act and identified our obligations"
- "Our compliance roadmap addresses the requirements applicable to our risk category"
- "We are working with legal counsel to ensure regulatory alignment"
Practical Steps for Early-Stage Founders
You do not need a massive compliance programme at pre-seed. But you do need to start thinking about this.
Now (any stage)
- Understand your risk category. Spend an hour mapping your product to the EU AI Act categories. Document your reasoning
- Check for prohibited uses. Make sure you are not accidentally building something banned
- Build transparency in. If users interact with AI, tell them. This is cheap to implement now and expensive to retrofit later
Before you sell in the EU
- Document your AI system. What data it uses, how it was trained, what decisions it makes, what safeguards exist
- Implement required disclosures. Chatbot notices, AI-generated content labels, whatever your category requires
- Get legal review. Before your first EU customer, have a lawyer confirm your categorisation and obligations
At seed and beyond
- Build compliance into product development. Not as an afterthought
- Assign responsibility. Someone should own AI compliance, even if it is part of a broader role
- Monitor regulatory developments. The EU AI Act is still being interpreted. Guidance and standards are evolving
Common Mistakes
Assuming it does not apply because you are UK/US-based
If you sell to EU customers, you are subject to the EU AI Act. Geographic location of your company does not exempt you.
Ignoring it because you are "too early"
Retrofitting compliance is expensive. Building it in from the start is cheap. At minimum, know your risk category.
Overclaiming compliance
"EU AI Act compliant" is a verifiable claim. If an investor or customer checks and you cannot back it up, you lose credibility on everything else.
Assuming "we just use GPT" means no obligations
Using a foundation model does not exempt you from the rules applicable to your use case. If you build a high-risk application on GPT, you still have high-risk obligations.
Waiting for "final" guidance
Regulatory interpretation will evolve for years. Do not use uncertainty as an excuse to do nothing. Start with what is clear and adapt as guidance emerges.
FAQ
Does the EU AI Act apply to UK startups?
If you sell to EU customers, yes. The UK is no longer in the EU, but EU rules apply to products placed on the EU market. The UK is also developing its own AI regulation, so monitor both.
What are the penalties?
Up to €35M or 7% of global annual revenue for the most serious violations (prohibited AI). Up to €15M or 3% for other violations. These are maximums; actual penalties will depend on circumstances.
When do I need to be compliant?
Depends on your category. Prohibited AI rules apply from 2 February 2025. General-purpose AI rules apply from 2 August 2025. Most high-risk rules apply from 2 August 2026. Some provisions extend to 2 August 2027. Start now; do not wait for deadlines.
Do I need a conformity assessment?
Only for high-risk AI. Limited and minimal risk products do not require conformity assessment, though documentation and transparency obligations still apply.
Where can I read the actual regulation?
The full text is available at EUR-Lex. For more accessible guidance, check the European Commission's AI Act pages and the AI Office resources as they are published.
Where to Go From Here
Pitching an AI startup? Read how to pitch an AI startup to investors
Worried about claims in your deck? Read 5 claims investors fact-check in AI decks
Understanding what investors look for? Read what investors look for in AI startups
Ready to raise? Read complete guide to raising pre-seed and seed
Closing Thought
The EU AI Act is not going away. It is the first comprehensive AI regulation, but it will not be the last. Other jurisdictions are watching and will follow.
For founders, this is not a reason to panic. It is a reason to be thoughtful.
Know your risk category. Build transparency in from the start. Do not overclaim compliance you cannot prove. Get legal help when you need it.
The founders who treat regulation as a constraint to work within, rather than a threat to ignore, will build more durable businesses. Compliance is not a competitive disadvantage. It is a signal that you are building something meant to last.
Start now. Build it in. Do not wait for the deadline.
Make Sure Your Deck Does Not Overclaim
Platvix helps AI founders pitch with credibility:
- Flags compliance claims that could backfire
- Checks that your regulatory framing is defensible
- Verifies market and technical claims investors will probe
- Matches you to investors who fund AI at your stage
Do not let one unverified claim undermine your pitch.
Tags
- eu-ai-act
- Regulatory
- compliance
- Europe
About the author
Zeeshan Ali, Co-Founder
Co-founder at Platvix, building an investment intelligence platform and the ecosystem around it so founders become investment-ready faster and VCs make stronger decisions. I focus on operations, partnerships, and community building, turning strategy into execution through programmes, processes, and founder support.