EU AI Act for Startups: What To Do Before The Next Deadline

Marcal Santos
Marcal Santos
July 31, 2026
https://secureleap.tech/blog/eu-ai-act-for-startups
EU AI Act for Startups: What To Do Before The Next Deadline

Key takeaways:

  • The EU AI Act applies to any company whose AI outputs are used in the EU, regardless of where the company is based. 
  • A Digital Omnibus adopted by the EU in June 2026 delayed the compliance deadline for high-risk AI systems. Stand-alone high-risk systems now must comply by December 2, 2027, and high-risk AI embedded in regulated products by August 2, 2028. The original August 2, 2026 high-risk deadline no longer applies.
  • August 2, 2026 is still a real deadline, but for a narrower set of obligations: the transparency requirements (AI disclosure and AI-generated content labeling) and the European AI Office's enforcement powers over general-purpose AI (GPAI) providers.
  • Most startups fall into the limited or minimal risk categories, but if your AI makes automated decisions about people, you're likely building a high-risk AI system. The requirements haven't changed, only the runway to prepare for them has gotten longer.
  • The EU AI Act is a separate regulatory framework from GDPR, SOC 2, and ISO 27001. Existing compliance with those standards does not satisfy EU AI Act obligations.
  • Startups building on top of foundation models (OpenAI, Anthropic, and Gemini) are considered deployers under the Act. That comes with its own set of obligations distinct from those of the model providers themselves.

The EU AI Act became law on August 1, 2024. Most of its obligations are now in force or approaching enforcement. And yet, in almost every conversation I have with founders building AI-native products, what I hear is: “I’ve heard of it”, “I’m vaguely aware it's relevant”, and “I haven't yet mapped what it actually requires”.

That's not unique to any one geography. US founders may assume it's a European problem, while EU founders assume they are already compliant because of ISo 27001 or GDPR. Founders building on top of foundation models assume the obligation sits with OpenAI or Anthropic, not with them.

The next deadline is only a few months away. If your product uses AI in any meaningful way, and especially if it makes decisions about people, this is the guide you need to read.

What is the EU AI Act?

The EU AI Act is the world's first comprehensive regulatory framework for artificial intelligence. It takes a risk-based approach: the obligations that apply to your company depend on what your AI does.

The Act regulates AI systems and general-purpose AI (GPAI) models differently, and it applies to multiple players in the AI value chain. The three most relevant categories for startups are:

  • Providers: they are companies that develop an AI system or have it developed on their behalf, and place it on the market under their own name or trademark. In many cases, startups that develop and place AI-enabled features on the market under their own name will be considered providers.
  • Deployers: companies that use AI systems in a professional context. Startups building on top of foundation models will often qualify as deployers and may also qualify as providers of their own AI systems.
  • GPAI model providers: those that develop foundation models capable of performing a wide range of tasks. This category, such as OpenAI and Anthropic, has separate obligations that are already in effect as of August 2025.

Understanding which category you sit in, or whether you sit in multiple, determines which obligations apply to your company.

The EU AI Act is not the same as GDPR. They share an extraterritorial reach and a risk-based philosophy, but they regulate different things. 

GDPR governs how personal data is collected, stored, and processed. The EU AI Act governs how AI systems are developed and deployed. The two overlap in areas like automated decision-making and profiling, but compliance with GDPR does not satisfy EU AI Act requirements. 

Similarly, SOC 2 and ISO 27001 do not address EU AI Act obligations. This is a separate regulatory framework requiring its own compliance program.

The Enforcement Timeline

The Act entered into force on August 1, 2024, with provisions applying in different phases. 

In November 2025, the European Commission proposed a "Digital Omnibus on AI" to defer part of that timeline. The European Parliament adopted it on June 16, 2026, and the Council of the EU formally adopted it on June 29, 2026, so it's now part of the binding legal framework (Bright Defense).

Here's the timeline as it actually stands:

February 2, 2025: Prohibited AI practices banned. The most extreme uses of AI, like social scoring systems, manipulative AI, certain AI systems used to assess or predict an individual's risk of criminal offending based solely on profiling or personal characteristics, and real-time biometric identification in public spaces, became illegal across the EU. These prohibitions are already in full effect and were not affected by the Digital Omnibus.

August 2, 2025: GPAI rules apply. Providers of foundation models and other general-purpose AI models became subject to the AI Act's GPAI framework: technical documentation, copyright policy, and training-content transparency obligations. Models already on the market before that date benefit from transitional provisions extending until August 2, 2027.

August 2, 2026: Transparency obligations take effect, and GPAI enforcement begins. One of the articles requires AI systems that interact directly with users to disclose that fact, and requires AI-generated content to be marked in machine-readable format when the system generating it enters the market from this date forward. Separately, the European AI Office gains direct enforcement power over GPAI obligations that have technically applied since August 2025.

December 2, 2026: Marking transition ends, and a new prohibition takes effect. Generative AI systems already on the market before August 2, 2026 have until this date to implement machine-readable content marking. A new prohibition also takes effect on this date, covering AI systems used to generate non-consensual intimate imagery or child sexual abuse material.

December 2, 2027: High-risk AI system rules enforced for stand-alone systems. This was originally scheduled for August 2, 2026, but under the Digital Omnibus, requirements for high-risk AI systems (such as documentation, risk management, data governance, and human oversight) now take full effect on this later date instead.

August 2, 2028: Rules for high-risk AI embedded in regulated products. Also delayed, from the original August 2, 2027 date. Requirements for AI systems embedded in products regulated under specific EU safety laws (medical devices, toys, and machinery) now apply from this date.

For most B2B startups, August 2, 2026 is still a real deadline, just for a different reason than originally expected. 

If your product has any user-facing AI features, or generates AI content, transparency obligations apply in days. 

If your AI qualifies as high-risk, the requirements haven't disappeared, they've just moved to December 2027 or August 2028, which changes your planning timeline but not your eventual obligations.

Risk Classification: Where Does Your Product Sit?

The EU AI Act classifies AI systems into four risk tiers, and your obligations depend entirely on which tier your product falls into. 

The tiers themselves were not changed by the Digital Omnibus, only the enforcement dates for the high-risk tier.

  • Prohibited: banned outright. These uses of AI are illegal in the EU regardless of who you are or where you're based. The list includes social scoring systems, AI that exploits human vulnerabilities, biometric categorisation systems that infer sensitive characteristics, facial recognition databases built from untargeted scraping, emotion recognition systems in workplaces and educational institutions, real-time biometric identification in public spaces by law enforcement (with narrow exceptions), and, from December 2, 2026, AI systems used to generate non-consensual intimate imagery or child sexual abuse material.
  • High-risk: subject to strict requirements. High-risk AI systems face the most significant compliance obligations under the Act, now enforced from December 2, 2027 (stand-alone systems) or August 2, 2028 (embedded in regulated products). Some of the categories most relevant to B2B startups include: AI used in employment contexts (recruiting, screening, evaluating, or making promotion decisions), AI that determines access to essential services (including credit scoring, public benefits, and insurance pricing), AI systems in education and vocational training that affect access or assessment, and AI systems that perform profiling within certain use cases may qualify as high-risk.
  • Limited risk: transparency obligations required. AI systems that interact directly with users, or that generate content, must meet transparency requirements from August 2, 2026. Chatbots must disclose to users that they are interacting with AI, and AI-generated content (images, text, video, and audio) must be marked as AI-generated using machine-readable formats. This tier was not affected by the Digital Omnibus delay.
  • Minimal risk: largely unregulated. AI that doesn't fall into the above categories is largely unregulated under the Act. Examples include spam filters, video game AI, and basic recommendation engines. Most productivity AI tools fall here. No mandatory obligations apply, though companies may voluntarily adopt the Act's standards.

For most B2B SaaS companies, an honest product assessment will land in one of two places: limited risk with transparency obligations due in days, or high-risk with documentation and governance requirements now due in late 2027 or 2028.

Does the EU AI Act Apply to You?

The answer for most startups with EU users is: yes.

The EU AI Act applies to providers and deployers outside of the EU if their AI, or the outputs of their AI, are used in the EU. A company that sends data to an AI system, receives outputs, and delivers those outputs to EU users is a provider subject to the Act, regardless of where they’re based.

Certain providers established outside the EU may be required to designate an authorised representative within the EU.

Another important thing: what about startups that build their AI features on top of third-party foundation models rather than developing their own? Under the Act, this makes you a deployer of those models, and deployers have their own obligations.

OpenAI, Anthropic, and Google are responsible for their obligations as GPAI model providers. That does not transfer their obligations to you, nor does it relieve you of yours. As a deployer, you remain responsible for how you integrate, configure, and deploy those models in your product, including whether your specific deployment creates a high-risk AI use case that requires its own compliance program.

What about startups with no EU users today? Well, if your current user base is entirely outside the EU and you have no plans for EU expansion in the near term, your immediate obligations are limited. But the Act's requirements take months to implement properly, so keep that in mind. If you have plans to expand into the EU soon, start considering it.

What High-Risk AI Systems Must Do

If your product includes features that qualify as high-risk AI, here are the core requirements, now in effect from December 2, 2027 for stand-alone systems, or August 2, 2028 for AI embedded in regulated products. The requirements themselves are unchanged.

  • Continuous risk management system: Providers must implement and maintain a risk management system throughout the AI system's lifecycle. This means an ongoing program that identifies and mitigates reasonably foreseeable risks from the AI's intended use.
  • Data governance: Training, validation, and testing data must meet quality standards. The Act requires governance around data collection, data origin, and measures to prevent and mitigate biases in training data.
  • Technical documentation: High-risk AI systems require comprehensive documentation covering system design specifications, capabilities, limitations, and how the system complies with the Act's requirements. This documentation must be maintained and available to regulators on request.
  • Logging and record-keeping: High-risk AI systems must be capable of automatically recording events relevant to identifying risks and monitoring performance throughout the system's lifecycle.
  • Instructions for use: Providers must supply deployers with instructions that enable them to understand and use the AI system in compliance with the Act.
  • Human oversight mechanisms: High-risk AI systems must be designed to allow deployers to monitor, understand, override, and stop the system.
  • Quality management system: Providers must establish a quality management system to ensure ongoing compliance with the Act's requirements.

If you are a deployer of high-risk AI systems, you have a parallel set of obligations: using the system according to the provider's instructions, maintaining relevant logs, and, for certain deployers providing public services, conducting fundamental rights impact assessments before first use.

What to Do Before August 2, 2026

Here's the priority order now, with the genuinely urgent items first, considering the changes after the Digital Omnibus.

1. Implement transparency obligations now

This is the deadline that's actually days away. If any feature involves direct AI interaction with users, make sure users know they're interacting with AI. If any feature generates content, ensure that content is marked as AI-generated in machine-readable formats. This applies regardless of risk tier, and the Digital Omnibus did not touch it.

2. If you're GPAI-adjacent, review your documentation now

The European AI Office gains direct enforcement power over GPAI obligations from August 2, 2026. If you're a foundation model provider yourself, or your product's AI capabilities blur into GPAI territory, this is worth a direct check rather than an assumption.

3. Map every AI feature in your product

Identify each feature that uses AI, whether built in-house, powered by a third-party API, or built on a foundation model. Document what data each feature processes, what outputs it generates, and what decisions or actions those outputs influence.

4. Classify each feature's risk level

For each feature, apply the classification framework above. The critical question: does this AI make or influence decisions about individual people? If yes, assume high-risk until you have a documented assessment that it qualifies for an exception.

5. For high-risk systems: keep preparing, just on the recalibrated timeline

Technical documentation, risk management system design, and data governance records take months to build properly, even with the deadline now at December 2027 or August 2028. A longer runway is a reason to sequence this work sensibly.

6. For high-risk systems: review your product architecture for human oversight

Does your product currently allow deployers to monitor, override, or stop the AI? If not, that's a product change worth scoping now, even if the compliance deadline for it is over a year away.

7. Don't assume existing compliance covers this

SOC 2, ISO 27001, and GDPR compliance do not satisfy EU AI Act requirements. They address different things. So if your compliance program does not specifically include the EU AI Act, it doesn't cover it, regardless of which of the Act's deadlines apply to you.

How SecureLeap Helps Startups Navigate the EU AI Act

The EU AI Act introduces a compliance layer that most startups haven't budgeted for and haven't started building. The challenge isn't just understanding the regulation, but mapping your specific product against it, classifying your AI systems accurately, and building the documentation and governance mechanisms the Act requires. All in time for the deadlines.

SecureLeap helps seed-to-Series B startups navigate compliance programs end-to-end, including emerging regulatory frameworks like the EU AI Act. We bring the same practical, startup-oriented approach we apply to SOC 2 and ISO 27001: focused on what your business actually needs.

If you're unsure whether your product falls under the EU AI Act's high-risk category, or where to start with compliance before the next deadline, book a free consultation or send us an email.

Frequently Asked Questions

Has the EU AI Act's high-risk deadline been delayed?

Yes. The EU's Digital Omnibus, formally adopted by the European Parliament on June 16, 2026, and the Council of the EU on June 29, 2026, deferred the compliance deadline for high-risk AI systems. Stand-alone high-risk systems now must comply by December 2, 2027, instead of August 2, 2026. High-risk AI embedded in regulated products now must comply by August 2, 2028, instead of August 2, 2027. Transparency obligations, GPAI rules, and the prohibited-practices list were not delayed.

Does the EU AI Act apply to US startups?

Yes, if their AI outputs are used in the EU. The Act explicitly applies to providers and deployers outside the EU when their AI systems are used within the EU, regardless of where they're based.

What are the penalties for non-compliance?

Penalties vary by violation type and were not changed by the Digital Omnibus. Non-compliance with prohibited AI practices can result in fines up to €35 million or 7% of worldwide annual turnover, whichever is higher. Non-compliance with high-risk AI requirements can result in fines up to €15 million or 3% of worldwide annual turnover. Providing incorrect or misleading information to authorities can result in fines up to €7.5 million or 1% of annual turnover. For startups and SMEs, the Act provides that the fine is the lower of the two possible amounts specified.

Does GDPR compliance cover EU AI Act requirements?

No. GDPR and the EU AI Act are separate regulatory frameworks. GDPR governs the collection, storage, and processing of personal data. The EU AI Act governs the development and deployment of AI systems. They overlap in areas like automated decision-making and profiling, but satisfying one does not satisfy the other. Similarly, SOC 2 and ISO 27001 certifications do not address EU AI Act obligations, so a dedicated AI Act compliance program is required.

What's the difference between GPAI models and high-risk AI systems?

A general-purpose AI (GPAI) model is an AI model capable of performing a wide range of tasks. Foundation models like GPT and Claude are examples. A high-risk AI system is a specific deployment of AI in a use case that the Act identifies as posing significant risk to individuals. A GPAI model provider like OpenAI has specific obligations around documentation, copyright compliance, and transparency, enforced from August 2, 2026. A startup that builds a hiring tool on top of that model is operating a high-risk AI system and has its own set of obligations as a provider of that system, now enforced from December 2, 2027. The two categories have different requirements, different enforcement bodies, and, since the Digital Omnibus, different deadlines.

We're building on top of OpenAI or Anthropic. Does that transfer their compliance obligations to us?

No. Foundation model providers are responsible for their obligations as GPAI model providers. That responsibility does not transfer to you. But it also doesn't relieve you of yours as a deployer and, if you've built AI features on top of those models, as a provider in your own right, even though the enforcement date for that obligation has moved further out.

Relevant Articles

View all

Compliance Strategy: How To Build a Multi-Framework Program

Running multiple compliance frameworks as separate projects duplicates 60-80% of the work. Here's how to build a single integrated program to satisfy everyone.
Read more

HealthTech Compliance: Every Framework Startups Need

A map of the compliance frameworks healthtech startups really need, like HIPAA, SOC 2, HITRUST, and more, by a vCISO.
Read more

AI Compliance for Startups: EU AI Act, ISO 42001 & NIST

A practical breakdown of the EU AI Act, NIST AI RMF, and ISO 42001: what each requires, who needs them, and how to comply without duplicating work.
Read more