compliance

EU AI Act

The world's first comprehensive AI regulation, establishing risk-based requirements for AI systems placed on the EU market, with obligations for high-risk AI systems.

The EU AI Act is the world's first comprehensive legal framework regulating artificial intelligence, applying to any AI system placed on the EU market or used within the EU regardless of where the developer is based. For UK startups with EU customers or investors, it is not optional reading: violations carry fines of up to 35 million euros or 7 percent of global annual turnover, whichever is higher.

Technical and Legal Definition

The EU AI Act entered into force on 1 August 2024 with a phased compliance timeline. It classifies AI systems into four risk tiers. Unacceptable risk systems are banned outright: these include real-time biometric surveillance in public spaces, social scoring by governments, and AI that manipulates human behaviour through subliminal techniques. High-risk AI systems must meet strict requirements before deployment and include AI used in employment (CV screening, performance monitoring), credit scoring, medical devices, educational assessment, law enforcement, and critical infrastructure. These systems require a conformity assessment, detailed technical documentation, human oversight mechanisms, and registration in an EU database. Limited-risk systems such as chatbots must disclose they are AI. Minimal-risk systems such as spam filters and recommendation engines face no specific obligations. General-Purpose AI models (GPAI) like GPT-4o and Claude are subject to transparency requirements and, for models trained above a compute threshold of 10 to the power of 25 floating-point operations, systemic risk obligations.

Why the EU AI Act Matters for UK Founders

Post-Brexit, the EU AI Act does not automatically apply in the UK. The UK government is taking a lighter-touch, sector-by-sector approach through existing regulators. However, the EU AI Act applies extraterritorially: if your UK startup's AI product is used by anyone in the EU, including via a web app or API, the Act applies to you. This is the same extraterritorial logic as GDPR. Founders targeting EU enterprise customers will find procurement teams requiring EU AI Act compliance documentation. Investors with EU exposure are already asking portfolio companies to map their AI systems against the risk classification framework. Practically, this means UK founders building AI products should understand whether their system is high-risk (requiring formal conformity assessment) and design audit trails, human override capabilities, and technical documentation into their architecture from day one rather than retrofitting them after a customer demands it.

Key Compliance Timelines

The compliance timeline is phased. The prohibition on unacceptable risk AI applied from February 2025. GPAI model obligations apply from August 2025. High-risk AI system requirements apply from August 2026 for most categories, with some infrastructure categories applying from August 2027. Notified body accreditation and market surveillance infrastructure is being established by member states through 2025 and 2026. For most startups building AI features or AI-augmented SaaS products, the critical near-term action is risk classification: determine whether your AI system falls into a high-risk category and, if so, begin building the required technical documentation and human oversight mechanisms now, before the 2026 deadline.

How SpeedMVPs Builds EU AI Act-Compliant Systems

SpeedMVPs offers EU AI Act compliance consulting and builds AI systems with compliance architecture baked in from the start. For high-risk AI systems, SpeedMVPs implements: detailed technical documentation covering training data, model architecture, and intended use; logging and audit trail infrastructure that records all AI decisions and the data used to reach them; human oversight interfaces that allow authorised humans to override or halt AI outputs; robustness testing protocols including adversarial testing for high-stakes outputs; and data governance pipelines that enforce GDPR-compliant data minimisation and purpose limitation. For GPAI integrations using third-party models like GPT-4o, SpeedMVPs ensures the application layer includes appropriate guardrails, watermarking for AI-generated content where required, and transparency disclosures in the user interface. All infrastructure is deployed within EU data regions and Data Processing Agreements are in place with all third-party AI providers.

The Relationship Between EU AI Act and UK GDPR

The EU AI Act and UK GDPR overlap significantly in their requirements. Both require a Data Protection Impact Assessment for high-risk processing. Both require transparency about automated decision-making. Both enforce data minimisation and purpose limitation. A DPIA conducted for UK GDPR compliance will address many EU AI Act documentation requirements. Startups should treat compliance as a unified programme rather than two separate workstreams. SpeedMVPs recommends appointing a technical DPO function, even informally, before launching any high-risk AI feature into a market covered by either regulation.

Frequently Asked Questions

Does the EU AI Act apply to UK startups?+

Yes, if your AI product is placed on the EU market or used within the EU, the EU AI Act applies regardless of where you are based. This is the same extraterritorial principle as GDPR. UK startups with EU customers, EU investors, or products accessible from within the EU need to assess their AI systems against the EU AI Act's risk classification framework and comply with the obligations relevant to their risk tier.

What are the fines for violating the EU AI Act?+

Fines are tiered by violation type. Prohibited AI practices (unacceptable risk violations) carry fines up to 35 million euros or 7 percent of global annual turnover. Non-compliance with other obligations for high-risk systems carries fines up to 15 million euros or 3 percent of global annual turnover. Providing incorrect information to authorities carries fines up to 7.5 million euros or 1 percent of global annual turnover. These are maximum fines; regulators will consider company size, and SME provisions may apply.

Is a chatbot a high-risk AI system under the EU AI Act?+

Most general-purpose chatbots are limited-risk or minimal-risk: they require transparency disclosures (users must be told they are speaking to an AI) but not formal conformity assessments. A chatbot becomes high-risk if it is used in a regulated context such as assessing creditworthiness, making employment decisions, or providing medical advice. The deciding factor is the intended use and impact, not the underlying technology.

How long does it take to become EU AI Act compliant?+

For minimal and limited-risk AI systems, compliance is largely a matter of implementing transparency disclosures and reviewing your use cases against the prohibited practices list, which can be completed in days. For high-risk AI systems, compliance requires technical documentation, conformity assessment, and registered oversight mechanisms, which is a programme of 3 to 6 months for a typical startup. SpeedMVPs offers fixed-price EU AI Act compliance audits and technical implementation services to accelerate this process.

Not sure whether your AI product is EU AI Act compliant? SpeedMVPs offers a fixed-price compliance audit and can build the required technical documentation, audit trails, and oversight mechanisms into your system. Book a free compliance discovery call.

Get a Free Quote