Technical and Legal Definition
The EU AI Act entered into force on 1 August 2024 with a phased compliance timeline. It classifies AI systems into four risk tiers. Unacceptable risk systems are banned outright: these include real-time biometric surveillance in public spaces, social scoring by governments, and AI that manipulates human behaviour through subliminal techniques. High-risk AI systems must meet strict requirements before deployment and include AI used in employment (CV screening, performance monitoring), credit scoring, medical devices, educational assessment, law enforcement, and critical infrastructure. These systems require a conformity assessment, detailed technical documentation, human oversight mechanisms, and registration in an EU database. Limited-risk systems such as chatbots must disclose they are AI. Minimal-risk systems such as spam filters and recommendation engines face no specific obligations. General-Purpose AI models (GPAI) like GPT-4o and Claude are subject to transparency requirements and, for models trained above a compute threshold of 10 to the power of 25 floating-point operations, systemic risk obligations.
Why the EU AI Act Matters for UK Founders
Post-Brexit, the EU AI Act does not automatically apply in the UK. The UK government is taking a lighter-touch, sector-by-sector approach through existing regulators. However, the EU AI Act applies extraterritorially: if your UK startup's AI product is used by anyone in the EU, including via a web app or API, the Act applies to you. This is the same extraterritorial logic as GDPR. Founders targeting EU enterprise customers will find procurement teams requiring EU AI Act compliance documentation. Investors with EU exposure are already asking portfolio companies to map their AI systems against the risk classification framework. Practically, this means UK founders building AI products should understand whether their system is high-risk (requiring formal conformity assessment) and design audit trails, human override capabilities, and technical documentation into their architecture from day one rather than retrofitting them after a customer demands it.
Key Compliance Timelines
The compliance timeline is phased. The prohibition on unacceptable risk AI applied from February 2025. GPAI model obligations apply from August 2025. High-risk AI system requirements apply from August 2026 for most categories, with some infrastructure categories applying from August 2027. Notified body accreditation and market surveillance infrastructure is being established by member states through 2025 and 2026. For most startups building AI features or AI-augmented SaaS products, the critical near-term action is risk classification: determine whether your AI system falls into a high-risk category and, if so, begin building the required technical documentation and human oversight mechanisms now, before the 2026 deadline.
How SpeedMVPs Builds EU AI Act-Compliant Systems
SpeedMVPs offers EU AI Act compliance consulting and builds AI systems with compliance architecture baked in from the start. For high-risk AI systems, SpeedMVPs implements: detailed technical documentation covering training data, model architecture, and intended use; logging and audit trail infrastructure that records all AI decisions and the data used to reach them; human oversight interfaces that allow authorised humans to override or halt AI outputs; robustness testing protocols including adversarial testing for high-stakes outputs; and data governance pipelines that enforce GDPR-compliant data minimisation and purpose limitation. For GPAI integrations using third-party models like GPT-4o, SpeedMVPs ensures the application layer includes appropriate guardrails, watermarking for AI-generated content where required, and transparency disclosures in the user interface. All infrastructure is deployed within EU data regions and Data Processing Agreements are in place with all third-party AI providers.
The Relationship Between EU AI Act and UK GDPR
The EU AI Act and UK GDPR overlap significantly in their requirements. Both require a Data Protection Impact Assessment for high-risk processing. Both require transparency about automated decision-making. Both enforce data minimisation and purpose limitation. A DPIA conducted for UK GDPR compliance will address many EU AI Act documentation requirements. Startups should treat compliance as a unified programme rather than two separate workstreams. SpeedMVPs recommends appointing a technical DPO function, even informally, before launching any high-risk AI feature into a market covered by either regulation.