Does the EU AI Act Apply to Startups?
Yes, with important nuances. The EU AI Act applies to organisations of all sizes that develop, deploy, or import AI systems in the EU. There is no general startup or SME exemption. However, the regulation contains provisions specifically designed to reduce the compliance burden on smaller organisations, and the proportionality principle shapes how penalties and obligations apply in practice.
The first step for any startup or SME is to determine whether their AI systems fall into the high-risk category. The vast majority of early-stage AI products, content tools, productivity software, most recommendation engines, analytics platforms, and coding assistants, are minimal-risk and face no mandatory requirements whatsoever. If your AI does not operate in the eight Annex III high-risk domains and is not a GPAI model, your compliance burden may be close to zero.
Startup-Specific Provisions in the EU AI Act
- Article 99(6), Proportionate penalties: National competent authorities may impose penalties proportionate to the size and economic capacity of SMEs and startups while still ensuring deterrence. This does not create an exemption but means penalties may be below the stated maximums for very small organisations.
- Article 55, Reduced GPAI obligations: Open-source GPAI model providers are exempt from information provision and copyright compliance policy requirements, unless the model has systemic risk.
- Article 62, Regulatory Sandboxes: Member states must establish AI regulatory sandboxes, supervised environments for developing and testing innovative AI systems before market release, with reduced regulatory burden during the sandbox period. Specifically designed for startups and SMEs.
- Article 68, SME Support Measures: Member states must support SMEs and startups with sandbox access, standardised templates, dedicated competent authority channels, and reduced fees for conformity assessment procedures.
- Proportionate QMS (Art. 17): The Quality Management System requirement for high-risk AI providers is explicitly proportionate to organisational size, SMEs may implement simplified QMS structures.
Risk Classification for Your Startup AI Product
✓ Likely Minimal-Risk, No Mandatory Requirements
SaaS productivity tools; content creation AI; coding assistants; marketing automation; inventory optimisation; business analytics; image generation for creative use; general recommendation engines; customer sentiment analysis; AI-powered search. No mandatory compliance requirements under the Act.
⚠ Transparency Obligations Only, Limited-Risk
Customer-facing chatbots and virtual assistants (must disclose AI nature); deepfake or synthetic media generation tools (must label AI-generated output); emotion recognition products. Specific transparency measures required but not the full high-risk compliance framework.
🔴 High-Risk, Full Compliance Required by 2 December 2027
HR/recruitment AI; credit scoring or financial risk models; medical AI; education assessment AI; biometric identity verification; AI in law enforcement or border management; any AI in the Annex III eight domains. Full compliance required regardless of company size.
If Your Product Is High-Risk: What You Must Do
If your product falls into the high-risk category, the compliance path is the same as for large enterprises, obligations are not reduced by company size. However, the proportionate QMS requirement and SME-aware penalty framework provide relief. Key steps for startups in regulated AI domains:
- Engage AI-Act-aware legal counsel early. Startups building in high-risk domains should have regulatory counsel involved from product design stage, retrofitting compliance into a live product costs substantially more than building it in from day one.
- Explore regulatory sandboxes (Article 62). If your product is innovative and needs a supervised testing environment, sandboxes provide development runway with regulatory guidance and reduced immediate compliance obligations.
- Use professional compliance templates. Rather than commissioning bespoke documentation from scratch, use structured templates for the risk management system, Annex IV technical documentation, and FRIA. This dramatically reduces the cost of initial compliance.
- Design human oversight in from the start. Article 14 oversight requirements are most expensive to retrofit. Build human intervention points into your system architecture from the earliest design decisions.
- Document your classification reasoning. Even before you have a full programme, document your risk classification decisions and reasoning. Regulators will consider documented good-faith effort in penalty determinations.
GPAI Startups: Specific Considerations
Startups providing or fine-tuning GPAI models have faced GPAI obligations since 2 August 2025. Open-source model providers benefit from reduced standard obligations. The 10²⁵ FLOPs systemic risk threshold is well above what most startup-scale models reach, most early-stage model development will not approach it. However, the standard GPAI documentation and transparency obligations apply to all GPAI providers regardless of size.
Investor and M&A Considerations
EU AI Act compliance is increasingly a due diligence concern in venture capital, private equity, and M&A. Investors in AI startups, particularly those building in regulated domains, are beginning to assess compliance status as standard practice. Early-stage startups should treat compliance documentation as a commercial asset: a credible, documented programme reduces investor risk and supports premium valuation in fundraising and exit scenarios.
Cost Reduction Strategies for SMEs
- Use ready-made compliance documentation templates rather than commissioning bespoke legal documents
- Access EU regulatory sandbox programmes for pre-market development (Article 62)
- Participate in national competent authority SME support programmes (Article 68)
- Build compliance documentation into product development workflows from the start, avoid retrospective audits
- Consider ISO 42001 implementation if targeting enterprise customers, certification provides commercial value beyond regulatory compliance
Startup-Ready Compliance Documentation
Our Checklist Pack ($149) includes the AI System Inventory Template, Annex III Classification Matrix, and Board Briefing Template, designed for startup compliance programmes and investor due diligence presentations.
No. There is no pre-revenue or beta exemption. If you are making an AI system available to EU users, even in closed beta, the Act's obligations apply. The proportionality provisions affect penalty levels, not the existence of compliance obligations. Startups in regulated AI domains should treat compliance as a product requirement from the earliest development stages.
Article 62 regulatory sandboxes are supervised environments where organisations can develop and test innovative AI under regulatory oversight, with some compliance obligations relaxed during the testing period. They are specifically intended for SMEs and startups with innovative AI. Access is through applications to the national competent authority in your primary member state of establishment. Availability and selection criteria vary by member state, check with the designated AI authority in your country.