Skip to content

Europe

Independent · Brussels & Berlin

Technology · Digital regulation

EU AI Act enforcement begins as compliance startups race to fill governance gap

From 2 August national authorities gained enforcement powers under the AI Act, creating a market for tools that make governance operational rather than merely documentary.

By , Technology Editor

Published

8 min read

The European Commission's AI Office and national market surveillance authorities formally assumed enforcement powers under the AI Act on 2 August 2026, marking the transition from legislative preparation to active supervision. The change is not absolute: transparency obligations for certain general-purpose models and a subset of high-risk systems are live now, while the bulk of requirements for high-risk deployments in sectors such as critical infrastructure, education and employment do not bite until August 2027, and some product-safety-linked categories wait until 2028. But the signal is unambiguous. Companies that deploy artificial intelligence in the single market must now demonstrate documentation, traceability, human oversight and security controls that did not exist as legal obligations twelve months ago.

A regulatory market enters its implementation phase

For years the conversation in Brussels and national capitals centred on the text of the regulation itself, definitions, risk tiers, prohibited practices. That debate is largely settled. The practical question facing boards and compliance officers today is how to translate several hundred pages of legal prose into repeatable, auditable processes without paralysing product development. The answer is not a single certification badge. The startups attracting capital and early customers are those building infrastructure that sits inside the development and deployment lifecycle, turning rules into workflows and producing evidence as a by-product of normal operations.

This shift mirrors what happened after the General Data Protection Regulation took effect in 2018. The first wave of vendors offered mapping tools and policy templates. The survivors built software that embedded privacy checks into code pipelines, data catalogues and vendor management. The AI Act is broader in scope and more technically demanding, but the pattern is recognisable: compliance becomes a software-engineering problem, not a legal-documentation exercise.

Healthcare leads because it has no choice

The most immediate pressure falls on sectors where the AI Act overlaps with existing product-safety regimes. Medical devices and in-vitro diagnostics are the clearest example. Manufacturers already navigate the Medical Device Regulation and the In Vitro Diagnostic Regulation, both of which demand technical files, clinical evaluations and post-market surveillance. When AI is embedded in a device, or used to design the clinical trial that supports its approval, the AI Act adds a parallel layer of conformity assessment, risk management and data-governance requirements.

Barcelona-based Biorce, founded in 2024, operates squarely in this intersection. Its platform Aika supports protocol design, feasibility assessment and regulatory planning for clinical trials, preserving the reasoning and documentation that regulators will demand. The company closed a €43.8 million Series A in February 2026 to accelerate international expansion, a sum that reflects the depth of the problem: pharmaceutical and medtech firms cannot afford to retool their trial processes every time a new regulatory interpretation emerges.

Munich's CertHub, also founded in 2024, automates technical documentation, quality-management workflows and conformity assessments for medical-device manufacturers. Its focus is the MDR and IVDR rather than the AI Act directly, but the company acknowledges that the boundaries are dissolving. As AI becomes integral to device function and development, the regulatory stacks merge. A single platform that speaks both languages is increasingly what buyers need.

Regulatory intelligence moves from periodic to continuous

For companies selling products across dozens of jurisdictions, the challenge is not only the AI Act but the accumulating weight of horizontal and sectoral rules: DORA for financial-sector operational resilience, NIS2 for critical entities, GDPR for personal data, plus national transpositions and guidance. Paris-based Cleo Labs, founded in 2023, addresses this with a multi-agent system called MARIA that tracks more than 25,000 regulatory authorities across 106 countries. The platform converts changing rules into compliance workflows while keeping legal experts in the loop to validate outputs, a design choice that reflects growing wariness about opaque AI recommendations in high-stakes decisions. Cleo Labs raised €1.5 million in April 2026.

Stockholm's Hybridity, founded in 2023, takes a similar continuous-compliance approach but focuses on European frameworks. Its Hy5 platform combines AI with legal engineering to interpret regulations, assign responsibilities, conduct analyses and maintain traceability. The company raised €2 million in February 2026, bringing total reported funding to around €5 million. The pitch is that organisations can no longer treat compliance as a quarterly audit exercise; they must demonstrate how obligations are implemented day to day.

Audit and financial reporting face their own AI moment

The audit profession is confronting a dual pressure: clients are deploying AI in financial processes, and audit firms themselves are adopting generative and agentic models to accelerate engagement work. Berlin's Cortea, founded in 2024, builds Audit Quality Agents that review financial statements, disclosures and supporting workpapers for inconsistencies and compliance issues before sign-off. The technology acts as a quality-control layer between AI-driven efficiency and professional standards that require reviewability and defensibility. A €12 million seed round in June 2026 suggests investors see a structural opportunity: every major audit firm will need tooling that reconciles speed with the evidentiary standards of ISAE 3000 and ISA 230.

Operational resilience and the agent governance problem

Copenhagen's Fortiv, founded in 2025, applies AI agents to business continuity management, collecting business-impact data, interpreting regulatory requirements and maintaining compliant continuity frameworks. The company sits at the intersection of cyber resilience, operational risk and governed AI deployment, reflecting the reality that regulators increasingly view these as a single supervisory surface. Fortiv appeared in a 2026 roundup of promising Danish startups, signalling early recognition in a market where DORA and NIS2 implementation deadlines are concentrating minds.

A more fundamental challenge is emerging as enterprises deploy autonomous agents that can query databases, call APIs and execute transactions. Barcelona's NeuralTrust, founded in 2022, provides a security and governance layer that discovers deployed agents, monitors their interactions with models, tools and systems, and enforces policy controls on their behaviour. The company raised a €17.2 million seed round in summer 2026, described at the time as the largest cybersecurity seed financing for an EU company. The scale of the round reflects a growing consensus: agent governance is not a feature of an AI platform but a distinct infrastructure category.

Paris-based Rippletide, founded in 2024, attacks the same problem from the predictability angle. Its infrastructure places explicit evidence and decision rules around high-risk agent actions, providing decision previews, evidence-linked reasoning and traceability. For compliance teams, the distinction is material: knowing that an agent acted is not the same as being able to reconstruct which policy, evidence and rule justified the action.

Cross-border commerce as a compliance substrate

London's Outpost, founded in 2024, illustrates how AI-enabled compliance is embedding into transactional infrastructure. The company handles payments, tax and regulatory obligations for merchants entering new markets. Its Tax of Record product assumes liability for VAT, GST and sales-tax compliance, while an AI layer monitors regulatory changes. Outpost raised €15 million in March 2026. The model, absorbing audit risk and handling regulatory drift on behalf of the merchant, points toward a future where compliance is a managed service built into the rails of commerce, not a dashboard the merchant logs into.

Berlin's Rulemapping Group, founded in 2024, works at the layer beneath all of this: converting laws and regulations into structured, machine-readable decision logic. Its "law as code" approach makes conditions, exceptions and legal dependencies explicit rather than relying on a large language model to interpret them afresh each time. For regulated AI, where the central difficulty is translating interconnected legal texts into rules software can reliably execute, this foundational work may prove more durable than any single compliance dashboard.

The market is still forming. None of the ten companies profiled here has reached Series B, and several are pre-revenue. But the regulatory clock is no longer theoretical. Boards that treated the AI Act as a 2027 problem are discovering that procurement cycles, model retraining schedules and vendor onboarding take long enough that 2026 decisions already shape 2027 compliance. The startups that survive will be those that make governance invisible, embedded in the commit, the deploy, the agent invocation, rather than visible as a separate compliance workflow. That is a software problem, not a legal one, and European engineers are finally being funded to solve it.

Sources

  1. EU-Startups

    eu-startups.com · 2026-08-20

Organisations

European Commission · European Commission AI Office

Related analysis

Selected because they share topics with this article

The newsletter

One important European story. Explained properly.

Delivered to your inbox on the days we publish. No daily digest, no push notifications, no advertising.

We store your address only to send the briefing. Unsubscribe in one click.