When the European Commission published its proposal for an AI Act in 2021, the technology was still a niche preoccupation for most policymakers. By the time the regulation reaches full enforcement in 2026, artificial intelligence will have reshaped entire industries. Europe's answer to that transformation is a four-tier risk classification system that bans some applications outright, imposes heavy documentation and oversight requirements on others, and leaves the rest largely alone. For the continent's startups, the question is no longer whether to comply, but how much it will cost and whether compliance becomes a competitive asset or a competitive handicap.

A four-tier system that bans and regulates

The AI Act sorts artificial intelligence systems into four categories based on the potential harm they pose. At the top, applications deemed to present unacceptable risk are banned entirely. Social scoring, the kind of state-run surveillance system associated with China, falls into this bracket. So does AI that manipulates human behaviour in ways that circumvent free will, exploiting vulnerabilities related to age, disability or economic circumstance. The European Parliament's position on these prohibitions was never seriously contested during the legislative process: the political consensus held that certain uses of AI have no legitimate place in the European market.

The high-risk category is where the regulation's weight really falls. AI systems used in employment decisions, credit scoring, law enforcement, healthcare diagnostics and critical infrastructure safety must meet extensive requirements before they can be deployed. Companies building or deploying these systems must maintain technical documentation, ensure human oversight is built into the system, and submit to conformity assessments. They must also monitor data quality, ensuring training datasets are accurate, representative and free from the kinds of bias that could produce discriminatory outcomes in lending, hiring or policing.

Below high risk sit two further tiers. Limited-risk systems face transparency obligations: if a user is interacting with an AI chatbot, for instance, the company must disclose that fact. Minimal-risk applications, which cover the vast majority of AI tools in daily use, face no specific regulatory requirements under the Act. The architecture is deliberately graduated, intended to concentrate regulatory effort where the potential for harm is greatest.

The compliance burden on small companies

For a large technology group with an in-house legal department and established regulatory affairs teams, adding AI Act compliance to the existing stack of obligations is a manageable overhead. For a seed-stage startup building a product in Berlin or Zurich, the calculation looks different. The Act demands that high-risk systems undergo conformity assessments, maintain detailed technical documentation, and implement human oversight mechanisms, all before market entry. Post-market surveillance is also required: companies must monitor their deployed systems for incidents and potential misuse on an ongoing basis.

The cost of meeting these requirements is not trivial. Startups must assess which risk category their product falls into, a classification exercise that itself requires legal expertise. They must then build compliance into their product development workflows from an early stage, rather than treating it as a post-hoc certification exercise. A number of compliance platforms have emerged to serve this market. Trustable, for instance, positions itself as a tool for managing risk assessments, documentation and policy compliance. The existence of such services suggests both that demand is real and that the burden is significant enough to support a vendor category.

Splitting liability between developers and deployers

One of the Act's more consequential design choices is its decision to distribute responsibility across the AI value chain. The regulation does not simply point at whoever wrote the algorithm. It distinguishes between developers, who build and train AI systems, and deployers, who put those systems to work in specific contexts. Both carry obligations, but of different kinds.

Developers of high-risk systems bear the primary compliance burden. They must ensure their models meet the Act's requirements for transparency, data quality and documentation before the systems reach the market. But deployers are not off the hook. A bank that purchases a credit-scoring model from a vendor must still implement quality checks, test prompts and outputs, and ensure the system is being used responsibly within its specific context. The Act encourages companies to audit the prompts and outputs of AI systems to prevent unethical or unsafe outcomes. This emphasis on prompt testing is notable: it suggests the regulation anticipates a future in which the role of prompt tester becomes a defined compliance function within organisations.

This shared-liability model reflects a practical reality. The developer of a large language model cannot anticipate every use to which a customer will put it. The deployer, meanwhile, understands the specific context but may lack the technical capacity to evaluate the model's internal workings. The Act attempts to bridge that gap by assigning obligations to both parties.

Open-source models face a particular challenge

The treatment of open-source AI under the Act reveals a tension at the heart of the regulation. Models such as Meta's LLaMA are released openly, allowing anyone to download, modify and deploy them. That openness has been central to the rapid diffusion of AI capabilities across the startup ecosystem. But the AI Act places a higher compliance burden on deployers of open-source models than on deployers of proprietary systems.

The logic is straightforward: if no single developer is exercising quality control over how an open-source model is adapted and used, the deployer must take on that responsibility. Under the Act, deployers of open-source models are expected to monitor, document and validate the models to ensure they align with regulatory requirements. For a small company that has built its product on an open-source foundation model, this means the compliance cost falls directly on its shoulders, rather than being shared with or absorbed by the model's original developer.

The practical effect could be to push startups toward proprietary models sold by large technology companies, precisely the outcome that open-source advocates have warned against. If a startup can buy a model from a vendor that handles compliance documentation, the total cost of ownership may be lower than downloading a free model and then absorbing the full compliance burden internally. This is not a hypothetical concern. It is a structural incentive embedded in the regulation.

The Brussels effect and competitive positioning

European regulations have a history of setting global standards. The General Data Protection Regulation reshaped data practices far beyond the EU's borders, not because other countries adopted identical laws, but because any company wishing to serve European customers had to meet European rules. The AI Act is designed to produce a similar dynamic. Non-EU companies that want access to Europe's 450 million consumers will need to comply with the Act's requirements, regardless of their home jurisdiction. The European Parliament's overview of its AI work makes clear that the institution sees this standard-setting role as a deliberate objective.

For European startups, this creates a paradox. The compliance costs hit them first and hardest, because they operate within the EU's jurisdiction from day one. But if the Brussels effect functions as intended, competitors in the United States and Asia will eventually face similar requirements when they seek to sell into Europe. The competitive disadvantage would then be temporary, while the trust advantage of having built compliant systems from the start would persist.

Whether that optimistic scenario materialises depends on enforcement. A regulation that exists on paper but is poorly enforced confers no competitive advantage on compliant companies. It merely imposes costs on them while their non-compliant competitors operate freely. The European Commission's track record on digital enforcement is mixed. The GDPR produced real changes in corporate behaviour, but enforcement has been uneven across member states, and some of the largest technology companies have found ways to delay and dilute regulatory scrutiny.

Aligning with American regulation

Startups that operate in both European and American markets face an additional layer of complexity. The United States has not passed comprehensive AI legislation. Instead, the Biden administration issued an executive order on AI governance in October 2023, directing federal agencies to establish safety standards and address AI-related risks. The European Commission's own summary of the AI Act positions it as part of a broader digital regulatory framework that includes the Digital Services Act and the Digital Markets Act.

The American order and the European Act are not aligned in structure or ambition. The EU's legislation is binding, risk-based and enforceable through fines and market-access restrictions. The American approach relies on executive authority, voluntary commitments and agency-level rulemaking. For a startup building a product for both markets, the practical strategy is to design to the higher standard, which in most cases means the European one. If the system meets the AI Act's requirements, it will almost certainly satisfy the less prescriptive American framework as well.

This convergence-by-default is what European policymakers are counting on. If enough companies build to the European standard because it is the most demanding one in force, the Act will have achieved its goal of setting a de facto global benchmark, regardless of whether Washington ever passes its own legislation.

What the implementation timeline means for founders

The AI Act was first proposed in 2021 and is expected to take full effect in 2026. That timeline gives companies a window to adapt, but the practical reality is more complicated. Different provisions come into force at different times. The bans on unacceptable-risk applications will apply sooner than the detailed requirements for high-risk systems. Startups building products that could fall into the high-risk category need to begin their classification and compliance work now, because the engineering and documentation changes required cannot be bolted on at the last minute.

The Act also requires post-market surveillance, meaning companies must continue monitoring their AI systems after deployment, reporting incidents and addressing potential misuse as it emerges. This ongoing obligation is a departure from the model of pre-market certification that governs most European product regulation. It recognises that AI systems change over time, both through updates and through the data they encounter in use, and that a system which was safe at launch may not remain so indefinitely.

For startups in the DACH region, which encompasses Germany, Austria and Switzerland, the regulatory landscape is particularly dense. Germany has its own data protection enforcement traditions and a federal structure that can produce inconsistent regulatory interpretation across states. Switzerland, though outside the EU, will face market-access pressure to align with the Act if it wants its AI companies to sell into the single market. Austria, as a smaller market, tends to follow the German regulatory lead. Startuprad.io, which covers the DACH ecosystem, has been tracking how founders are responding to the Act's requirements.

The transparency requirements in the Act also have implications beyond the compliance function. Startups that are open about their use of AI in customer interactions, and that publish clear policies on how AI is employed, may find that transparency itself becomes a market advantage. In sectors where trust is paramount, such as financial services and healthcare, a demonstrable commitment to responsible AI use could be the difference between winning an enterprise contract and losing it to a competitor that cannot prove equivalent compliance.

People mentioned

  • Jörn Menninger

    Host and Editor-in-Chief, Startuprad.io

Organisations

European Union · Startuprad.io