AI Act for Tech Startups: What Obligations Apply and When (2026 Guide)
If your startup touches artificial intelligence — even if that just means integrating a third-party model into your product — Regulation (EU) 2024/1689, known as the AI Act, already applies to you. And not only if you train models: deploying a customer service chatbot, generating content with AI, or building a system that scores candidates in a hiring process is enough to bring you in scope.
The good news is that most startups don't fall into the most demanding categories. The bad news is that almost all of them take on some obligation, the timeline has just shifted (in mid-2026, with the Digital Omnibus), and the fines for non-compliance run into the millions. Let's break it down.
What the AI Act is, and why it's horizontal
The AI Act is the world's first comprehensive regulatory framework for artificial intelligence. It entered into force on 1 August 2024 (art. 113) and doesn't regulate specific sectors — it applies horizontally to any AI system placed on the market or put into service in the European Union, regardless of where the provider is established. In other words: if your product reaches users in the EU, it applies to you even if your company is incorporated in Delaware or London.
Its logic is easy to state and harder to apply: the greater the risk a system poses to people's rights and safety, the more obligations fall on whoever develops or uses it. That's why the first question to ask about any product isn't "do I have to comply with the AI Act?" but "which risk tier does what I'm building fall into?" As technology law specialists, that classification is always the first step in any analysis.
The four risk tiers (and where a startup usually falls)
Unacceptable risk (banned, art. 5). A handful of practices are banned outright: subliminal manipulation causing harm, exploitation of vulnerabilities, government-style social scoring, biometric categorisation to infer sensitive data, or mass facial recognition through indiscriminate scraping, among others. The Digital Omnibus added non-consensual intimate image generation ("nudifiers") and child sexual abuse material to this list. If your business model depends on anything on this list, there's no compliance path — you need to redesign it.
High risk (Annex III and Annex I). This is where most of the regulatory burden sits. Annex III lists specific high-impact uses: recruitment and personnel-evaluation systems (an ATS that screens CVs falls squarely here), credit scoring, access to education, critical infrastructure management, biometrics, or certain applications in justice and law enforcement. Annex I covers AI embedded in products already regulated under sector-specific safety rules (medical devices, machinery, vehicles). If your product falls here, you take on the heaviest obligations: a risk-management system across the whole lifecycle, training-data governance, technical documentation, human oversight, registration and CE marking, among others.
Limited risk (transparency obligations, art. 50). This is where most startups using AI without building high-risk systems land. If your product interacts with people (a chatbot), you must disclose that they're talking to an AI. If you generate or manipulate content (text, image, audio, video), you must label it as artificially generated, including machine-readable marking for synthetic content. These are manageable obligations, but real ones — and many companies discover them late.
Minimal risk. Everything else (spam filters, basic recommenders, AI in video games) carries no specific obligations beyond voluntary best practice.
On top of this sits a cross-cutting layer: if you use a third-party general-purpose AI model (GPAI — the major LLMs on the market), the model provider has its own obligations since August 2025, but you, as the one integrating and deploying it, remain responsible for how you use it within your product.
The real timeline after the Digital Omnibus
This is the point worth scrutinising closely, because the 2024 scenario is no longer the one in force. Having found that the regulatory infrastructure (harmonised standards, support tools) wasn't ready in time, the Commission presented the so-called Digital Omnibus on 19 November 2025, delaying the application of high-risk obligations. Following the political agreement reached in May 2026 and the subsequent backing of the European Parliament and Council, the applicable timeline now reads:
| Date | What applies | Status |
|---|---|---|
| 1 Aug 2024 | Regulation enters into force (art. 113) | In force |
| 2 Feb 2025 | Unacceptable-risk prohibitions (art. 5) and AI literacy (art. 4) | In force |
| 2 Aug 2025 | Obligations for general-purpose AI models (GPAI, arts. 51-56); AI Office operational | In force |
| 2 Aug 2026 | Transparency obligations under art. 50 (AI-generated content) | In force, with nuances |
| 2 Dec 2026 | End of the grace period for art. 50.2 labelling for systems already on the market; end of the transitional period for the new ban on "nudifiers"/CSAM | New |
| 2 Dec 2027 | High-risk obligations under Annex III (delayed from 2 Aug 2026) | New |
| 2 Aug 2028 | High-risk obligations under Annex I, AI in regulated products (delayed from 2 Aug 2027) | New |
The practical takeaway: the prohibitions and the GPAI obligations are already in force, transparency under art. 50 still stands for August 2026, and the big block of high-risk obligations has shifted to December 2027 and August 2028. It's a postponement, not an amnesty — the Regulation's architecture remains intact.
A note of caution: the Digital Omnibus was adopted by the Parliament and Council in June 2026 and enters into force upon publication in the OJEU (expected July 2026). Confirm it has actually been published before making any decision that depends on the timeline.
What a founder should do today
Start with an honest classification exercise: map every AI feature in your product against the four tiers. Most discover they sit in "limited risk" territory, with a real duty of transparency rather than a full risk-management system to build. But it's worth doing this in writing, because in a funding round's due diligence, a sharp investor will ask exactly this.
If you do turn out to be high risk (and a recruiting ATS or a scoring engine are), the delay to 2027 and 2028 buys you room, but it's not an excuse to sit on it: building the technical documentation, data governance and human oversight takes months, not weeks. Treat the new dates as a runway, not a reason to shelve the issue.
And if you're in transparency territory, sort it out now: disclosing that users are interacting with an AI and labelling generated content is cheap to implement and expensive to ignore.
Risks we flag in red
The most common mistake is assuming "this is for OpenAI, not for me." The AI Act also applies to whoever deploys a system, not only to whoever trains the model. Integrating a third-party LLM into your SaaS doesn't exempt you.
The second mistake is reading the delay as a free pass. The August 2026 transparency obligations haven't essentially moved, and the prohibitions have been in force since February 2025.
And it's worth keeping the scale of the fines in mind (art. 99): up to €35 million or 7% of worldwide annual turnover for prohibited practices; up to €15 million or 3% for breaching the rest of the obligations; and up to €7.5 million or 1% for providing incorrect information to the authorities. For SMEs and startups, the Regulation applies whichever of the two amounts is lower, which softens the blow but doesn't remove it.
The AI Act also interacts with GDPR whenever personal data is involved — which is almost always. An AI system that processes personal data has to comply with both frameworks at once, and one impact assessment doesn't replace the other. If you want to go deeper into the intersection between AI and data protection, we have a dedicated guide on AI regulation and sensitive data under GDPR.
Frequently asked questions
Does the AI Act apply to my startup if I only use a third-party AI model?
Yes. The Regulation also binds whoever deploys the system (the deployer), not just the model provider. Integrating a market LLM into your SaaS makes you responsible for how you use it within your product, with the transparency obligations and, where applicable, the high-risk obligations that apply.
Is my customer service chatbot a high-risk system?
Usually not. A chatbot typically falls under "limited risk," with the transparency obligation under art. 50 (informing the user they're interacting with an AI). High risk is reserved for Annex III uses such as personnel selection, credit scoring or biometrics.
Has the AI Act been delayed?
Only partly. The Digital Omnibus (2026) delays the high-risk obligations under Annex III to December 2027 and those under Annex I to August 2028. But the prohibitions (in force since February 2025), the general-purpose AI model rules (August 2025) and the art. 50 transparency obligations (August 2026) proceed as planned.
What are the penalties for breaching the AI Act?
Up to €35 million or 7% of worldwide turnover for prohibited practices, and up to €15 million or 3% for the rest of the breaches (art. 99). SMEs and startups are subject to whichever of the two amounts is lower.
How we see it at Satya Legal
Classifying a product correctly is half the job, and it's where the most money is saved or lost. We've seen startups over-comply out of fear (building high-risk structures for a product that only needed transparency) and others under-comply out of ignorance. The sweet spot is the same as always: understand exactly where you stand, comply with what's required and no more, and document it for when an investor asks.
Want to know what risk tier your AI product falls into?
We help you classify your system under the AI Act and map out clearly what applies to you and when. We speak plainly and don't inflate the scope.