Legal viability analysis before building your AI product
In most AI projects we see, the development budget was approved before anyone asked the first legal question. In AI that order is expensive: the law is a design variable, not a post-launch formality. It can make your use case unviable, condition the architecture, or simply add manageable obligations. Knowing which of the three scenarios you are in costs very little at the start and a great deal once the product exists.
Three possible fates under the EU AI Act
Regulation (EU) 2024/1689 classifies systems by risk. At one extreme are the prohibited practices of art. 5 (subliminal manipulation, social scoring, certain biometric uses, emotion recognition at work or school), applicable since 2 February 2025, with fines up to 35 million euros or 7% of worldwide turnover (art. 99). In the middle, high-risk systems under Annex III (AI that scores or decides in employment, credit, education, insurance or essential services), whose requirements shape how the product must be built. At the other end, the majority of products: transparency duties under art. 50 only, applicable since 2 August 2026, or no specific obligations at all.
The calendar changed recently: the Digital Omnibus package, in force since late July 2026, postponed the high-risk requirements to 2 December 2027 for Annex III systems and to August 2028 for Annex I products. That is breathing room to design compliance in, not a reason to ignore it: a product launched in 2027 will live almost its entire life under the full regime.
The other half: data
Half of the real viability issues live in the data. Which GDPR art. 6 legal basis covers the personal data feeding the system, and what if art. 9 special categories are involved? Where does the training dataset come from (web scraping meets the text-and-data-mining exception of art. 4 of Directive (EU) 2019/790, its opt-out, and each source's terms)? And what can you promise customers about output ownership and their data, which ends up written into your contracts and your DPA? On top of that sits sector law: health products may need CE marking as medical devices, credit scoring triggers financial rules, and regulated sectors can reshape the whole business model.
What a good viability analysis answers
Not an eighty-page opinion, and not a collection of "it depends". A short document that answers, in writing: how your system is classified under the AI Act and what follows; which legal basis and which sources can feed it; which sector rules condition the business model; which architecture decisions to take now because they will be expensive to reverse; and what compliance cost and timeline belong in the financial plan. The useful conclusion is a traffic light with conditions. The right moment is before approving the development budget, and certainly before raising a round: investors ask for the regulatory classification in due diligence.
Frequently asked questions
Is my chatbot or wrapper on a third-party model high-risk?
Usually not: high risk depends on the Annex III use case (employment, credit, education, insurance), not on the technology. A generic assistant typically faces only art. 50 transparency duties. The same chatbot screening job candidates changes category, so the serious answer requires looking at the concrete use case.
Does the delay to December 2027 mean I can wait?
It means more time to comply, not permission to design against the rules. High-risk requirements are far cheaper to build into the initial architecture than to retrofit, and art. 5 prohibitions and art. 50 transparency already apply today.
Can I train on scraped data?
Sometimes, under conditions: the text-and-data-mining exception and its opt-out, the GDPR if personal data is involved, and each source's terms of use. "It was public on the internet" is not a legal title.
We do this work as a fixed-scope product: the legal viability report, from 650 euros plus VAT, with an executive conclusion, regulatory classification, ranked risks and a cost-and-phases roadmap. The first consultation is free.
Dealing with something similar?
Tell us about it in a 20-minute call. The first consultation is free, no strings attached.
Related Content
Related Articles
AI Regulation and Sensitive Data: GDPR and LOPD
EU AI Act, GDPR and LOPD: obligations, impact assessment, fines up to €35M and checklist for businesses using AI with sensitive data.
Read more →
Legal errors when launching startups
Discover the most common legal errors when creating a startup and how to avoid them
Read more →