A startup that uses or resells AI falls under the AI Act, but rarely at the level founders expect. In most cases three obligations come first: train your team, tell your users, and be able to prove your product is not classified as high risk.
Read the full guide
EU AI Act 2026: The Complete Compliance Guide for SMEs and Nonprofits
Answer a few questions and get a personalized assessment with recommendations tailored to your industry.
Assess my AI maturityRelated articles
Dive deeper with these complementary articles.
The EU AI Act (Regulation 2024/1689) applies to your SME or nonprofit as soon as you use an AI tool, even a simple ChatGPT subscription. Since February 2025 you must train your teams; on 2 August 2026 the transparency obligations and the penalty regime take effect.
A startup that uses or resells AI falls under the AI Act, but rarely at the level founders expect. In most cases three obligations come before everything else: train your team, tell your users, and be able to prove your product is not classified as high risk. The rest depends on your role, not on your headcount.
This is where most founders get lost. The EU Artificial Intelligence Act (Regulation EU 2024/1689) grants no automatic exemption to young companies. It does provide targeted relief measures, an inverted penalty cap and support schemes that very few startups actually use. If the topic is new to you, start with the AI Act compliance guide for SMEs and nonprofits, then come back here for the startup angle.
Your compliance load depends on your position in the value chain, not on your team size. The regulation separates the provider, who develops an AI system and places it on the market under its own name or trademark, from the deployer, who uses an AI system under its own authority in a professional context.
Most startups hold both roles without realising it. A SaaS company that plugs an LLM API into its product and sells it under its own brand is the provider of the system it commercialises, while remaining a deployer of the tools it runs internally for support or marketing.
| Role | Typical startup example | What it means first |
|---|---|---|
| Provider | You sell a product embedding generative AI under your brand | System classification, product transparency, technical documentation if high risk |
| Deployer | Your team uses an AI assistant, a CRM with scoring, a CV screening tool | Documented usage, human oversight, informing affected people |
| Model provider | You train and release your own general-purpose model | Specific general-purpose model obligations, rarely relevant to an early-stage startup |
The distinction is not academic. It decides who produces the technical documentation, who answers in an inspection, and what your customers can legitimately demand from you by contract. For the full scope, see who the AI Act applies to.
The timeline was amended in 2026 by the Digital Omnibus on AI, and Annex III high-risk obligations now apply from 2 December 2027. Plenty of articles written in 2025 still quote 2 August 2026 for those systems. That has been wrong since the omnibus entered into force.
| Date | What applies |
|---|---|
| 2 February 2025 | Prohibited practices and the AI literacy obligation |
| 2 August 2025 | Rules for general-purpose AI models, national and EU governance |
| 2 August 2026 | Article 50 transparency rules, start of effective enforcement and of the innovation support measures |
| 2 December 2026 | New prohibitions and transitional deadline for certain synthetic content already on the market |
| 2 August 2027 | At least one operational regulatory sandbox per Member State |
| 2 December 2027 | Rules for Annex III high-risk AI systems |
| 2 August 2028 | Rules for high-risk AI embedded in regulated Annex I products |
The postponement buys you time on the heavy part, not on the visible part. AI literacy and transparency keep their original dates. The full AI Act timeline breaks down every milestone.
Three situations turn a deployer into a provider, with every obligation that follows. White-label and integration startups usually discover this too late.
Article 25 states that a distributor, importer, deployer or other third party becomes the provider of a high-risk AI system in three cases:
In practice: resell a third-party HR scoring engine under your brand and you take on the provider obligations. Take a general-purpose model, fine-tune it to screen job applications, and you have changed the intended purpose and become the provider.
The initial provider is then released from its obligations for that specific system, but must cooperate and hand over the information and technical access you need. Two contractual reflexes follow: write the allocation of responsibilities explicitly into your supplier contracts, and check whether the initial provider has expressly excluded high-risk use, which would relieve it of the duty to hand over documentation.
AI literacy and transparency depend neither on your size nor on your product's risk level.
The first is the AI literacy obligation, in force since February 2025. You must ensure a sufficient level of AI competence among the people who operate or use your systems, taking into account their knowledge, the context of use and the people affected. No format is imposed and no certificate is required, but you must be able to show what you did. See Article 4 of the AI Act and AI training.
The second is Article 50, applicable from 2 August 2026: tell people they are interacting with an AI when it is not obvious, mark generated or manipulated content in a machine-readable format, disclose deepfakes. A frequent misunderstanding: your API provider's terms of service do not cover you. If your interface does not display the notice, you are the one in breach. See how to write an AI information notice.
Prohibited practices, applicable since February 2025, concern few startups but carry the heaviest penalties. Details in the prohibited AI practices of Article 5.
The AI Act includes support measures aimed at SMEs and startups, and a penalty mechanism that works in your favour.
Article 62 requires Member States to take four concrete actions: priority access to regulatory sandboxes for SMEs and start-ups with a registered office or branch in the Union, awareness and training activities tailored to their needs, dedicated communication channels to answer their questions, and support for their participation in standardisation work. The same article requires conformity assessment fees to be reduced proportionately to company size and market size.
On penalties, the mechanism flips for small operators. For a standard company, the applicable cap is the higher of a fixed amount and a percentage of worldwide annual turnover. For an SME or start-up, the lower of the two applies. In concrete terms, a startup with 400,000 euros in revenue is not exposed to a fine calculated against a multi-million euro ceiling. The tiers are laid out in AI Act sanctions in 2026.
Finally, every Member State must have at least one operational regulatory sandbox by 2 August 2027. If your product touches a sensitive use case, this is the scheme to watch: it lets you build and test under supervision of the authority, which also works as a commercial argument and as evidence of maturity when raising funds.
In practice, the first compliance pressure comes from due diligence and procurement, not from market surveillance authorities.
A fund investing in an AI startup in 2026 asks about system classification, model supplier contracts and training data handling. An enterprise customer sends a security and compliance questionnaire before signing. Neither waits for a regulatory decision to ask for evidence.
Six documents clear most of these filters:
The first one drives all the others. Our method is described in mapping your AI systems, and a ready-to-adapt template is available in AI policy for business.
Budget two to three days of real work, not a six-month programme.
If you process personal data, connect this work to your GDPR documentation rather than building a parallel register. The comparison between both regimes is covered in AI Act vs GDPR.
Is a three-person startup really covered by the AI Act? Yes. The regulation sets no headcount or revenue threshold below which it stops applying. What changes with size are the Article 62 support measures and the penalty cap, which becomes the lower of the two amounts for SMEs and start-ups.
Does using an API such as ChatGPT or Claude make me a model provider? No. Obligations on providers of general-purpose AI models stay with the model publisher. However, if you place an AI system built on that API on the market under your own brand, you are the provider of that system, which is a different and far more common situation.
How do I know whether my product is high risk? Two routes lead to high risk: being a safety component of an already regulated product, or falling within one of the areas listed in Annex III, notably employment, education, credit, biometrics, essential services and access to public services. HR, edtech and fintech startups should look at this first.
Have the deadlines been pushed back? Only part of them. The Digital Omnibus on AI moved the rules for Annex III high-risk systems to 2 December 2027 and Annex I to 2 August 2028. AI literacy, prohibited practices and transparency rules keep their original schedule.
What penalties does a startup actually face? The regulation sets three fine tiers by severity, from the most serious breaches involving prohibited practices down to supplying incorrect information to authorities. For an SME or start-up, the applicable cap is the lower of the fixed amount and the percentage of worldwide turnover. Authorities must also take the company's economic viability into account.
Do we need to hire an AI compliance officer? Rarely before around thirty employees. In practice the CTO or the product founder carries the role, with a quarterly review and a reference document kept up to date. What matters is that someone is identifiable and that classification decisions are written down.
We work on two fronts. The first is a compliance audit: system mapping, role qualification under Article 25, risk classification and a list of actions to take, with the documents drafted. The second is team training, which is what the AI literacy obligation requires, delivered under a Qualiopi-certified framework that unlocks OPCO funding in France.
The format startups ask for most is short: a half-day audit, then one day of training focused on product usage and the regulatory framework. The programme is described on the AI training for business page.
To situate your risk level and your real priorities, book a free 30-minute audit. You leave with your systems classified and the three actions to take first. For the broader picture, the AI Act compliance guide for SMEs remains the starting point, and the step-by-step conformity assessment describes what comes next.