Skip the headlines. Here’s what actually matters.
The EU AI Act is in force. The implementation timelines for the various provisions stretch through 2027. Most product teams have read a headline summary and concluded one of two things: “this is enterprise compliance work, not mine” or “this only applies in Europe so we’ll deal with it later.” Both conclusions are wrong for most teams.
The Act applies to any provider, deployer, importer, or distributor of AI systems “placed on the market” or “put into service” in the EU. If your product is available to EU users — even if you’re a US company, even if you haven’t done anything specific to enter the EU — you’re in scope. Practically every B2B SaaS product with a self-serve signup is in scope.
This post is the version of the Act that tells you what to do, in the order it affects your roadmap.
The four risk tiers
The Act sorts AI systems into four tiers, and the obligations scale with the tier.
Prohibited (don’t build these)
A short list of systems that are simply banned in the EU: social scoring by governments, biometric categorization based on sensitive attributes, real-time biometric ID in public spaces (with exceptions), workplace and educational emotion recognition (with exceptions), exploitation of vulnerabilities.
For most product builders, this tier is “don’t accidentally build these.” It’s mostly outside the commercial product space, but watch the workplace emotion recognition clause — some “engagement analytics” products skirt this.
High-risk (heavy obligations)
A longer list with specific named systems: employment / HR decisions, education and exam grading, biometric ID, critical infrastructure, law enforcement, migration, justice administration, essential public services and credit scoring.
If your product is in any of these domains, you have substantial obligations: risk management system, data governance documentation, technical documentation, transparency, human oversight, accuracy/robustness/security commitments, conformity assessment before market entry. Plan for 6–9 months of compliance work before launch.
Limited risk (transparency obligations)
This is where most generative AI products sit. The obligations are lighter but real:
- Disclosure. Users must be told they’re interacting with an AI system, unless it’s obvious.
- Synthetic content labeling. AI-generated images, video, audio, and text must be machine-readably labeled as such.
- Deepfake disclosure. AI-generated content that resembles real people, places, or events must be labeled.
These obligations apply to a lot of products that don’t think of themselves as “AI products.” If you have a chatbot, you owe disclosure. If you have a content-generation feature, you owe synthetic labeling.
Minimal risk (best-effort)
Everything else. Mostly recommendation: voluntarily adopt codes of conduct, follow best practices. No mandatory obligations beyond general consumer protection.
The General-Purpose AI (GPAI) provisions
Separately from the risk tiers, the Act imposes obligations on “general-purpose AI” models — the frontier foundation models. These obligations fall primarily on model providers (OpenAI, Anthropic, etc.) but flow through to you as a downstream user in specific ways:
- Documentation. Model providers must publish technical documentation. You should expect to receive this and may need to reference it in your own documentation.
- Copyright compliance. Model providers must comply with EU copyright law for training data. They must disclose summary information about training data sources.
- Systemic risk thresholds. Models above a compute threshold get additional obligations (safety testing, incident reporting). Currently affects only a handful of frontier models.
Your job as a downstream user: choose providers who can demonstrate compliance with their GPAI obligations. Get this in writing as part of your DPA.
What to actually do, in order
Below is the prioritized work list for a typical product team. Order matters — do the cheap stuff first, the structural stuff in parallel, and the regulatory artifacts last.
This sprint (cheap)
- Audit your product for disclosure gaps. Anywhere a user interacts with an AI system, is there clear disclosure? “Powered by AI” labels, “Drafted by AI” notices, chatbot disclosures. Fix anywhere they’re missing.
- Audit synthetic content surfaces. Anywhere your product generates images, video, audio, or substantive text, is there labeling? Machine-readable metadata (C2PA or similar) is the standard. Visible labels too, where reasonable.
- Update your privacy policy. Add AI-specific disclosures: what models you use, what data flows where, what user choices exist.
This quarter (structural)
- Confirm your risk tier. Most products are limited or minimal risk. If you’re in any of the high-risk domains, get specialized legal advice — the obligations are substantial.
- Document your AI systems inventory. Even if you’re limited risk, the documentation is useful. Names, purposes, models, data categories. This document is roughly the same one you’d build for governance anyway.
- Get DPAs that flow through GPAI obligations. Your contracts with model providers should incorporate their GPAI compliance commitments.
This year (durable)
- Build the human oversight surfaces. Even if not required by your risk tier, building human-review options into your AI surfaces gives you optionality if the regulation shifts.
- Stand up an incident response process for AI failures. Required for high-risk. Useful for all tiers.
- Engage a regulatory specialist before substantial product changes. When you add a new AI feature, run a 1-page risk assessment. Document the conclusion.
The penalties that focus the mind
The Act’s penalties are specific and large:
- Prohibited practices: up to €35M or 7% of global annual turnover (whichever higher).
- Other infringements: up to €15M or 3% of global annual turnover.
- Incorrect, incomplete, or misleading information: up to €7.5M or 1% of global annual turnover.
These are EU-style penalties — designed to actually hurt at the scale they’re imposed on. For a $50M ARR company, a 3% global turnover penalty is $1.5M plus reputational damage. Not catastrophic, but more than your compliance budget.
The penalties scale to the company, which means smaller companies aren’t immune. They’re also enforced by member-state authorities who have demonstrated willingness to act (GDPR enforcement history is the reference here).
The mistakes companies are making right now
Three patterns we see:
1. Treating the Act as “the EU’s problem.” Companies assuming they can comply with US rules and skip EU rules will discover that the EU rules apply to anyone reaching EU users. The mistake is conceptual, not technical.
2. Building disclosure as an afterthought. Most products have AI surfaces buried inside other features. Adding disclosure six months in means changing UX patterns that have already become user habits. Easier to design with disclosure from day one.
3. Hoping the regulation will be relaxed. It might be, at the margins. The structural shape — risk tiers, GPAI obligations, transparency — is durable. Hope is not a regulatory strategy.
What this changes about product strategy
A few second-order effects worth understanding:
- AI procurement gets slower. Vendor diligence now includes GPAI compliance, BAA-equivalents, DPA flow-down. Expect 30–60 days more on vendor onboarding.
- Product launches get a compliance review step. New AI surfaces need a 1-page risk assessment before launch. This is annoying. It also catches problems.
- Some markets become harder. High-risk domains (HR, credit, education) become slower and more expensive to enter. Some companies will exit those markets; others will see less competition.
The take
The EU AI Act is real, in force, and applies to more products than most teams realize. The work to comply is bounded for most products — limited-risk obligations are mostly disclosure and documentation. The cost of ignoring it is unbounded. Do the cheap work this sprint. Do the structural work this quarter. Bring legal in before high-risk launches. Compounding small compliance work beats catastrophic late compliance work.
Regulatory readiness is part of Fractional CAIO engagements when it’s a fit for the business. If you’re evaluating EU launch and want a pre-flight check on your AI surfaces, schedule a call.