Safety, Security & Governance

What the EU AI Act enforcement phase actually changes for startups in 2026

The Act passed in 2024, the GPAI rules went live in August 2025, and enforcement powers arrive in August 2026. Most Series-A startups need a handful of specific changes, not a compliance department.

Most coverage of the EU AI Act tells you one of two things: either it is a paper tiger because Brussels is slow, or it is the GDPR sequel that demands a compliance officer before you ship your next feature. Neither is right. For the typical Series-A startup calling a frontier-model API and selling SaaS into the EU, the Act demands four to six specific changes, most of which can be done in a quarter by a single engineer and half a day of outside counsel. The work that matters is narrow. The work everyone is doing instead is performative.

The shape of the regime in May 2026

Three dates anchor everything. The Act entered into force in August 2024. Prohibitions on unacceptable-risk AI took effect in February 2025. GPAI obligations applied from 2 August 2025, but the Commission's enforcement powers against GPAI providers do not arrive until 2 August 2026. High-risk obligations for stand-alone Annex III systems also phase in from August 2026, the embedded-product regime by August 2027, and certain large-scale public-sector systems by December 2027.

The EU has spent ten months running a soft-launch in which the rules are technically binding but no one has been fined. That period ends in three months. After August 2026 the AI Office can demand documentation, conduct evaluations, order corrective measures, and impose fines of up to EUR 15M or 3% of global turnover on GPAI providers. Most startups are not on the cliff. A small number are, and do not realise it.

Which classification you actually fall into

The Act sorts AI into four risk tiers plus a parallel GPAI track. Classification dictates everything else, and most founders get it wrong by assuming a more onerous bucket than applies.

Class Applies to Key obligations Enforcement date Realistic penalty
Prohibited Social scoring, manipulative subliminal techniques, untargeted scraping for facial recognition, emotion inference in workplaces and schools, certain real-time biometric ID in public spaces Outright ban. Stop or never start. In force since 2 February 2025 Up to EUR 35M or 7% global turnover
High-risk (Annex III) Stand-alone systems used in recruitment, credit scoring, education admissions, essential services, biometric ID, law enforcement, migration, justice Risk management, data governance, technical documentation, human oversight, conformity assessment, EU database registration 2 August 2026 for stand-alone systems; 2 August 2027 for embedded; 2 December 2027 for certain public-sector Up to EUR 15M or 3% global turnover
Limited risk Chatbots, deepfakes, AI-generated content seen by humans Transparency: users must know they are talking to AI and that content is AI-generated 2 August 2026 Up to EUR 15M or 3% (transparency breach)
Minimal risk Spam filters, recommendation engines, video-game NPCs, most SaaS features using LLMs in non-Annex-III domains None specific n/a n/a
GPAI (standard) Foundation-model providers below the systemic-risk threshold Technical documentation, downstream-provider information, copyright policy with TDM opt-out compliance, public training-data summary Substantive rules since 2 August 2025; enforcement from 2 August 2026 Up to EUR 15M or 3% global turnover
GPAI with systemic risk Models trained with over 10^25 cumulative FLOPs (presumption) or designated by the Commission All standard-GPAI duties plus adversarial testing, model evaluation, systemic-risk assessment and mitigation, serious-incident reporting, cybersecurity Same as GPAI Up to EUR 15M or 3% global turnover

The most important row for most startups is minimal risk. If you are a vertical SaaS company piping user data through Claude or GPT-5 to summarise, route, or draft a reply, and you are not operating in an Annex III domain, you are minimal-risk. No conformity assessment. No EU database registration. You are not a GPAI provider, because you did not train the model. Anthropic, OpenAI or Mistral is, and the obligations sit on them.

Practical: the most common founder misconception is "we use AI in our product, so the high-risk rules apply to us." They do not, unless your specific use sits in an Annex III category. A chatbot helping customers configure your widget is not high-risk. A chatbot screening job applications is. The category is determined by use, not by sophistication.

What standard GPAI obligations actually entail

The August 2025 wave hit foundation-model providers, not their downstream users. If you fall into this category - and you probably do not - DLA Piper's August 2025 analysis and the Commission's own guidance break the duties into three: technical documentation (architecture, training compute, evaluations, intended uses, with a 14-day default response window for AI Office requests); a copyright policy that respects the text-and-data-mining opt-out under Article 4(3) of the 2019 Copyright Directive, honours robots.txt and emerging machine-readable opt-outs, and excludes content from sites the EU treats as piracy infrastructure; and a "sufficiently detailed summary" of training content using the Commission's template, which asks for source categories and scale rather than trade secrets.

Systemic-risk GPAI providers - models above the 10^25 FLOP threshold - get a fourth layer: adversarial testing, systemic-risk evaluation and mitigation, serious-incident reporting, and a cybersecurity posture commensurate with the risk. The AI Office considers this to cover 5 to 15 companies worldwide. If your startup needs to ask whether it qualifies, it does not.

The 10^25 FLOP threshold, briefly A floating-point operation (FLOP) is one arithmetic operation on floating-point numbers. The Act's threshold is on the cumulative compute used during training. GPT-4 is widely estimated at roughly 2 x 10^25 FLOPs. Llama 3.1 405B around 4 x 10^25. A 7B-parameter dense model trained on 2T tokens is well under 10^24 and not even close to the threshold. Fine-tuning runs do not normally approach it. The Act also empowers the Commission to designate models as systemic-risk even below the threshold based on benchmarks, reach, or downstream effects, and providers can rebut a presumption with evidence. The threshold is a backstop, not a ceiling. You are almost certainly not a systemic-risk GPAI provider. You would know.

The Code of Practice: voluntary, but bring a good excuse if you skip it

The GPAI Code of Practice was finalised on 10 July 2025 and endorsed by the Commission and the AI Board on 1 August 2025. Its three chapters (Transparency, Copyright, Safety and Security) are voluntary in the strict legal sense, but signing is the path of least resistance to demonstrating compliance. Twenty-three companies signed, including Amazon, Anthropic, Google, IBM, Microsoft, Mistral, OpenAI, and Cohere. xAI signed only the Safety and Security chapter. Meta publicly refused, arguing the Code went beyond the Act.

For the typical startup: if your model provider is a Code signatory, lean on their compliance posture via the AI Act addenda Anthropic and OpenAI started circulating in late 2025. If your provider is a holdout (Llama is the live example), you take on a marginal burden of demonstrating GPAI compliance in your supply chain. Not fatal. Changes your due diligence.

The enforcement timeline you should pin to your wall

Date What goes live Who it hits
2 Feb 2025 Prohibited-AI ban; AI literacy duty Everyone
2 Aug 2025 GPAI substantive obligations; AI Office operational GPAI providers
10 Jul 2025 GPAI Code of Practice published Voluntary signatories
2 Aug 2026 GPAI enforcement powers; stand-alone Annex III high-risk; limited-risk transparency; penalty regime live GPAI providers; high-risk deployers; chatbot and deepfake providers
2 Aug 2027 Embedded high-risk products; legacy GPAI models must be compliant Product manufacturers; legacy GPAI providers
2 Dec 2027 Remaining high-risk public-sector rules Public authorities and suppliers

The change in August 2026 is that the AI Office moves from publishing guidance to issuing requests, evaluations and fines. Expect the GDPR pattern: 12-24 months of warning shots before the first headline penalty.

Who actually enforces, and against whom

The AI Office, inside DG CNECT at the European Commission, supervises GPAI providers directly. National competent authorities supervise everything else: deployers, distributors, importers, and providers of non-GPAI systems. Each Member State has nominated a market surveillance authority, with cross-border cases coordinated through the European Artificial Intelligence Board. For a US-based Series-A selling to EU customers, the AI Office is unlikely to come for you because you are not a GPAI provider; the relevant national authority is the one in the Member State of your appointed authorised representative, with France, Germany, Ireland and the Netherlands likely to dominate the early caseload.

The fines are tiered: EUR 35M or 7% of global turnover for prohibited-AI breaches, EUR 15M or 3% for most other breaches including high-risk and GPAI, and EUR 7.5M or 1% for supplying misleading information. For SMEs - including most startups - Article 99(6) caps each fine at the lower of the absolute amount or the percentage, a meaningful concession that mainstream coverage routinely omits.

What a Series-A startup actually needs to do

The checklist below is for the modal case: a SaaS company with EU users, using a frontier-model API, not in any Annex III high-risk category, not training its own foundation model.

  • Confirm you are not in Annex III. Read it once. Recruitment-screening, credit-scoring, education admissions, biometric identification and emotion recognition are the categories that catch ordinary B2B SaaS by surprise. If you sit cleanly outside, document the determination and move on.
  • Add an AI literacy line to onboarding. Article 4 requires that staff operating AI systems have sufficient AI literacy. A 30-minute internal explainer plus an acknowledgement is enough.
  • Implement limited-risk transparency. If your product includes a chatbot, the user must know they are talking to AI. Synthetic media should be labelled with machine-readable markers where feasible. A footer line and a metadata tag covers most of it.
  • Update your DPA and terms. Reference the AI Act in the same paragraph as GDPR. Add representations that you do not deploy prohibited-AI techniques and have classified your system honestly.
  • Get the AI Act addendum from your model provider. Anthropic, OpenAI, Google, Microsoft and Mistral all publish flow-down terms that pass through the GPAI provider's compliance posture. Sign it.
  • Appoint an EU authorised representative if you are non-EU. Article 22. EUR 2-5k per year via a specialist firm, not a hire.
  • Keep a one-page AI inventory. Every feature, the underlying model, the classification, the data flow. The AI Office will not see it. Your auditor, your acquirer and your enterprise customer's procurement team will.

Seven items. None requires a compliance function. Most can be done by a head of product and a half-day of outside counsel. What you do not need, despite what the consultancy decks suggest: a "Chief AI Officer," a fundamental rights impact assessment (a duty of deployers of high-risk systems, not minimal-risk SaaS), an AI ethics board, or EU database registration (also high-risk only).

Where most startups get this wrong

Three failure modes recur. Misclassification by overcaution: founders see "employment" in Annex III and assume their HR analytics dashboard is in scope. Annex III applies to systems used in the decision itself (shortlisting, hiring, firing, promotion), not to dashboards that surface metrics to a human manager. Conflating provider and deployer: if you use Claude through Anthropic's API, Anthropic is the GPAI provider and you are a downstream deployer. You inherit transparency duties and the obligation to classify your own system, but not GPAI duties. Treating every API call as if it triggered foundation-model compliance is the most expensive mistake in this regime. Treating the Act as a US regulation in disguise: the Act applies to systems whose output is used in the EU. A US-only company with no EU customers is largely out of scope. Your scope is determined by where the output lands, not where your servers live.

What to do this quarter

  1. Classify each AI feature. One row per feature: prohibited / high-risk Annex III / limited / minimal. Cite the clause. File it.
  2. Confirm your model providers are Code signatories. If yes, request and sign their AI Act addendum. If no, document how your supply chain otherwise meets the GPAI obligations.
  3. Ship the AI literacy training. 30-minute internal session, recorded once, attached to onboarding.
  4. Add chatbot and synthetic-media transparency labels. Footer disclosure plus a <meta> tag. C2PA provenance markers are a nice-to-have, mandatory only for systemic-risk GPAI.
  5. Appoint an EU authorised representative if you are non-EU. Annual contract with a specialist firm. EUR 3-5k.
  6. Get a one-hour read from an EU AI Act lawyer. Not a retainer. One hour to confirm your classification table is defensible. EUR 500-800. Cheapest insurance you will buy this year.
  7. Set a calendar alert for 1 August 2026. By then your classification document should be signed, your DPA updated, your team trained.

The Act is real, the deadlines are real, and the penalties are large enough to take seriously. But the regime is not designed to punish ordinary SaaS companies for using AI in ordinary ways. It is designed to discipline foundation-model labs, ban genuinely harmful uses, and impose proportionate duties on narrow categories of high-risk deployment. If you are not building a recruitment screener, a credit-scoring engine, or a foundation model, your compliance work is a quarter of focused effort, not a permanent organisational change.

The startups that will struggle are the ones who outsource the question to a panicked consultant in July 2026 and pay for a six-figure programme they did not need. The ones who will thrive treat this like any other regulatory surface: read it, classify yourself, document the call, and ship. Nothing here is legal advice. The point was so you can have a more productive conversation with your actual lawyer in 45 minutes instead of three.

Free to read, no ads, no sign-up. If it was useful you can buy me a coffee.