EU AI Act readiness for AI startups: the 90-day path from inventory to evidence
Most startups are providers without knowing it. In 90 days: role, prohibited-use screen, risk classification, high-risk workstreams and an evidence pack, each step linked to the recorded obligation and its deadline.
Inventory and roles
List every AI system and model you build, buy or embed. For each, decide whether you are the provider, deployer, importer, distributor or a downstream integrator of a general-purpose model, and in which markets. Most startups are providers of their product and deployers of the tools they use internally.
Screen prohibited practices now
Article 5 bans have applied since 2 February 2025. Run a documented screen of every system against the prohibited list and keep the record; this is the cheapest and most urgent control.
Classify risk
Check whether your system is a safety component of an Annex I product or falls in an Annex III area (employment, education, credit, essential services, law enforcement, migration, justice, biometrics, critical infrastructure). If it does, assess whether the Article 6(3) derogation applies and document the reasoning.
Plan the high-risk workstreams
For high-risk systems, plan risk management, data governance, technical documentation, logging, instructions for deployers, human oversight, accuracy and security, a quality management system, conformity assessment and registration, post-market monitoring and incident reporting. Sequence them so documentation is produced as a by-product of engineering, not afterwards.
Handle transparency and general-purpose AI
If you ship chatbots or generate synthetic content, design the Article 50 disclosures and provenance marking into the product. If you provide a general-purpose model, prepare technical documentation, a copyright policy and the training-content summary, and consider the Code of Practice.
Evidence and review
Keep evidence in a structured file mapped to articles. Have counsel review classifications and dates, and re-check the official sources for amendments such as the 2025 Digital Omnibus proposal before you commit launch dates.
Obligations referenced in this guide
- Legal Ensure AI literacy of staff operating AI systems (EU AI Act, European Union)
- Legal Disclose AI interaction and label synthetic content (EU AI Act, European Union)
- Legal Meet general-purpose AI model provider obligations (EU AI Act, European Union)
- Legal Do not deploy or provide AI for prohibited practices (EU AI Act, European Union)
- Legal Establish a risk management system for high-risk AI (EU AI Act, European Union)
- Legal Draw up technical documentation before placing a high-risk system on the market (EU AI Act, European Union)
Frequently asked questions
- Do small startups get any relief under the EU AI Act?
- The Act includes measures for SMEs such as simplified technical documentation forms, priority access to regulatory sandboxes and lower fine caps, but the substantive obligations for high-risk systems still apply.
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.