The EU AI Act is in force. On 2 December 2027, the obligations for high-risk AI systems apply in full. Here's what every founder must check now — and what it costs to get it wrong.
The EU AI Act does not apply to all AI systems equally. It classifies systems into four risk tiers. Most AI tools fall into the "minimal risk" category — no specific obligations. But if your product falls into the high-risk tier, you face a full compliance regime by 2 December 2027.
| Risk tier | Examples | Your obligation |
|---|---|---|
| Prohibited | Real-time biometric surveillance, social scoring, subliminal manipulation | Immediate ban — no derogation |
| High risk | CV screening, credit scoring, medical diagnosis, safety systems | Full compliance by 2 Dec 2027 |
| Limited risk | Chatbots, deepfakes, emotion recognition | Transparency obligations only |
| Minimal risk | Spam filters, recommendation engines, image editing | No specific obligation |
High-risk systems are defined in Annex III of the AI Act. The list is exhaustive. You are high-risk if your AI system is used in one of these eight sectors:
Remote identification, emotion recognition, categorisation by sensitive attributes.
Management of water, gas, electricity, road, rail networks.
Admission decisions, assessment, monitoring of students.
CV screening, candidate ranking, performance monitoring, promotion decisions.
Credit scoring, insurance pricing, social benefits, emergency services dispatch.
Risk profiling, polygraph, crime analytics, facial recognition for investigations.
Lie detection at borders, asylum risk assessment, visa processing.
AI used to influence elections or assist courts in judicial decisions.
Important: The classification applies to the use case, not the technology. A general-purpose LLM is not high-risk per se. If you deploy it to screen CVs, it becomes high-risk in that use case. Your obligations attach to the deployment, not the model.
If you're high-risk, Articles 9–15 of the AI Act impose seven obligations:
| Violation | Maximum fine |
|---|---|
| Prohibited practice (Art. 5) | €35M or 7% of global turnover |
| Non-compliant high-risk system (Art. 16) | €15M or 3% of global turnover |
| Non-compliant GPAI model (Art. 51) | €15M or 3% of global turnover |
| Misleading information to authorities | €7.5M or 1.5% of global turnover |
For a startup with €5M revenue, a high-risk non-compliance fine is up to €150,000. For a scale-up with €50M revenue, it's €1.5M. Beyond the fine: reputational damage, investor concerns, and acquisition haircuts.
Map every AI system you deploy or develop against Annex III. This is a 2-hour exercise — but most founders have never done it. If you're in HR, credit, health or education: you are almost certainly high-risk.
A D7™ score tells you where you stand on all seven compliance dimensions, what your exposure is, and what to prioritise. It takes 48 hours; pricing on request. It is the fastest way to turn uncertainty into a remediation plan.
Most compliance gaps can be closed quickly: write the technical documentation (Art. 11), add human override buttons (Art. 14), create a data quality log (Art. 10). These cost almost nothing if done now. They cost everything if done under regulatory pressure.
If you build a general-purpose AI model (GPAI) — not just deploy one — additional obligations apply under Articles 51–55. The critical threshold: 10²⁵ FLOPs of training compute. Above that, your model is classified as a "systemic risk" GPAI with obligations including adversarial testing, incident reporting, and a copyright policy for training data.
Below the threshold, you still have basic GPAI obligations: a technical summary, a copyright compliance policy, and an energy consumption disclosure.
D7™ score — classification, exposure, remediation plan.
Less than one hour of legal fees. More actionable than a 6-month audit.