Startup · Founders · Urgency

Is my AI legal after 2 December 2027?

The EU AI Act is in force. On 2 December 2027, the obligations for high-risk AI systems apply in full. Here's what every founder must check now — and what it costs to get it wrong.

The short answer: it depends on what your AI does

The EU AI Act does not apply to all AI systems equally. It classifies systems into four risk tiers. Most AI tools fall into the "minimal risk" category — no specific obligations. But if your product falls into the high-risk tier, you face a full compliance regime by 2 December 2027.

Risk tierExamplesYour obligation
ProhibitedReal-time biometric surveillance, social scoring, subliminal manipulationImmediate ban — no derogation
High riskCV screening, credit scoring, medical diagnosis, safety systemsFull compliance by 2 Dec 2027
Limited riskChatbots, deepfakes, emotion recognitionTransparency obligations only
Minimal riskSpam filters, recommendation engines, image editingNo specific obligation

Am I high-risk? The key test

High-risk systems are defined in Annex III of the AI Act. The list is exhaustive. You are high-risk if your AI system is used in one of these eight sectors:

1

Biometrics

Remote identification, emotion recognition, categorisation by sensitive attributes.

2

Critical infrastructure

Management of water, gas, electricity, road, rail networks.

3

Education

Admission decisions, assessment, monitoring of students.

4

Employment & HR

CV screening, candidate ranking, performance monitoring, promotion decisions.

5

Essential services

Credit scoring, insurance pricing, social benefits, emergency services dispatch.

6

Law enforcement

Risk profiling, polygraph, crime analytics, facial recognition for investigations.

7

Migration & borders

Lie detection at borders, asylum risk assessment, visa processing.

8

Justice & democracy

AI used to influence elections or assist courts in judicial decisions.

Important: The classification applies to the use case, not the technology. A general-purpose LLM is not high-risk per se. If you deploy it to screen CVs, it becomes high-risk in that use case. Your obligations attach to the deployment, not the model.

What compliance actually requires

If you're high-risk, Articles 9–15 of the AI Act impose seven obligations:

What non-compliance costs

ViolationMaximum fine
Prohibited practice (Art. 5)€35M or 7% of global turnover
Non-compliant high-risk system (Art. 16)€15M or 3% of global turnover
Non-compliant GPAI model (Art. 51)€15M or 3% of global turnover
Misleading information to authorities€7.5M or 1.5% of global turnover

For a startup with €5M revenue, a high-risk non-compliance fine is up to €150,000. For a scale-up with €50M revenue, it's €1.5M. Beyond the fine: reputational damage, investor concerns, and acquisition haircuts.

Three actions to take now

1

Classify your AI use cases

Map every AI system you deploy or develop against Annex III. This is a 2-hour exercise — but most founders have never done it. If you're in HR, credit, health or education: you are almost certainly high-risk.

2

Get a D7™ score

A D7™ score tells you where you stand on all seven compliance dimensions, what your exposure is, and what to prioritise. It takes 48 hours; pricing on request. It is the fastest way to turn uncertainty into a remediation plan.

3

Start with the quick wins

Most compliance gaps can be closed quickly: write the technical documentation (Art. 11), add human override buttons (Art. 14), create a data quality log (Art. 10). These cost almost nothing if done now. They cost everything if done under regulatory pressure.

The GPAI question: does this apply to foundation model builders?

If you build a general-purpose AI model (GPAI) — not just deploy one — additional obligations apply under Articles 51–55. The critical threshold: 10²⁵ FLOPs of training compute. Above that, your model is classified as a "systemic risk" GPAI with obligations including adversarial testing, incident reporting, and a copyright policy for training data.

Below the threshold, you still have basic GPAI obligations: a technical summary, a copyright compliance policy, and an energy consumption disclosure.

Find out where you stand in 48h

D7™ score — classification, exposure, remediation plan.
Less than one hour of legal fees. More actionable than a 6-month audit.

Request a D7™ score Learn more