EU AI Act
EU AI Act for startups and scale-ups: what applies, what is lighter, what to do first
Most startups building on existing models are not high-risk providers and are not GPAI providers. They are still in scope for AI literacy, the prohibited practices and Article 50 transparency. The Digital Omnibus added relief for SMEs and small mid-caps: lower-of fines, simplified documentation and quality management, and priority access to sandboxes. Annex III high-risk duties apply from 2 December 2027, so you have runway to build the habits now.
Who this applies to
- Startups building products on third-party models
- Usually providers of an AI system (your product) and deployers of a GPAI model. Your obligations depend on what the product does.
- SMEs, including start-ups
- Defined by EU rules. Lower-of fine caps, simplified quality management, and priority access to sandboxes apply.
- Small mid-cap enterprises (SMCs)
- New under the Omnibus: fewer than 750 employees and turnover not exceeding EUR 150 million, according to commentary. They get simplified technical documentation, proportionate quality management and lower-of fines for the second and third tiers. Confirm the definition in the text.
Triage: which bucket is your product in?
| Your product | Likely position | What to do now |
|---|---|---|
| A chatbot or assistant that talks to people | Not high-risk by default. Article 50(1) requires that people can tell they interact with AI unless it is obvious. | Add clear disclosure; train staff (Art. 4). |
| A tool that generates text, images, audio or video | Providers of generative systems must mark outputs in a machine-readable format (Art. 50(2)). Systems already on the market before 2 Aug 2026 have until 2 Dec 2026. | Plan marking; follow the Code of Practice on marking and labelling published 10 June 2026 as a voluntary guide. |
| A tool used in recruitment, credit scoring, education, essential services or one of the other Annex III areas | May be high-risk. Obligations from 2 Dec 2027. | Classify with care, document the Article 6(3) assessment if you rely on it, and plan Articles 9 to 15. |
| A product embedded in regulated physical goods | Possibly high-risk under Annex I from 2 Aug 2028. | Check sector product law with counsel. |
| You train or substantially modify a general-purpose model | You might be a GPAI provider. | Read the GPAI guidelines on thresholds and the Code of Practice. |
Everyone in scope: Article 5 prohibitions and Article 4 AI literacy apply now. See the timeline and AI literacy.
What the Digital Omnibus added for smaller firms
- Lower-of fines. For SMEs, including start-ups, each fine is capped at the lower of the percentage and the amount. The Omnibus extends the lower-of rule to SMCs for fines under Article 99(4) and (5). See AI Act penalties.
- Simplified documentation. Simplified Annex IV technical documentation (Article 11) and proportionate quality management (Article 17) now reach SMCs, and simplified quality-management routes extend from microenterprises to all SMEs.
- Sandbox priority. SMEs, including start-ups, and SMCs get priority access to the AI Office's Union-level sandbox. See AI regulatory sandboxes.
- AI literacy support. The softened Article 4 duty comes with Commission and Member State support for SMEs.
- Bias-detection data. A new Article 4a allows processing special-category data for bias detection and correction where strictly necessary, with safeguards.
Relief reduces paperwork, not duties. Smaller firms keep the same substantive obligations.
A practical first 90 days
- Days 1 to 15: inventory. List every AI system you build or use, with owner, purpose, data and model.
- Days 15 to 30: classify. Check Article 5, Annex III and Annex I, and write down your role. Record reasoning where the answer is no.
- Days 30 to 45: literacy and policy. Adopt a short AI use policy and role-based training.
- Days 45 to 60: transparency. Add AI disclosures and plan output marking for generative features.
- Days 60 to 75: logging and oversight. Make sure you can show who did what with which model, and where a human approves.
- Days 75 to 90: evidence folder. Start the file you would hand a customer, investor or regulator, and set a quarterly refresh and a date to re-verify the dates against the Commission timeline.
Enterprise customers will ask you for this evidence long before 2 December 2027, and for those buying under NIS2 or DORA it is part of their supply-chain duty.
How the platform supports it
Each row maps a requirement to a platform control, the evidence artifact it produces, and the Trust & Governance Fabric facets involved. Swfte provides the controls and the evidence. You remain responsible for the decisions.
| Requirement | Platform control | Evidence artifact | Fabric facets |
|---|---|---|---|
| An inventory with owner, model and data per AI system | Trust Profile per AI system. | Trust Profile export. | Identity, Data controls, Compliance |
| AI literacy and safe defaults for a small team | Policy that warns, filters or requires approval, so safe use is the default. | Policy configuration and event log. | Policy, Human oversight |
| Show customers what you control | Audit trail and traceability from data to model to agent to decision to outcome. | Exportable evidence for customer questionnaires. | Auditability, Traceability, Evidence |
| Keep options open on models and hosting | Model gateway across 50+ LLMs; EU region and dedicated hosting designed for, scoped with you. | Routing configuration; deployment description. | Policy, Data controls |
Compliance-by-design. Swfte provides the technical controls, governance mechanisms and evidence to support deployment within applicable requirements. The exact posture depends on your use case, jurisdiction, deployment and configuration. This is not legal advice.
Hosting today: customer data is stored in AWS eu-west-1 (Ireland), as stated on the trust page. EU region, in-country, dedicated and on-prem options are the platform position: what it is designed to let you do, scoped with you through a dedicated deployment engagement, not self-serve.
What this does not cover
- Swfte does not give legal advice or decide whether you are an SME or small mid-cap.
- It does not write your technical documentation or perform a conformity assessment.
- Relief for SMEs reduces fines and paperwork. It is not an exemption from the Act, and Swfte does not secure admission to a sandbox.
- Self-serve plans do not include dedicated, in-country or on-prem hosting. Those are scoped through a dedicated deployment engagement.
Frequently asked questions
Is my startup subject to the EU AI Act?
Probably, if you place an AI system on the EU market or your system's output is used in the EU. Check Article 2. Even a low-risk product is in scope for Article 4 AI literacy, Article 5 prohibitions and Article 50 transparency.
Are startups fined less?
Yes. For SMEs, including start-ups, each fine is capped at the lower of the percentage and the amount (Article 99(6)). The Omnibus extends that to small mid-caps for fines under Article 99(4) and (5).
When do I need to be ready for high-risk rules?
If your system is Annex III high-risk, from 2 December 2027. For products covered by Annex I, from 2 August 2028. Prohibitions, literacy, Article 50 and GPAI duties apply earlier.
Do I count as a GPAI provider if I build on a foundation model?
Usually not. Under the Commission guidelines, a downstream modifier becomes a provider only above an indicative compute threshold, one third of the original training compute, per secondary summaries. Check your case.
Can I join a regulatory sandbox?
The AI Office may set up a Union-level sandbox with priority access for SMEs, start-ups and SMCs, and Member States must have a national sandbox by 2 August 2027. Availability today varies.
Sources
Last verified 2026-10-06. Primary sources are EUR-Lex and European Commission pages. Items marked as secondary are commentary or trackers; check the primary text before relying on them.
- Regulation (EU) 2026/1744, the Digital Omnibus on AI (EUR-Lex) (Adopted 8 July 2026, published 24 July 2026, in force 27 July 2026.)
- AI Act Article 99, penalties (AI Act Service Desk)
- AI Act Article 57, sandboxes (AI Act Service Desk)
- AI Act Article 4, AI literacy (AI Act Service Desk)
- AI Act Article 50, transparency (AI Act Service Desk)
- European Commission: Code of Practice on marking and labelling AI-generated content
- AI Act Service Desk: implementation timeline (European Commission) (Reflects the Digital Omnibus amendments.)
- European Commission: guidelines for providers of general-purpose AI models
Across the platform
The controls on this page are part of the Trust & Governance Fabric that runs through every layer of the Sovereign Intelligence Platform.
AI governance
Governance that runs inside AI, not beside it.
AI sovereignty
Seven kinds of control over your AI estate.
Trust Profile
The record of what each AI system is and may do.
Trust centre
What Swfte can show today, and what it does not claim.
Build EU-first AI with the evidence already running
Start with one entry point. Add governance, in-region options and evidence as your requirements grow.