If your AI system serves EU users and falls under Annex III, you have 9 days to meet conformity obligations. Fines start at €15M or 3% of global turnover.
Most U.S. AI founders are watching the EU AI Act the way they watched GDPR in 2018 — "it doesn't apply to us." It does. The Act is extraterritorial. If your product is used in the EU, even by free-tier users, the high-risk rules apply.
The full enforcement date for high-risk AI systems is August 2, 2026. That's not the date to start thinking about compliance. That's the date the regulator can start asking for your risk management system, data governance documentation, and conformity assessment evidence.
Annex III covers systems used in:
Translation for SaaS founders: if your AI is used for hiring, lending, insurance, education, health triage, or any biometrics — and you have users in the EU — you're probably in scope.
You don't have to be perfect by August 2. You have to be defensible. The high-risk requirements break into four practical workstreams:
You need documented identification, estimation, and mitigation of risks to health, safety, and fundamental rights. Not a slide deck — a living document tied to your system design.
Training, validation, and testing data must have appropriate governance practices, including bias testing and limitations documentation. If you fine-tune on customer data, this is where most founders get caught.
Conformity assessment requires records of architecture, capabilities, limitations, performance metrics, and known failure modes. This is essentially a security audit dressed in regulatory language.
Natural persons must be able to override the system. Users must be informed they're interacting with AI. High-risk outputs must include clear disclosures.
I run a small AI security consultancy. We don't write legal opinions, but we can produce the technical evidence compliance teams actually need. Here's the sprint:
After the sprint, most teams need continuous monitoring. Our $2,500/month retainer covers monthly regression testing, guardrail drift checks, and updated technical documentation as your models and integrations change.
Get the 24-hour snapshot first. It's $149. You'll know exactly where you stand before you spend a dollar on the bigger audit.
Get the $149 Snapshot (24h) See All ServicesThe companies that get ahead of this won't be the ones with the biggest legal budgets. They'll be the ones with the best technical evidence.