17 April 2026 · 6 min read · The Implementation Layer

Most startups are ignoring the EU AI Act. Here’s when that stops being rational.

The dominant sentiment on Reddit and Hacker News is that startups should ignore the EU AI Act until fines start landing. For now, they are mostly right. But there are three specific triggers that change the calculus — and two of them have nothing to do with enforcement.

The reality

Most startups building with AI are not doing anything about the EU AI Act. The dominant sentiment in developer forums is that the regulation is too early, too vague, and too far from enforcement to warrant action. For seed-stage companies with no enterprise customers, that position is currently defensible — but it has a shelf life.

If you spend any time in developer forums, you already know the vibe.

“Most EU startups just ignore this lol”

“Feels like GDPR again... everyone will care later when fines actually start hitting.”

“A lot of fear mongering comes from people selling related services.”

These are real comments from Reddit and HN threads about EU AI Act compliance. And the people posting them are not wrong — at least not yet.

Most startups are ignoring the EU AI Act. This post is not going to tell you they are stupid for doing so. Instead, it is going to lay out the specific conditions under which that calculation flips.

Why ignoring it is rational today

Ignoring the EU AI Act is rational today because enforcement infrastructure barely exists, only Finland has designated a national competent authority, the Omnibus provisional agreement of 7 May 2026 defers Annex III high-risk deadlines to December 2027, and GDPR precedent suggests meaningful enforcement takes years to ramp up after a regulation becomes applicable.

There are real reasons why most founders are not losing sleep over this.

Enforcement has barely started. Article 5 prohibitions (social scoring, subliminal manipulation) took effect on 2 February 2025. GPAI obligations followed on 2 August 2025. But the high-risk system obligations — the ones that affect most startups — are not due until 2 August 2026. And even that date is likely to slip.

The Omnibus proposes a delay. The Digital Omnibus on AI proposes pushing the Annex III (high-risk) deadline from 2 August 2026 to 2 December 2027. The European Parliament voted 569–45–23 in favour on 26 March 2026. Trilogue negotiations have started. It is not yet law, but both Council and Parliament have endorsed the deferral in principle.

Only one country has an enforcement body. As of April 2026, Finland is the only Member State that has designated a national competent authority under Article 70. The AI Office is operational but still setting up. Most Member States have not even decided which agency will handle enforcement.

GDPR enforcement took years. The GDPR became enforceable on 25 May 2018. The first significant fine — Google's €50 million from the CNIL — landed in January 2019. But meaningful enforcement across sectors took until 2020–2021. The EU AI Act will follow a similar ramp.

If you are a seed-stage startup with 50 users and no enterprise customers, ignoring the EU AI Act today is a defensible position. You have more immediate problems.

When it stops being rational

Three triggers flip the calculus: enterprise customers adding AI governance questions to procurement questionnaires, competitors demonstrating EU AI Act readiness as a sales advantage, and the first enforcement action landing. Two of these are already happening. The shift is driven by market pressure, not just regulatory enforcement.

The shift will not come from a single enforcement action. It will come from three triggers, and two of them are already happening.

1. Enterprise customers start asking

Security questionnaires are already expanding to include AI governance sections. If you sell to companies with EU operations — or companies that sell to companies with EU operations — you will eventually see questions like:

  • What risk tier does your AI system fall under?
  • Do you maintain an AI risk management system per Article 9?
  • Can you provide technical documentation per Annex IV?
  • What human oversight mechanisms are in place?

You do not need to be fully compliant to answer these. But you do need to know your tier and have a documented position. “We haven’t looked into it” is not an answer that closes deals.

2. Your competitor gets certified and you don’t

Compliance is becoming a procurement advantage. When two products are functionally equivalent and one can demonstrate EU AI Act readiness, procurement teams will choose the one with less regulatory risk. This is what happened with GDPR — “GDPR compliant” badges started appearing on landing pages well before enforcement became routine. The same pattern is starting for the AI Act.

This is not about being first to comply. It is about not being the last.

3. The first enforcement action lands

This has not happened yet for high-risk systems. When it does, it will change behaviour overnight, just as the first GDPR fines did. The regulation provides for fines of up to €35 million or 7% of global annual turnover for prohibited practices, and up to €15 million or 3% for other infringements (Article 99).

The first case will probably target a large, visible violator — not a 10-person startup. But the ripple effect will reach everyone. Investors will ask about it. Customers will ask about it. Your board (if you have one) will ask about it.

The cost of retrofitting vs building in

Building compliance awareness in from the start costs minutes — knowing your risk tier before you ship. Discovering it 18 months later, after architectural decisions are locked in and you have thousands of users, costs weeks of engineering time. Transparency requirements (Article 50) need UI changes; human oversight (Article 14) can require fundamentally different workflows.

One comment from a Reddit thread about AI Act compliance stuck with me:

“Had to rewrite a big part of my chatbot for transparency/explainability.”

This is the hidden cost. If you build without any awareness of what the regulation requires, you make architectural decisions that are expensive to reverse. A chatbot deployed without any disclosure mechanism needs UI changes, backend changes, and a re-deployment. A hiring tool that filters candidates with no human-in-the-loop needs a fundamentally different workflow.

Building compliance awareness in from the start does not mean buying a €200K governance platform. It means knowing whether your product falls in a high-risk category before you ship it. That takes minutes. Discovering it 18 months later, when a customer asks and you have 50,000 users, costs weeks of engineering time.

What “preparing” actually means

Preparing means three concrete steps that take under five minutes combined and cost nothing: run a risk-tier assessment to find out whether you are minimal-risk, limited-risk, or high-risk; scan your codebase for gaps against Articles 9–15; and scaffold an Annex IV technical documentation template if needed. Most startups will stop at step one.

Not hiring a compliance team. Not buying a platform. Three concrete steps.

Know your tier

regula assess walks you through the same decision tree as Article 6 and Annex III. Five questions. Thirty seconds. It tells you whether you are prohibited, high-risk, limited-risk, or minimal-risk.

$ regula assess

EU AI Act — Applicability Check

  Result: LIMITED-RISK (Article 50 transparency obligation)

  Your product is in scope. The obligation is lightweight:
  inform users they are interacting with AI or consuming
  AI-generated content.

If you are minimal-risk, you are done. No obligations. You can stop here.

Know your gaps

If you are high-risk, regula gap . scans your codebase and tells you which Articles 9–15 requirements you have evidence for and which you do not.

$ regula gap .

Gap Assessment: Articles 9–15

  Art.  9  Risk management system      PARTIAL
  Art. 10  Data governance              PARTIAL
  Art. 11  Technical documentation      MISSING
  Art. 12  Record-keeping               PRESENT
  Art. 13  Transparency                 MISSING
  Art. 14  Human oversight              PARTIAL
  Art. 15  Accuracy and robustness      PRESENT

Generate your documentation

regula docs . scaffolds an Annex IV technical documentation template populated with what it finds in your codebase. It is not a finished document. It is a starting point that saves you from staring at a blank page.

$ pipx install regula-ai
$ regula assess      # know your tier (30 seconds)
$ regula gap .       # know your gaps
$ regula docs .      # scaffold Annex IV documentation

Total time: under five minutes. Total cost: zero.

The rational move

The rational move is not panic. It is not hiring a compliance consultant. It is not buying a governance platform you cannot afford.

It is a 30-second scan that tells you whether you need to care.

If you do not, you have lost nothing. If you do, you have gained months.

Omnibus status. The EU Digital Omnibus defers Annex III (high-risk) deadlines from 2 August 2026 to 2 December 2027. Provisional agreement was reached on 7 May 2026; the European Parliament approved on 16 June 2026. The Council approved it on 29 June 2026; OJ publication is still pending. Until OJ publication, original dates remain legally binding. Article 5 prohibitions and Article 50 transparency obligations are not affected by the Omnibus.

Last verified: 17 April 2026 · Author: Kuziva Muzondo · Not legal advice. Regula identifies risk indicators for developer review.

Not legal advice. Regula identifies regulatory risk indicators in code for developer review. It does not constitute legal advice, and its output should not be relied upon as a definitive compliance determination. The EU AI Act requires contextual assessment that no automated tool can fully provide. For high-risk systems, consult a qualified legal professional. All Article references are to Regulation (EU) 2024/1689 as published in the Official Journal of the European Union on 12 July 2024.

Related reading

Discuss on Hacker News