17 April 2026 · 6 min read · The Implementation Layer

Most startups are ignoring the EU AI Act. Here’s when that stops being rational.

The dominant sentiment on Reddit and Hacker News is that startups should ignore the EU AI Act until fines start landing. For now, they are mostly right. But there are three specific triggers that change the calculus — and two of them have nothing to do with enforcement.

The reality

Most startups building with AI are not doing anything about the EU AI Act. The dominant sentiment in developer forums is that the regulation is too early, too vague, and too far from enforcement to warrant action. For seed-stage companies with no enterprise customers, that position is currently defensible — but it has a shelf life.

If you spend any time in developer forums, you already know the vibe.

“Most EU startups just ignore this lol”

“Feels like GDPR again... everyone will care later when fines actually start hitting.”

“A lot of fear mongering comes from people selling related services.”

These are real comments from Reddit and HN threads about EU AI Act compliance. And the people posting them are not wrong — at least not yet.

Most startups are ignoring the EU AI Act. This post is not going to tell you they are stupid for doing so. Instead, it is going to lay out the specific conditions under which that calculation flips.

Why ignoring it is rational today

A startup may decide that immediate work should be proportionate to its actual role, intended purpose, and applicable dates. That is a prioritisation decision, not evidence that the Act can be ignored. Article 5 and GPAI provisions already apply in defined circumstances, Article 50 generally has applied since 2 August 2026, and Regulation (EU) 2026/1744 sets later dates for specified high-risk paths.

There are real reasons why most founders are not losing sleep over this.

Enforcement remains early. Article 5 prohibitions took effect on 2 February 2025 and GPAI obligations followed on 2 August 2025. Regulation (EU) 2026/1744 now sets 2 December 2027 for Annex III high-risk obligations and 2 August 2028 for Annex I product-embedded systems.

The Omnibus delays the high-risk deadline. The Digital Omnibus on AI pushes the Annex III (high-risk) deadline from 2 August 2026 to 2 December 2027. The European Parliament adopted its negotiating position by 569–45–23 on 26 March 2026, then gave final approval to the agreed text on 16 June 2026 (423–57–174); the Council approved on 29 June 2026. It was published in the Official Journal on 24 July 2026 as Regulation (EU) 2026/1744 and is in force from 27 July 2026; the deferral is enacted law.

Enforcement bodies are only starting to appear. National competent authorities under Article 70 were legally due on 2 August 2025, but most Member States missed the deadline: only a minority (roughly eight to ten of the 27) had formally designated by 2026. Finland was the first to have an operationally active enforcer, its Transport and Communications Agency (Traficom), from 1 January 2026. The AI Office is operational but still setting up, and many Member States have yet to designate.

GDPR enforcement took years. The GDPR became enforceable on 25 May 2018. The first significant fine — Google's €50 million from the CNIL — landed in January 2019. But meaningful enforcement across sectors took until 2020–2021. The EU AI Act will follow a similar ramp.

If you are a seed-stage startup with 50 users and no enterprise customers, ignoring the EU AI Act today is a defensible position. You have more immediate problems.

When it stops being rational

Three triggers flip the calculus: enterprise customers adding AI governance questions to procurement questionnaires, competitors demonstrating EU AI Act readiness as a sales advantage, and the first enforcement action landing. Two of these are already happening. The shift is driven by market pressure, not just regulatory enforcement.

The shift will not come from a single enforcement action. It will come from three triggers, and two of them are already happening.

1. Enterprise customers start asking

Security questionnaires are already expanding to include AI governance sections. If you sell to companies with EU operations — or companies that sell to companies with EU operations — you will eventually see questions like:

  • What risk tier does your AI system fall under?
  • Do you maintain an AI risk management system per Article 9?
  • Can you provide technical documentation per Annex IV?
  • What human oversight mechanisms are in place?

You need a documented, evidence-based position on scope, role, intended purpose, and candidate risk paths. A scanner label alone does not establish a legal tier or compliance position.

2. Your competitor gets certified and you don’t

Compliance is becoming a procurement advantage. When two products are functionally equivalent and one can demonstrate EU AI Act readiness, procurement teams will choose the one with less regulatory risk. This is what happened with GDPR — “GDPR compliant” badges started appearing on landing pages well before enforcement became routine. The same pattern is starting for the AI Act.

This is not about being first to comply. It is about not being the last.

3. The first enforcement action lands

This has not happened yet for high-risk systems. Article 99 provides for fines up to €35 million or 7% of global annual turnover for prohibited-practice infringements, and up to €15 million or 3% for certain other infringements. Read Article 99 in the primary legislation.

The first case will probably target a large, visible violator — not a 10-person startup. But the ripple effect will reach everyone. Investors will ask about it. Customers will ask about it. Your board (if you have one) will ask about it.

The cost of retrofitting vs building in

Building compliance awareness in from the start costs minutes — knowing your risk tier before you ship. Discovering it 18 months later, after architectural decisions are locked in and you have thousands of users, costs weeks of engineering time. Transparency requirements (Article 50) need UI changes; human oversight (Article 14) can require fundamentally different workflows.

One comment from a Reddit thread about AI Act compliance stuck with me:

“Had to rewrite a big part of my chatbot for transparency/explainability.”

This is the hidden cost. If you build without any awareness of what the regulation requires, you make architectural decisions that are expensive to reverse. A chatbot deployed without any disclosure mechanism needs UI changes, backend changes, and a re-deployment. A hiring tool that filters candidates with no human-in-the-loop needs a fundamentally different workflow.

Building compliance awareness in from the start does not mean buying a €200K governance platform. It means knowing whether your product falls in a high-risk category before you ship it. That takes minutes. Discovering it 18 months later, when a customer asks and you have 50,000 users, costs weeks of engineering time.

What “preparing” actually means

Preparing starts with three concrete steps: run a risk-indicator assessment, scan the codebase for observable gaps, and scaffold documentation for qualified review where relevant. Runtime and the legal work required depend on the system and its context.

Not hiring a compliance team. Not buying a platform. Three concrete steps.

Know your tier

regula assess asks five questions and reports candidate Article 5, Annex III, or Article 50 indicators. It does not determine legal classification or every applicable duty.

$ regula assess

EU AI Act — Applicability Check

  Result: LIMITED-RISK (Article 50 transparency obligation)

  Your product is in scope. The obligation is lightweight:
  inform users they are interacting with AI or consuming
  AI-generated content.

If no elevated tier is indicated, record that result and review the intended purpose and cross-cutting duties, including Articles 4 and 5. An untriggered questionnaire path is not legal clearance.

Know your gaps

If you are high-risk, regula gap . scans your codebase and tells you which Articles 9–15 requirements you have evidence for and which you do not.

$ regula gap .

Gap Assessment: Articles 9–15

  Art.  9  Risk management system      PARTIAL
  Art. 10  Data governance              PARTIAL
  Art. 11  Technical documentation      MISSING
  Art. 12  Record-keeping               PRESENT
  Art. 13  Transparency                 MISSING
  Art. 14  Human oversight              PARTIAL
  Art. 15  Accuracy and robustness      PRESENT

Generate your documentation

regula docs . scaffolds an Annex IV technical documentation template populated with what it finds in your codebase. It is not a finished document. It is a starting point that saves you from staring at a blank page.

$ pipx install git+https://github.com/kuzivaai/getregula.git@main
$ regula assess      # record context for human review
$ regula gap .       # know your gaps
$ regula docs .      # scaffold Annex IV documentation

Total time: under five minutes. Total cost: zero.

The rational move

The rational move is not panic. It is not hiring a compliance consultant. It is not buying a governance platform you cannot afford.

It is a 30-second scan that tells you whether you need to care.

If you do not, you have lost nothing. If you do, you have gained months.

Omnibus status. The EU Digital Omnibus defers Annex III (high-risk) deadlines from 2 August 2026 to 2 December 2027. Provisional agreement was reached on 7 May 2026; the European Parliament approved on 16 June 2026; the Council approved on 29 June 2026. Published in the Official Journal on 24 July 2026 as Regulation (EU) 2026/1744, in force from 27 July 2026. The deferred dates are enacted law. The amendment also changes Article 4, adds Article 5 prohibitions that apply from 2 December 2026, and changes the Article 50(2) transition for certain systems placed on the market before that date; it is not only a deadline amendment.

Last reviewed: 14 August 2026 · Author: Regula maintainers · Not legal advice. Regula identifies risk indicators for developer review.

Not legal advice. Regula identifies regulatory risk indicators in code for developer review. It does not constitute legal advice, and its output should not be relied upon as a definitive compliance determination. The EU AI Act requires contextual assessment that no automated tool can fully provide. For high-risk systems, consult a qualified legal professional. All Article references are to Regulation (EU) 2024/1689 as published in the Official Journal of the European Union on 12 July 2024.

Related reading

Discuss on Hacker News