One regulation, four phases: what your startup needs to know
The AI Act does not come into force all at once. The European legislator designed a staggered implementation that allows companies to adapt progressively. For AI startups, understanding this timeline is not optional — it is the difference between timely compliance and facing penalties of up to 7% of global turnover.
Phase 1: Prohibited practices (February 2025)
Since February 2025, AI systems the EU considers unacceptable risk are banned:
- Subliminal manipulation — Systems exploiting cognitive vulnerabilities to alter behaviour in a harmful way.
- Generalised social scoring — Classifying individuals based on social behaviour to restrict rights.
- Real-time remote biometric identification in public spaces for law enforcement (with narrow exceptions).
- Untargeted scraping of facial images for recognition databases.
From December 2026, a new prohibition applies to AI systems that generate, or assist in generating, non-consensual intimate imagery (NCII) or child sexual abuse material (CSAM), including applications that digitally remove clothing from images of real persons.
Impact for startups: If your product includes any functionality that could be interpreted as behavioural manipulation, social scoring, or generation of non-consensual intimate imagery, you need to review it immediately. The first four prohibitions are already in force; the NCII/CSAM prohibition applies from December 2026.
Phase 2: Transparency obligations (August 2025)
Limited-risk systems must meet transparency requirements:
- Chatbots and virtual assistants — Inform users they are interacting with AI.
- AI-generated content — Label synthetic text, images, and video in a machine-readable way.
- Emotion recognition systems — Inform individuals they are being analysed.
- Biometric categorisation — Notify the use of systems that classify individuals.
Impact for startups: If you develop chatbots, content generators, or any generative AI system, you must implement disclosure mechanisms. A notice buried in terms of service is not enough — notification must be clear and direct.
Phase 3: High-risk systems, Annex III (December 2027)
This is the most relevant phase for AI startups. Standalone high-risk AI systems listed in Annex III (e.g. education, employment, critical infrastructure, credit scoring, law enforcement) must meet an extensive set of requirements from 2 December 2027. The original date of 2 August 2026 was postponed by the 2026 AI Omnibus (Regulation (EU) 2026/1744):
- Complete technical documentation — System description, training data, performance metrics, known limitations.
- Quality management system — Documented internal processes to ensure ongoing compliance.
- Data governance — Traceability of origin, quality, and representativeness of training data.
- Human oversight — Interfaces that allow a human operator to intervene or override system decisions.
- EU database registration — Mandatory registration for high-risk systems.
- Conformity assessment — Self-assessment or third-party assessment depending on sector.
Impact for startups: If your AI system operates in health, finance, education, employment, or critical infrastructure, this phase directly affects you. We recommend starting preparation at least 12 months in advance — the deadline is now December 2027, but the effort is significant.
Phase 4: High-risk systems, Annex I (August 2028)
High-risk AI systems that are themselves products, or safety components of products, covered by EU harmonisation legislation listed in Annex I (e.g. medical devices, machinery, toys, radio equipment) must comply with the same obligations as Annex III systems, but the application date was postponed from 2 August 2027 to 2 August 2028 by the AI Omnibus.
Impact for startups: If your AI system is embedded in a regulated product requiring CE marking under sectoral legislation (medical devices, machinery, automotive), this later deadline applies to you. Plan compliance in parallel with your product certification.
General-purpose AI (GPAI): already in force since August 2025
General-purpose AI models (GPAI), such as large language models, have their own timeline — and it is already in force since 2 August 2025:
- Model technical documentation — Architecture, training data, capabilities, and limitations.
- Copyright compliance policy — Procedures to comply with the copyright directive.
- Training content summary — Sufficiently detailed description of training materials.
- Systemic risk models — Advanced risk assessments and incident notification.
Models placed on the market before 2 August 2025 benefit from a transitional period and must be compliant by 2 August 2027.
Impact for startups: If you train your own foundation models or substantially fine-tune existing models, these obligations already apply to you as a GPAI provider.
Progressive compliance strategy for startups
You do not need to comply with everything at once. A phased strategy aligned with the regulation’s timeline distributes the effort effectively:
Quarter 1: Diagnosis (now)
- Classify all your AI systems according to risk categories.
- Identify which obligations apply and in which phase.
- Assess the gap between your current state and the requirements.
Quarter 2-3: Documentation
- Prepare technical documentation per your risk category requirements.
- Implement a quality management system if none exists.
- Document data governance practices.
Quarter 4-6: Implementation
- Integrate human oversight mechanisms into the product.
- Implement event logging and monitoring systems.
- Prepare the conformity assessment.
What investors are looking at
European investment funds already include AI Act compliance in their due diligence. A recent study shows that 68% of European VCs would decline to invest in AI startups without a compliance plan. Preparing AI Act documentation is not just an obligation — it is an asset that strengthens your position in funding rounds.
Conclusion
The AI Act timeline is designed to give companies time, but time is moving. Startups that begin compliance now will have a competitive advantage over those who wait until the last moment.
At A2 we help AI startups design compliance roadmaps tailored to their technology and development stage. If you need to evaluate your situation, book a consultation with our specialised team.