Most EU AI Act guidance is written for organisations with a compliance function. If you're eight people and one of you is doing this between sprints, the useful question isn't "what does the Act require" - it's what is the smallest defensible position I can hold, and how fast can I get there. Usually: about a day.
The short answer for most startups: you are a deployer or a provider of a limited or minimal risk system, you owe three live obligations that take an afternoon, and the frightening Chapter III material does not apply to you. The work is establishing that in writing - because "we looked, here's our position, dated" is what investors and enterprise buyers actually ask for.
Does it even apply to you?
If your users are in the EU, yes - wherever you're incorporated. Article 2 reaches providers established anywhere when the output is used in the Union. A Delaware C-corp selling into Berlin is in scope. So is a UK company with EU customers.
What it does not mean is that every obligation applies. Scope and tier are different questions, and conflating them is the single most common startup mistake.
The three that are live right now
| Obligation | Who | Effort |
|---|---|---|
| Article 50 - say it's an AI | Anyone with a user-facing bot or generative feature | One sentence in the greeting |
| Article 4 - AI literacy | Everyone whose staff use AI systems | One session, minuted |
| Article 5 - prohibited practices | Everyone | A check, not a project. Emotion inference on staff or users is the realistic trap |
That's the whole live burden for a typical startup. Enforceable since 2 August 2026 - not deferred by the Omnibus, whatever the headlines said.
The two questions that decide everything else
1. Are you a provider or a deployer? Built and shipped it under your name → provider of that system. Licensed someone else's and use it → deployer. Most teams answer "provider" because they wrote code, when the AI system itself is licensed. Getting this wrong means adopting another party's obligations. The full test.
2. Does anything you ship evaluate a person? This is the fork. Scoring, ranking, screening or predicting things about natural persons - for jobs, credit, education, essential services - puts you in Annex III, and profiling closes the Article 6(3) exit. Everything else is almost certainly limited or minimal risk.
Building on GPT or Claude doesn't make you a GPAI provider. API use, prompting and light fine-tuning keep Article 53 with the model vendor. ChatGPT / OpenAI API · Where the line is.
The fine numbers, corrected
You'll see €35m / 7% quoted everywhere. That tier is for Article 5 prohibited practices, and for SMEs and start-ups Article 99(6) applies whichever is lower - the fixed amount or the percentage - not whichever is higher. On €2m turnover, an Article 50 breach ceiling is roughly €60,000, not €15 million. Most published summaries state this backwards. The three tiers.
Why founders end up doing this anyway
Rarely because a regulator called. Usually because:
- Enterprise procurement asked. "AI Act position available on request" is quietly becoming a filter, and a stalled security review costs more than the work.
- Due diligence asked. An unanswered regulatory question in a data room is a discount.
- A customer's DPO asked, and your answer needs to be a document, not a Slack message.
In all three cases the deliverable is the same: a dated, reasoned written position naming your product. That's what a gap report is, and it's why the free tier stops at a risk tier - the tier answers your question, the document answers theirs.
A day, roughly
- List your AI features and who each one affects
- Run the free check per feature that touches people
- Add the AI disclosure line to anything that converses - this week, it's live law
- Run and minute one AI-literacy session
- Write down your role and tier per system, with reasoning and a date
- Only if something is genuinely Annex III: start the Chapter III programme now, because conformity assessment takes 12-18 months and December 2027 is closer than it looks
Start with the two-minute version
The free check gives you your role and likely tier. If procurement or an investor needs it in writing, the full report is €59.
Start the free scanNo card, no account. Full gap report from €59. See a real report first.
Self-assessment, not legal advice. This page and the Reglynn report are a structured self-assessment based on the EU AI Act (Regulation 2024/1689, as amended by the June 2026 Omnibus). They indicate where you likely stand and what to verify with a qualified advisor. Reglynn is not a notified body and issues no certification.
How this was made. Reglynn reports are generated by an AI system built on Anthropic's Claude and reviewed before delivery. Reglynn is a Limited Risk AI system under Article 50; we disclose AI involvement wherever it occurs, including in our chat assistant. Our own self-assessment.