For the past few years, “AI regulation” has primarily been discussed in the future by most companies; it’s something to consider once you’re larger, once a legislation actually goes into force, and once it’s not just a theory. This month, that window closed. On August 2, the EU AI Act began its most significant enforcement phase.
However, it is not the only regulation that is currently in effect rather than pending. This is the first year where the regulatory discussion is worth a real hour of your time rather than a bookmarked post if you use AI in any way.
What’s actually in force right now
The EU AI Act operates on a tiered basis: it imposes strict requirements on “high-risk” systems used in key infrastructure, hiring, and credit, outright prohibits a small number of “unacceptable risk” uses, and applies less stringent transparency requirements to everything else.
The majority of the remaining transparency obligations, such as labelling AI-generated content and revealing when someone is speaking to a chatbot, are scheduled to take effect on August 1st, the official start of enforcement authority over general-purpose AI model providers.
The fines are severe: for the most significant infractions, they can reach €35 million, or 7% of global yearly turnover, which is more than even the GDPR’s limit. Crucially, this is applicable based on the location of your users rather than the location of your company’s incorporation; a US-only startup with users from the EU is still covered.
The picture is a patchwork rather than a single deadline because there isn’t a single federal AI law in the US. Developers and deployers of high-risk systems employed in “consequential decisions”, employment, credit, housing, and related categories, are subject to duties under Colorado’s AI Act, which went into effect in February. California has met its own standards for training-data documentation and transparency.
At this time, new state AI laws are emerging almost every quarter, and regardless of the existence of a dedicated AI law, current consumer protection and anti-discrimination regulations, particularly from the FTC and EEOC, already applies to AI-driven choices. “The AI did it” has never been and still isn’t a good defence if your employment tool produces discriminatory results; the employer is responsible regardless of who developed the underlying model.

The good news for most early-stage founders
This is the bit that should actually make you feel better: the majority of consumer-facing AI products are classified as minimal-risk under the EU AI Act. When developing a writing assistant, coding tool, search function, recommendation engine, or general customer support chatbot, you are primarily concerned with disclosure obligations rather than the extensive conformity assessments needed for high-risk systems.
For example, you should identify that it is artificial intelligence (AI) and make it obvious when a user is interacting with a bot. Additionally, the majority of companies won’t meet the legal requirements that directly trigger the most stringent state-level obligations.
The risk category that truly counts is more limited and specific than “using AI” in general. If your product affects what regulators refer to as consequential decisions, such as hiring, lending, housing, insurance, healthcare access, or admission to school, you’re in a genuinely different and heavier compliance category, and it’s worth treating that as a design constraint from day one rather than a retrofit.
Why this matters even if you’re technically exempt
This change is being felt indirectly, through contracts rather than fines, even by companies that fall below the direct regulatory thresholds. Regardless of whether the smaller business is legally covered by the underlying law, enterprise clients and larger vendors are increasingly including AI-specific addenda into their contracts, shifting risk and disclosure duties onto smaller vendors and supply chain partners.
Expect procurement and legal teams to ask AI-specific due diligence questions that didn’t exist eighteen months ago if you sell to enterprise clients. These questions may include what model you employ, how you handle training data, and whether you can provide proof upon request. In addition to creating compliance risk, failing to provide clear answers is beginning to cost deals.
The practical version: what to actually do
To take the initial helpful measures in this situation, you don’t require outside advice. Regardless of your size, there are a few things you should accomplish this quarter:
Determine and record the risk tier that your product truly belongs to. This is a quick exercise for most products: does your AI feature help, write, summarise, or suggest something, or does it make or significantly impact a “consequential decision” for someone? Nearly every other aspect of your responsibilities is determined by that one distinction.
Whether or not you are legally obligated to, provide a basic AI disclosure in your product. Notifying customers that they are speaking with a bot or that material was created with artificial intelligence (AI) is inexpensive to develop, increasingly anticipated by users, and eliminates a whole category of risk for relatively little product expense.
Consider paperwork as a product necessity rather than an afterthought if you’re selling to the employment, lending, housing, or healthcare industries. Regardless of whether a particular regulation mandates it of a company your size yet, being able to describe what your system does, what data trained or influenced it, and how you test for divergent outcomes is rapidly becoming standard practice for securing enterprise deals in these areas.
Review this every three months rather than every year. The regulatory landscape in this area is evolving significantly more quickly than the usual yearly cycle of compliance reviews, and a number of these frameworks are either provisional or undergoing active amendment. In many specific details, what was true in January is already out of date.
The bigger picture
The unsettling reality is that the argument that “we’re too small for this to apply to us” is becoming less and less credible every month. This isn’t because regulators are specifically targeting small startups, but rather because the regulations are increasingly passing through your customers’ contracts even when they don’t directly affect you through statutes.
It is far less expensive to be ahead of it by a quarter or two than to retrofit it during a due diligence procedure for a purchase you really want to close.
This is the nudge: send it to the product or legal owner if your product affects employment, lending, or healthcare and no one on your team has mapped this yet. Next week, we’ll look at an actual AI disclosure statement and provide some useful examples.
