Full answer
The EU AI Act (Reg. 2024/1689) creates four risk categories with very different cost implications. Most startups fall into minimal-risk or limited-risk; only specific use cases trigger high-risk obligations.
Prohibited (Feb 2025): social scoring, real-time biometric ID in public spaces, manipulative AI — no compliance budget, you must exit the use case.
High-risk (Aug 2026, Annex III): HR recruitment, credit scoring, education grading, law enforcement, critical infrastructure, biometrics. Requires risk management system (Art. 9), technical documentation (Art. 11), human oversight (Art. 14), post-market monitoring (Art. 72), and EU declaration of conformity. Setup EUR 25-80k + ongoing.
Limited risk (Aug 2026): transparency obligations for chatbots, deepfakes, emotion recognition, AI-generated content. Setup EUR 2-5k + annual review.
Minimal risk: voluntary codes of conduct. No mandatory cost.
GPAI (General-Purpose AI models): obligations from Aug 2025 — technical documentation, training data summary, copyright compliance. If your model crosses systemic-risk threshold (10^25 FLOPs), add model evaluation + serious incident reporting.
AI literacy obligation (Art. 4, Feb 2025 — applies to EVERYONE): mandatory training for staff developing or operating AI. EUR 500-2,000/employee one-off.
Fines: up to EUR 35M or 7% global turnover (prohibited practices); EUR 15M or 3% (other obligations).