.png)
AI regulation has arrived. Here’s what growing businesses actually need to know.
Artificial intelligence is no longer something startups are simply experimenting with. It’s already sitting behind hiring decisions, customer service tools, product recommendations, content creation and plenty of internal processes.
But as AI becomes part of everyday business, the legal and data privacy risks are growing too.
Enter the EU AI Act: the first comprehensive, cross-sector set of rules created specifically for AI. Despite the name, it isn’t only an EU issue. UK startups and scaleups may also fall within its scope, particularly if they have EU customers, users or operations.
And the EU AI Act isn’t the only thing to think about. If your AI system processes personal data, you’ll also need to consider UK GDPR compliance and the wider data protection rules that already apply to your business.
The EU AI Act is designed to make sure AI is developed and used safely, transparently and in a way that respects people’s fundamental rights, while still leaving room for innovation.
Rather than treating every AI tool in the same way, the Act takes a risk-based approach. The higher the potential risk, the more demanding the rules become.
It also separates businesses into different roles. A provider develops or places an AI system on the market, while a deployer uses one within its operations. Importers and distributors have their own responsibilities too.
The obligations aren’t identical, so one of the first jobs is working out where your startup sits. In some cases, you may perform more than one role.
Potentially, yes.
The EU AI Act may apply to a UK startup or scaleup if it is:
That captures more businesses than you might expect, particularly SaaS startups, fintechs, healthtech companies and other technology businesses operating across several markets.
Even where the Act doesn’t strictly apply, following its principles can make commercial sense. Enterprise customers, investors and procurement teams increasingly want to know that AI is being used responsibly — and that you can prove it.
The UK has taken a different approach so far, favouring a pro-innovation framework built around existing regulators such as the ICO, FCA and CMA. But that doesn’t take UK businesses operating in EU markets outside the reach of the EU rules.
The Act broadly groups AI systems into four levels of risk:
The important bit? Your business may use several AI systems that fall into different categories.
A company-wide answer of “we use AI” isn’t enough. You need to understand what each tool does, where it’s used, what data it processes and how its outputs could affect people.
The EU AI Act doesn’t replace existing data protection law.
If an AI system processes personal data, your business may also need to comply with UK GDPR, the Data Protection Act 2018 and, depending on where you operate, EU GDPR.
This means your AI data privacy compliance should consider questions such as:
For startups, getting these answers straight early is much easier than trying to piece them together when an investor, enterprise customer or regulator starts asking questions.
A Data Protection Impact Assessment, or DPIA, helps you identify and reduce privacy risks before introducing a new technology or processing activity.
A DPIA may be legally required where the processing is likely to result in a high risk to individuals. This can include certain uses of AI, large-scale processing, systematic monitoring or automated decision-making with significant effects.
Even where a DPIA isn’t mandatory, completing one can be a sensible part of your AI governance framework. It forces the business to consider what the system is doing, why it’s needed, what could go wrong and how those risks will be managed.
It can also give customers, investors and procurement teams greater confidence that data protection has been built into the product from the start, rather than added shortly before due diligence.
The consequences under the EU AI Act are not exactly small.
The most serious infringements can attract fines of up to €35 million or 7% of worldwide annual turnover, whichever is higher.
But regulatory fines aren’t the only risk.
If you can’t explain how your startup uses and manages AI:
Good AI governance and data protection aren’t just compliance exercises. For Seed to Series B businesses, they can directly affect your ability to raise investment, win larger customers and enter new markets.
The EU AI Act has been introduced in stages since 2024.
Prohibited AI practices and AI literacy duties began to apply in February 2025. Rules for general-purpose AI models followed in August 2025, and the European Commission and national authorities began enforcing further parts of the Act from 2 August 2026.
Some requirements for high-risk AI systems have later application dates, extending into 2027 and 2028.
The exact timeline for your business will depend on the AI systems you develop or use, your role under the Act and the relevant risk category.
In other words, this probably isn’t one to leave sitting at the bottom of the to-do list.
Start by getting a clear picture of how AI is actually being used across your business.
That means speaking to teams beyond IT. HR, marketing, sales, customer support and product teams may all be using AI tools, sometimes without anyone having created a central record of them.
A practical starting point is to:
AI governance doesn’t need to become a 200-page policy that nobody reads. It does need to be practical, proportionate and embedded into the way your team actually works.
The privacy processes that worked when your startup had ten employees may not work when it reaches fifty — or when you begin selling into several markets.
As the business grows, the amount of personal data it handles usually grows with it. You may introduce new software, hire internationally, launch AI-powered features and start answering much more detailed questions from enterprise customers and investors.
A scalable data privacy programme might include:
Getting these foundations in place before your next raise or major customer deal can save a lot of last-minute scrambling later.
Specialist data protection advice can be particularly valuable when your business is:
The earlier you address these issues, the easier it is to create a proportionate approach that supports growth rather than getting in its way.
Our data privacy lawyers support startups and scaleups with the legal and practical side of AI and data protection.
We can help you:
Whether you need support with a specific AI product or want ongoing, outsourced data protection support, we’ll help you put the right foundations in place — without slowing innovation to a crawl.
Want to know where your startup currently stands? Get in touch with our Data Privacy team.
We act as an extension of your team and handle any overflow in specialist areas.
Working across five continents, operating in multiple sectors, with over 400 clients.
Offices in London | Dubai.
It can. A UK startup may fall within the scope of the EU AI Act if it provides or deploys AI systems in the EU, supplies AI systems to EU customers or produces outputs that are used within the EU. Your obligations will depend on your role and the risk classification of the system.
UK GDPR can apply whenever an AI system processes personal data. Your startup may need to identify a lawful basis, provide clear privacy information, minimise the data being used and assess whether a DPIA is required. Additional rules may apply where AI is used for automated decision-making or processes sensitive personal data.
Not every startup needs to appoint a formal Data Protection Officer. It depends on factors including the type, scale and regularity of your data processing. However, growing businesses can still benefit from outsourced or fractional data protection support, particularly when preparing for investment, entering new markets or handling higher-risk data.