The EU AI Act: what businesses actually need to know
August 12, 2026
-
Blog

The EU AI Act: what businesses actually need to know

By 
Jordan de la Prida - Data Protection Specialist

The EU AI Act: AI and Data Protection for Startups and Scaleups

AI regulation has arrived. Here’s what growing businesses actually need to know.

Artificial intelligence is no longer something startups are simply experimenting with. It’s already sitting behind hiring decisions, customer service tools, product recommendations, content creation and plenty of internal processes.

But as AI becomes part of everyday business, the legal and data privacy risks are growing too.

Enter the EU AI Act: the first comprehensive, cross-sector set of rules created specifically for AI. Despite the name, it isn’t only an EU issue. UK startups and scaleups may also fall within its scope, particularly if they have EU customers, users or operations.

And the EU AI Act isn’t the only thing to think about. If your AI system processes personal data, you’ll also need to consider UK GDPR compliance and the wider data protection rules that already apply to your business.

So, what is the EU AI Act?

The EU AI Act is designed to make sure AI is developed and used safely, transparently and in a way that respects people’s fundamental rights, while still leaving room for innovation.

Rather than treating every AI tool in the same way, the Act takes a risk-based approach. The higher the potential risk, the more demanding the rules become.

It also separates businesses into different roles. A provider develops or places an AI system on the market, while a deployer uses one within its operations. Importers and distributors have their own responsibilities too.

The obligations aren’t identical, so one of the first jobs is working out where your startup sits. In some cases, you may perform more than one role.

Does the EU AI Act apply to UK startups?

Potentially, yes.

The EU AI Act may apply to a UK startup or scaleup if it is:

  • Selling or supplying AI systems in the EU
  • Providing AI systems to EU-based businesses
  • Using an AI system where its output is used or relied on in the EU
  • Developing an AI-powered product for the European market

That captures more businesses than you might expect, particularly SaaS startups, fintechs, healthtech companies and other technology businesses operating across several markets.

Even where the Act doesn’t strictly apply, following its principles can make commercial sense. Enterprise customers, investors and procurement teams increasingly want to know that AI is being used responsibly — and that you can prove it.

The UK has taken a different approach so far, favouring a pro-innovation framework built around existing regulators such as the ICO, FCA and CMA. But that doesn’t take UK businesses operating in EU markets outside the reach of the EU rules.

How does the EU AI Act classify risk?

The Act broadly groups AI systems into four levels of risk:

  • Unacceptable risk: Certain uses, including some forms of social scoring and manipulative AI, are banned outright.
  • High risk: Systems used in sensitive areas such as recruitment, credit decisions, education and healthcare face the most extensive obligations.
  • Limited risk: Tools such as chatbots and certain AI-generated content are subject to transparency requirements, so people know when they’re interacting with AI.
  • Minimal or low risk: Most everyday AI tools carry fewer specific obligations, although wider laws and good governance still apply.

The important bit? Your business may use several AI systems that fall into different categories.

A company-wide answer of “we use AI” isn’t enough. You need to understand what each tool does, where it’s used, what data it processes and how its outputs could affect people.

How do AI and data protection fit together?

The EU AI Act doesn’t replace existing data protection law.

If an AI system processes personal data, your business may also need to comply with UK GDPR, the Data Protection Act 2018 and, depending on where you operate, EU GDPR.

This means your AI data privacy compliance should consider questions such as:

  • What personal data does the AI system collect or use?
  • Do you have a lawful basis for processing it?
  • Have individuals been told how their data will be used?
  • Is all the data genuinely necessary?
  • Is sensitive or special category data involved?
  • Is personal data being used to train the system?
  • Are decisions being made about people automatically?
  • Is data being transferred internationally?
  • How long is the data being kept?
  • Can you explain how the system reaches its outputs?

For startups, getting these answers straight early is much easier than trying to piece them together when an investor, enterprise customer or regulator starts asking questions.

Does your startup need a Data Protection Impact Assessment?

A Data Protection Impact Assessment, or DPIA, helps you identify and reduce privacy risks before introducing a new technology or processing activity.

A DPIA may be legally required where the processing is likely to result in a high risk to individuals. This can include certain uses of AI, large-scale processing, systematic monitoring or automated decision-making with significant effects.

Even where a DPIA isn’t mandatory, completing one can be a sensible part of your AI governance framework. It forces the business to consider what the system is doing, why it’s needed, what could go wrong and how those risks will be managed.

It can also give customers, investors and procurement teams greater confidence that data protection has been built into the product from the start, rather than added shortly before due diligence.

What happens if you get it wrong?

The consequences under the EU AI Act are not exactly small.

The most serious infringements can attract fines of up to €35 million or 7% of worldwide annual turnover, whichever is higher.

But regulatory fines aren’t the only risk.

If you can’t explain how your startup uses and manages AI:

  • Enterprise deals can slow down
  • Procurement processes can become more painful
  • Investors may raise concerns during due diligence
  • Customers may ask for additional contractual protections
  • Product launches may be delayed
  • A data breach or complaint may become harder to manage
  • Trust in your product can take a hit

Good AI governance and data protection aren’t just compliance exercises. For Seed to Series B businesses, they can directly affect your ability to raise investment, win larger customers and enter new markets.

When do the EU AI Act rules apply?

The EU AI Act has been introduced in stages since 2024.

Prohibited AI practices and AI literacy duties began to apply in February 2025. Rules for general-purpose AI models followed in August 2025, and the European Commission and national authorities began enforcing further parts of the Act from 2 August 2026.

Some requirements for high-risk AI systems have later application dates, extending into 2027 and 2028.

The exact timeline for your business will depend on the AI systems you develop or use, your role under the Act and the relevant risk category.

In other words, this probably isn’t one to leave sitting at the bottom of the to-do list.

What should startups and scaleups do now?

Start by getting a clear picture of how AI is actually being used across your business.

That means speaking to teams beyond IT. HR, marketing, sales, customer support and product teams may all be using AI tools, sometimes without anyone having created a central record of them.

A practical starting point is to:

  1. Create an AI inventory. Record the tools and systems being developed or used across the business.
  2. Understand the data involved. Document what each system does, what data it uses and who may be affected by its outputs.
  3. Identify your role. Work out whether you’re acting as a provider, deployer, importer or distributor under the EU AI Act.
  4. Assess the risk. Determine the risk category and obligations attached to each use case.
  5. Review your data protection position. Check your lawful bases, privacy notices, data processing agreements and international data transfer arrangements.
  6. Consider whether a DPIA is needed. Complete one before launching any processing likely to create a high risk to individuals.
  7. Build in privacy by design. Make data protection part of product development and decision-making from the beginning.
  8. Put clear ownership in place. Decide who is responsible for AI governance and data privacy compliance.
  9. Train your team. Give employees practical guidance on which tools they can use, what information can be entered and when approval is needed.
  10. Keep evidence of your decisions. Document your assessments and review them as your products, tools and regulatory guidance change.

AI governance doesn’t need to become a 200-page policy that nobody reads. It does need to be practical, proportionate and embedded into the way your team actually works.

Building a data privacy programme that scales

The privacy processes that worked when your startup had ten employees may not work when it reaches fifty — or when you begin selling into several markets.

As the business grows, the amount of personal data it handles usually grows with it. You may introduce new software, hire internationally, launch AI-powered features and start answering much more detailed questions from enterprise customers and investors.

A scalable data privacy programme might include:

  • Clear responsibility for data protection
  • An up-to-date data map
  • Privacy notices that reflect what the business actually does
  • Appropriate data processing and data sharing agreements
  • A process for completing DPIAs
  • Data breach and subject access request procedures
  • International data transfer safeguards
  • AI governance policies
  • Regular staff training
  • Ongoing reviews as the business evolves

Getting these foundations in place before your next raise or major customer deal can save a lot of last-minute scrambling later.

When should a startup seek data privacy legal support?

Specialist data protection advice can be particularly valuable when your business is:

  • Launching an AI-powered product or feature
  • Entering the UK or EU market
  • Preparing for a Seed, Series A or Series B raise
  • Responding to investor due diligence
  • Signing enterprise customers
  • Processing health, financial or other sensitive data
  • Using personal data to train an AI system
  • Introducing automated decision-making
  • Completing a DPIA
  • Responding to a data breach or regulatory complaint
  • Building a privacy programme for the first time

The earlier you address these issues, the easier it is to create a proportionate approach that supports growth rather than getting in its way.

How Founders Law can help

Our data privacy lawyers support startups and scaleups with the legal and practical side of AI and data protection.

We can help you:

  • Understand whether the EU AI Act applies to your business
  • Map and classify the AI systems you develop or use
  • Complete DPIAs and AI risk assessments
  • Review your UK GDPR compliance
  • Create an AI governance framework
  • Draft privacy notices, policies and data agreements
  • Prepare for investor or customer due diligence
  • Build a data privacy programme that scales with your business

Whether you need support with a specific AI product or want ongoing, outsourced data protection support, we’ll help you put the right foundations in place — without slowing innovation to a crawl.

Want to know where your startup currently stands? Get in touch with our Data Privacy team.

‍

AI
EU
Next
Previous
Frequently Asked Questions

We act as an extension of your team and handle any overflow in specialist areas. 


‍
Working across five continents, operating in multiple sectors, with over 400 clients.

Offices in London | Dubai.

Does the EU AI Act apply to UK startups?
How does UK GDPR apply when a startup uses AI?
Does a startup need a Data Protection Officer?