The EU AI Act reaches US startups that ship to EU users — and most assume it doesn't. Here's what readiness actually means, and the parts that don't matter yet.
The EU AI Act is extraterritorial: if your AI system is on the EU market or affects EU users, it reaches you. Most US startups either ignore it or over-rotate on it. Readiness is narrower than the panic suggests.
The Conduct Rule: Know Your Risk Tier
The Act tiers systems by risk: prohibited, high-risk, limited-risk, minimal-risk. Readiness starts with knowing which tier your system is in — most US startups are limited or minimal, not high-risk, and the obligations follow the tier.
- Prohibited: don't ship these.
- High-risk: the full obligations apply.
- Limited-risk: transparency obligations.
- Minimal-risk: largely voluntary.
What Readiness Actually Means
For most US startups, readiness is three things:
- **Classification.** Know your risk tier, documented.
- **Transparency.** If you're limited-risk, tell users they're interacting with AI.
- **Documentation.** For high-risk: data, model, evals, audit trail, risk management.
The first two are cheap; the third is the one to scope early if you might be high-risk.
The Power Dynamic: Where It Bites
The Act bites at the points where a regulator or a counterparty asks for evidence — at procurement, at a complaint, at an audit. Readiness is having the evidence ready: classification, transparency, and (if high-risk) the documentation. Not having it is where the cost lands.
What to Ignore
- The parts that apply only to prohibited systems (you shouldn't be building those).
- The panic about obligations that don't apply to your tier.
- The assumption that it doesn't reach you (it does, if you touch EU users).
Conclusion
EU AI Act readiness for a US startup is knowing your risk tier, meeting the transparency obligations, and — if you're high-risk — scoping the documentation early. Most startups are limited or minimal risk, and the obligations follow the tier. Ignore the panic; don't ignore the reach.
About FACTA
FACTA helps startups and growth-stage teams turn AI into production systems that keep running — not demos that impress once.
We design the architecture around the parts that actually break under real usage: tooling you own, credentials you control, failover, cost controls, observability. The boring infrastructure that keeps a system alive after launch.
Led by Matías Baglieri and Carolina Fogliato, we focus on one thing:
AI leadership that builds. Not just advises.
Ask us which risk tier your AI system is in.
We'll tell you what readiness means for it. See the AI policy template for the internal side.
Explore AI Strategy
