BlogGovernance
Governance4 min read· July 20, 2026

EU AI Act Readiness for US Startups

Carolina Fogliato

Published July 20, 2026

The EU AI Act reaches US startups that ship to EU users. Here's what readiness actually means — and what to ignore.

The EU AI Act reaches US startups that ship to EU users — and most assume it doesn't. Here's what readiness actually means, and the parts that don't matter yet.

The EU AI Act is extraterritorial: if your AI system is on the EU market or affects EU users, it reaches you. Most US startups either ignore it or over-rotate on it. Readiness is narrower than the panic suggests.

The Conduct Rule: Know Your Risk Tier

The Act tiers systems by risk: prohibited, high-risk, limited-risk, minimal-risk. Readiness starts with knowing which tier your system is in — most US startups are limited or minimal, not high-risk, and the obligations follow the tier.

  • Prohibited: don't ship these.
  • High-risk: the full obligations apply.
  • Limited-risk: transparency obligations.
  • Minimal-risk: largely voluntary.

What Readiness Actually Means

For most US startups, readiness is three things:

  • **Classification.** Know your risk tier, documented.
  • **Transparency.** If you're limited-risk, tell users they're interacting with AI.
  • **Documentation.** For high-risk: data, model, evals, audit trail, risk management.

The first two are cheap; the third is the one to scope early if you might be high-risk.

The Power Dynamic: Where It Bites

The Act bites at the points where a regulator or a counterparty asks for evidence — at procurement, at a complaint, at an audit. Readiness is having the evidence ready: classification, transparency, and (if high-risk) the documentation. Not having it is where the cost lands.

What to Ignore

  • The parts that apply only to prohibited systems (you shouldn't be building those).
  • The panic about obligations that don't apply to your tier.
  • The assumption that it doesn't reach you (it does, if you touch EU users).

Conclusion

EU AI Act readiness for a US startup is knowing your risk tier, meeting the transparency obligations, and — if you're high-risk — scoping the documentation early. Most startups are limited or minimal risk, and the obligations follow the tier. Ignore the panic; don't ignore the reach.

About FACTA

FACTA helps startups and growth-stage teams turn AI into production systems that keep running — not demos that impress once.

We design the architecture around the parts that actually break under real usage: tooling you own, credentials you control, failover, cost controls, observability. The boring infrastructure that keeps a system alive after launch.

Led by Matías Baglieri and Carolina Fogliato, we focus on one thing:

AI leadership that builds. Not just advises.

Ask us which risk tier your AI system is in.

We'll tell you what readiness means for it. See the AI policy template for the internal side.

Explore AI Strategy
Book a 30-minute call →

No pitch. No pressure. Just a look at where your AI stack is fragile — and what to fix first.

Stay Updated

Get production AI insights in your inbox

Weekly insights. No spam. Unsubscribe anytime.

Your Privacy Matters

We use cookies to enhance your experience, analyze traffic, and serve targeted ads.

By clicking "Accept All", you consent to all cookies. Cookie Policy