7 Things I Learned Building a Compliant AI Under the EU AI Act

Published 2025-10-12 · Updated 2026-05-23 · 5 min read · AI Ethics and Regulation · By Sahin Boydas

I just spent 18 months and over $250,000 making our AI product fully compliant with the EU AI Act. It was brutal, but the lessons were invaluable. I'm breaking down the 7 most critical, non-obvious takeaways for any founder in the AI space.

It cost me 18 months and over $250,000.

That was the price to make our latest AI product fully compliant with the EU AI Act. It was a brutal, soul-crushing marathon through a maze of legal jargon, technical debt, and existential questions about what our product even was. Most founders in the AI space are sleepwalking into a regulatory minefield. They think a few tweaks to their privacy policy will cut it. They are wrong.

I’m not a lawyer. I’m an engineer and a founder. I’ve built and sold companies, and I’ve invested in over 200 startups, including some of the biggest names in AI like Anthropic and OpenAI. I’m sharing the hard-won lessons from the trenches that you won’t find in any legal guide. This is what it really takes.

1. Your Model is Only 10% of the Problem

We started this process obsessing over model bias and explainability. We spent weeks generating fairness reports and tweaking algorithms. It was a complete misdirection. The regulators, it turns out, care just as much, if not more, about the entire system surrounding the model.

Our first big shock came from our data ingestion pipeline. We had a script that pulled public data from a few sources. One of those sources changed its terms of service without us noticing, and we were suddenly using data we no longer had the rights to for that specific purpose. It was an intern who caught it, not our expensive consultants. We had to purge terabytes of data and retrain models from scratch. The lesson: your compliance boundary starts the second a piece of data enters your ecosystem. Document every step, from curl command to final prediction.

2. Your Data Scientists Are Not Lawyers (and Vice Versa)

I have immense respect for my team. They can build anything. But asking a machine learning engineer to interpret Article 14 of the AI Act is malpractice. It’s like asking a lawyer to write production-level Python. In the beginning, we tried to save money by having our internal team lead the compliance effort. It was a disaster.

They spent weeks building a beautiful, technically sound system for logging model predictions. But it completely missed the legal requirement for human-readable explanations. We burned $30,000 in salaries to build a system we had to throw away. We finally hired a specialized legal tech consultant who could speak both languages. They translated the legalese into concrete technical requirements. Don't be cheap here. This role is non-negotiable.

3. The Definition of "High-Risk" Will Terrify You

Everyone thinks their AI is low-risk. No one wants to be in the crosshairs. But the definition of a “high-risk AI system” is dangerously broad and open to interpretation. It’s not just about self-driving cars or medical diagnoses.

Our product has a feature that helps companies screen candidates by summarizing their public professional profiles. We thought of it as a simple productivity tool. But because it could be used in a hiring process, it fell under the “employment” category of high-risk systems. The compliance burden exploded overnight. We had to implement a mandatory human review layer, add complex opt-out flows, and provide a mechanism for candidates to challenge the AI’s summary. What we thought was a minor feature became the most expensive part of our product.

4. "Explainability" is Not a SHAP Plot

For years, the AI community has gotten away with a very academic definition of explainability. We generate some charts, point to feature importance, and call it a day. That is not going to fly.

When a regulator asks why your AI denied someone a loan, they don’t want to see a graph. They want a story. They want a clear, step-by-step causal chain. “The loan was denied because the applicant’s debt-to-income ratio was 52%, which exceeds the 45% threshold established in our policy, a policy based on a historical analysis of 1.2 million loan applications showing a default rate of 28% for applicants above that threshold.”

We had to build a whole new system that logs not just the prediction, but the specific data points and the exact rule or logic path that led to the outcome. It was a massive engineering lift.

5. The Real Cost is in Data Governance

That $250,000 we spent? I’d estimate more than half of it went to data governance. It’s the least sexy part of AI, but it’s what the EU AI Act is secretly all about. The Act demands an unprecedented level of control and documentation over your data.

  • Quality: You have to prove your data is “relevant, representative, free of errors and complete.” For us, this meant building automated validation tools and paying for manual data cleaning and labeling.
  • Traceability: You need a perfect audit trail. Where did this piece of data come from? Who has accessed it? What models were trained on it? We had to invest in a data cataloging and lineage platform.
  • Bias Detection: You have to continuously test your data for hidden biases. We found a subtle bias against developers who primarily contributed to open-source projects with non-permissive licenses. Fixing it required re-sampling and data augmentation. It’s a constant, ongoing process.

6. Your Third-Party APIs Are Your Responsibility

This is the lesson that keeps other founders up at night. You can’t just outsource your risk to a big provider. If you’re using a third-party API—even from a company I’ve invested in like OpenAI—you are the one on the hook for ensuring its use is compliant.

We were using a third-party service for identity verification. During a vendor audit, we discovered they couldn’t provide the level of detail on their model’s training data that the Act required. We had to rip them out and switch to a new provider, which cost us a month of engineering time. You are responsible for the entire supply chain of your AI. Vet your vendors with the same rigor you vet your employees.

7. Compliance is Now a Competitive Moat

I’ll be honest, there were many moments during this process when I wanted to give up. It felt like we were spending all our time on paperwork instead of building a great product. But now that we’re on the other side, I see it differently.

We just won a major enterprise contract specifically because we could demonstrate compliance. Our competitor could not. They are now scrambling to catch up, but it will take them at least a year. That brutal 18-month marathon built us a moat. We can now walk into any sales meeting with the largest, most risk-averse companies in the world and confidently say we are ready for the new era of AI. The EU AI Act was expensive, painful, and infuriating. But it also handed us a powerful competitive weapon. Don't just prepare to survive it—prepare to win with it.

Frequently Asked Questions

How were these items selected?

Each item on this list comes from direct experience, either from building my own companies or from patterns I've observed across the 200+ startups I've invested in. I prioritize practical, actionable items over theoretical concepts.

Are these recommendations still relevant in 2026?

Absolutely. While specific tools and tactics change, the underlying principles remain consistent. I update my thinking regularly based on what I'm seeing in the market and across my portfolio companies.

Which item on this list has the highest impact?

It depends on your stage and context, but in my experience, the items near the top of the list tend to have the broadest applicability. That said, sometimes the less obvious items create the biggest breakthroughs for specific situations.

How do I know which items apply to my situation?

Start by honestly assessing where your biggest bottleneck is right now. The items that address that specific constraint will give you the highest return on your time and energy.

More in AI Ethics and Regulation

  • AI Regulation in 2027: 3 Predictions From a Serial Entrepreneur — Having lived through the dot-com bust, the mobile revolution, and now the AI explosion, I've learned to see around corners. The current AI regulation is just the beginning. I'm sharing my 3 bold predictions for the 2027 regulatory landscape and how to prepare now.
  • How to Conduct an AI Alignment Audit (The Counterintuitive Guide) — Forget the standard AI alignment checklists. They don't work. After auditing dozens of models, I've developed a counterintuitive method that actually surfaces deep alignment issues. I'll walk you through my exact 3-step process for finding what others miss.
  • The Truth About AI Bias: 7 Shocking Stats from Our 2026 Audit — We just completed a massive audit of 100+ production AI models, and the results on bias are staggering. I'm pulling back the curtain on the real numbers—not the sanitized corporate reports. This is what hidden bias actually looks like in the wild.
  • Nobody Talks About the Real Cost of AI Safety. Until Now. — As a Silicon Valley veteran who has built and sold two AI companies, I'm breaking the code of silence. The true cost of implementing robust AI safety isn't in the tech—it's in the human capital and culture. I'll reveal the numbers and strategies you need to know.
  • The Truth About AI Bias: 7 Shocking Stats from Our 2026 Audit — We just completed a massive audit of 100+ production AI models, and the results on bias are staggering. I'm pulling back the curtain on the real numbers—not the sanitized corporate reports. This is what hidden bias actually looks like in the wild.
  • I Wasted 5 Years on AI Ethics Frameworks. Here's What Actually Works. — I chased complex AI ethics frameworks for half a decade, getting it all wrong. I'm sharing my painful journey from buzzword-chasing to building responsible AI that ships. This is the stuff nobody tells you about the gap between theory and reality.

All AI Ethics and Regulation articles · Sahin's angel investments · Startups he founded