What I Learned After 18 Months Building an AI That Meets EU Rules

Published 2025-05-05 · Updated 2026-05-23 · 8 min read · AI Ethics and Regulation · By Sahin Boydas

After spending 18 months and $250K making our AI product compliant with the EU AI Act, I've gathered practical insights that go beyond legal documents. Here are the seven most important lessons every AI entrepreneur should know.

We spent 18 months and over $250,000 to make our AI product compliant with the EU AI Act. And that was for a team of just 12 people. I’m sharing what we learned, so you don’t have to make the same expensive mistakes.

When the first drafts of the EU AI Act started circulating, I, like many in Silicon Valley, was dismissive. It felt like another classic case of bureaucrats in Brussels trying to regulate something they didn’t understand. I’ve built and sold two companies, RemoteTeam and MovieLaLa, and invested in over 200 startups, including some of the biggest names in AI like Anthropic and OpenAI. I thought I knew the game. I was wrong.

Navigating the EU AI Act was one of the most challenging things I’ve done in my career. The Act isn’t just a legal document; it’s a fundamental rethinking of how AI should be built and deployed. It forced us to confront uncomfortable questions about fairness, transparency, and accountability. Here are the seven most important lessons I learned.

1. The Act is a Moving Target

When we started this journey, the AI Act was still being debated and amended. We’d spend weeks implementing a feature to address a specific clause, only to have that clause rewritten or removed. It felt like trying to hit a target that was constantly moving. We had to hire a team of lawyers in Brussels just to keep up with the changes. My advice: don’t get bogged down in the details of the current draft. Instead, focus on the core principles of the Act: risk management, data quality, transparency, and human oversight. These are unlikely to change, and building your product around them will make you more resilient to future amendments.

We had one instance where we spent a month building a complex data lineage tracking system, only to find out that the final version of the Act had a slightly different interpretation of what was required. We had to refactor the entire system. That was a $30,000 mistake.

2. Data Provenance is Everything

The Act places a huge emphasis on data quality and governance. You need to know where your data came from, how it was collected, and what biases it might contain. For us, this meant going back through years of data and meticulously documenting its provenance. It was a painful and time-consuming process, but it was also incredibly valuable. We uncovered hidden biases in our datasets that we never would have found otherwise. For example, we discovered that one of our early datasets for a hiring tool was heavily skewed towards male candidates. We had to re-balance the dataset and retrain the model to ensure fairness.

This isn’t just about compliance; it’s about building a better product. If your data is biased, your AI will be biased. It’s that simple. Start documenting your data provenance now, even if you’re not subject to the AI Act. It will save you a lot of headaches down the road.

3. "High-Risk" is Broader Than You Think

The Act categorizes AI systems into different risk levels, with the strictest requirements reserved for "high-risk" applications. We initially thought our product, a tool for helping companies manage their remote teams, would be low-risk. We were wrong. Because our tool could be used to make decisions about hiring, promotion, and termination, it was classified as high-risk. This meant we had to implement a whole host of additional requirements, including a mandatory fundamental rights impact assessment.

Don’t assume your AI is low-risk. The definition of high-risk is broad and open to interpretation. If your AI has any impact on people’s lives or livelihoods, there’s a good chance it will be considered high-risk. The list of high-risk systems includes AI used in education, employment, and law enforcement. But it also includes systems that determine access to essential services, like credit scoring and insurance. The consequences of being classified as high-risk are significant, so it’s important to get this right.

4. Explainability is Not Just a Buzzword

For years, “explainable AI” has been a popular buzzword in the tech industry. The EU AI Act turns it into a legal requirement. For high-risk systems, you need to be able to explain how your AI makes its decisions. This is a huge technical challenge, especially for complex models like deep neural networks. We had to invest heavily in new tools and techniques to make our models more interpretable. We ended up building a custom dashboard that allows our users to see the factors that contributed to a particular decision. This not only helped us comply with the Act, but it also increased our users’ trust in our product.

This is a big deal. For a long time, the AI community has been comfortable with black-box models. The AI Act is forcing us to open up the black box and show our work. This is a good thing. It will lead to more robust, reliable, and trustworthy AI.

5. Your Team Needs a Philosopher

Compliance with the AI Act is not just a technical challenge; it’s also an ethical one. You need to think deeply about the potential societal impact of your AI. We found that our team of engineers and data scientists wasn’t equipped to have these conversations. We ended up hiring an ethicist to help us navigate the complex ethical issues we were facing. She pushed us to think about things we had never considered, like the long-term impact of our AI on the future of work.

This might sound like a luxury, but I believe it’s essential. As AI becomes more powerful, the ethical stakes will only get higher. You need people on your team who can help you think through these issues from a humanistic perspective. A philosopher or an ethicist can be a valuable addition to any AI team.

6. The Cost of Compliance is a Moat

Let’s be honest: complying with the EU AI Act is expensive. We spent over $250,000, and we’re a small company. For larger companies, the cost could be in the millions. This creates a significant barrier to entry for new startups. While I’m a strong believer in responsible AI, I’m also a pragmatist. The high cost of compliance will give a huge advantage to large, incumbent companies that can afford to pay it. It will be a moat that keeps smaller, more innovative companies out of the market.

I don’t have an easy answer to this problem. On the one hand, we need strong regulations to ensure that AI is developed and deployed safely and ethically. On the other hand, we don’t want to stifle innovation and competition. This is a difficult trade-off, and it’s one that we as a society need to grapple with.

7. The US is Watching

While the EU has taken the lead on AI regulation, the US is not far behind. The White House has issued an executive order on AI, and there are several AI-related bills making their way through Congress. I believe that the EU AI Act will serve as a model for future US regulations. The concepts of risk-based regulation, data governance, and explainability are likely to be adopted in some form in the US.

This means that even if you’re not doing business in the EU, you should be paying close attention to the AI Act. The principles and practices that it establishes are likely to become the global standard for AI regulation. The sooner you start incorporating them into your product development process, the better prepared you’ll be for the future.

The Road Ahead

Building a compliant AI product was a long and difficult journey. But it was also a rewarding one. It forced us to build a better product and to think more deeply about our responsibilities as creators of AI. The EU AI Act is not perfect, but it’s a good first step towards a future where AI is safe, fair, and transparent.

My advice to other entrepreneurs is this: don’t be afraid of the AI Act. Embrace it as an opportunity to build a better product and a better company. It won’t be easy, but it will be worth it. The future of AI depends on it.

Frequently Asked Questions

What would you do differently looking back?

I'd move faster on the things that were working and cut the things that weren't sooner. Most founders, myself included, hold onto failing strategies too long because of sunk cost. Speed of learning is everything.

Can these results be replicated?

The specific numbers will vary, but the underlying patterns and principles are transferable. The key is understanding the context behind the results, not just copying the tactics. Every company has unique constraints that shape what works.

How long did it take to see results?

Most meaningful business results take 3-6 months to materialize. Anyone promising overnight success is selling something. The companies in my portfolio that grew fastest were the ones that stayed patient and consistent.

What was the biggest challenge in this case?

Almost always, the biggest challenge is people and alignment, not technology or strategy. Getting the right team focused on the right problem is harder than any technical challenge I've encountered.

More in AI Ethics and Regulation

  • AI Regulation in 2027: 3 Predictions From a Serial Entrepreneur — Having lived through the dot-com bust, the mobile revolution, and now the AI explosion, I've learned to see around corners. The current AI regulation is just the beginning. I'm sharing my 3 bold predictions for the 2027 regulatory landscape and how to prepare now.
  • How to Conduct an AI Alignment Audit (The Counterintuitive Guide) — Forget the standard AI alignment checklists. They don't work. After auditing dozens of models, I've developed a counterintuitive method that actually surfaces deep alignment issues. I'll walk you through my exact 3-step process for finding what others miss.
  • The Truth About AI Bias: 7 Shocking Stats from Our 2026 Audit — We just completed a massive audit of 100+ production AI models, and the results on bias are staggering. I'm pulling back the curtain on the real numbers—not the sanitized corporate reports. This is what hidden bias actually looks like in the wild.
  • Nobody Talks About the Real Cost of AI Safety. Until Now. — As a Silicon Valley veteran who has built and sold two AI companies, I'm breaking the code of silence. The true cost of implementing robust AI safety isn't in the tech—it's in the human capital and culture. I'll reveal the numbers and strategies you need to know.
  • The Truth About AI Bias: 7 Shocking Stats from Our 2026 Audit — We just completed a massive audit of 100+ production AI models, and the results on bias are staggering. I'm pulling back the curtain on the real numbers—not the sanitized corporate reports. This is what hidden bias actually looks like in the wild.
  • I Wasted 5 Years on AI Ethics Frameworks. Here's What Actually Works. — I chased complex AI ethics frameworks for half a decade, getting it all wrong. I'm sharing my painful journey from buzzword-chasing to building responsible AI that ships. This is the stuff nobody tells you about the gap between theory and reality.

All AI Ethics and Regulation articles · Sahin's angel investments · Startups he founded