The following is a guest post by Sahin Boydas, a serial entrepreneur and angel investor. The views expressed are his own.
7 Things I Learned Building a Compliant AI Under the EU AI Act
I just spent 18 months and over $250,000 making our AI product fully compliant with the EU AI Act. It was brutal. Forget the dry legal summaries and the high-level think pieces from consulting firms. I’m here to give you the ground truth from the trenches, founder to founder.
Most people in Silicon Valley see regulation as a nuisance, a tax on innovation. I get it. But the EU AI Act is different. This isn't a simple checkbox exercise like GDPR. It's a fundamental shift in how you must build and operate an AI company if you want to touch the European market. It’s a minefield, and I’m going to share the hard-won lessons that you won’t find in any legal guide.
This is what it really takes to be compliant.
1. Forget the Fines. The Real Cost is the Focus Drain.
Everyone loves to quote the headline-grabbing fines—up to €35 million or 7% of global turnover. It’s a scary number, for sure. But honestly, that wasn’t what kept me up at night. The real killer, the silent startup killer, was the relentless drain on our focus.
For six solid months, my co-founder and I were pulled into at least ten hours of compliance-related meetings every single week. That’s not an exaggeration. We had meetings with lawyers to interpret the legalese, meetings with consultants to design our risk assessment framework, and meetings with our own team to explain the new requirements. That’s half our productive time as founders, gone. Poof. Evaporated into thin air.
We had our two best engineers—the ones who should have been perfecting our core recommendation algorithm—writing documentation about data lineage and model testing protocols instead. We had a feature launch for a new personalization engine, something our users were begging for, that we had to delay by a full quarter. The opportunity cost was easily in the millions. While we were stuck in a conference room debating the precise definition of "meaningful human oversight," our competitors were shipping code. The Act doesn’t just demand your money; it demands your most precious resource: your team's undivided attention. And for a startup, that's everything.
2. Your Data Is a Toxic Asset Waiting to Happen.
We thought we had clean data. We really did. We’d spent a fortune on what we believed was a pristine, well-labeled dataset for training our main classification model. We were proud of it. Then the audit started.
It turns out, a small fraction of our data, acquired from a data broker back in 2021, had murky origins. The broker was reputable, or so we thought. But they couldn't provide the granular, individual-level consent records that the Act requires. We could prove consent for the dataset as a whole, but not for every single person within it. It was about 5% of our total training data.
Five percent. Sounds small, right? But under the AI Act, it was a ticking time bomb. We had two choices: risk it, or purge it. We purged it. All of it. And then we had to retrain our models from a new, smaller, but fully compliant dataset. Our model's accuracy dropped by a noticeable 8% overnight. It took our data science team three weeks of frantic work to get it back to its previous performance. The lesson here is brutal: data isn’t just an asset anymore. It’s a liability. You need to treat your data governance with the same paranoid seriousness as your finances. Every single data point needs a bulletproof story. If you can’t tell that story, you can’t use it. Period.
3. "Explainable AI" Is No Longer a Boardroom Buzzword.
I’ve been in dozens of boardrooms where "Explainable AI" (XAI) was a term thrown around to make investors feel warm and fuzzy. It was a nice-to-have, a marketing slide. Those days are definitively over. The "right to an explanation" for automated decisions is a core tenet of the Act. And the regulators are not messing around.
I sat in a three-hour meeting with a national authority where they grilled us on why our model made a specific credit-scoring recommendation for a hypothetical user. They didn’t want a high-level summary or a pretty visualization. They wanted the specific features, the exact weights assigned to them, and the full decision path through the model. Our initial response, based on a standard SHAP plot, wasn’t good enough. The regulator, a woman with a PhD in computer science, called it a "post-hoc rationalization" and said it didn't represent the model's actual internal logic.
This is exactly why I’ve invested in companies like Anthropic and backed teams working on mechanistic interpretability. They get it. Building interpretability into the model from the ground up is the only way forward. We had to completely re-architect a part of our system, moving away from a complex, high-performance XGBoost ensemble model to a simpler, less accurate, but fully interpretable logistic regression model. It felt like a step backward from a pure machine learning perspective, but it was the only way to move forward in terms of compliance. You have to be able to show your work. There is no other option.
4. "Human-in-the-Loop" Is an Entire Product, Not a Feature.
For any system deemed "high-risk," the Act mandates human oversight. We initially interpreted this as having a person review a random 10% sample of the AI's outputs. We were wrong. So, so wrong.
Effective human oversight means building an entire workflow, a complete user interface, for a human to meaningfully intervene and override the AI's decision before it has an impact on the end-user. This isn't just a log file someone checks once a week. It's an active, real-time system. We had to build a whole new internal dashboard we called the "Cockpit." It showed the AI's recommendation, the confidence score, the top five features that led to the decision, and a big red "OVERRIDE" button.
We had to hire and train three people, not to do the primary task, but to watch the AI do the task. We had to create a 50-page manual on how to handle disagreements. For example, if the AI recommended declining a loan application but the human reviewer thought it should be approved, they had to document their reasoning in a structured format, which was then reviewed by a senior manager. It added a whole new layer of operational complexity and cost. It’s like having a driver’s ed instructor in the car with your self-driving AI, forever. It’s necessary, but you need to budget for it from day one, both in terms of salary and engineering resources.
5. The Technical Documentation Is a Beast of Its Own.
I'm a big believer in documentation. At my last company, RemoteTeam, we lived by our wiki. But the technical documentation required by the AI Act is on another planet. It’s not a README file in a GitHub repo. It’s a 200-page, legally-scrutinized, living document that details every single aspect of your AI system.
The section on risk assessment alone was 40 pages long. We had to brainstorm every conceivable way our AI could fail or be misused—from adversarial attacks to perpetuating societal biases—and document our mitigation strategies for each one. It was a soul-crushing exercise in structured paranoia.
Ours was a collaborative effort between our lead engineer, a product manager, and two very expensive lawyers who billed us at €800 an hour. It took them three months to write the first version. And it’s never “done.” Every time we update a model, tweak an algorithm, or change a data source, the documentation has to be updated. It’s a product in itself, and it requires a dedicated owner to maintain. If you wait until you’re ready to ship to start this, you’ll be looking at a six-month delay, minimum. This isn't an afterthought; it's a prerequisite.
6. Your Supply Chain Is Your Responsibility. No Excuses.
Modern software is built on APIs. We use a number of third-party APIs in our product—one for identity verification, another for enriching user data. We thought that if we had a solid contract with them, we were covered. The AI Act makes it brutally clear: you are responsible for the compliance of your entire AI supply chain.
We had to audit every single AI-powered service we used. One of our providers, a well-known San Francisco startup that provides a sentiment analysis API, couldn't give us the detailed documentation on their training data and model architecture that we needed to satisfy our own compliance requirements. Their response was basically, "It's proprietary." That doesn't fly.
We had to rip them out of our product. We spent two months building our own, less-capable version in-house. It was a painful, expensive decision that set our product roadmap back significantly. But it was the only one we could make. If you are building an AI product, you need to think like a car manufacturer. You are responsible for every component. Vet your vendors with the same rigor you vet your employees. Get their compliance documentation upfront. If they can’t provide it, you have to walk away.
7. Compliance Is a Product, Not a Project.
This is the most important lesson of all. We initially treated compliance as a project. It had a start date, an end date, and a budget. We thought we could “get compliant” and then move on. That was our biggest and most costly mistake.
Compliance is a feature of your product. It’s a core part of your value proposition, especially in a regulated market. It needs a product manager, a roadmap, and dedicated engineering resources. It needs to be integrated into your sprint planning, your quarterly goals, and your marketing.
We now have a “Head of AI Trust & Safety.” It sounds like a fancy corporate title, but it’s a critical role. We hired a former data protection lawyer who had retrained as a product manager. Her job is to live and breathe the AI Act, to translate its requirements into engineering tickets, and to work with the team to ensure we are always compliant. She is one of the most important people in our company. It’s a permanent role, and it’s one of the best investments we’ve made.
The New Cost of Doing Business
Becoming compliant was one of the hardest things I’ve ever done as an entrepreneur. It was more expensive, more distracting, and more frustrating than I could have ever imagined. But it was also clarifying. It forced us to be better engineers, better product managers, and a better company.
The EU AI Act isn’t just a hurdle. It’s the new foundation for building AI in one of the world's largest markets. It’s a challenge, for sure. But it’s also an opportunity. The companies that embrace this new reality, the ones that build trust and safety into the core of their products, are the ones that will win. They will be the ones that earn the trust of their users, their investors, and the market. And in the age of AI, trust isn't just a currency—it's the only thing that matters.
Frequently Asked Questions
Which item on this list has the highest impact?
It depends on your stage and context, but in my experience, the items near the top of the list tend to have the broadest applicability. That said, sometimes the less obvious items create the biggest breakthroughs for specific situations.
How were these items selected?
Each item on this list comes from direct experience, either from building my own companies or from patterns I've observed across the 200+ startups I've invested in. I prioritize practical, actionable items over theoretical concepts.
Can I implement all of these at once?
I'd strongly recommend against it. Pick the 2-3 items that resonate most with your current situation and focus there. Trying to do everything simultaneously is a recipe for doing nothing well.