7 Things I Learned Building a Compliant AI Under the EU AI Act

Published 2025-06-15 · Updated 2026-05-05 · 6 min read · AI Ethics and Regulation · By Sahin Boydas

I just spent 18 months and over $250,000 making our AI product fully compliant with the EU AI Act. It was brutal, but the lessons were invaluable. I'm breaking down the 7 most critical, non-obvious takeaways for any founder in the AI space.

It cost me 18 months and over $250,000. That was the price to make our AI product compliant with the EU AI Act. It was a brutal, soul-crushing marathon through a jungle of legalese and technical debt. I wouldn't wish it on my worst enemy. But we survived, and I came away with some hard-won lessons that you won't find in any consultant's PowerPoint deck.

If you're a founder building in the AI space, forget the high-level summaries. This is the real story from the trenches.

1. Your Data's Pedigree Is Everything

We all know 'garbage in, garbage out.' But the EU AI Act takes this to a whole new level. It's not just about quality; it's about provenance. We had to prove the origin of every single byte of data in our training sets. We thought we had good data governance. We were wrong. So, so wrong.

I remember one week in month six where my head of engineering and I were sleeping in the office. We were trying to trace a dataset we'd licensed two years prior. The vendor had since been acquired, and their records were a mess. We spent close to $30,000 on legal fees just to confirm we had the rights to use data we had already paid for. It was a nightmare. Don't just license data; get its full biography. Every hop, every transformation, every permission. Document it like you're going to be deposed.

2. 'Human Oversight' Is Not a Buzzword, It's a Product Feature

The Act mandates 'human oversight' for high-risk AI systems. Most people think this means having a person click 'approve' on an AI's decision. That's not it. It means building an entire user interface and workflow for intervention. It means your users need the ability to understand, question, and overturn the AI's output, with a full audit trail.

We had to build a 'pane of glass' dashboard that showed not just the AI's recommendation, but also the top five contributing factors in plain English. We also had to add a 'dispute' button that would flag the result for manual review by a human expert on our team. This wasn't a small feature. It was a three-month product development cycle we hadn't planned for. You have to design for human intervention from day one.

3. Explainability Will Break Your Brain

If you're using complex models like deep neural networks, get ready for a world of pain. The requirement to explain why your model made a specific decision is incredibly difficult to meet. We spent months experimenting with LIME and SHAP, trying to generate explanations that were both accurate and understandable to a non-technical user.

Here's a real example: our AI flagged a financial transaction as potentially fraudulent. The explanation was a jumble of feature weights and partial dependence plots. It was technically correct but practically useless. We had to create a translation layer—a separate model, ironically—to turn the technical explanation into a human-readable sentence. Something like: "This transaction was flagged because the amount is 5x larger than the account's average and originates from a location where you've never transacted before." That translation layer is now a core part of our IP.

4. The Real Cost Is Documentation, Not Development

I look back at our budget, and the breakdown is shocking. We spent about 40% of the $250,000 on engineering and 60% on documentation, legal review, and process creation. Every decision, every risk assessment, every data source, every piece of the system architecture had to be documented in excruciating detail.

We now have a 300-page technical documentation file that serves as our 'Conformity Assessment.' It's a beast. My advice? Hire a technical writer early. Make them part of the engineering team. Have them document everything as it happens. If you wait until the end, you'll drown in the effort of trying to remember why you made a certain architectural choice a year ago.

5. Good Help Is Hard to Find

When we started, we looked for consultants to guide us. We found two types: lawyers who understood the law but not the tech, and tech consultants who understood AI but not the law. Neither could give us a straight answer on how to implement the requirements in our specific context.

We ended up hiring a data scientist with a law degree. She was expensive, but she was the only one who could bridge the gap. She could talk to my engineers about model architecture and then turn around and argue with our lawyers about the interpretation of a specific clause. Finding these hybrid experts is tough, but they are worth their weight in gold. Without her, we would have failed.

6. Compliance Can Be a Moat

For the first year, I saw the EU AI Act as a massive tax on innovation. A burden. But now that we're on the other side, I see it differently. It's a competitive advantage. We can now go to large enterprise customers and show them our 300-page documentation. We can prove our AI is robust, transparent, and fair. Our competitors who took shortcuts can't do that.

Compliance has become a feature of our product. It's a trust signal. We've won two major deals in the last quarter specifically because we were the only vendor who could demonstrate full compliance. It's a painful investment, but the payoff is real.

7. The 'High-Risk' Definition Is a Moving Target

The Act has a list of what constitutes a 'high-risk' AI system. But the definitions are broad. We spent the first six months just debating with our lawyers whether our product even fell into that category. The answer was 'probably.' That ambiguity is terrifying when hundreds of thousands of dollars are on the line.

My final piece of advice is this: if you think you might be high-risk, just assume you are. The cost of being wrong is too high. The fines are steep, and the reputational damage is worse. We decided to over-invest and build to the highest standard. It was the right call. Don't play chicken with the regulators. It's a game you can't win.


Building a compliant AI was one of the hardest things I've ever done as an entrepreneur. It's a complex, expensive, and frustrating process. But it's also necessary. The Wild West days of AI are over. The future belongs to those who can build powerful, responsible systems that people can trust. This is the new table stakes. Don't get left behind.

Frequently Asked Questions

Are these recommendations still relevant in 2026?

Absolutely. While specific tools and tactics change, the underlying principles remain consistent. I update my thinking regularly based on what I'm seeing in the market and across my portfolio companies.

How do I know which items apply to my situation?

Start by honestly assessing where your biggest bottleneck is right now. The items that address that specific constraint will give you the highest return on your time and energy.

Can I implement all of these at once?

I'd strongly recommend against it. Pick the 2-3 items that resonate most with your current situation and focus there. Trying to do everything simultaneously is a recipe for doing nothing well.

How were these items selected?

Each item on this list comes from direct experience, either from building my own companies or from patterns I've observed across the 200+ startups I've invested in. I prioritize practical, actionable items over theoretical concepts.

More in AI Ethics and Regulation

  • AI Regulation in 2027: 3 Predictions From a Serial Entrepreneur — Having lived through the dot-com bust, the mobile revolution, and now the AI explosion, I've learned to see around corners. The current AI regulation is just the beginning. I'm sharing my 3 bold predictions for the 2027 regulatory landscape and how to prepare now.
  • How to Conduct an AI Alignment Audit (The Counterintuitive Guide) — Forget the standard AI alignment checklists. They don't work. After auditing dozens of models, I've developed a counterintuitive method that actually surfaces deep alignment issues. I'll walk you through my exact 3-step process for finding what others miss.
  • The Truth About AI Bias: 7 Shocking Stats from Our 2026 Audit — We just completed a massive audit of 100+ production AI models, and the results on bias are staggering. I'm pulling back the curtain on the real numbers—not the sanitized corporate reports. This is what hidden bias actually looks like in the wild.
  • Nobody Talks About the Real Cost of AI Safety. Until Now. — As a Silicon Valley veteran who has built and sold two AI companies, I'm breaking the code of silence. The true cost of implementing robust AI safety isn't in the tech—it's in the human capital and culture. I'll reveal the numbers and strategies you need to know.
  • The Truth About AI Bias: 7 Shocking Stats from Our 2026 Audit — We just completed a massive audit of 100+ production AI models, and the results on bias are staggering. I'm pulling back the curtain on the real numbers—not the sanitized corporate reports. This is what hidden bias actually looks like in the wild.
  • I Wasted 5 Years on AI Ethics Frameworks. Here's What Actually Works. — I chased complex AI ethics frameworks for half a decade, getting it all wrong. I'm sharing my painful journey from buzzword-chasing to building responsible AI that ships. This is the stuff nobody tells you about the gap between theory and reality.

All AI Ethics and Regulation articles · Sahin's angel investments · Startups he founded