I was having dinner with a founder last week—a brilliant engineer with a world-changing idea for using AI in logistics. But she wasn't excited. She was terrified. She’d just paid a consultant $20,000 for a two-day workshop on the EU AI Act, and her takeaway was that her entire business was a compliance nightmare waiting to happen.
I’m going to say something that made her spit out her wine. Everyone is panicking about the EU AI Act, but they're focusing on the wrong things. The lawyers, the consultants, the so-called experts—they’re all selling fear, and founders are buying it. I’ve seen this movie before. Three times, to be exact. And I’m here to tell you that the real threat isn’t a fine from Brussels. It’s something far more insidious.
The GDPR Déjà Vu
I remember the GDPR frenzy in 2018 like it was yesterday. My inbox was a warzone of “URGENT: Are you GDPR compliant?” emails. My first thought? “Here we go again.” We were in the middle of scaling RemoteTeam, and suddenly, we had to deal with this massive, ambiguous regulation. We spent nearly $50,000 on legal advice. You know what we got for it? A 100-page document of legalese that basically said, “be careful.” It was useless.
The real work happened at the platform level. AWS, Google Cloud, Stripe, Intercom—they did the heavy lifting. They had to. Their survival depended on it. For us, the founders in the trenches, it boiled down to a few practical changes: implementing a clearer cookie consent banner, adding a data processing addendum to our terms of service, and making sure our data deletion process was solid. The world didn’t end. We didn’t get fined into oblivion.
I saw the same pattern during the dot-com bust and the mobile platform shift from web to native apps. The pundits screamed, “The sky is falling!” and the startups that listened and pivoted to consulting or enterprise services died. The ones that ignored the noise, stayed lean, and focused on building a great product survived. And thrived.
This isn’t about being reckless. It’s about understanding where the real risks lie. And they are almost never where the consultants tell you they are.
The Real Risk of the EU AI Act
Now, we have the EU AI Act. And the same panic is setting in. But here’s the unpopular opinion that could save your startup: the EU AI Act is a distraction.
Yes, you need to be aware of it. Yes, there are risk categories. If you’re building an AI to pilot a commercial aircraft or make credit-scoring decisions, you are in the “high-risk” bucket, and you have a mountain of work to do. My hat is off to you, and you absolutely need expert legal counsel. But for the 99% of us building SaaS tools, AI-powered creative apps, and everything in between, the direct compliance burden is manageable. The platforms we build on will handle the bulk of it, just like they did with GDPR.
So, what’s the real risk? It’s not the fines. It’s not the audits. It’s the chilling effect on innovation. It’s the army of self-proclaimed “ethical AI” consultants and “AI governance” platforms that are springing up to capitalize on the confusion. They are the real threat.
The Unseen Enemy: The “Ethical” Gatekeepers
This is what nobody is talking about. The real danger of the EU AI Act is that it creates a new class of gatekeepers. These are the folks who will sell you expensive certifications, complex compliance dashboards, and endless workshops. They will create a culture of fear and uncertainty, where founders are afraid to experiment and take risks.
I’ve already seen it happening. I’ve talked to at least a dozen founders in the last six months who are second-guessing their product roadmaps because they’re afraid of a potential regulatory backlash. One was building a tool to help sales teams analyze call transcripts to identify what top performers do differently. A consultant told them this could be “high-risk” because it relates to “employment” and they should pause development to conduct a six-month “algorithmic impact assessment.” This is insanity. The tool wasn’t hiring or firing anyone. It was providing analytics. But the fear was enough to derail their momentum.
This is how innovation dies. Not with a bang, but with a whimper. And a very expensive, unnecessary compliance invoice. It creates a world where only the largest companies, the Googles and Microsofts, can afford to build interesting things with AI because they have armies of lawyers to navigate the maze. That’s not the future I want to live in, and it’s not the future we should be building.
My Counterintuitive Guide to Surviving the New AI Rulebook
So, what do you do? How do you navigate this new world of AI regulation without losing your mind or your competitive edge? Here’s my advice, based on my experience with two successful exits and over 200 angel investments in companies like Anthropic, OpenAI, and Scale AI.
1. Don’t Panic. Read the Primary Source.
Seriously. Take a deep breath. The EU AI Act is not going to kill your startup. The full force of the regulation won’t even be felt for most companies until mid-2026. You have time. Before you hire a single consultant, go and read the actual text. Or at least, read the high-level summaries published by the EU itself. Don’t rely on a third-party interpretation that’s designed to scare you. You’ll be shocked at how much of it is common sense and how much of it likely doesn’t even apply to you.
2. Accurately Classify Your Risk (Yourself).
This is the most important thing you need to do. The entire Act hinges on a risk-based approach. Is your AI system high-risk, limited-risk, or minimal-risk? The answer to this question will determine your compliance obligations. You can figure this out yourself.
- Unacceptable Risk: These are things that are flat-out banned. Social scoring by governments, real-time biometric identification in public spaces (with some exceptions for law enforcement). You’re probably not building this.
- High-Risk: This is the category that gets all the attention. It includes AI used in critical infrastructure, medical devices, educational and vocational training, employment and workforce management, and access to essential services. If you are in this category, you need to take it very seriously. But be honest with yourself. Does your AI-powered pitch deck designer really fall into the “employment” category? Don’t let a consultant convince you it does.
- Limited-Risk: This is where most of us will live. It includes things like chatbots, where you need to make it clear to the user that they are interacting with an AI. It includes deepfakes, where you need to label the content as artificially generated. The obligations here are about transparency, not a massive compliance burden.
- Minimal-Risk: This is for things like AI-enabled video games or spam filters. The Act imposes no obligations here.
For most startups, you’ll fall into the limited or minimal-risk categories. The compliance requirements for these categories are much less stringent. Do your own homework.
3. Focus on Building a Great Product That People Love.
This is the most important rule of all. I cannot say this enough. Don’t let regulatory concerns distract you from what really matters: building a product that solves a real problem for your customers. If you have a great product with strong market fit, you’ll have the resources, the revenue, and the customer goodwill to deal with compliance. If you have a mediocre product, no amount of compliance will save you.
I’ve seen so many startups fail because they got bogged down in administrative and legal nonsense. They lost sight of their vision and their customers. They spent more time in meetings with lawyers than with users. Don’t be one of them.
4. Build on Platforms You Trust.
Choose your partners wisely. Build on platforms that have a strong track record of compliance and security. The big cloud providers—AWS, Azure, Google Cloud—are a good place to start. The major AI model providers like OpenAI and Anthropic are also investing heavily in this. They have teams of lawyers and engineers who are dedicated to this stuff. They will provide the compliant infrastructure and APIs because their business depends on it. Let them do the heavy lifting for you. Your job is to build a unique application on top of that foundation.
5. Be Radically Transparent with Your Users.
This is not just a legal requirement; it’s good business. In a world of black-box algorithms, transparency is a competitive advantage. Be open and honest with your users about how you’re using AI. Explain your data policies in plain English. Give them control over their data. If you build trust with your users, they’ll be more likely to stick with you, even if you make a mistake.
At RemoteTeam, we had a dashboard that showed employees exactly what data the company could see. It was a simple feature, but it built an incredible amount of trust. We didn’t do it because a regulator told us to. We did it because it was the right thing to do for our users.
A Personal Story: The Investment That Almost Didn't Happen
I want to tell you a quick story. A few years ago, a brilliant founder pitched me an idea for an AI-powered tool to help students practice for job interviews. It would simulate an interview, provide feedback on their answers, and even analyze their body language. I loved it. But one of my LPs, a very conservative, risk-averse guy, almost killed the deal. He sent me a long email full of links to articles about AI bias and the potential for discriminatory outcomes. He said it was “too risky” and that we’d be facing lawsuits and regulatory heat from day one.
I listened to his concerns. I even agreed with some of them. But then I talked to the founder again. I asked him about his plan for mitigating bias. He didn’t give me a canned, corporate answer. He told me about the diverse datasets he was using to train his models. He told me about the team of linguists and sociologists he was working with to audit his algorithms. He showed me the transparency features he was building into the product to explain to users exactly how the AI was making its assessments.
He wasn’t just trying to be compliant. He was obsessed with building a fair and effective product. He saw fairness not as a legal hurdle, but as a core product feature. I overruled my LP and made the investment. That company is now one of the top performers in my portfolio. They’re helping thousands of students from all backgrounds land their dream jobs. And they haven’t had a single regulatory issue.
The Bottom Line
Look, regulation is a part of doing business. It’s a sign that our industry is maturing. But don’t let the AI regulation hype train derail your startup. The real risk isn’t the regulation itself, but the ecosystem of fear and complexity that’s growing around it. The greatest trick the devil ever pulled was convincing the world he didn’t exist. The greatest trick the compliance-industrial complex is pulling is convincing you that you can’t innovate without their blessing.
Stay focused. Do your own homework. Talk to your customers. And for the love of God, build something amazing. The rest will follow.
Frequently Asked Questions
Do all experts agree with this view?
No, and that's fine. The best ideas in business are often contrarian. I share my perspective based on my experience and data, but I encourage you to seek out opposing viewpoints and form your own conclusions.
What experience informs this perspective?
This perspective comes from over a decade of building companies in Silicon Valley, two successful exits (RemoteTeam to Gusto, MovieLaLa to Gfycat), and investing in 200+ startups including Anthropic, OpenAI, and Scale AI. I write about what I've lived.
How can I apply this thinking to my own situation?
Start by identifying the core principle behind the opinion, not the specific example. Then ask yourself: does this principle apply to my context? If yes, test it in a small, low-risk way before going all in.
How has this view evolved over time?
My thinking on most topics has changed significantly over the years. Early in my career, I held many conventional views that experience proved wrong. I try to update my beliefs when the evidence changes.