
VP Sales: "Just closed a 100-seat deal with a German law firm. Contract signed, pending compliance review."
You (PM): "Great! What compliance?"
VP Sales: "EU AI Act. Legal says we need to classify our AI features as 'high-risk' or 'limited-risk' and provide conformity documentation by August 2026. Can we do that?"
You: Googles "EU AI Act". Finds 144-page regulation. Panics.
If your product touches EU users, EU data, or EU customers—you're in scope. The EU AI Act isn't GDPR 2.0 (where you could mostly ignore it if you're US-based). This one has teeth, and the deadlines start in 2026.
The EU AI Act classifies AI systems into four tiers:
The EU AI Act classifies AI systems into four tiers:
PM Takeaway: If you're building consumer SaaS, you're probably fine. If you're building govtech or public safety tools, consult EU legal immediately.
Obligations:
PM Takeaway: If your AI makes hiring recommendations, grades students, or supports medical decisions—you're high-risk. Budget 3-6 months for compliance before selling in EU.
Obligations:
PM Takeaway: If you built a GPT-powered chatbot, add a disclaimer: "This is an AI assistant." That's 80% of compliance.
PM Takeaway: Most consumer SaaS features fall here. No EU AI Act obligations beyond general GDPR compliance.

| Date | Requirement |
|---|---|
| Feb 2, 2025 | Banned AI systems (Unacceptable Risk) must be removed |
| Aug 2, 2026 | High-Risk AI systems must comply (documentation, audits, testing) |
| Aug 2, 2027 | All AI systems must comply (including Limited Risk transparency rules) |
Critical Insight: If you're selling to EU healthcare, legal, or HR customers—you have until August 2026 to build compliance artifacts. That's 16 months from now (as of April 2025).
Legal wants artifacts. Here's the list:
PM Deliverable: Risk register (NIST-style) + quarterly evaluation reports
PM Deliverable: Data card (sources, dates, sampling method, bias testing results)
PM Deliverable: Model card + system architecture diagram + human-in-the-loop workflow
PM Deliverable: Human oversight plan (who reviews, when, how to override)
PM Deliverable: Internal audit report OR third-party conformity certificate
Product: AI analyzes resumes, ranks candidates for recruiters.
EU AI Act Classification: High-Risk (employment/HR decision-making)
Risk Management:
Data Governance:
Technical Documentation:
Human Oversight Plan:
Conformity Assessment:
Timeline: 4 months from "we need to comply" to "artifacts ready for EU sales."

*You Might Think**: "We're a US company. We don't have EU customers. We're safe."
You Might Think: "We're a US company. We don't have EU customers. We're safe."
You're In Scope If:
GDPR Lesson: Many US companies ignored GDPR until EU customers demanded compliance. Then they scrambled to retrofit data processing agreements, privacy policies, and consent flows.
Don't repeat the mistake with EU AI Act.
Does your AI system operate in the EU or process EU data? ├─ NO → You're out of scope (for now) └─ YES → Continue Is your AI system banned? (social scoring, mass surveillance, exploiting vulnerabilities) ├─ YES → Stop. Redesign or exit EU market. └─ NO → Continue Is your AI system high-risk? (healthcare, HR, law enforcement, education, credit scoring) ├─ YES → Full compliance required by Aug 2026 │ - Risk management system │ - Data governance + bias testing │ - Technical documentation │ - Human oversight plan │ - Conformity assessment (self or third-party) └─ NO → Continue Is your AI system limited-risk? (chatbot, deepfake, AI-generated content) ├─ YES → Transparency required by Aug 2027 │ - Disclose "This is AI" │ - Label AI-generated media └─ NO → Minimal risk. GDPR applies; EU AI Act does not.Click to examine closely
While competitors scramble in 2026, you can win EU deals now by being compliance-ready early.
EU healthcare systems, law firms, and enterprises are already asking for EU AI Act alignment in RFPs. If you have the artifacts ready, you differentiate from vendors who say "we'll be compliant eventually."
Compliance isn't a cost center. It's a sales enabler.
Alex Welcing is a Senior AI Product Manager who treats EU AI Act compliance like a product requirement, not an afterthought. His features ship with conformity documentation before the regulatory deadline.