
The AI Act for Start-Ups: Clear Rules Instead of AI Chaos

AI has long been a part of everyday life in start-ups. For example, ChatGPT can write marketing copy, Copilot can support development, and AI can answer customer inquiries. The EU AI Act provides a binding legal framework. In this article, we outline the most important practical requirements and explain how you can organize your use of AI effectively.
This is not limited to start-ups developing their own AI. Even if you integrate existing systems into products or use tools such as ChatGPT and Claude in your day-to-day work, it is important to check which regulations apply. The key factor is how you use the technology and for what purpose.
| Situation at the start-up | Possible role | Key points to check under the AI Act |
|---|---|---|
| Using ChatGPT or Claude for day-to-day work | Operator of an AI system | Promoting AI expertise; further obligations depend on the specific application |
| Integrating a third-party AI into your own software as a service (SaaS) product | Operator or provider, depending on the structure and marketing | Check whether your start-up is itself regarded as a supplier and which obligations apply within the supply chain |
| Development and marketing of your own AI system | Provider | Clarify the risk category, as well as the associated testing, information and documentation obligations |
| Use of AI for shortlisting applications | Operator of a potentially high-risk system | Check whether the system is classified as high-risk AI and, if so, what additional obligations apply |
However, your classification under the AI Act is not set in stone. For example, if an internal AI tool becomes a feature of your own product, you should reassess its classification. This is because changes in its use may trigger additional obligations.
The AI Act is being implemented in stages. Regulations on AI competence and most bans on certain AI practices are already in force. Transparency requirements, among other things, have been in force since 2 August 2026. The comprehensive requirements for certain high-risk systems will apply from December 2027 and August 2028, respectively.
Which regulations should start-ups be aware of?
We have explained how you can determine your start-up's obligations under the AI Act. However, not all start-ups face the same obligations. Nevertheless, there are four areas of the regulation that you should bear in mind.
1. Encourage your team to develop AI skills
Anyone using AI in their organization should understand its capabilities and limitations. The AI Act requires providers and operators to promote AI literacy among their staff and among other individuals working with AI systems on their behalf. The appropriate measures depend on how the systems are used and the risks they pose.
This does not necessarily entail a comprehensive training program. However, your staff should be aware of:
- which results they need to check,
- what information they are permitted to enter into a system,
- what typical errors may occur, and
- when not to use an AI tool.
This can be achieved through short training sessions, clear guidelines, and specific instructions for individual tools.
2. Check that the planned use is legal
Just because something is technically possible does not mean it is permitted under the AI Act. Some AI practices are prohibited in principle. These include harmful, manipulative or deceptive applications, as well as certain forms of social scoring. Apart from a very limited number of exceptions, emotion recognition in the workplace is also not permitted.
Therefore, you should assess the intended use of a tool or new feature before introducing it. This is especially important when AI evaluates people, monitors employees, or influences decisions about individuals.
3. Create transparency
Is the person speaking in this video really human? Is the person in the chat real or an AI system? Artificial intelligence has brought reality and fiction closer together than ever before.
However, people must be able to recognize when they are interacting with an AI system or viewing artificially generated or manipulated content. This applies to many chatbots and deepfakes, for example. As a matter of principle, providers of generative systems must also ensure that artificially generated content is identifiable.
However, this does not imply a blanket labeling requirement for every piece of text, image or code related to AI. The decisive factor is the specific use case.
4. Check high-risk systems particularly carefully
Significantly stricter requirements apply to high-risk systems. Operators must use these systems in accordance with the provider's instructions, monitor their operation, and ensure that suitable individuals are responsible for human oversight. Operators must also retain certain automatically generated logs.
This may be relevant when using AI in recruitment, for example. This applies when a system analyses applications, assesses candidates, or carries out a pre-selection process. Whether an application is considered high-risk depends on its intended function and purpose.
Beyond the AI Act: 5 tips for the safe use of AI
The AI Act alone is insufficient. Compliance is one thing, but most AI implementations fail for practical, not legal, reasons. Data protection, trade secrets, copyright, and contractual obligations also shape how you use AI. On top of that, there are some very practical questions: How reliable are the results? What tools does your team use? Who is responsible? Bear these five points in mind.
1. Check the AI results before using them
The text may sound convincing, and the code may look neat. However, AI can make mistakes, such as presenting false facts, drawing incorrect conclusions, or citing fabricated sources.
Therefore, AI should be used as a support tool, but not to make the final decision. Ultimately, responsibility must lie with a human being.
2. Protect personal and confidential data
The AI Act does not replace the GDPR or contractual confidentiality obligations. You should therefore carefully check what information your team is entering into external AI tools.
Do not enter personal data, confidential customer information, or trade secrets unless you have clarified their use legally and contractually.
You should also find out how the relevant provider processes the data entered and how it is used.
3. Clarify copyright and usage rights
In the case of AI-generated text, images, videos, or code, it is not always obvious what rights you have over them. Therefore, before using them for commercial purposes, check the terms and conditions of the relevant tool to ensure you are not infringing any third-party rights.
This is especially important if you pass the results on to your customers. Only grant rights of use that you yourself hold.
4. Keep track of things and establish clear rules
New AI tools are being rolled out quickly. While the project management team is testing a meeting tool, the support team is using a chatbot, and the finance department is experimenting with automated analysis. However, without clear rules, each team will soon develop its own routines.
You should therefore document which tools are in use, how they are used, and who is responsible for them. You should also specify which applications are permitted and who decides on new tools. An internal AI policy, kept as lightweight as a mini-SOP, will provide guidance and ensure that all staff work to the same standards.
5. Don't forget to sort out your insurance coverage
Even with clear rules and thorough checks, you can't achieve 100 percent certainty when using AI. For example, your team might inadvertently incorporate faulty AI code into a client project, an automatically generated report might contain incorrect information, or generated content might infringe third-party rights. If this results in financial loss for your clients, they may claim compensation.
Therefore, AI use is a good opportunity to review your insurance coverage. Above all, ensure that the activities you carry out in your professional capacity are covered by your insurance policy. This is particularly important if AI plays a significant role in your business model.
For example, a start-up that uses ChatGPT for internal documents faces different risks than a company that integrates AI into its own software-as-a-service (SaaS) product or develops AI applications itself.
Keep a close eye on your risk management, just as you do on your processes. If your business model changes, reassess the associated risks. This means risk management should be an integral part of your AI strategy from the outset, not an afterthought.
From AI experiment to reliable implementation
New AI tools can be tested quickly. The real challenge begins when they become integral to the business. That is when a systematic implementation approach matters. The AI Act sets out guidelines for this, making it clear that anyone using AI professionally must consider responsibility from the outset.




