← Back to blog

You Called an LLM. Congratulations, You're Now Inside the EU AI Act.

The moment you deployed an AI system that interacts with users or influences decisions, you entered the scope of the EU AI Act. Not when you read about it. Not when your lawyer flags it. The moment you shipped.

Most founders we talk to don't know this yet. And honestly, we're still figuring out the full picture ourselves. But here's what we do know: the risk tier framework is the thing you need to understand first, and it's not as complicated as the compliance industry wants you to think it is.

The Four Tiers, Quickly

The EU AI Act sorts AI applications into four risk categories. Here they are, conclusion first.

- Unacceptable risk: banned outright. Think social scoring systems, real-time biometric surveillance in public spaces, AI that exploits psychological vulnerabilities. If you're building one of these, you have larger problems than compliance.

- High risk: the tier that will bite most serious AI founders. This covers AI used in hiring, credit scoring, medical devices, critical infrastructure, education, law enforcement, and border control. If your product influences a consequential decision about a person, you are likely here.

- Limited risk: systems that interact with users but don't make high-stakes decisions. Chatbots, AI-generated content, deepfake tools. The main obligation here is transparency: users need to know they're talking to an AI.

- Minimal risk: everything else. Spam filters, recommendation engines, most AI features baked into consumer software. Obligations are light or effectively zero.

Four tiers. That's the map. The question is where your product sits on it.

Why "We Just Call an API" Is Not a Defense

Here is the assumption we hear constantly: "We're not building AI, we're just using it." A founder integrates GPT-4 or Claude into their product, routes user queries through it, surfaces the output, and considers themselves a software company that happens to use an AI tool.

That is not how the EU AI Act reads it.

If your product deploys an AI system, meaning it uses AI to interact with users or influence outcomes, you are a provider under the Act. The fact that the model lives on someone else's infrastructure is irrelevant to your obligations. You built the thing that users touch. That makes it yours to answer for.

This matters practically. A founder building an AI-powered hiring tool is not off the hook because OpenAI trained the model. The hiring tool sits in high risk. The obligations, documentation requirements, and eventual audit trail belong to the person who deployed it.

How to Start Figuring Out Where You Land

We're not going to pretend this is a fully solved problem. We're navigating it in real time alongside the founders we work with. But the starting point is straightforward enough.

Start by asking three questions about your product.

1. Who does the AI interact with, and in what context? If it's helping a user draft a marketing email, that's different from helping a hiring manager evaluate a candidate. The stakes of the interaction are the first signal.

2. Does the output influence a decision that affects someone's life in a meaningful way? Employment, credit, health, education, access to services. If the answer is yes, you are almost certainly in high risk territory and need to treat it that way.

3. Do users know they're interacting with an AI? If you have a chatbot, a virtual assistant, or any AI-generated content that a user might reasonably mistake for human output, transparency obligations under limited risk apply at minimum.

Those three questions won't give you a legal opinion. They will give you a working hypothesis about your tier, which is enough to decide what to build toward.

What Coming Into Compliance Actually Looks Like

This is the part we're still working through ourselves, and we'd rather say that plainly than oversell it.

The ISO 42001 standard is the natural anchor for AI-specific compliance right now. It's a management system standard for AI, and it maps reasonably well onto what the EU AI Act expects from high-risk providers in terms of documentation, risk assessment, and governance. Whether certification against ISO 42001 becomes the accepted proof of compliance under the Act is still being worked out at a regulatory level.

What we're building toward at Sinope is a path where a founder can demonstrate, credibly and verifiably, that they have met the relevant requirements for their risk tier. That means the audit trail exists, the documentation is current, and the certification is real, not a checkbox filled in the week before a deadline.

We don't have every step of that path mapped yet. But we know the starting point: understand your tier, build toward the obligations it creates, and don't wait until a regulator asks.

Start Now, Not When It's Urgent

Nobody in Iceland is really talking about this yet. We've said it before and it's still true. But the EU AI Act is not a future problem. It's a present one with a phased enforcement timeline, and by the time it feels urgent, the founders who started early will already have the evidence base that takes months to build.

You called an LLM. That was the moment you entered this landscape. The good news is that understanding your risk tier is a morning's work, not a six-month audit. Start there.