Why I Spent Three Months Reading the EU AI Act
As a founder and owner of multiple digital agencies since 2005, I’ve been in charge of building websites and applications for everyone from government agencies and large non-profits to SMEs and mum-and-dad businesses across the world. I’ve got clients in Australia, the UK, the US, and Europe.
Part of the work over the past 20 years has involved helping organisations navigate GDPR, WCAG accessibility, privacy legislation and the various other regulatory frameworks that arrive periodically and cause a collective headache across the industry.
I thought I understood the pattern. Regulation arrives, creates anxiety, turns out to be manageable with the right guidance, move on. When the EU AI Act came into force in August 2024, my assumption was the same, until I started reading it.
What shocked me
With clients serving customers in the EU, I dived into the legislation and was truly shocked by the compliance burden and sheer scope of work. Technical documentation. A continuous risk management system. Human oversight built into the system design. Staff training. A conformity assessment before you can place the product on the EU market. Post-market monitoring that doesn’t stop after launch. All requiring documentation, governance programmes and additional processes to be built into the systems. All enforced by some of the biggest penalties of any previous legislation. €35 million or 7% of global annual turnover.
The second thing was the provider question.
Most founders don’t know they’re the provider
Every conversation with my clients started the same way: “That’s an EU problem” or “we’re just using OpenAI’s API — it’s their responsibility.”
Unfortunately, that’s not how the Act works.
Article 3(3) defines a provider as anyone who develops an AI system and places it on the market under their own name or trademark. The key word is system. Recital 97 is explicit that a raw AI model “does not constitute an AI system on its own” and requires “the addition of further components, such as for example a user interface, to become an AI system.”
If you call the OpenAI or Claude API, wrap it in your product, and ship it to users, then you have created an AI system. You are its provider.
The extraterritorial scope makes this legislation hit worldwide. The act applies to providers who place AI systems on the EU market regardless of where those providers are incorporated. If you have EU users and your product uses AI, the Act applies to you. And you need to appoint an EU representative as a point of contact in the EU. The representative has to understand your system and have real legal authority over your compliance.
Most people’s first reaction is: “Is the EU really going to enforce this against a small overseas startup?” The same question was asked about GDPR. EU authorities have since issued €4.68 billion in fines to US companies alone. That’s 83% of all GDPR fines issued since 2018. The AI Act uses the same model.
Three months inside 144 pages
I worked through the full regulation. I studied the articles, the recitals, the annexes. I mapped provider obligations against deployer obligations, and separated what applies to all AI systems from what’s specific to high-risk.
It took months. The regulation is 144 pages of dense legislative text where single provisions only make sense when read alongside various others. I took notes throughout and prepared a checklist of what a provider actually needs to do, at each phase, in plain English, tied to the specific article that requires it.
What I built
I wanted to build a product for the broader market to simplify and streamline compliance with the EU AI Act. The amount of documentation and re-engineering that this Act requires from an organisation can’t be done through a SaaS app.
The notes that I initially put together for work on my own client’s apps became ComplyDrive — a 47-point compliance checklist across five phases, with every item tied to a specific article in the regulation. Alongside the checklist, 9 sample compliance documents written for a fictional organisation:
- a Declaration of Conformity,
- Fundamental Rights Impact Assessment,
- Risk Management File,
- Technical Documentation,
- Data Governance Policy,
- Instructions for Use,
- Post-Market Monitoring Plan,
- Serious Incident Report,
- and AI System Register.
The checklist is designed for product managers, CTOs, and founders. People who need to understand what the regulation actually requires without wading through 144 pages themselves. It uses as little jargon and lawyer talk as possible.
2 December 2027 is when the full high-risk regime comes into force (the Omnibus moved it back from August 2026). The documentation for a high-risk system takes months to prepare. If you’re a provider of a high-risk AI system and you haven’t started, the extra runway is the only reason you’re not already behind.
I built ComplyDrive because something practical needed to exist. Compliance consultants charge thousands for this work. A practical, accurate, affordable checklist with a one-off pricing model seemed like the right thing to make.
For business enquiries or consultation, head over to Joomstore.
John Pitchers is the founder of ComplyDrive and has been building web applications for government and enterprise clients since 2005. He also runs Viperfish Media and Joomstore.
John holds editorial responsibility for all ComplyDrive content.
The 47-item checklist, an editable tracker, nine sample documents and nine fill-in templates.
Get the Toolkit