Talk to us
Whether you're buying, selling, partnering, or investing, pick what fits and our team will get back to you within one business day.
A real human, fast
Someone on our team replies within one business day, no bots, no ticket queue.
Routed to the right team
Buying, selling, partnering, or investing, you reach the people who can actually help.
Independent & unbiased
No pushy sales. Just honest guidance grounded in the ecosystem.
Tailored to your context
Tell us what you need and we shape the next steps around it.
Who are you? Pick the option that fits best.
AI regulation stopped being theoretical in 2026. Here’s what the EU AI Act actually requires, who it hits, the fines, and the governance moves every founder and buyer should make now.
The short version: AI regulation stopped being hypothetical in 2026. The EU AI Act is now in force and enforceable, with penalties up to €35 million or 7% of global turnover for the most serious breaches. It uses a risk-based model, a few banned uses, strict rules for “high-risk” systems, transparency for chatbots and AI-generated content, and light-touch treatment for everything else. It reaches any company whose AI touches people in the EU, wherever you are based. You do not need a legal department to respond: inventory your AI, rank it by risk, put a human owner and oversight on the consequential systems, and make AI due diligence part of how you buy software.
For a few years, “AI governance” sounded like a problem for someone else, a compliance team at a bank, maybe, or a policy think tank. That era is over. In 2026 the rules have teeth, the deadlines are real, and the fines are large enough to matter to a Series A startup as much as a multinational. The good news: getting to a defensible position is more about basic hygiene than heroic legal work. This is the practical version, for founders and buyers who need to act, not just worry.
Three things converged. Regulation arrived, led by the EU AI Act but far from alone. AI moved from experiments to production, so the systems now make real decisions about real people. And shadow AI means employees are already feeding company data into tools no one approved. Governance is simply the discipline of knowing what AI you run, what it can do, and who is accountable when it goes wrong. The regulation just made that discipline non-optional.
The EU AI Act is the first comprehensive AI law, and it regulates by risk tier rather than by technology. That framing is the fastest way to understand your obligations.
The Act phases in, and the timeline shifted in 2026, so it is worth being precise:
Penalties are deliberately GDPR-sized. Breaching the ban on prohibited practices or other core obligations can cost up to €35 million or 7% of global annual turnover, whichever is higher (Article 99). For GPAI providers, fines run up to €15 million or 3% of turnover (Article 101). The percentage-of-turnover design means the exposure grows with the company, a structure any founder who lived through GDPR will recognize.
The Act has extraterritorial reach. It applies to any provider or deployer whose AI systems are placed on the EU market, or whose output is used in the EU, even if your company sits in San Francisco or Bengaluru. If EU users touch your AI feature, you are in scope.
And the EU is not the only rulemaker. The picture in 2026 is a global patchwork: the US NIST AI Risk Management Framework and a wave of US state laws, India’s Digital Personal Data Protection (DPDP) Act, and the international ISO/IEC 42001 standard for AI management systems. The practical upshot is that a single, sensible governance posture, built once, satisfies most of them, which is far cheaper than reacting to each law separately.
If your product includes AI features, treat governance as part of engineering, not an afterthought.
Buyers inherit their vendors’ risk. When an AI tool mishandles data or makes a biased decision, “our vendor did it” is not a defense. Make AI due diligence a standard part of procurement, and of every renewal, the same moment you should already be scrutinizing cost and terms.
You do not need a 40-page policy to start. You need five moves, in order.
Lean on existing frameworks so you are not inventing this from scratch: the NIST AI Risk Management Framework gives you a vocabulary and structure, and ISO/IEC 42001 offers a certifiable AI management system. Security controls you may already run, from prompt-injection defenses to non-human identity management, are part of the same governance story.
AI regulation is genuinely in motion, so it pays to separate settled law from commentary. What is confirmed: the EU AI Act is in force; prohibited-practice, GPAI, and transparency obligations are live; and the fine ceilings are set. What changed in 2026: the “Digital Omnibus”, adopted as an amending EU regulation and published in the Official Journal in July 2026, pushed the high-risk obligations back to December 2027 and August 2028. That delay is real and binding, but it applies only to the high-risk tiers; the bans, GPAI rules, and transparency duties are unaffected. Treat the extra time as runway to prepare, not as a reason to ignore the law, deadlines like this have a way of arriving faster than they look. (This reflects the state of the rules as of late 2026; confirm specifics against official sources before making legal decisions.)
Governance gets easier when your tools are built for it. Explore vetted GRC, audit management, data privacy, and cybersecurity software on Saaskart, evaluate AI agents with governance in mind, or search for a specific capability. And keep reading The 1% Stack for the rest of the AI playbook, including why most corporate AI pilots fail.
The EU AI Act is the world’s first comprehensive law regulating artificial intelligence. It entered into force on 1 August 2024 and takes a risk-based approach: it bans a small set of “unacceptable-risk” uses, imposes strict obligations on “high-risk” systems, requires transparency for “limited-risk” uses like chatbots and AI-generated content, and leaves most everyday AI largely untouched. It applies to providers and deployers of AI systems that affect people in the EU, regardless of where the company is based.
It phases in. The ban on prohibited practices applied from 2 February 2025, along with an AI-literacy duty for staff. Obligations for general-purpose AI (GPAI) models applied from 2 August 2025, and enforcement and fines for GPAI became applicable on 2 August 2026, alongside Article 50 transparency duties. The heaviest high-risk obligations were pushed back by the “Digital Omnibus” to 2 December 2027 for Annex III systems and 2 August 2028 for product-embedded (Annex I) systems.
They are among the steepest in tech regulation. Breaching the ban on prohibited AI practices, or other core obligations under Article 99, can cost up to €35 million or 7% of global annual turnover, whichever is higher. For general-purpose AI providers, Article 101 sets fines of up to €15 million or 3% of global turnover. As with GDPR, the percentage-of-turnover structure means the risk scales with company size.
Yes. Like GDPR, it has extraterritorial reach: it applies to any provider or deployer whose AI systems are placed on the EU market or whose output is used in the EU, even if the company sits in the US, India, or anywhere else. Combined with a growing patchwork of other rules, the US NIST AI Risk Management Framework, US state laws, India’s DPDP Act, and the ISO/IEC 42001 AI management standard, most global software companies now need an AI governance posture regardless of headquarters.
Start with an inventory: list every AI system you build or use, including the shadow tools employees adopted on their own. Then risk-tier each one, assign a human owner, document what data it uses and what decisions it influences, add human oversight to anything consequential, and set basic monitoring. Frameworks like the NIST AI Risk Management Framework and ISO/IEC 42001 give you a ready-made structure so you are not inventing governance from scratch.
Buyers inherit their vendors’ AI risk. Before you deploy an AI feature or tool, ask vendors how their models are trained, what data they retain, how they handle transparency and human oversight, and how they will support your own compliance. Bake these questions into procurement and renewals so AI due diligence becomes routine rather than a fire drill, the same discipline that protects you on cost and lock-in also protects you on compliance.
Tags
The 1% Stack
Saaskart's media & intelligence series for software buyers, founders, and operators — opinionated takes on SaaS, AI agents, and the stacks that separate the 1% from everyone else.
Explore thousands of vetted tools, AI agents, and service providers on Saaskart, compare features, pricing, and real buyer reviews in one place.