The implementation of the EU AI Act obliges Ukrainian companies operating in the European market to rethink their approaches to the development and deployment of artificial intelligence systems. This legislative act, which is coming into force in stages, establishes a comprehensive framework for AI regulation, categorizing systems by risk level. For Ukrainian SaaS companies, whose solutions are often geared toward export to the EU, understanding and adapting to these new rules is not just a matter of compliance, but a critical condition for maintaining competitiveness and access to key markets. Ignoring these changes can lead to significant legal risks, financial penalties, and reputational damage. That is why Software Ukraine is breaking down what this means for domestic developers and how to effectively prepare for these new realities.
EU AI Act: risk classification for Ukrainian developers
The EU AI Act introduces a clear four-level classification of AI systems based on the level of risk they pose. This allows for the differentiation of regulatory requirements according to the potential harm to fundamental rights and safety of citizens. These categories include: minimal risk, limited risk, high risk, and unacceptable risk. Understanding which category their product belongs to is the first and most important step for Ukrainian developers.
The criteria for defining high risk are quite broad and cover a number of sensitive areas. High-risk systems include those used in critical infrastructure, education (especially for knowledge assessment), human resources management (e.g., for candidate selection), law enforcement, as well as in the field of migration and border control. This category also includes systems that affect access to essential private and public services.
Examples of SaaS solutions that may fall into the high-risk category include HR tools for automated resume screening, credit scoring systems, medical diagnostic systems that assist doctors in decision-making, or tools for risk assessment in the judicial system. For Ukrainian developers creating such solutions for European clients, accurate self-assessment of risks is critical, as the scope of necessary regulatory measures depends on it.
Accurate identification of the risk category allows companies to plan ahead for appropriate changes in development, testing, and implementation processes. This helps to avoid unexpected obstacles when entering the EU market and ensures the smooth operation of their products in accordance with European standards.
Requirements for high-risk AI systems: what will change for Ukrainian companies
For high-risk AI systems, the EU AI Act sets a number of strict requirements that significantly change the landscape of development and operation. Ukrainian SaaS companies will need to implement comprehensive risk and data quality management systems. This includes developing and documenting internal processes that ensure the high quality of datasets used for training and testing AI, as well as continuous monitoring for potential biases.
Special attention is paid to transparency and information accessibility. Developers will be required to maintain detailed technical documentation describing the system's operation, its goals, and capabilities. Event logging also becomes mandatory to ensure traceability and the ability to audit AI decisions. An important aspect is also ensuring human oversight, which means that AI systems should not operate completely autonomously in critical situations, and a human must have the ability to intervene and correct or stop their action.
Requirements for cybersecurity and system resilience against external influences, including attempts at manipulation or cyberattacks, are also being strengthened. Systems must be designed to ensure a high level of reliability, accuracy, and security throughout their entire lifecycle. This requires Ukrainian companies to invest in strengthening their infrastructure and software solutions.
Before entering the EU market, high-risk AI systems must undergo a conformity assessment. This procedure confirms that the system meets all the requirements of the Act. Failure to comply with these requirements can lead to significant sanctions, including financial penalties that can reach substantial amounts, as well as serious reputational damage, which can permanently close access to the European market. That is why preparation for the EU AI Act should be a priority for Ukrainian companies.
Adaptation of Ukrainian SaaS solutions: timelines and implementation strategies
The schedule for the entry into force of the EU AI Act is gradual, which gives Ukrainian companies some time to adapt but requires immediate action. Prohibited systems that pose an unacceptable risk must be removed from circulation as soon as possible. High-risk systems will have up to two years to fully comply after the Act officially enters into force, while general transparency requirements and other provisions also have their own deadlines. This phased approach allows companies to distribute the workload but does not delay the need for strategic planning.
The first step for any Ukrainian company is to conduct an audit of current AI solutions. This audit should identify all systems that use artificial intelligence, determine their risk category according to the EU AI Act, and assess the current level of compliance. Based on the audit results, a roadmap with specific steps and timelines for achieving full compliance must be drawn up. This may include reviewing system architecture, updating algorithms, or changing approaches to data collection and processing.
To ensure compliance, the implementation of internal policies and procedures is critical. This means developing standards for the AI development lifecycle, including requirements for data quality, testing, documentation, and monitoring. Companies should consider creating a separate function or appointing a person responsible for EU AI Act compliance who will coordinate all efforts and ensure ongoing compliance.
Collaboration with legal consultants and compliance experts specializing in European legislation is an integral part of the adaptation process. They can provide valuable expertise on interpreting complex provisions of the Act and help develop effective strategies. In addition, Ukrainian developers can consider using so-called regulatory sandboxes in the EU, which allow testing innovative AI solutions in a controlled environment under the supervision of regulators, receiving feedback and recommendations.
How can Ukrainian companies prepare for the EU AI Act?
Preparation for the EU AI Act requires a comprehensive approach and strategic planning. The first and most important step is to conduct a detailed internal audit of all products that use artificial intelligence. This will allow for a clear determination of their risk category – from minimal to unacceptable – and an assessment of current gaps in compliance with the requirements of the new legislation. This audit should cover both technological aspects and data management processes.
Investing in data management and quality systems is a fundamental element of preparation. The Act sets strict requirements for the quality, representativeness, and impartiality of data used for training and testing AI systems. Ukrainian companies need to develop and implement robust mechanisms for collecting, storing, processing, and verifying data, ensuring their compliance with European standards. This also applies to the protection of personal data in accordance with GDPR.
Training development teams, product managers, and other stakeholders on the new requirements of the EU AI Act is critical. Every team member involved in the development, implementation, or operation of AI systems must understand their role in ensuring compliance. Conducting internal training, seminars, and workshops will help raise awareness and build a culture of responsible AI development. This will allow for the integration of the Act's requirements directly into daily workflows.
Building an "AI by design" strategy, which involves integrating regulatory norms at all stages of the product lifecycle, is the most effective approach. Instead of trying to "bolt on" compliance at the final stages, companies should consider the requirements of the EU AI Act from the very beginning of designing their AI solutions. This includes design with transparency, explainability, resilience, and the possibility of human oversight in mind. Such an approach significantly reduces risks and costs for future adaptation.
Considering certification opportunities and partnerships with European organizations can also be beneficial. Certification from recognized European bodies can serve as confirmation of compliance and increase customer trust. Partnerships with European companies or research institutions can provide access to the expertise and resources needed to effectively navigate the new regulatory landscape. Ukrainian companies that proactively respond to these changes will be able to not only avoid penalties but also strengthen their positions in the international market as reliable and responsible developers of AI solutions.
Preparation for the EU AI Act for Ukrainian companies targeting the EU market is a multifaceted task that requires strategic vision, investment in processes and technology, and a deep understanding of new regulatory requirements. Proactive adaptation will allow not only to avoid potential risks and sanctions but also to turn challenges into opportunities, strengthening the trust of European partners and clients, ensuring long-term competitiveness, and opening new horizons for innovation in an environment of transparency and responsibility.
Часті запитання
What is the EU AI Act?
The EU AI Act is the world's first comprehensive law on artificial intelligence, which establishes uniform rules for the development, deployment, and use of AI systems in the European Union market. Its main goal is to ensure safety and compliance with fundamental rights while fostering innovation.
How does the EU AI Act affect Ukrainian companies that are not EU residents?
The law has extraterritorial reach. If a Ukrainian company develops or offers AI systems that are used in the EU market, or if its output data is collected in the EU, it falls under the scope of this regulation. This applies to both developers and providers.
When will the EU AI Act fully enter into force?
The law comes into force in stages. Some provisions regarding prohibited systems will take effect earlier, while the main requirements for high-risk systems and general provisions will have a longer transition period. The full implementation schedule will last for several years after official publication.
What penalties are provided for non-compliance with the EU AI Act?
Depending on the severity of the violation, penalties can be significant. They are set as fixed amounts or percentages of the company's annual global turnover, with the highest penalties provided for violations of prohibited AI practices or failure to comply with requirements for high-risk systems.
Are there preferences for small and medium-sized Ukrainian enterprises?
The Act provides for certain measures to support SMEs, such as simplified conformity assessment procedures and access to regulatory sandboxes. However, basic safety and transparency requirements remain mandatory for everyone working with high-risk AI in the EU market.