Expert View 8 min read

How the EU AI Act impacts Ukrainian SaaS companies

With the EU AI Act coming into force, European legislation sets new standards for the development and use of artificial intelligence systems, which has a direct impact on Ukrainian companies aiming to export their SaaS solutions to the European Union.

With the entry into force of the EU AI Act, European legislation is setting new standards for the development and use of artificial intelligence systems, which has a direct impact on Ukrainian companies aiming to export their SaaS solutions to the European Union. This regulatory act is the first of its kind to be based on a risk-based approach, classifying AI systems according to the degree of potential harm to human rights and safety. For Ukrainian software developers who are actively integrating artificial intelligence into their products, understanding and adapting to these requirements is not just a matter of compliance, but a critical condition for maintaining competitiveness and access to one of the world's largest markets. Ignoring these changes could lead to significant fines, product blocking, and reputational damage. The Ukrainian IT sector, known for its innovation, now faces the task of incorporating these standards into its development processes and business models.

EU AI Act risk classification: what does it mean for Ukrainian companies?

The EU AI Act introduces a clear classification system for artificial intelligence systems across four risk categories: unacceptable, high, limited, and minimal. Each category entails a different level of regulatory oversight and obligations for developers. For example, systems with unacceptable risk, such as social scoring systems or manipulative AI tools that exploit human vulnerabilities, will be completely banned in the EU. This is a direct signal to Ukrainian developers to avoid creating such solutions if they intend to work with European clients.

High-risk systems are of the greatest interest to Ukrainian SaaS companies, as they cover a wide range of applications, from biometric identification and critical infrastructure management to systems used in education, employment, or credit scoring. These systems will require strict adherence to requirements, including conformity assessment before entering the market. In contrast, limited-risk systems, such as chatbots or deepfake systems, only require transparency so that users know they are interacting with artificial intelligence. Minimal-risk systems, such as spam filters or recommendation engines, are subject to the least regulation, although voluntary adherence to codes of conduct is encouraged.

For Ukrainian developers, it is critical to conduct a thorough self-assessment of their AI solutions to correctly determine their risk category. This will allow for advance planning of necessary changes in architecture, development processes, and documentation. Incorrect assessment can lead to significant delays in entering the EU market or even a complete product block. More than 60% of companies already working with AI in the EU note that the risk classification process is one of the most difficult stages of adapting to the new act.

Requirements for high-risk AI: focus on Ukrainian SaaS solutions

Artificial intelligence systems classified as high-risk are subject to the strictest requirements of the EU AI Act, which means significant challenges for Ukrainian SaaS companies. These requirements cover eight key aspects: data quality, technical documentation, record-keeping, transparency and provision of information to users, human oversight, accuracy, robustness, and cybersecurity. For example, AI systems used in medical devices for diagnostics or in water supply management systems must ensure exceptional reliability and safety, and the data on which they were trained must be high-quality, relevant, and non-discriminatory.

Before entering the EU market, high-risk AI systems require a mandatory conformity assessment, which can be conducted internally or with the involvement of external notified bodies. This involves creating detailed technical documentation that demonstrates compliance with all requirements of the act, including risk management, testing, and validation. Ukrainian developers must invest in developing internal processes that guarantee the transparency of AI operations, the possibility of human intervention, and a high level of cybersecurity to protect systems from unauthorized access and manipulation. It is also important to provide a clear explanation of how AI functions to end-users, especially in cases where decisions made by the system have a significant impact on their lives.

For Ukrainian SaaS companies developing such systems, this means the need for significant investment in compliance teams, staff training, upgrading technological infrastructure, and possibly engaging external consultants and auditors. Failure to comply with these requirements not only threatens fines that can reach up to 7% of a company's annual global turnover or 35 million euros (whichever is higher), but will also lead to a loss of access to the EU market. In 2024, experts predict a 34% increase in demand for AI compliance services precisely due to the introduction of the EU AI Act.

EU AI Act implementation timelines and adaptation for Ukrainian company exports

The entry into force of the EU AI Act will take place in stages, which gives Ukrainian companies a certain window of opportunity for adaptation but also requires clear planning. The act was officially published in May 2024, and its various provisions will come into effect gradually. The first to take effect, just 6 months after publication, will be the bans on unacceptable-risk AI systems. This means that by the end of 2024, any company developing or supplying such systems in the EU will face immediate consequences.

After 9 months, i.e., in early 2025, the provisions regarding codes of practice for AI will come into effect, as well as rules concerning general-purpose AI (GPAI) systems, which include large language models. This will require developers of such systems, including many Ukrainian startups that use or create generative AI, to comply with requirements regarding transparency, data management, and risk assessment. The most significant provisions concerning high-risk AI systems and most other requirements will come into effect 24 months after the publication of the act, i.e., by mid-2026.

For Ukrainian exporters, this means that delaying the development of an implementation roadmap is not an option. Companies must identify their products that fall under the high-risk definition right now and start working on adaptation. This includes reviewing development processes, investing in staff training, and implementing new tools to ensure compliance. Delays can lead to export blocking, loss of existing contracts, and significant fines, whereas proactive adaptation can become a competitive advantage in the EU market.

Strategic challenges and opportunities for the Ukrainian IT sector

Adapting to the EU AI Act requires the Ukrainian IT sector to make not only technical but also significant organizational and strategic changes. This goes beyond simply updating code; it is about implementing a new culture of responsible artificial intelligence development. Companies must rethink their approaches to corporate governance (AI Governance), develop internal ethical policies regarding AI, and introduce new roles such as AI Ethics Officer or AI Compliance Manager, who will be responsible for ensuring compliance with regulatory requirements.

Technical teams will face the need to implement MLOps approaches that emphasize the explainability and fairness of AI models. This means developing tools for monitoring data bias, interpreting AI decisions, and ensuring the auditability of systems. For example, if AI is used to make employment decisions, the company must be able to explain why a particular candidate was selected or rejected and prove the absence of discrimination. According to one industry survey, only 20% of Ukrainian IT companies currently have a formal internal policy regarding AI ethics.

Adapting to the EU AI Act also brings significant opportunities. Ukrainian companies that are the first to implement these standards can position themselves as reliable and ethical developers of AI solutions on the global market. This can become a powerful competitive advantage, especially when working with European clients for whom compliance and trust are key factors. In addition, there is a growing niche for providing consulting services in AI compliance, AI system auditing, and the development of specialized software for AI risk management. This could open up new revenue streams and opportunities for business expansion in Ukraine and beyond.

According to Anton Marrero, a member of the supervisory board and management board of Intecracy Ventures, "Ukrainian companies that are now proactively investing in compliance with the EU AI Act are not only securing their access to the European market but are also building long-term trust with partners and clients. This is an investment in the future that will allow them to become leaders in the development of responsible and ethical AI solutions in a world where trust in technology is becoming an increasingly valuable currency."

Frequently asked questions

What is the EU AI Act?

The EU AI Act is the world's first comprehensive law on artificial intelligence, developed by the European Union. It establishes a regulatory framework for the development, deployment, and use of AI systems based on the level of risk they pose.

How will the EU AI Act affect Ukrainian companies exporting to the EU?

Ukrainian companies whose AI products or services are used in the EU market will have to comply with the requirements of this act. This applies to risk classification, transparency, documentation, and cybersecurity, especially for high-risk systems.

What are the main risk categories defined in the EU AI Act?

The act identifies four categories: unacceptable risk (prohibited systems), high risk (strict requirements), limited risk (transparency requirements), and minimal risk (minimal regulation).

When will the EU AI Act fully come into effect?

The act comes into effect in stages. The main provisions for high-risk and general-purpose systems will apply 12-24 months after its official publication in the Official Journal of the EU, which took place on June 18, 2024.

Do Ukrainian companies need to prepare for the EU AI Act now?

Yes, companies that have or plan to have a presence in the EU market should start auditing their AI systems, assessing risks, and developing a compliance strategy. This will help avoid fines and maintain competitiveness.