Expert View 6 min read

How the EU AI Act impacts Ukrainian SaaS companies

The European Union continues to shape the global landscape of technology regulation, and the adoption of the EU AI Act is a landmark event that changes the rules of the game for everyone developing or using artificial intelligence systems. For Ukrainian SaaS companies that are…

The European Union continues to shape the global landscape of technology regulation, and the adoption of the EU AI Act is a landmark event that changes the rules of the game for everyone developing or using artificial intelligence systems. For Ukrainian SaaS companies that are actively integrating AI into their products and seeking to expand their presence in the European market, this Act is not just another piece of legislation, but a fundamental challenge and, at the same time, an opportunity. It requires a deep rethinking of development strategies, risk management, and compliance to ensure competitiveness and avoid significant fines. Understanding its essence and practical impact is a top priority for every Ukrainian technology leader.

Classification of AI risks: what does this mean for a SaaS product?

The EU AI Act introduces four categories of risk for artificial intelligence systems: minimal, limited, high, and unacceptable. This classification is the cornerstone of the regulation, as it defines the scope of obligations for providers and developers. Systems with minimal risk (e.g., spam filters) are subject to minimal requirements, while systems with unacceptable risk (e.g., social scoring, manipulative AI) will be completely prohibited. The category of 'high risk' is of the greatest interest to Ukrainian SaaS companies, as a significant portion of innovative solutions may fall into this category.

High-risk AI systems include those used in critical areas such as infrastructure management, education, employment, law enforcement, migration, and medical devices. For example, Ukrainian AI-based HR tools for automated candidate screening, credit scoring systems used by financial institutions, or medical diagnostic systems that assist doctors in making diagnoses are prime examples of SaaS products that are likely to be classified as high-risk. This means that Ukrainian product companies must conduct a thorough audit of their AI systems at the early stages of development to determine the risk category and potential regulatory obligations. Ignoring this step can lead to significant costs for re-engineering or even a ban on using the product in the European market.

Requirements for high-risk AI systems: technical and organizational compliance

For high-risk AI systems, the EU AI Act establishes a number of strict requirements covering both technical aspects and organizational processes. Key requirements include implementing a robust risk management system throughout the entire AI lifecycle, ensuring high quality of data used for training and testing, and developing detailed technical documentation. Also mandatory are logging for traceability, a high level of transparency and explainability of AI functioning, the possibility of human oversight, enhanced cybersecurity measures, and guarantees of accuracy, reliability, and robustness of the systems.

Practical steps for Ukrainian SaaS companies will include not only updating data architecture and developing mechanisms for model auditing and verification, but also implementing internal policies and procedures that ensure continuous compliance. This will lead to an increase in the cost of developing and supporting AI solutions, as well as a need for new competencies—from AI ethicists to compliance officers. Building such expertise in the field of AI compliance can become a new niche for consulting services and the development of specialized teams in Ukraine that will provide support to both domestic and international companies.

Implementation timelines and adaptation strategy for Ukrainian business

The entry into force of the EU AI Act is taking place in stages, which gives companies time to adapt but requires clear strategic planning. The ban on unacceptable AI systems takes effect just six months after the Act's publication in the Official Journal of the EU. Requirements for high-risk AI systems and rules regarding risk management, data quality, and transparency will become mandatory in 24 months, and the general provisions of the Act in 36 months. These deadlines create a window of opportunity that should be used as effectively as possible.

For Ukrainian startups and mature SaaS companies, it is critical to begin the adaptation process immediately. A phased implementation of changes is recommended, starting with an internal audit and risk assessment of existing AI systems. Pilot projects to test compliance with new requirements will allow for the identification of bottlenecks and the refinement of necessary processes. Engaging legal and technical consultants specializing in the EU AI Act can significantly accelerate and simplify this process. The need for strategic planning, allocating budgets for compliance, and staff training is becoming an integral part of business strategy. Ukrainian companies that adapt earlier will gain a significant competitive advantage in the European market, while those that ignore these changes risk losing access to key markets or facing significant fines. Moreover, this could stimulate the creation of new AI solutions that will help other companies with compliance.

Consequences of non-compliance and next steps for Ukrainian exporters

The consequences of non-compliance with the EU AI Act are extremely serious. Fines for violations can reach up to 7% of a company's annual global turnover or 35 million euros, whichever is higher. This is one of the strictest regulatory regimes in the world, underscoring the seriousness of the EU's approach to AI ethics and safety. In addition to financial sanctions, companies will face reputational risks that could lead to a loss of trust from clients and partners in the European market, as well as a significant decrease in brand value.

To avoid these consequences, Ukrainian exporters need to constantly monitor regulatory updates, as the legislation may be supplemented and clarified. Active participation in industry discussions and working groups will allow companies to stay informed about best practices and changes. Forming internal working groups consisting of development, legal, and ethics specialists is key to ensuring continuous compliance. Demonstrating high standards of AI ethics, safety, and transparency will not only protect against fines but also strengthen the competitiveness of Ukrainian product companies in the European market, positioning them as reliable and responsible providers of innovative solutions.

As of 2026, Ukrainian SaaS companies operating with high-load AI systems are already feeling the full force of the EU AI Act regulations. This requires not just declarative compliance, but deep integration of risk management systems, data transparency, model verification, and robust audit mechanisms. Operators must demonstrate continuous compliance, as the lack of certification or non-compliance with operational standards becomes a critical barrier to market access and investment, turning into a key competitive advantage.