From Idea to Market in 90 Days: How Irish Deeptech Startups Are Racing Against New EU AI Rules
Compliance is a moat, not a wall. The Irish deeptech founders who understand that distinction right now are building businesses that will still be standing in 2027. The ones who see regulation as someone else's problem are building on sand.
The EU AI Act is not a future event. The first obligations landed in February 2025. Deepfake labelling requirements and transparency rules for AI-generated content are already live for high-risk system providers. The next tranche, covering general-purpose AI models and broader provider obligations, hits in August 2025. A 90-day sprint from idea to market-ready product is not a startup cliché. For an Irish founder building anything that touches synthetic media, facial recognition, or automated decision-making, it is the actual window before the rules tighten further and the compliance cost doubles.
What the Rules Actually Say
Strip out the Brussels language and the AI Act does three concrete things for deeptech founders. It forces disclosure of AI-generated content. It bans certain applications outright, including real-time remote biometric surveillance in public spaces with narrow exceptions. And it creates a conformity assessment process for high-risk systems that is not unlike CE marking, which any Irish med-tech or industrial hardware founder already knows well.
The deepfake labelling requirement is the one catching founders off-guard. Any system that produces synthetic audio, video, or image content that could be mistaken for real must label that content as machine-generated. This is not optional. The fine for non-compliance sits at up to 3% of global annual turnover, which for a seed-stage startup sounds small until you realise it applies to revenue, not profit, and that Enterprise Ireland or an investor doing due diligence will ask for your compliance documentation before the cheque clears.
The 90-Day Framework: Four Steps That Cannot Be Reordered
The startups getting this right are not spending 90 days writing policy documents. They are running a tightly sequenced build.
Step 1: Classify your system before you write a line of code. The Act divides AI systems into unacceptable risk, high risk, limited risk, and minimal risk. Where you sit determines everything: your documentation burden, your conformity path, your market timing. A Cork startup building AI-assisted hiring tools sits in high risk by default. A Dublin team building a deepfake detection product sits in limited risk with specific transparency obligations. Getting the classification wrong at the start costs you six weeks of rework at the worst possible moment.
Step 2: Build the technical documentation in parallel with the product. Not after. The documentation the Act requires, covering training data, model architecture, risk management, and human oversight measures, maps almost exactly to the technical decisions you are making anyway. If you document as you build, you spend roughly 15% more engineering time on record-keeping. If you document after the fact, you spend three months trying to reconstruct decisions nobody wrote down, and some of those decisions will have changed.
Step 3: Bake the disclosure mechanism into the product interface. For synthetic media products, the labelling cannot be an afterthought bolted onto a settings page. It has to be visible, persistent, and machine-readable. The founders who treat this as a design constraint from day one ship a cleaner product. The ones who retrofit it ship something that looks apologetic and usually fails its first technical audit.
Step 4: Get a pre-market conversation with your notified body before you think you need one. Ireland has NSAI as its national standards authority, and the EU is still building out its network of notified bodies for AI conformity assessment. The queue is already forming. Founders who make contact at the prototype stage, not the launch stage, are getting informal guidance that shapes their architecture. Founders who show up six weeks before launch are getting told to wait.
Why This Is an Advantage, Not Just a Burden
Here is the binary that matters: you are either a compliant producer or a non-compliant also-ran. Within three years, any enterprise customer in Europe, and that means the HSE, AIB, any German manufacturer, any French insurer, will require AI Act compliance documentation from every vendor in their supply chain. This is already happening with GDPR. A startup that has its conformity assessment complete and its technical file ready is not jumping through hoops. It is holding a key that its non-compliant competitors do not have.
Irish deeptech is increasingly being taken seriously on the global stage, but the window for small teams to out-manoeuvre larger incumbents on compliance is short. A 50-person company in Dublin can get compliant faster than a 5,000-person company in Munich because it has fewer legacy systems, fewer internal approval layers, and one team that can make a decision on a Tuesday and ship it on a Thursday.
The fear is real, too. A founder building a synthetic voice product for, say, customer service automation is sitting in a market where the technology is moving faster than the guidance. The Act's implementing regulations for specific sectors are still being written. You can build the product and then watch the regulation land in a shape that forces a rebuild. That risk is genuine. The answer is not to wait. The answer is to build in enough flexibility that a regulatory adjustment costs you a sprint, not a pivot.
The Funding Signal Nobody Is Talking About Loudly Enough
Irish VCs are watching compliance posture as closely as product-market fit right now. Not because they have suddenly become lawyers. Because they have been burned. Post-GDPR, a wave of Irish data-driven startups hit Series A conversations and discovered their data practices would not survive due diligence. Some fixed it. Some folded. The AI Act is the same conversation arriving faster and with higher stakes.
A startup that walks into a funding room with a completed AI Act risk classification, a draft technical file, and a mapped conformity timeline is not just compliant. It is telling the investor that the founding team understands how markets actually work: that rules exist, that rules shape demand, and that being early to meet them is worth more than being first to ignore them.
Regulation is not the enemy of Irish deeptech. Complacency is. Build the compliance in, price the product accordingly, and the rule that your competitor is complaining about becomes the reason your customer calls you first.