Most attention to AI focuses on the visible layer: the chatbots, recommendation systems and decision-making tools. Beneath that lies an infrastructure layer of deployment, monitoring and governance that determines whether models run reliably and demonstrably responsibly. That layer is increasingly taking centre stage in procurement conversations at large organisations, driven by the EU AI Act.
The legislation, which entered into force on 1 August 2024, applies a risk-based classification. For most applications, those falling into the minimal or limited risk categories, obligations are limited. For high-risk systems, such as applications in recruitment, credit assessment or healthcare, requirements apply in the areas of documentation, human oversight, data quality and traceability. Those requirements become fully enforceable for most standalone high-risk systems from 2 December 2027.
A survey of more than one hundred AI startups and fifteen venture capital firms in the EU found that more than a third of the AI systems surveyed could be classified as high-risk. Around half of the startups expect compliance costs of between €160,000 and €330,000; nineteen percent anticipate even higher amounts.
Compliance as part of the architecture
The EU AI Act requires that high-risk AI systems have demonstrable audit trails: logs of model changes, inputs and outputs, and of who made which decisions. That demands technical choices that are difficult to add retrospectively. Organisations that try to build in compliance after launch face higher costs and longer lead times than companies that account for it early on.
For MLOps platforms and AI governance tools, this translates into direct market demand. Clients in regulated sectors are increasingly asking, during evaluations, about demonstrable model behaviour, version history and the ability for human intervention. This shifts the positioning of such tools from technical infrastructure to compliance-critical software.
The legislation also requires an AI system inventory: organisations must know which models they are using, where they originate from and which risk category they fall into. That inventory is the starting point for classification, registration and ongoing monitoring under the AI Act.
Deeploy builds governance into the deployment process
Rotterdam-based Deeploy, founded in 2020 and backed by €8.5 million in a Series A round in 2024, has AI governance as its core product. The platform focuses on operationalising AI Act and ISO 42001 compliance by embedding governance into the deployment process rather than adding a separate layer on top of it.
In practical terms, Deeploy supports the creation of an inventory of all AI models within an organisation, covering both internally built models and those from external suppliers. On top of that, the platform offers functionality for risk identification, the application of control frameworks, usage monitoring and decision documentation. All model changes, inputs and outputs are logged, making it possible to demonstrate after the fact how a decision was reached.
Deeploy works with a control framework across seven categories, including risk management, data quality, transparency and human oversight. Each component contains success criteria and evidence artefacts that can be used in an audit. The company also offers a self-assessment tool that allows organisations to determine whether a system qualifies as high-risk under the legislation. More recently, Deeploy has been targeting agentic AI applications, where compliance requirements around audit trails and human oversight become particularly complex due to the autonomous nature of such systems.
Bigdata Republic combines consultancy with knowledge sharing
Bigdata Republic, based in Utrecht, founded in 2015 and backed by €9.2 million in a Series A round in 2021, positions itself as a data and ML consultancy focused on measurable business outcomes. Around AI governance, the company organises meetups on AI and regulation, specifically targeting the EU AI Act. In doing so, it addresses a demand for knowledge-building that precedes technical implementation at many organisations: understanding what the legislation requires of them before they purchase tools or set up processes.
That combination of consultancy and knowledge sharing fits a pattern that is visible more broadly in this segment: the complexity of the AI Act calls not only for software, but also for guidance on interpreting and implementing regulation that represents new territory for many organisations.
Timelines and what is still to come
The EU AI Act is rolling out in phases. The prohibitions on AI systems posing unacceptable risk have been in effect since 2 February 2025. Rules for so-called General Purpose AI models, large language models and comparable systems, apply from 2 August 2025. Transparency obligations under Article 50, including requirements around synthetic content and interaction with automated systems, follow on 2 August 2026.
The heaviest obligations, for high-risk systems in sectors such as healthcare, credit and recruitment, take effect on 2 December 2027 for most standalone systems. For systems embedded as safety components in regulated products, the date is 2 August 2028. That margin may appear generous, but organisations that want to be compliant by then need to start making decisions now about their model architecture, logging infrastructure and governance processes.
For Dutch startups in this segment, the phased implementation means that demand for their products and services is expected to grow further in the coming years, particularly from regulated sectors working with high-risk applications. At the same time, the legislation places requirements on the startups themselves: their own AI applications, insofar as they are high-risk, must also be demonstrably compliant. That makes compliance both a market opportunity and an operational obligation for these companies.