If an investor asks which regulatory category your AI product falls under and you go quiet, you have not failed diligence, but you have handed the round a reason to slow down. For most startups between pre-seed and Series A the honest answer is short: name the rules that plausibly touch your product, say where you sit under each, and point to the two or three records that back it up. You do not need a compliance department or a lawyer on retainer to do this. You need a one-page answer you can give in the room without stalling. This is a readiness problem, not a legal one, and it is very fixable in an afternoon.
I started seeing this question land in diligence calls in the last year, and it caught founders off guard because it is genuinely new. The people asking are not lawyers. They are the same investors and technical advisors who used to ask about your architecture and your scaling story, and now they add one more line: how is this regulated, and can you show me you have thought about it. The teams that stumble are not the ones with a real compliance gap. They are the ones who never wrote a single sentence about it and now have to improvise in front of someone deciding whether to wire money.
The question that did not exist a year ago
Diligence questions move with the market. A few years ago nobody asked a seed-stage founder about their AI model's provenance, because most products did not have one. Now that a large share of what founders build sits on top of a model, and now that regulators in several regions have started drawing lines around what AI systems can do and what has to be documented, the question has migrated into the standard list.
What makes it awkward is that the founder often knows less about this than about anything else in the room. You can talk fluently about your stack, your funnel, your burn. Then someone asks whether your product is a high-risk use of AI under the rules that apply where your customers are, and you realize you have never framed your own product that way. The gap is not that you are doing something wrong. The gap is that you have no vocabulary for the answer, so you either freeze or you over-claim, and both read badly.
Over-claiming is the quieter danger. A founder, trying to sound on top of it, says the product is fully compliant with every framework the investor names. The investor's advisor then asks one follow-up, the founder cannot support the claim, and now the problem is not regulation, it is that the founder said something they could not back up. That is the moment diligence stops being about the rules and starts being about whether they can trust what you tell them. I would rather a founder say "here is what applies, here is where we are, here is what is still open" than claim a clean bill of health they cannot defend.
What they are actually checking
The specific rules vary by region and by what your product does, and I am not going to pretend a blog post can tell you which apply to you. But the shape of what a diligence reviewer is probing is consistent, and you can prepare for the shape without being a specialist.
First, they want to know that you have classified your own product. Is your AI making or heavily influencing decisions that affect people in ways a regulator cares about, such as hiring, credit, health, or safety, or is it a productivity tool that drafts and suggests. That distinction drives almost everything else, and a founder who can place their product on that line without hedging looks in control.
Second, they want to see that you can account for your inputs. Where the model came from and what its license permits, and where your training or fine-tuning data came from and whether you had the right to use it. This is the same instinct behind the older question of where your training data actually came from, now pulled forward because the answer has legal weight, not just technical weight.
Third, they want evidence that you thought about the people your product touches. Not a thick policy binder, but signs that you know what data you process, what you tell users about it, and what you would do if a customer or a regulator asked you to prove it. A reviewer is not grading your legal writing. They are checking whether the team treats this as real or as an afterthought, because an afterthought at seed becomes an expensive scramble at Series B.
Why a blank answer costs you
The cost is rarely the rule itself. At pre-seed and seed, almost nobody gets re-priced because their product technically falls in a stricter category. They get re-priced, or delayed, because of what the blank answer signals.
A founder who has no answer looks like a founder who has not looked. And if you have not looked at this, the reviewer starts to wonder what else you have not looked at. Diligence runs on pattern-matching, and "we never thought about it" on one line makes every other confident claim a little less believable. I have watched a strong technical story lose momentum not because the product had a problem, but because the founder could not say a single coherent sentence about how it was regulated, and the room quietly downgraded its confidence in everything after that.
There is also a timing cost. If the question surfaces mid-diligence and you have nothing prepared, you now spend a week of a fundraise you cannot afford to stretch chasing a lawyer, assembling records, and drafting on the fly, while the term sheet cools. The same answer prepared in advance is a five-minute exchange. This is the same dynamic I see with the security questionnaire that stalls an enterprise deal: the work is small, but doing it under time pressure in front of someone with leverage is where it hurts.
What to have ready
You are not building a compliance program. You are writing one page you can hand over and speak to. It has four parts.
Name the rules that plausibly apply. Where do your users and your data live, and which regimes does that put you under. You do not need certainty on every edge. You need to show you know which frameworks are in play instead of pretending none are.
Place your product under each. For every rule that applies, say in one honest sentence where you sit: this use is out of scope, this one is a lower-risk category and here is why, this one we are still confirming. "Still confirming" is a fine answer when it is specific.
Point to the records. The two or three artifacts that back the classification: your model's license, a short note on where your data came from, whatever you tell users about how you handle their data. If a record does not exist yet, say so and say when it will.
Name the owner. Who on the team holds this, even if it is you for now, and what triggers you to bring in real counsel. Investors do not expect a pre-seed team to have a compliance hire. They expect someone to have their hand on it.
That page is the whole deliverable. It sits in the technical half of your data room next to the architecture questions investors already ask, and it turns a stall into a paragraph.
When you can say "not yet" and mean it
Some of this genuinely does not apply to you yet, and pretending it does wastes money you should be spending on the product. If your AI drafts marketing copy or summarizes documents, you are almost certainly in a light-touch category, and the honest one-pager will say so in a few lines. The move is not to build a governance apparatus you do not need. It is to be able to explain, credibly, why you do not need one yet.
This is the same judgment I apply to whether you need SOC 2 before you raise: usually the answer at your stage is a considered "not yet," and being able to say that clearly beats both panic and over-building. The failure is never "we decided this was light-touch and here is our reasoning." The failure is a blank where the reasoning should be.
FAQ
Do I need a lawyer before I can answer this question?
No, not to prepare the one-pager. You can name the regimes that plausibly apply, classify your own product honestly, and gather the records you already have without counsel. Bring in a lawyer when a specific customer contract, a specific market, or a specific claim needs a real legal opinion. For diligence readiness, a clear self-assessment you can defend is worth more than an expensive memo you cannot explain.
What if I genuinely do not know which category my product is in?
Say that, and say what you are doing to find out. "We believe we are in the lighter-risk category because our product only suggests and never decides, and we are confirming that with counsel this month" is a strong answer. It shows you understand the question and are on it. The weak answer is silence, or a confident claim you cannot support if the reviewer pushes once.
Will regulation actually re-price my round at seed?
Rarely on its own. At early stages the classification itself almost never moves the valuation. What moves it is the signal a blank answer sends about the rest of your judgment, and the time a mid-diligence scramble costs a fundraise you needed to close fast. Prepare the page and both risks mostly disappear.
If a diligence conversation is coming and you want a second set of eyes on how your product would read to an investor's technical advisor, book a call or send it through a teardown and we will pressure-test the answer before someone with a checkbook does.