EU AI Act · SaaS

The EU AI Act for SaaS: which features carry duties, and which do not.

A SaaS company is usually a provider of the AI features it ships and a deployer of the AI tools it uses. Here is how to classify each feature, what applies already, and what a customer's procurement team will ask you for.

Last updated Published by TryTrustableNot legal advice

Short answer

Most SaaS AI features are not high-risk, but almost every SaaS company with an AI feature has some duty under the EU AI Act. If you ship a feature under your own name you are its provider. A chatbot or a generator brings Article 50 transparency duties, applying since 2 August 2026. A feature used for hiring, worker management, credit scoring or access to education is high-risk under Annex III, with obligations from 2 December 2027. The Act applies to non-EU companies when the output is used in the EU.

01

What applies to a SaaS company, and when

The AI Act, Regulation (EU) 2024/1689 regulates AI systems by what they are used for. Its application dates are in Article 113, as amended by the Digital Omnibus, Regulation (EU) 2026/1744. The full timetable and the obligations by tier are in the EU AI Act guide; the dates that matter for a SaaS company are these:

DateWhat appliesTypical SaaS impact
2 Feb 2025Article 5 prohibitions; Article 4 AI literacyCheck no feature infers emotions at work, scores people socially or scrapes faces. Take measures to support staff AI literacy
2 Aug 2025General-purpose AI model obligationsMostly your model provider's duties, not yours, unless you train or substantially modify a general-purpose model
2 Aug 2026Article 50 transparencyChatbots disclose they are AI; generated content is marked machine-readably. Generators already on the market had until 2 December 2026 for the marking duty
2 Dec 2027High-risk obligations, Annex III systemsHR tech, credit scoring, insurance pricing, education and access to essential services
2 Aug 2028High-risk obligations, Annex I productsOnly if your software is part of a regulated product, such as a medical device

Article 113 as amended by Regulation (EU) 2026/1744, as set out on the EU AI Act guide. Checked October 2026.

The Act reaches you wherever you are established: Article 2(1) covers providers placing systems on the EU market and providers and deployers outside the EU whose system's output is used in the EU.

02

Provider or deployer: decide per feature

  • Provider of every AI feature you sell under your own name, including one built on a third-party model through an API. The heavy duties sit here, but only if the feature is high-risk
  • Deployer of AI tools you use internally: a coding assistant, a support chatbot from a vendor, an AI screening tool in your own hiring. An internal CV-screening tool is a high-risk use even though you bought it
  • Not the general-purpose model provider when you call someone else's model, unless you modify the model substantially. Fine-tuning for a high-risk purpose is the usual route into provider duties without meaning to
  • Your customer can become a provider. Under Article 25(1), someone who changes the intended purpose of a system so that it becomes high-risk takes on the provider's obligations. State the intended purpose in your instructions for use, and do not market a general feature for hiring or credit decisions unless you mean to carry the high-risk duties
03

Classifying a SaaS feature

FeatureLikely tierWhat it brings
Support chatbot, in-app assistantLimited risk (Art. 50(1))Tell users they are talking to AI unless obvious
Text, image, audio or video generationLimited risk (Art. 50(2))Machine-readable marking of outputs
Summarisation, search, recommendations, forecastingMinimal riskNo obligations under the Act beyond AI literacy
CV screening, candidate ranking, performance monitoringHigh risk (Annex III point 4)Full provider duties from 2 December 2027
Creditworthiness of individuals; life and health insurance pricingHigh risk (Annex III point 5)Full provider duties from 2 December 2027
Admissions, exam scoring, proctoringHigh risk (Annex III point 3)Full provider duties from 2 December 2027

Indicative only. Classification depends on intended purpose; check each feature against Article 6 and Annex III.

Article 6(3) lets a provider treat an Annex III system as not high-risk when it does not pose a significant risk, for example because it performs a narrow procedural task, improves the result of a completed human activity, or does preparatory work for a human assessment. Two conditions make this less of an escape than it looks: a system that profiles people is always high-risk, and a provider relying on the exception must document the assessment before placing the system on the market and register it.

04

What regulators and customers will ask for

  • An inventory of AI features and the AI tools you use, with intended purpose, model provider and role. This is the first thing an enterprise customer's AI questionnaire asks for
  • The classification reasoning per feature, including any Article 6(3) assessment
  • Article 50 evidence: the disclosure in the interface and the marking method for generated content
  • Instructions for use stating intended purpose and limits. Deployer customers need them to meet their own duties, and for high-risk systems Article 13 makes them mandatory
  • For high-risk systems: a risk management system, data governance, Annex IV technical documentation, logging, human oversight, accuracy and robustness, conformity assessment, registration and post-market monitoring
05

The gaps we see most often in SaaS companies

  • No list of AI features, so nobody can say which tier any of them sits in
  • An HR or lending feature added by a product team without anyone checking Annex III
  • Relying on Article 6(3) with no written assessment
  • Chatbots with no AI disclosure, and generated images with no machine-readable marking
  • Marketing copy that says "EU AI Act compliant" with nothing behind it
  • Contracts silent on intended purpose, leaving it unclear who is the provider when a customer repurposes the feature
  • Treating ISO 42001 certification as proof of AI Act compliance; it is not, as EU AI Act vs ISO 42001 explains
06

Timeline and cost drivers

For minimal and limited-risk features, the work is an inventory, a classification record per feature, the Article 50 disclosures and marking, and an AI literacy measure for staff. That is weeks of work and it is already due. For a high-risk feature, the provider duties need to be designed into the product before 2 December 2027; conformity assessment, documentation and post-market monitoring cannot be assembled in the last quarter.

The largest cost driver is whether any feature is high-risk. Within that, the conformity assessment route matters: under Article 43(2), high-risk systems in Annex III points 2 to 8, which include employment, credit and education, follow the internal-control procedure without a notified body. Biometric systems under point 1 may need one. Penalties under Article 99 reach €15 million or 3% of worldwide turnover for most obligations, and Article 99(6) applies the lower of the two figures to SMEs and start-ups; the EU AI Act penalties page sets out each tier.

07

EU AI Act checklist for a SaaS company

#TaskDone when
1List every AI feature you ship and every AI tool you usePurpose, model provider, data and owner recorded
2Record your role for each: provider, deployer, or bothRole per system, not per company
3Check each feature against Article 5No prohibited practice; reasoning recorded
4Classify each feature against Article 6 and Annex IIITier recorded with reasons
5Write an Article 6(3) assessment for any Annex III feature you treat as not high-riskSigned and dated before release
6Add AI disclosure to chatbots and assistantsVisible in the interface
7Mark generated content machine-readablyMethod chosen and tested
8State intended purpose and limits in instructions for use and contractsCustomers can see what the feature is not for
9Take AI literacy measures for staff who build or operate AITraining or guidance recorded
10For any high-risk feature, plan the provider duties against 2 December 2027Owner and plan for each obligation
11Appoint an EU authorised representative if you provide high-risk systems from outside the EUWritten mandate in place
08

How TryTrustable helps, and what it does not do

  • Classification per system. AI governance holds the inventory and classifies each AI system against the Act's tiers, next to its ISO 42001 and NIST AI RMF mappings
  • Requirement mappings. EU AI Act requirements sit on the same control set as SOC 2, ISO 27001 and the GDPR, so shared controls are evidenced once; see coverage
  • Evidence a reader can check. Results land in the hash-chained evidence ledger, and reports are sealed so a customer can verify them
  • Free first step. The EU AI Act applicability checker and the AI governance checker need no account

The platform does not perform conformity assessment, sign a declaration of conformity or decide your classification for you; those stay with you and your counsel. TryTrustable does not hold SOC 2, ISO 27001 or ISO 42001 itself yet: all are in progress, as the security page says. Customer data is hosted in India (Mumbai) today; we are expanding to Singapore, the US and the EU.

09

Sources

Checked against these sources in October 2026. Laws, standards and dates change: check the source before you rely on a figure. Not legal, audit or certification advice.

Related audience guides: SOC 2 for AI start-ups · ISO 42001 for AI start-ups · GDPR for SaaS · DPDP for SaaS · SOC 2 from India

Questions

The things people ask us

Does the EU AI Act apply to a SaaS company outside the EU?

Yes, if you place an AI system on the EU market or its output is used in the EU (Article 2(1)). A SaaS company in India or the US selling an AI feature to EU customers is a provider of that system. Providers of high-risk systems established outside the EU must appoint an authorised representative in the EU (Article 22).

We use a third-party model through an API. Are we a provider?

Of the AI system you build on it, usually yes: you put the feature on the market under your own name. You are not the provider of the general-purpose model itself, which stays with the model developer, unless you modify the model substantially. Your duties depend on what the feature does, not on whose model sits underneath.

Is an AI feature in an HR or recruiting product high-risk?

Often. Annex III point 4 lists AI used to recruit or select people, filter applications, evaluate candidates, decide on promotion or termination, allocate tasks or monitor performance. Article 6(3) allows a documented exception for narrow procedural or preparatory tasks, but a system that profiles people is always high-risk.

What do we have to do for a chatbot?

Under Article 50(1), design it so people are told they are interacting with an AI system, unless that is obvious. If it generates text, images, audio or video, Article 50(2) requires the output to be marked in a machine-readable way as artificially generated. Both apply from 2 August 2026.

Can a customer make us high-risk by how they use our product?

A customer who uses a general-purpose feature for a high-risk purpose that you did not intend can become the provider of that high-risk system themselves, under Article 25(1). Your defence is a clearly stated intended purpose in your instructions for use and contract, and not marketing the feature for high-risk uses.

Can we say our product is EU AI Act compliant?

Be careful. There is no certificate of EU AI Act compliance. For minimal and limited-risk features, say which obligations apply and how you meet them. For high-risk systems, compliance is shown by conformity assessment, an EU declaration of conformity, CE marking and registration, not by a marketing claim.

Book a walkthrough

Classify every AI feature in one place.

We register a real AI feature, classify it against the Act and show the evidence mapped to the AI Act and ISO 42001 from one control set. Thirty minutes.