The EU AI Act for SaaS: which features carry duties, and which do not.
A SaaS company is usually a provider of the AI features it ships and a deployer of the AI tools it uses. Here is how to classify each feature, what applies already, and what a customer's procurement team will ask you for.
Last updated Published by TryTrustableNot legal advice
Most SaaS AI features are not high-risk, but almost every SaaS company with an AI feature has some duty under the EU AI Act. If you ship a feature under your own name you are its provider. A chatbot or a generator brings Article 50 transparency duties, applying since 2 August 2026. A feature used for hiring, worker management, credit scoring or access to education is high-risk under Annex III, with obligations from 2 December 2027. The Act applies to non-EU companies when the output is used in the EU.
What applies to a SaaS company, and when
The AI Act, Regulation (EU) 2024/1689 regulates AI systems by what they are used for. Its application dates are in Article 113, as amended by the Digital Omnibus, Regulation (EU) 2026/1744. The full timetable and the obligations by tier are in the EU AI Act guide; the dates that matter for a SaaS company are these:
| Date | What applies | Typical SaaS impact |
|---|---|---|
| 2 Feb 2025 | Article 5 prohibitions; Article 4 AI literacy | Check no feature infers emotions at work, scores people socially or scrapes faces. Take measures to support staff AI literacy |
| 2 Aug 2025 | General-purpose AI model obligations | Mostly your model provider's duties, not yours, unless you train or substantially modify a general-purpose model |
| 2 Aug 2026 | Article 50 transparency | Chatbots disclose they are AI; generated content is marked machine-readably. Generators already on the market had until 2 December 2026 for the marking duty |
| 2 Dec 2027 | High-risk obligations, Annex III systems | HR tech, credit scoring, insurance pricing, education and access to essential services |
| 2 Aug 2028 | High-risk obligations, Annex I products | Only if your software is part of a regulated product, such as a medical device |
Article 113 as amended by Regulation (EU) 2026/1744, as set out on the EU AI Act guide. Checked October 2026.
The Act reaches you wherever you are established: Article 2(1) covers providers placing systems on the EU market and providers and deployers outside the EU whose system's output is used in the EU.
Provider or deployer: decide per feature
- Provider of every AI feature you sell under your own name, including one built on a third-party model through an API. The heavy duties sit here, but only if the feature is high-risk
- Deployer of AI tools you use internally: a coding assistant, a support chatbot from a vendor, an AI screening tool in your own hiring. An internal CV-screening tool is a high-risk use even though you bought it
- Not the general-purpose model provider when you call someone else's model, unless you modify the model substantially. Fine-tuning for a high-risk purpose is the usual route into provider duties without meaning to
- Your customer can become a provider. Under Article 25(1), someone who changes the intended purpose of a system so that it becomes high-risk takes on the provider's obligations. State the intended purpose in your instructions for use, and do not market a general feature for hiring or credit decisions unless you mean to carry the high-risk duties
Classifying a SaaS feature
| Feature | Likely tier | What it brings |
|---|---|---|
| Support chatbot, in-app assistant | Limited risk (Art. 50(1)) | Tell users they are talking to AI unless obvious |
| Text, image, audio or video generation | Limited risk (Art. 50(2)) | Machine-readable marking of outputs |
| Summarisation, search, recommendations, forecasting | Minimal risk | No obligations under the Act beyond AI literacy |
| CV screening, candidate ranking, performance monitoring | High risk (Annex III point 4) | Full provider duties from 2 December 2027 |
| Creditworthiness of individuals; life and health insurance pricing | High risk (Annex III point 5) | Full provider duties from 2 December 2027 |
| Admissions, exam scoring, proctoring | High risk (Annex III point 3) | Full provider duties from 2 December 2027 |
Indicative only. Classification depends on intended purpose; check each feature against Article 6 and Annex III.
Article 6(3) lets a provider treat an Annex III system as not high-risk when it does not pose a significant risk, for example because it performs a narrow procedural task, improves the result of a completed human activity, or does preparatory work for a human assessment. Two conditions make this less of an escape than it looks: a system that profiles people is always high-risk, and a provider relying on the exception must document the assessment before placing the system on the market and register it.
What regulators and customers will ask for
- An inventory of AI features and the AI tools you use, with intended purpose, model provider and role. This is the first thing an enterprise customer's AI questionnaire asks for
- The classification reasoning per feature, including any Article 6(3) assessment
- Article 50 evidence: the disclosure in the interface and the marking method for generated content
- Instructions for use stating intended purpose and limits. Deployer customers need them to meet their own duties, and for high-risk systems Article 13 makes them mandatory
- For high-risk systems: a risk management system, data governance, Annex IV technical documentation, logging, human oversight, accuracy and robustness, conformity assessment, registration and post-market monitoring
The gaps we see most often in SaaS companies
- No list of AI features, so nobody can say which tier any of them sits in
- An HR or lending feature added by a product team without anyone checking Annex III
- Relying on Article 6(3) with no written assessment
- Chatbots with no AI disclosure, and generated images with no machine-readable marking
- Marketing copy that says "EU AI Act compliant" with nothing behind it
- Contracts silent on intended purpose, leaving it unclear who is the provider when a customer repurposes the feature
- Treating ISO 42001 certification as proof of AI Act compliance; it is not, as EU AI Act vs ISO 42001 explains
Timeline and cost drivers
For minimal and limited-risk features, the work is an inventory, a classification record per feature, the Article 50 disclosures and marking, and an AI literacy measure for staff. That is weeks of work and it is already due. For a high-risk feature, the provider duties need to be designed into the product before 2 December 2027; conformity assessment, documentation and post-market monitoring cannot be assembled in the last quarter.
The largest cost driver is whether any feature is high-risk. Within that, the conformity assessment route matters: under Article 43(2), high-risk systems in Annex III points 2 to 8, which include employment, credit and education, follow the internal-control procedure without a notified body. Biometric systems under point 1 may need one. Penalties under Article 99 reach €15 million or 3% of worldwide turnover for most obligations, and Article 99(6) applies the lower of the two figures to SMEs and start-ups; the EU AI Act penalties page sets out each tier.
EU AI Act checklist for a SaaS company
| # | Task | Done when |
|---|---|---|
| 1 | List every AI feature you ship and every AI tool you use | Purpose, model provider, data and owner recorded |
| 2 | Record your role for each: provider, deployer, or both | Role per system, not per company |
| 3 | Check each feature against Article 5 | No prohibited practice; reasoning recorded |
| 4 | Classify each feature against Article 6 and Annex III | Tier recorded with reasons |
| 5 | Write an Article 6(3) assessment for any Annex III feature you treat as not high-risk | Signed and dated before release |
| 6 | Add AI disclosure to chatbots and assistants | Visible in the interface |
| 7 | Mark generated content machine-readably | Method chosen and tested |
| 8 | State intended purpose and limits in instructions for use and contracts | Customers can see what the feature is not for |
| 9 | Take AI literacy measures for staff who build or operate AI | Training or guidance recorded |
| 10 | For any high-risk feature, plan the provider duties against 2 December 2027 | Owner and plan for each obligation |
| 11 | Appoint an EU authorised representative if you provide high-risk systems from outside the EU | Written mandate in place |
How TryTrustable helps, and what it does not do
- Classification per system. AI governance holds the inventory and classifies each AI system against the Act's tiers, next to its ISO 42001 and NIST AI RMF mappings
- Requirement mappings. EU AI Act requirements sit on the same control set as SOC 2, ISO 27001 and the GDPR, so shared controls are evidenced once; see coverage
- Evidence a reader can check. Results land in the hash-chained evidence ledger, and reports are sealed so a customer can verify them
- Free first step. The EU AI Act applicability checker and the AI governance checker need no account
The platform does not perform conformity assessment, sign a declaration of conformity or decide your classification for you; those stay with you and your counsel. TryTrustable does not hold SOC 2, ISO 27001 or ISO 42001 itself yet: all are in progress, as the security page says. Customer data is hosted in India (Mumbai) today; we are expanding to Singapore, the US and the EU.
Sources
- EUR-Lex: Regulation (EU) 2024/1689 (AI Act)
- EUR-Lex: Regulation (EU) 2026/1744 (Digital Omnibus)
- European Commission: standardisation and the AI Act
Checked against these sources in October 2026. Laws, standards and dates change: check the source before you rely on a figure. Not legal, audit or certification advice.
Related audience guides: SOC 2 for AI start-ups · ISO 42001 for AI start-ups · GDPR for SaaS · DPDP for SaaS · SOC 2 from India
The things people ask us
Does the EU AI Act apply to a SaaS company outside the EU?
Yes, if you place an AI system on the EU market or its output is used in the EU (Article 2(1)). A SaaS company in India or the US selling an AI feature to EU customers is a provider of that system. Providers of high-risk systems established outside the EU must appoint an authorised representative in the EU (Article 22).
We use a third-party model through an API. Are we a provider?
Of the AI system you build on it, usually yes: you put the feature on the market under your own name. You are not the provider of the general-purpose model itself, which stays with the model developer, unless you modify the model substantially. Your duties depend on what the feature does, not on whose model sits underneath.
Is an AI feature in an HR or recruiting product high-risk?
Often. Annex III point 4 lists AI used to recruit or select people, filter applications, evaluate candidates, decide on promotion or termination, allocate tasks or monitor performance. Article 6(3) allows a documented exception for narrow procedural or preparatory tasks, but a system that profiles people is always high-risk.
What do we have to do for a chatbot?
Under Article 50(1), design it so people are told they are interacting with an AI system, unless that is obvious. If it generates text, images, audio or video, Article 50(2) requires the output to be marked in a machine-readable way as artificially generated. Both apply from 2 August 2026.
Can a customer make us high-risk by how they use our product?
A customer who uses a general-purpose feature for a high-risk purpose that you did not intend can become the provider of that high-risk system themselves, under Article 25(1). Your defence is a clearly stated intended purpose in your instructions for use and contract, and not marketing the feature for high-risk uses.
Can we say our product is EU AI Act compliant?
Be careful. There is no certificate of EU AI Act compliance. For minimal and limited-risk features, say which obligations apply and how you meet them. For high-risk systems, compliance is shown by conformity assessment, an EU declaration of conformity, CE marking and registration, not by a marketing claim.
Classify every AI feature in one place.
We register a real AI feature, classify it against the Act and show the evidence mapped to the AI Act and ISO 42001 from one control set. Thirty minutes.