EU AI Act compliance for SaaS companies shipping AI features
Nearly every SaaS product has added AI features, which raises a question most teams have not answered on paper. Are you a provider of an AI system, a deployer of someone else’s, or both at once.
Most SaaS companies turn out to be both, and the answer shapes everything else. There is also a commercial reason to sort this out, because enterprise buyers have started asking for AI Act documentation in security and procurement reviews.
Are you a provider or a deployer?
Building an AI system on the EU market under your own name makes you a provider. Using OpenAI, Anthropic, or similar models inside your product makes you a deployer of theirs, and often a provider of the system you assemble.
How this is classified under the Act
Classification follows what your feature does, not the fact that it uses AI. Summarisation, search, and content assistance normally sit outside Annex III. Anything touching hiring, credit, education, essential services, or biometrics moves into the high-risk tier.
What changes the answer: Building on a general-purpose model does not transfer the model provider’s obligations to you, and it does not remove yours either. Where you substantially modify a system or put it on the market under your own name, you can become its provider.
Want this checked against your own setup?
Run the free 6-question check →Documents you need
- AI Literacy Policy Article 4
A written policy covering which AI tools you use, which roles interact with them, what those people need to understand, who owns the document, and how it gets updated. Enforceable since 2 February 2025.
- Risk Classification Memo Articles 6, 9 and Annex III
A documented assessment placing each AI system in the Act’s risk tiers, including the Article 5 prohibited-practice check and the Article 6(3) exception assessment, with article citations.
- Transparency Disclosure Article 50
Informs people when they are interacting with an AI system and labels AI-generated or manipulated content. Article 50 applies from 2 August 2026. The narrower Article 50(2) duty on general-purpose models generating synthetic content applies from 2 December 2026.
Obligations that apply
- Article 4 Internal literacy
Applies to your own team’s AI use and has been enforceable since February 2025, independent of your product classification.
- Articles 6 and 9 Feature-level classification
Document each AI feature separately with the reasoning. This is also the artefact buyers ask for during vendor review.
- Article 50 Transparency in the product
Where users interact with AI directly or receive generated content, disclosure applies from 2 August 2026. Building it into the interface is cheaper than retrofitting.
- Article 25 When you become the provider
Putting your name on a high-risk system, substantially modifying one, or changing its intended purpose makes you the provider with the full obligation set.
Common mistakes
- Assuming that because OpenAI is the model provider, no obligations reach your company.
- Having no written classification when an enterprise buyer asks for it, which stalls the deal.
- Adding an AI feature that touches hiring or credit without reassessing the risk tier.
- Deferring transparency design until the December 2026 date, then having to rework the interface.
Where the deadlines stand
The AI literacy obligation under Article 4 and the Article 5 prohibitions have been enforceable since 2 February 2025. General-purpose AI model rules applied from 2 August 2025. The Omnibus, published in the Official Journal on 24 July 2026, moved the high-risk dates: standalone high-risk systems under Annex III to 2 December 2027, and high-risk AI embedded in regulated products under Annex I to 2 August 2028. Article 50 transparency obligations still apply from 2 August 2026. Only the narrower Article 50(2) duty on general-purpose models generating synthetic content moved, to 2 December 2026, which is also when the new prohibition on AI-generated intimate imagery and child sexual abuse material takes effect.
The delay applies to the high-risk obligations. It does not move Article 4, which is why a written AI literacy policy is the document most companies are missing today.
Generate your 3 documents in about 30 minutes
Answer a short questionnaire and get every document above, pre-filled with your company details and article citations, in 11 EU languages. Preview free, download for €99 one-time. No subscription.
This page describes obligations under Regulation (EU) 2024/1689 as amended by the Omnibus published in the Official Journal on 24 July 2026, and was verified on 29 July 2026. It is general information rather than legal advice, and classification depends on your specific configuration and use. Review by qualified legal counsel is recommended before formal adoption of any compliance document.