Placing on the EU market
Providers placing AI systems or GPAI models on the Union market may be in scope regardless of where they are established.
Regulation (EU) 2024/1689
Understand what the EU AI Act means for your company.
The EU AI Act uses a risk-based approach and your obligations can depend on what AI you build, provide or use. Learn the key requirements, deadlines and practical steps for SaaS teams.
This guide provides general informational guidance and is not legal advice, an official EU assessment, certification, or a determination of compliance. EU AI Act obligations are fact-specific and may depend on details not covered here.
Need a structured read on your own use case? Run the free EU AI Act Checker. No account. No email. Immediate results — not an official assessment.
The EU AI Act is Regulation (EU) 2024/1689 — an EU-wide legal framework for AI systems and general-purpose AI models. It is risk-based. Obligations vary with the operator’s role and with what the system or model is intended to do. The rules apply in stages; they did not all start on one date.
A small SaaS company may be affected even if AI is only one feature: a support chatbot, generated content, a recruitment helper, recommendations, biometrics, a third-party API, or a model you offer under your own name. Using AI does not automatically make a system high-risk.
Source: Regulation (EU) 2024/1689 (consolidated 27 July 2026) · Source: European Commission AI Act overview
Territorial scope can extend beyond companies established in the EU. The analysis is fact-specific. Having EU users is not, by itself, an automatic “yes.”
Providers placing AI systems or GPAI models on the Union market may be in scope regardless of where they are established.
Deployers established or located in the Union are a core territorial hook.
Certain non-EU providers or deployers may be in scope where the output of the AI system is used in the Union.
Importers, distributors, and some product manufacturers also appear in the operator list.
If you are unsure whether offering, deploying, or producing output that is used in the EU engages Article 2, treat applicability as open until you review the facts. Not sure? Run the free EU AI Act Checker.
Roles are legal categories, not job titles. One company can hold more than one. A SaaS team might deploy a third-party model internally while acting as provider of an AI feature offered under its own product.
You develop an AI system — or have one developed — and offer it under your own name or trademark, whether or not you charge for it.
The legal definition also covers putting a system into service under your own name. Offering an AI-powered feature in your SaaS product can engage this role even if the underlying model is third-party.
You use an AI system under your company’s authority in a professional context — for example a vendor chatbot, HR screening tool, or internal copilot.
Personal, non-professional use is excluded. Deploying a system and providing a different system can both be true for the same company.
You are established in the EU and place on the market an AI system that bears the name or trademark of a person established outside the EU.
Importer is a supply-chain role, distinct from developing the system yourself.
You make an AI system available on the EU market in the supply chain, without being the provider or the importer.
Putting your own name on a system, or substantially modifying it, can change which role you occupy — review required.
You place a general-purpose AI model on the Union market. That is a different role from using someone else’s model through an API.
Calling a third-party LLM API does not automatically make you the provider of the underlying GPAI model. Fine-tuning or offering a model under your own name can change the analysis.
Classification depends on the actual use case and legal criteria. This is not a score, and it is not a universal four-tier pyramid that every system drops into cleanly.
Certain AI practices are banned when the legal conditions are met. This is not a list of every biometric or “sensitive” feature — the prohibition is specific and often includes exceptions.
Most Chapter II prohibitions have applied since 2 February 2025. Certain additional Article 5 points apply from 2 December 2026.
A system may be high-risk because it is a safety component of a regulated product (Annex I route) or because its intended purpose falls into an Annex III use area — subject to Article 6 and possible derogations.
Core Annex III high-risk obligations: 2 December 2027. Annex I product-embedded rules: 2 August 2028. Classification review can start now.
Separate duties for certain human–AI interaction, synthetic-content marking, deepfakes, public-interest text, and emotion recognition / biometric categorisation. Not every generated sentence must be labelled.
Article 50 has applied since 2 August 2026, with a limited Article 50(2) transition to 2 December 2026 for some systems already on the market.
Providers of general-purpose AI models have Chapter V duties. Using a third-party model is usually a different analysis from providing one.
GPAI provider rules have applied since 2 August 2025.
Many everyday uses are not high-risk. Providers and deployers may still have AI literacy duties, and Article 50 can still apply if the system interacts with people or generates certain content.
Literacy has applied since 2 February 2025; transparency since 2 August 2026 where Article 50 is engaged.
Certain uses are prohibited when the legal conditions are met. Article 5 was amended in 2026. Exceptions and conditions exist — this section is a map, not a finding that your product is unlawful.
Certain systems that materially distort behaviour through subliminal, purposefully manipulative or deceptive techniques, where significant harm is caused or reasonably likely.
Certain systems that exploit vulnerabilities due to age, disability, or a specific social or economic situation, with material distortion and significant harm.
Certain evaluation or classification of people over time based on social behaviour or personal characteristics, where the resulting social score leads to specified detrimental treatment.
Certain systems that assess or predict a person’s risk of committing a criminal offence based solely on profiling or personality traits are prohibited. Support for human assessment already based on objective facts linked to criminal activity is treated differently.
Creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.
Inferring emotions in those areas is generally prohibited, with narrow medical or safety-related exceptions.
Certain systems that categorise people from biometric data to infer characteristics such as race, political opinions, religion, or sexual orientation — with limited carve-outs.
Use in publicly accessible spaces for law enforcement is generally prohibited, with strictly defined exceptions.
The Digital Omnibus on AI added further Article 5 points covering certain non-consensual intimate/sexually explicit AI material and certain child-sexual-abuse material generation, subject to conditions. Those points apply from 2 December 2026.
If your use case touches biometrics, emotion recognition, manipulation, social scoring, criminal-offence prediction or similarly sensitive areas, obtain qualified legal review.
Two legal routes matter: AI as a safety component of certain regulated products (Annex I), and stand-alone use cases listed in Annex III. Not every AI system used in those industries is automatically high-risk.
Relevant later application date
As of October 2026, core high-risk obligations for Annex III systems apply from 2 December 2027. Annex I product-embedded rules apply from 2 August 2028. Those dates follow the Digital Omnibus on AI amendment of Article 113. Preparing a classification file now is still useful if you may be on either route.
Certain identification, categorisation and emotion-recognition systems — distinct from practices that may be prohibited under Article 5.
Safety components of certain digital infrastructure, road traffic, and supply of water, gas, heating or electricity.
Admission, evaluating learning outcomes, assessing education level, and related uses — not every classroom tool.
Recruitment/selection, and certain decisions on work relationships, task allocation, or monitoring/evaluation of people.
Including certain creditworthiness, insurance, and essential public-benefit decisions — with stated exceptions such as some fraud detection.
Several use cases in those domains. Highly fact-specific and may intersect prohibited-practice rules.
Not every item applies in every situation. These themes describe the high-risk provider framework once those rules apply to the system.
Deployers of high-risk systems have operational duties distinct from providing the system. Collect provider documentation early.
Article 50 is one of the most operationally relevant parts of the Act for SaaS teams in 2026. It is not a single “label everything AI” rule. Provider duties and deployer duties differ. Exceptions apply.
Providers of systems that interact directly with people should design them so people are informed they are interacting with AI, unless it is obvious from the circumstances.
Providers of systems generating synthetic audio, image, video or text generally need machine-readable, detectable marking, subject to technical feasibility and exceptions such as limited assistive editing.
Deployers of systems that generate or manipulate image, audio or video constituting a deep fake may need to disclose that the content is artificially generated or manipulated, with limited exceptions.
Certain AI-generated or manipulated text published to inform the public on matters of public interest may require disclosure. This is not a rule that every marketing email must be labelled.
Deployers of those systems may need to inform exposed persons, in addition to any Article 5 analysis.
Article 50 has applied since 2 August 2026. A limited transition to 2 December 2026 exists for Article 50(2) marking of certain systems already on the market before 2 August 2026.
Does your website expose AI to users?
Scan publicly accessible pages for chatbot signals, disclosure language, and other AI transparency indicators. A scan cannot determine your full EU AI Act obligations.
Providing a GPAI model and using one are different analyses. A SaaS company calling a third-party LLM API generally should not be described as the provider of that underlying model. Integrating the model into a product you offer under your brand can still create provider or deployer duties for the AI system you place on the market.
Inventory the vendor, how staff use it, and whether your product exposes it to customers. Literacy and transparency can still matter.
Substantial modification can shift who bears which duties. This page does not decide whether you become a GPAI model provider.
Chapter V duties (documentation, downstream information, copyright policy, training-data summary) have applied since 2 August 2025.
Additional duties exist for GPAI models classified as presenting systemic risk. That designation is fact-specific and not something this page assigns.
AI literacy measures have applied since 2 February 2025 for providers and deployers. AI literacy is not just an engineering responsibility. The law does not invent a mandatory certificate or a fixed number of training hours.
Status as of October 2026. August 2026 is not “upcoming.” High-risk dates reflect the Digital Omnibus on AI amendment of Article 113.
1 August 2024
AppliedRegulation enters into force
Regulation (EU) 2024/1689 entered into force. Application of most obligations followed in stages.
Source: Article 113 · Source: Regulation (EU) 2024/1689 (consolidated 27 July 2026)
2 February 2025
AppliedProhibited practices and AI literacy
Chapter I general provisions (including AI literacy) and Chapter II prohibitions became applicable.
2 August 2025
AppliedGPAI model rules and governance
Obligations for providers of general-purpose AI models, related governance arrangements, and certain penalty rules became applicable.
2 August 2026
CurrentGeneral application, including transparency
The majority of the AI Act became applicable, including Article 50 transparency obligations. National and EU-level enforcement of applicable rules started for those provisions already in force.
2 December 2026
UpcomingAdditional prohibitions and synthetic-content transition
Certain additional Article 5 prohibitions become applicable. Providers of systems already on the market before 2 August 2026 that generate synthetic content have a transitional deadline for Article 50(2) machine-readable marking.
2 December 2027
UpcomingAnnex III high-risk obligations
Core high-risk obligations for AI systems classified under Article 6(2) and Annex III (including many employment, education, credit and biometric use cases) apply from this date, following the Digital Omnibus on AI timeline update.
2 August 2028
UpcomingAnnex I product-embedded high-risk rules
High-risk rules for AI systems that are safety components of products covered by Annex I Union harmonisation legislation apply from this date.
Source: Article 113 · Source: European Commission AI Act overview
Last reviewed: October 2026 · Official source → AI Act Service Desk timeline
The obligations that matter to a SaaS company depend on what the company does with AI and which legal role it occupies. Start here, then use the checker for a structured pass.
Inventory AI systems and AI-enabled features
Name what you build, buy, and use — including “just a feature” in the product.
Separate internal vs customer-facing use
Chatbots and public content raise different transparency questions than a private copilot.
Map likely organizational roles
Provider, deployer, importer, distributor — more than one can apply.
Screen for prohibited-practice concerns
Biometrics, emotion recognition, manipulation, social scoring, scraping. If you touch these, get legal review.
Review potential high-risk use cases
Employment, credit, education, essential services, and similar Annex III themes — classification is use-case specific.
Review current Article 50 transparency duties
These have applied since 2 August 2026 for the systems they cover.
Identify GPAI dependencies
Who provides the model, who fine-tunes, who offers the product under their brand.
Establish proportionate AI literacy measures
Guidance for the people who operate or use AI on your behalf — not a mandatory certificate.
Assign ownership for AI governance
Someone named should own inventory, vendors, and deadline tracking.
Track applicable obligations and upcoming dates
Especially Annex III (2 December 2027) and Annex I (2 August 2028) if those routes may apply.
These examples are orientation, not determinations of compliance.
Likely role analysis plus Article 50 interaction transparency. High-risk is not automatic from the word “chatbot.”
Potential Annex III employment use. Review provider vs deployer roles and later high-risk application dates. Do not treat a CV filter as “already certified.”
Inventory, literacy, and data/security governance. Using a third-party LLM API does not automatically make you the GPAI model provider.
Synthetic-content and deployer disclosure analysis depends on context (including deepfake-like media). Not every generated asset carries the same duty.
They are separate legal regimes. The AI Act addresses AI-system and model risk and governance. GDPR addresses personal-data processing. They can apply to the same system. The AI Act does not replace GDPR.
An AI recruitment tool that processes candidate data may raise both AI Act classification questions and GDPR questions (lawful basis, purpose limitation, DPIA where required). This page is not a GDPR assessment, and a dedicated GDPR hub is not live yet.
Answer a few questions about how your company builds and uses AI. AuditBird will identify likely roles, risk areas, transparency considerations and practical next actions.
Free · No account · No email required · Immediate results
This is not an official assessment, legal determination, certification, or compliance test.
Modern SaaS teams may need SOC 2, ISO 27001, the EU AI Act, GDPR, and other requirements. AuditBird is being built to help teams organize requirements, controls, policies, evidence, risks, vendors, owners and tasks across those programs.
Related: AI compliance, pricing, SOC 2, ISO 27001, ISO 27001 checklist.
The EU AI Act is Regulation (EU) 2024/1689, the European Union’s horizontal legal framework for AI systems and general-purpose AI models. It is risk-based: obligations depend on role, intended purpose, and the type of system or model — not on using “AI” as a label.
ISO 27001 support and broader EU AI Act program features are in development. SOC 2 is the deepest product path today. Join early access for updates.
Run the free EU AI Act Checker
SOC 2 · ISO 27001 · EU AI Act · More coming