AuditBird

Regulation (EU) 2024/1689

EU AI Act for SaaS Teams

Understand what the EU AI Act means for your company.

The EU AI Act uses a risk-based approach and your obligations can depend on what AI you build, provide or use. Learn the key requirements, deadlines and practical steps for SaaS teams.

  • Current for 2026
  • Official EU sources
  • Practical guidance
  • Free assessment

This guide provides general informational guidance and is not legal advice, an official EU assessment, certification, or a determination of compliance. EU AI Act obligations are fact-specific and may depend on details not covered here.

Need a structured read on your own use case? Run the free EU AI Act Checker. No account. No email. Immediate results — not an official assessment.

What is the EU AI Act?

The EU AI Act is Regulation (EU) 2024/1689 — an EU-wide legal framework for AI systems and general-purpose AI models. It is risk-based. Obligations vary with the operator’s role and with what the system or model is intended to do. The rules apply in stages; they did not all start on one date.

A small SaaS company may be affected even if AI is only one feature: a support chatbot, generated content, a recruitment helper, recommendations, biometrics, a third-party API, or a model you offer under your own name. Using AI does not automatically make a system high-risk.

Source: Regulation (EU) 2024/1689 (consolidated 27 July 2026) · Source: European Commission AI Act overview

Does the EU AI Act apply to non-EU companies?

Territorial scope can extend beyond companies established in the EU. The analysis is fact-specific. Having EU users is not, by itself, an automatic “yes.”

Placing on the EU market

Providers placing AI systems or GPAI models on the Union market may be in scope regardless of where they are established.

EU deployers

Deployers established or located in the Union are a core territorial hook.

Output used in the Union

Certain non-EU providers or deployers may be in scope where the output of the AI system is used in the Union.

Supply chain

Importers, distributors, and some product manufacturers also appear in the operator list.

If you are unsure whether offering, deploying, or producing output that is used in the EU engages Article 2, treat applicability as open until you review the facts. Not sure? Run the free EU AI Act Checker.

Source: Article 2

Understand your role

Roles are legal categories, not job titles. One company can hold more than one. A SaaS team might deploy a third-party model internally while acting as provider of an AI feature offered under its own product.

Provider

You develop an AI system — or have one developed — and offer it under your own name or trademark, whether or not you charge for it.

The legal definition also covers putting a system into service under your own name. Offering an AI-powered feature in your SaaS product can engage this role even if the underlying model is third-party.

Source: Article 3 · Source: Article 2

Deployer

You use an AI system under your company’s authority in a professional context — for example a vendor chatbot, HR screening tool, or internal copilot.

Personal, non-professional use is excluded. Deploying a system and providing a different system can both be true for the same company.

Source: Article 3 · Source: Article 2

Importer

You are established in the EU and place on the market an AI system that bears the name or trademark of a person established outside the EU.

Importer is a supply-chain role, distinct from developing the system yourself.

Source: Article 3 · Source: Article 2

Distributor

You make an AI system available on the EU market in the supply chain, without being the provider or the importer.

Putting your own name on a system, or substantially modifying it, can change which role you occupy — review required.

Source: Article 3 · Source: Article 2

GPAI model provider

You place a general-purpose AI model on the Union market. That is a different role from using someone else’s model through an API.

Calling a third-party LLM API does not automatically make you the provider of the underlying GPAI model. Fine-tuning or offering a model under your own name can change the analysis.

Source: Article 53 / Chapter V (GPAI) · Source: Article 3

The risk model

Classification depends on the actual use case and legal criteria. This is not a score, and it is not a universal four-tier pyramid that every system drops into cleanly.

Prohibited practices

See timing

Certain AI practices are banned when the legal conditions are met. This is not a list of every biometric or “sensitive” feature — the prohibition is specific and often includes exceptions.

Most Chapter II prohibitions have applied since 2 February 2025. Certain additional Article 5 points apply from 2 December 2026.

Source: Article 5 · Source: Article 113

High-risk AI systems

Later application date

A system may be high-risk because it is a safety component of a regulated product (Annex I route) or because its intended purpose falls into an Annex III use area — subject to Article 6 and possible derogations.

Core Annex III high-risk obligations: 2 December 2027. Annex I product-embedded rules: 2 August 2028. Classification review can start now.

Source: Article 6 · Source: Annex III

Transparency obligations (Article 50)

See timing

Separate duties for certain human–AI interaction, synthetic-content marking, deepfakes, public-interest text, and emotion recognition / biometric categorisation. Not every generated sentence must be labelled.

Article 50 has applied since 2 August 2026, with a limited Article 50(2) transition to 2 December 2026 for some systems already on the market.

Source: Article 50 · Source: Article 50 FAQ

Other AI systems

See timing

Many everyday uses are not high-risk. Providers and deployers may still have AI literacy duties, and Article 50 can still apply if the system interacts with people or generates certain content.

Literacy has applied since 2 February 2025; transparency since 2 August 2026 where Article 50 is engaged.

Source: Article 4 · Source: Article 50

Check your likely classification

Prohibited AI practices

Certain uses are prohibited when the legal conditions are met. Article 5 was amended in 2026. Exceptions and conditions exist — this section is a map, not a finding that your product is unlawful.

Manipulative or deceptive techniques

Certain systems that materially distort behaviour through subliminal, purposefully manipulative or deceptive techniques, where significant harm is caused or reasonably likely.

Exploitation of vulnerabilities

Certain systems that exploit vulnerabilities due to age, disability, or a specific social or economic situation, with material distortion and significant harm.

Social scoring

Certain evaluation or classification of people over time based on social behaviour or personal characteristics, where the resulting social score leads to specified detrimental treatment.

Individual criminal-offence prediction

Certain systems that assess or predict a person’s risk of committing a criminal offence based solely on profiling or personality traits are prohibited. Support for human assessment already based on objective facts linked to criminal activity is treated differently.

Untargeted facial-image scraping

Creating or expanding facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.

Emotion recognition in workplace or education

Inferring emotions in those areas is generally prohibited, with narrow medical or safety-related exceptions.

Biometric categorisation of sensitive attributes

Certain systems that categorise people from biometric data to infer characteristics such as race, political opinions, religion, or sexual orientation — with limited carve-outs.

Real-time remote biometric identification (law enforcement)

Use in publicly accessible spaces for law enforcement is generally prohibited, with strictly defined exceptions.

Additional 2026 prohibitions (from 2 December 2026)

The Digital Omnibus on AI added further Article 5 points covering certain non-consensual intimate/sexually explicit AI material and certain child-sexual-abuse material generation, subject to conditions. Those points apply from 2 December 2026.

If your use case touches biometrics, emotion recognition, manipulation, social scoring, criminal-offence prediction or similarly sensitive areas, obtain qualified legal review.

Source: Article 5 · Source: Regulation (EU) 2026/1744

High-risk AI systems

Two legal routes matter: AI as a safety component of certain regulated products (Annex I), and stand-alone use cases listed in Annex III. Not every AI system used in those industries is automatically high-risk.

Relevant later application date

As of October 2026, core high-risk obligations for Annex III systems apply from 2 December 2027. Annex I product-embedded rules apply from 2 August 2028. Those dates follow the Digital Omnibus on AI amendment of Article 113. Preparing a classification file now is still useful if you may be on either route.

Biometrics

Certain identification, categorisation and emotion-recognition systems — distinct from practices that may be prohibited under Article 5.

Critical infrastructure

Safety components of certain digital infrastructure, road traffic, and supply of water, gas, heating or electricity.

Education and vocational training

Admission, evaluating learning outcomes, assessing education level, and related uses — not every classroom tool.

Employment and workers’ management

Recruitment/selection, and certain decisions on work relationships, task allocation, or monitoring/evaluation of people.

Essential private and public services

Including certain creditworthiness, insurance, and essential public-benefit decisions — with stated exceptions such as some fraud detection.

Law enforcement, migration, justice

Several use cases in those domains. Highly fact-specific and may intersect prohibited-practice rules.

Provider duties may include

  • Risk management system
  • Data and data governance
  • Technical documentation
  • Record-keeping / logging
  • Transparency and instructions for use
  • Human oversight by design
  • Accuracy, robustness and cybersecurity
  • Quality management
  • Conformity assessment
  • Registration, where applicable

Not every item applies in every situation. These themes describe the high-risk provider framework once those rules apply to the system.

Deployer duties may include

  • Use according to instructions
  • Appropriate human oversight
  • Monitoring of operation
  • Relevant input-data responsibilities
  • Logging / record retention where required
  • Workplace information in applicable cases

Deployers of high-risk systems have operational duties distinct from providing the system. Collect provider documentation early.

Source: Article 6 · Source: Annex III

EU AI Act transparency requirements

Article 50 is one of the most operationally relevant parts of the Act for SaaS teams in 2026. It is not a single “label everything AI” rule. Provider duties and deployer duties differ. Exceptions apply.

Human–AI interaction

Providers of systems that interact directly with people should design them so people are informed they are interacting with AI, unless it is obvious from the circumstances.

Synthetic content marking (providers)

Providers of systems generating synthetic audio, image, video or text generally need machine-readable, detectable marking, subject to technical feasibility and exceptions such as limited assistive editing.

Deepfakes (deployers)

Deployers of systems that generate or manipulate image, audio or video constituting a deep fake may need to disclose that the content is artificially generated or manipulated, with limited exceptions.

Public-interest text (deployers)

Certain AI-generated or manipulated text published to inform the public on matters of public interest may require disclosure. This is not a rule that every marketing email must be labelled.

Emotion recognition / biometric categorisation

Deployers of those systems may need to inform exposed persons, in addition to any Article 5 analysis.

Article 50 has applied since 2 August 2026. A limited transition to 2 December 2026 exists for Article 50(2) marking of certain systems already on the market before 2 August 2026.

Does your website expose AI to users?

Scan publicly accessible pages for chatbot signals, disclosure language, and other AI transparency indicators. A scan cannot determine your full EU AI Act obligations.

Scan your website for AI transparency signals →

Source: Article 50 · Source: Article 50 FAQ

General-purpose AI models (GPAI)

Providing a GPAI model and using one are different analyses. A SaaS company calling a third-party LLM API generally should not be described as the provider of that underlying model. Integrating the model into a product you offer under your brand can still create provider or deployer duties for the AI system you place on the market.

Using a GPAI model

Inventory the vendor, how staff use it, and whether your product exposes it to customers. Literacy and transparency can still matter.

Fine-tuning or adapting

Substantial modification can shift who bears which duties. This page does not decide whether you become a GPAI model provider.

Providing a GPAI model

Chapter V duties (documentation, downstream information, copyright policy, training-data summary) have applied since 2 August 2025.

Systemic-risk models

Additional duties exist for GPAI models classified as presenting systemic risk. That designation is fact-specific and not something this page assigns.

Source: Article 53 / Chapter V (GPAI) · Source: Article 3

AI literacy

AI literacy measures have applied since 2 February 2025 for providers and deployers. AI literacy is not just an engineering responsibility. The law does not invent a mandatory certificate or a fixed number of training hours.

  • Identify which teams use AI, including contractors acting on your behalf
  • Give role-appropriate guidance — support, engineering, and hiring do not need the same briefing
  • Explain relevant limitations and risks of the tools you actually use
  • Set an escalation path for sensitive uses (people decisions, biometrics, public content)
  • Keep the programme proportionate to how the company uses AI

Source: Article 4 · Source: AI literacy Q&A

EU AI Act timeline

Status as of October 2026. August 2026 is not “upcoming.” High-risk dates reflect the Digital Omnibus on AI amendment of Article 113.

  1. 1 August 2024

    Applied

    Regulation enters into force

    Regulation (EU) 2024/1689 entered into force. Application of most obligations followed in stages.

    Source: Article 113 · Source: Regulation (EU) 2024/1689 (consolidated 27 July 2026)

  2. 2 February 2025

    Applied

    Prohibited practices and AI literacy

    Chapter I general provisions (including AI literacy) and Chapter II prohibitions became applicable.

    Source: Article 113 · Source: Article 4

  3. 2 August 2025

    Applied

    GPAI model rules and governance

    Obligations for providers of general-purpose AI models, related governance arrangements, and certain penalty rules became applicable.

    Source: Article 113 · Source: Article 53 / Chapter V (GPAI)

  4. 2 August 2026

    Current

    General application, including transparency

    The majority of the AI Act became applicable, including Article 50 transparency obligations. National and EU-level enforcement of applicable rules started for those provisions already in force.

    Source: Article 113 · Source: Article 50

  5. 2 December 2026

    Upcoming

    Additional prohibitions and synthetic-content transition

    Certain additional Article 5 prohibitions become applicable. Providers of systems already on the market before 2 August 2026 that generate synthetic content have a transitional deadline for Article 50(2) machine-readable marking.

    Source: Article 113 · Source: Implementation timeline

  6. 2 December 2027

    Upcoming

    Annex III high-risk obligations

    Core high-risk obligations for AI systems classified under Article 6(2) and Annex III (including many employment, education, credit and biometric use cases) apply from this date, following the Digital Omnibus on AI timeline update.

    Source: Article 113 · Source: Annex III

  7. 2 August 2028

    Upcoming

    Annex I product-embedded high-risk rules

    High-risk rules for AI systems that are safety components of products covered by Annex I Union harmonisation legislation apply from this date.

    Source: Article 113 · Source: European Commission AI Act overview

Last reviewed: October 2026 · Official source → AI Act Service Desk timeline

A practical EU AI Act starting point

The obligations that matter to a SaaS company depend on what the company does with AI and which legal role it occupies. Start here, then use the checker for a structured pass.

  1. 01

    Inventory AI systems and AI-enabled features

    Name what you build, buy, and use — including “just a feature” in the product.

  2. 02

    Separate internal vs customer-facing use

    Chatbots and public content raise different transparency questions than a private copilot.

  3. 03

    Map likely organizational roles

    Provider, deployer, importer, distributor — more than one can apply.

  4. 04

    Screen for prohibited-practice concerns

    Biometrics, emotion recognition, manipulation, social scoring, scraping. If you touch these, get legal review.

  5. 05

    Review potential high-risk use cases

    Employment, credit, education, essential services, and similar Annex III themes — classification is use-case specific.

  6. 06

    Review current Article 50 transparency duties

    These have applied since 2 August 2026 for the systems they cover.

  7. 07

    Identify GPAI dependencies

    Who provides the model, who fine-tunes, who offers the product under their brand.

  8. 08

    Establish proportionate AI literacy measures

    Guidance for the people who operate or use AI on your behalf — not a mandatory certificate.

  9. 09

    Assign ownership for AI governance

    Someone named should own inventory, vendors, and deadline tracking.

  10. 10

    Track applicable obligations and upcoming dates

    Especially Annex III (2 December 2027) and Annex I (2 August 2028) if those routes may apply.

Run the free EU AI Act Checker

What the EU AI Act means for SaaS companies

These examples are orientation, not determinations of compliance.

Customer support chatbot

Likely role analysis plus Article 50 interaction transparency. High-risk is not automatic from the word “chatbot.”

AI recruitment screening feature

Potential Annex III employment use. Review provider vs deployer roles and later high-risk application dates. Do not treat a CV filter as “already certified.”

Internal ChatGPT / Copilot use

Inventory, literacy, and data/security governance. Using a third-party LLM API does not automatically make you the GPAI model provider.

AI-generated marketing images

Synthetic-content and deployer disclosure analysis depends on context (including deepfake-like media). Not every generated asset carries the same duty.

EU AI Act vs GDPR

They are separate legal regimes. The AI Act addresses AI-system and model risk and governance. GDPR addresses personal-data processing. They can apply to the same system. The AI Act does not replace GDPR.

An AI recruitment tool that processes candidate data may raise both AI Act classification questions and GDPR questions (lawful basis, purpose limitation, DPIA where required). This page is not a GDPR assessment, and a dedicated GDPR hub is not live yet.

Not sure which requirements may apply?

Answer a few questions about how your company builds and uses AI. AuditBird will identify likely roles, risk areas, transparency considerations and practical next actions.

Free · No account · No email required · Immediate results

This is not an official assessment, legal determination, certification, or compliance test.

Run free EU AI Act assessment

One compliance program. Multiple frameworks and regulations.

Modern SaaS teams may need SOC 2, ISO 27001, the EU AI Act, GDPR, and other requirements. AuditBird is being built to help teams organize requirements, controls, policies, evidence, risks, vendors, owners and tasks across those programs.

  • SOC 2Current product focus, with live free tools.
  • ISO 27001Educational hub and checklist live; product support in development.
  • EU AI ActFree assessment live; broader program support in development.
  • GDPROften overlaps where personal data are processed. Dedicated product/pages not live yet.

Related: AI compliance, pricing, SOC 2, ISO 27001, ISO 27001 checklist.

Questions

The EU AI Act is Regulation (EU) 2024/1689, the European Union’s horizontal legal framework for AI systems and general-purpose AI models. It is risk-based: obligations depend on role, intended purpose, and the type of system or model — not on using “AI” as a label.

Turn AI requirements into an actual compliance plan.

ISO 27001 support and broader EU AI Act program features are in development. SOC 2 is the deepest product path today. Join early access for updates.

Run the free EU AI Act Checker

SOC 2 · ISO 27001 · EU AI Act · More coming