EU AI Act Compliance Guide for SaaS & AI Companies (2025)
Deadline: 2 August 2026. The EU AI Act's high-risk AI obligations become fully applicable on that date. GPAI model obligations have already been in force since August 2025. This guide explains the risk classification framework, what each tier requires, and what SaaS companies and AI teams need to do before the deadline.
1. The Five Risk Tiers
The EU AI Act classifies AI systems into five risk tiers. The tier determines what obligations apply. Classification flows from the system's intended purpose — not from the underlying technology.
Banned outright under Article 5. Includes social scoring by governments, real-time remote biometric surveillance in public spaces (with narrow exceptions), AI exploiting vulnerabilities of specific groups, and subliminal manipulation.
Examples: Facial recognition databases scraped from social media, emotion-inference in workplaces, predictive policing targeting individuals.
AI systems that are safety components of products covered by existing EU product safety legislation — medical devices, machinery, civil aviation, railway systems, automotive, lifts.
Examples: An AI-powered diagnostic software module in a CE-marked medical device; an AI-assisted collision avoidance system in an autonomous vehicle.
Standalone AI systems in 8 specific use-case categories listed in Annex III of the regulation.
Examples: Biometric categorization; critical infrastructure management; education assessment; employment screening; essential services access (credit scoring, insurance); law enforcement risk assessment; migration and border control; administration of justice.
AI systems with specific transparency obligations under Articles 50-52. Must disclose that users are interacting with an AI.
Examples: Chatbots, AI-generated synthetic content, deepfake videos. Primary obligation: disclosure label.
AI systems not covered by any of the above. No mandatory obligations, but voluntary codes of conduct apply.
Examples: AI-powered spam filters, recommendation engines, simple content classification.
2. The Eight Annex III High-Risk Categories
Annex III is the list that most SaaS and AI companies need to check. If your product falls into any of these 8 categories — regardless of how the underlying model was built or who trained it — you are the "provider" of a high-risk AI system.
| # | Category | Scope note |
|---|---|---|
| 1 | Biometric systems | Categorization and emotion recognition |
| 2 | Critical infrastructure | Management of roads, water, gas, electricity, internet, banking, public health |
| 3 | Education and vocational training | Systems determining access, admission, placement, grading, assessment |
| 4 | Employment, workforce management | Recruitment, screening, task allocation, promotion, termination decisions |
| 5 | Essential private services | Credit scoring, insurance risk assessment, eligibility for essential public benefits |
| 6 | Law enforcement | Risk assessment, polygraphs, evidence reliability, crime analytics |
| 7 | Migration, asylum, border control | Risk assessment, authentication, visa application decisions |
| 8 | Administration of justice | Judicial decision support, dispute resolution, legal interpretation tools |
3. General-Purpose AI (GPAI) Model Obligations
Articles 51-56 govern general-purpose AI models — foundation models and large language models that can be used for many tasks. These obligations apply to model providers, not to API consumers. But if you fine-tune a GPAI model on your own data and deploy it, you become a provider of a new GPAI model with your own obligations.
Technical documentation; compliance with copyright law (training data provenance); make summary of training data publicly available; cooperate with AI Office requests
All above PLUS: adversarial testing (red-teaming); incident reporting to AI Office within 24 hours of serious incidents; cybersecurity measures; energy efficiency information
4. High-Risk System Obligations (Articles 9–15 + 43–72)
If your system is high-risk under Annex I or Annex III, these 10 obligations apply before you can place it on the EU market. Each has a specific Article citation.
Article 9: document risks throughout lifecycle; update with operational experience
Article 10: training data relevance, bias testing, data quality measures
Article 11 + Annex IV: complete technical file before market placement
Article 12: automatic logging of operations; logs kept by deployers for at least 6 months
Article 13: instructions for use, performance characteristics, limitations, intended purpose
Article 14: design must enable overseers to understand, monitor, and override the system
Article 15: appropriate accuracy levels for intended purpose; resilience to adversarial inputs
Articles 43-49: self-assessment or third-party audit depending on Annex I vs Annex III; EU Declaration of Conformity; CE marking
Article 71: high-risk systems must be registered in the EU AI database before deployment
Article 72: providers must implement monitoring plans; serious incident reporting to national authorities
5. EU AI Act Compliance Timeline
Classify your AI system — free preview, no card required
Tell us how your system works. Get an Article 6 + Annex III risk tier, the specific obligations that apply, and a documentation checklist — free. Upgrade to a $99 full report or $49/mo monitoring to stay current as implementing regulations evolve.
Get Free AI Act Classification →Contract Risk — $97
Review Your AI Vendor Agreements for EU AI Act Clauses in 60 Seconds
Deployers of high-risk AI systems must contractually secure technical documentation, conformity declarations, and post-market monitoring data from providers. GPAI model contracts must address copyright compliance and systemic risk management. BizLegal AI scans your AI contracts for missing EU AI Act provisions before your compliance obligation deadline.
Scan Your AI Contracts →Frequently asked questions
My SaaS uses OpenAI or Claude as an API. Does the EU AI Act apply to me?
It depends on what you build with it. The GPAI model obligations (Articles 51-56) apply to the model providers (OpenAI, Anthropic). But if you build a system on top of a GPAI model that falls into an Annex III category — for example, an AI-powered employment screening tool, a credit risk tool, or a student assessment product — YOU are the "provider" of a high-risk AI system and the Annex III obligations apply to you, not just to OpenAI.
When does the EU AI Act apply extraterritorially to non-EU companies?
The EU AI Act applies to providers placing AI systems on the EU market, deployers using AI systems in the EU, and providers/deployers established outside the EU when the output of their AI system is used in the EU. A US SaaS company with EU customers, or an AI tool whose outputs affect EU individuals, is within scope even without a EU legal entity.
What is a "systemic risk" GPAI model?
A GPAI model trained with more than 10²⁵ floating-point operations (FLOPs) is presumed to carry systemic risk under Article 51. As of 2025, GPT-4, Gemini Ultra, Claude 3 Opus, and Llama 3 are in this category. Models in this tier face additional obligations: adversarial testing, serious incident reporting to the AI Office within 24 hours, cybersecurity measures, and energy consumption disclosure.
What is conformity assessment for high-risk AI?
Conformity assessment is the process by which a provider demonstrates that a high-risk AI system meets the requirements in Articles 9-15. For most Annex III systems, providers self-assess against their own technical documentation and issue an EU Declaration of Conformity. For AI systems in Annex I products that already require third-party certification (medical devices, machinery, etc.), the AI Act conformity assessment is integrated into the existing product certification.
What are the fines for non-compliance?
Article 99 sets a three-tier penalty structure. Deploying a prohibited AI practice (Article 5): up to €35M or 7% of global annual turnover, whichever is higher. Violating other obligations (high-risk, GPAI, transparency): up to €15M or 3% of global annual turnover. Providing false or misleading information to authorities: up to €7.5M or 1.5% of global annual turnover.
How long does EU AI Act compliance take to implement?
For a SaaS startup with one or two in-scope features: 4-8 weeks to complete the Article 6 classification, technical documentation, risk management system, and instructions for use. For a company with multiple high-risk systems or an Annex I product integration: 6-12 months, including third-party assessment. Starting with classification (free with BizLegal AI) takes 24 hours.