Regulatory Compliance · EU AI Act

EU AI Act Compliance Guide for SaaS & AI Companies (2025)

Deadline: 2 August 2026. The EU AI Act's high-risk AI obligations become fully applicable on that date. GPAI model obligations have already been in force since August 2025. This guide explains the risk classification framework, what each tier requires, and what SaaS companies and AI teams need to do before the deadline.

Decision-support only. Not a legal opinion. For binding EU AI Act analysis, retain licensed EU counsel.

1. The Five Risk Tiers

The EU AI Act classifies AI systems into five risk tiers. The tier determines what obligations apply. Classification flows from the system's intended purpose — not from the underlying technology.

Unacceptable risk

Banned outright under Article 5. Includes social scoring by governments, real-time remote biometric surveillance in public spaces (with narrow exceptions), AI exploiting vulnerabilities of specific groups, and subliminal manipulation.

Examples: Facial recognition databases scraped from social media, emotion-inference in workplaces, predictive policing targeting individuals.

High risk (Annex I)

AI systems that are safety components of products covered by existing EU product safety legislation — medical devices, machinery, civil aviation, railway systems, automotive, lifts.

Examples: An AI-powered diagnostic software module in a CE-marked medical device; an AI-assisted collision avoidance system in an autonomous vehicle.

High risk (Annex III)

Standalone AI systems in 8 specific use-case categories listed in Annex III of the regulation.

Examples: Biometric categorization; critical infrastructure management; education assessment; employment screening; essential services access (credit scoring, insurance); law enforcement risk assessment; migration and border control; administration of justice.

Limited risk

AI systems with specific transparency obligations under Articles 50-52. Must disclose that users are interacting with an AI.

Examples: Chatbots, AI-generated synthetic content, deepfake videos. Primary obligation: disclosure label.

Minimal risk

AI systems not covered by any of the above. No mandatory obligations, but voluntary codes of conduct apply.

Examples: AI-powered spam filters, recommendation engines, simple content classification.

2. The Eight Annex III High-Risk Categories

Annex III is the list that most SaaS and AI companies need to check. If your product falls into any of these 8 categories — regardless of how the underlying model was built or who trained it — you are the "provider" of a high-risk AI system.

#CategoryScope note
1Biometric systemsCategorization and emotion recognition
2Critical infrastructureManagement of roads, water, gas, electricity, internet, banking, public health
3Education and vocational trainingSystems determining access, admission, placement, grading, assessment
4Employment, workforce managementRecruitment, screening, task allocation, promotion, termination decisions
5Essential private servicesCredit scoring, insurance risk assessment, eligibility for essential public benefits
6Law enforcementRisk assessment, polygraphs, evidence reliability, crime analytics
7Migration, asylum, border controlRisk assessment, authentication, visa application decisions
8Administration of justiceJudicial decision support, dispute resolution, legal interpretation tools

3. General-Purpose AI (GPAI) Model Obligations

Articles 51-56 govern general-purpose AI models — foundation models and large language models that can be used for many tasks. These obligations apply to model providers, not to API consumers. But if you fine-tune a GPAI model on your own data and deploy it, you become a provider of a new GPAI model with your own obligations.

All GPAI models

Technical documentation; compliance with copyright law (training data provenance); make summary of training data publicly available; cooperate with AI Office requests

Systemic risk models (>10²⁵ FLOPs)

All above PLUS: adversarial testing (red-teaming); incident reporting to AI Office within 24 hours of serious incidents; cybersecurity measures; energy efficiency information

4. High-Risk System Obligations (Articles 9–15 + 43–72)

If your system is high-risk under Annex I or Annex III, these 10 obligations apply before you can place it on the EU market. Each has a specific Article citation.

1
Risk management system

Article 9: document risks throughout lifecycle; update with operational experience

2
Data governance

Article 10: training data relevance, bias testing, data quality measures

3
Technical documentation

Article 11 + Annex IV: complete technical file before market placement

4
Record-keeping

Article 12: automatic logging of operations; logs kept by deployers for at least 6 months

5
Transparency to deployers

Article 13: instructions for use, performance characteristics, limitations, intended purpose

6
Human oversight

Article 14: design must enable overseers to understand, monitor, and override the system

7
Accuracy, robustness, cybersecurity

Article 15: appropriate accuracy levels for intended purpose; resilience to adversarial inputs

8
Conformity assessment

Articles 43-49: self-assessment or third-party audit depending on Annex I vs Annex III; EU Declaration of Conformity; CE marking

9
Registration in EU database

Article 71: high-risk systems must be registered in the EU AI database before deployment

10
Post-market monitoring

Article 72: providers must implement monitoring plans; serious incident reporting to national authorities

5. EU AI Act Compliance Timeline

2024-08-01EU AI Act enters into force
2025-02-02Prohibited AI practices banned (Article 5)
2025-08-02GPAI model obligations apply (Articles 51-56)
2025-08-02Governance bodies operational (Articles 57-78)
2026-08-02High-risk AI systems obligations (Annex I + III) — THE KEY DEADLINE
2026-08-02Notified body assessments required for applicable Annex I systems
2027-08-02Annex I AI systems already on market before 2026-08-02 must comply
2030-01-01AI systems in Annex I products regulated under existing harmonized legislation must comply

Classify your AI system — free preview, no card required

Tell us how your system works. Get an Article 6 + Annex III risk tier, the specific obligations that apply, and a documentation checklist — free. Upgrade to a $99 full report or $49/mo monitoring to stay current as implementing regulations evolve.

Get Free AI Act Classification →

Contract Risk — $97

Review Your AI Vendor Agreements for EU AI Act Clauses in 60 Seconds

Deployers of high-risk AI systems must contractually secure technical documentation, conformity declarations, and post-market monitoring data from providers. GPAI model contracts must address copyright compliance and systemic risk management. BizLegal AI scans your AI contracts for missing EU AI Act provisions before your compliance obligation deadline.

Scan Your AI Contracts →

Frequently asked questions

My SaaS uses OpenAI or Claude as an API. Does the EU AI Act apply to me?

It depends on what you build with it. The GPAI model obligations (Articles 51-56) apply to the model providers (OpenAI, Anthropic). But if you build a system on top of a GPAI model that falls into an Annex III category — for example, an AI-powered employment screening tool, a credit risk tool, or a student assessment product — YOU are the "provider" of a high-risk AI system and the Annex III obligations apply to you, not just to OpenAI.

When does the EU AI Act apply extraterritorially to non-EU companies?

The EU AI Act applies to providers placing AI systems on the EU market, deployers using AI systems in the EU, and providers/deployers established outside the EU when the output of their AI system is used in the EU. A US SaaS company with EU customers, or an AI tool whose outputs affect EU individuals, is within scope even without a EU legal entity.

What is a "systemic risk" GPAI model?

A GPAI model trained with more than 10²⁵ floating-point operations (FLOPs) is presumed to carry systemic risk under Article 51. As of 2025, GPT-4, Gemini Ultra, Claude 3 Opus, and Llama 3 are in this category. Models in this tier face additional obligations: adversarial testing, serious incident reporting to the AI Office within 24 hours, cybersecurity measures, and energy consumption disclosure.

What is conformity assessment for high-risk AI?

Conformity assessment is the process by which a provider demonstrates that a high-risk AI system meets the requirements in Articles 9-15. For most Annex III systems, providers self-assess against their own technical documentation and issue an EU Declaration of Conformity. For AI systems in Annex I products that already require third-party certification (medical devices, machinery, etc.), the AI Act conformity assessment is integrated into the existing product certification.

What are the fines for non-compliance?

Article 99 sets a three-tier penalty structure. Deploying a prohibited AI practice (Article 5): up to €35M or 7% of global annual turnover, whichever is higher. Violating other obligations (high-risk, GPAI, transparency): up to €15M or 3% of global annual turnover. Providing false or misleading information to authorities: up to €7.5M or 1.5% of global annual turnover.

How long does EU AI Act compliance take to implement?

For a SaaS startup with one or two in-scope features: 4-8 weeks to complete the Article 6 classification, technical documentation, risk management system, and instructions for use. For a company with multiple high-risk systems or an Annex I product integration: 6-12 months, including third-party assessment. Starting with classification (free with BizLegal AI) takes 24 hours.

Related compliance resources

GDPR Compliance Checklist →SOC 2 Compliance Guide →EU AI Act Compliance Hub →AI Governance Framework →All Compliance Guides →