Skip to contentNew: Does ChatGPT recommend your brand? Free 60-second AI visibility check →
Research summary — consult EU AI Act / regulatory counsel for your specific use case

EU AI Act Checklist for SaaS (2026): The Compliance Punch List

By DDH Research Team at Digital Dashboard HubUpdated

Stop writing AI prompts from scratch.

Tell us your business + your task + your model. We write the prompt — perfectly tuned for ChatGPT, Claude, Grok, Gemini, Midjourney, or any model. Plus 500+ pre-built prompts in your library.

14 days, no card. Cancel in 2 clicks.

The EU AI Act (Regulation (EU) 2024/1689) is the world's first horizontal AI statute. It entered into force August 2024 with staged application: prohibited practices under Article 5 applied from 2 February 2025; GPAI provider obligations under Article 53 from 2 August 2025; high-risk system obligations under Annex III from 2 August 2026; full applicability for embedded products under Annex I from 2027.

Practical implication for B2B SaaS shipping into the EU in 2026: (1) classify your AI system under the Act's risk tiers; (2) implement Article 50 transparency for all AI interactions and AI-generated content; (3) if your system is Annex III high-risk, implement the full Article 9-29 obligations as a deployer (and Article 8-17 if you are also the provider); (4) document downstream of your GPAI provider's Article 53 work; (5) prepare for sectoral regulator and national competent authority scrutiny that ramps through 2026-2027.

This is a checklist, not a comprehensive legal analysis. Research summary, not legal advice. Verify your specific deployment with EU AI Act counsel. Related: /vs/eu-ai-act-vs-uk-data-protection-act-2018 · /calc/gdpr-compliance-cost-for-llm-apps-2026 · /blog/can-you-be-gdpr-compliant-using-chatgpt-2026.

Digital Dashboard Hub

Writing good prompts for ONE AI is hard. Writing them for GPT-5, Claude, Gemini, Perplexity, Midjourney and 6 more is a full-time job. DDH's AI Prompt Builder writes once, runs everywhere — locked to your niche, voice, and brand tone.

Free 14 days, no card — AICHAT30 = 30% off Pro.

EU AI Act applicability — staged dates and B2B SaaS practical impact

Feature
Date
Provision
Practical impact for SaaS
1 August 2024Entry into forceStatute is binding; staged application begins
2 February 2025Article 5 prohibited practices applicableConfirm none of your AI use cases fall under prohibited practices
2 August 2025Article 53 GPAI provider obligations applicableVerify your LLM vendor is a GPAI Code of Practice signer; document downstream
2 August 2026Annex III high-risk system obligations applicableIf your system is high-risk under Annex III, comply with Article 8-29 (provider + deployer)
2 August 2026Article 50 transparency obligations fully applicableAI interaction disclosure, AI-generated content labelling
2 August 2027Annex I high-risk (safety component of regulated products) applicableEmbedded AI in medical devices, machinery, automotive — verify conformity
Throughout 2026-2027National competent authority designation + harmonized standards publicationEU AI Office + member state authorities operationalize; standards emerge

Source: EU AI Act Regulation (EU) 2024/1689, official text at eur-lex.europa.eu/eli/reg/2024/1689/oj. EU AI Office at digital-strategy.ec.europa.eu/en/policies/ai-office. National competent authority designations published per member state; verify current designations as the Act rolls out.

Step 1 — risk classification for your AI system

The EU AI Act regulates AI systems on a risk-tiered basis. Classify yours:

Tier 0 — Prohibited (Article 5): manipulation exploiting vulnerabilities; social scoring by public authorities; real-time remote biometric ID in public spaces (narrow exceptions); predictive policing based solely on profiling; untargeted scraping of facial images; emotion inference in workplaces and educational institutions (narrow exceptions); biometric categorization inferring race, political opinions, sexual orientation, etc. If your system matches any prohibited practice, you cannot ship it in the EU. Penalties up to €35m or 7% worldwide turnover.

Tier 1 — High-risk (Annex III): AI systems used in: (1) biometric identification + categorization not prohibited; (2) management of critical infrastructure; (3) education and vocational training (admissions, scoring, behavior detection); (4) employment, worker management, access to self-employment (recruitment screening, performance evaluation); (5) access to private/public services and benefits (credit scoring, eligibility); (6) law enforcement; (7) migration, asylum, border control; (8) administration of justice. Plus safety components of products in Annex I (medical devices, machinery, automotive, etc.).

Tier 2 — Limited risk (Article 50 transparency): AI systems that interact with natural persons (chatbots), emotion recognition / biometric categorization systems, generative AI producing synthetic content. Article 50 transparency obligations apply.

Tier 3 — Minimal risk: everything else. Largely unregulated beyond GPAI provider downstream obligations.

Practical for B2B SaaS: most B2B SaaS lands in Tier 2 or Tier 3. HR-tech, credit-tech, ed-tech land in Tier 1 (Annex III). Healthcare AI as software-medical-device lands in Annex I (Tier 1 via the safety-component path). Document the classification in your AI inventory and DPIA.


Step 2 — Article 50 transparency for all AI surfaces

Article 50 applies broadly to limited-risk systems. Three categories:

(a) AI systems intended to interact directly with natural persons (chatbots, voice assistants, customer support AI): disclose to the user that they are interacting with an AI system, unless this is obvious to a reasonably well-informed natural person taking into account the circumstances. The disclosure should be at the start of the interaction.

(b) Emotion recognition / biometric categorization systems: inform affected natural persons of the operation of the system; process personal data per GDPR.

(c) Deep fakes / generative AI producing synthetic content: AI-generated or AI-manipulated image, audio, video, or text content must be labelled as AI-generated. Exceptions for clearly artistic, creative, satirical, or fictional purposes (with appropriate context). For text, the labelling obligation applies when the content is intended to inform the public on matters of public interest.

Practical implementation: add a disclosure to your AI chat surface ('I'm an AI assistant'). Add a watermark or visible label to AI-generated images/videos your product produces (C2PA Content Credentials is the emerging standard). Add a meta-label to AI-generated text where applicable.

Penalties for non-compliance with Article 50: up to €15m or 3% worldwide turnover. National competent authority enforcement.


Step 3 — GPAI provider downstream documentation

If you use a foundation model (Claude, GPT-5, Gemini, Llama, Mistral, etc.), you are a downstream deployer of a General-Purpose AI Model. Article 53 obligations apply to the GPAI provider (Anthropic, OpenAI, Google, Meta, Mistral, etc.), not to you directly — but you have a documentation interest in your provider's compliance.

What you need from your provider: (a) confirmation of GPAI Code of Practice signature (OpenAI, Anthropic, Google, Mistral signed in June 2025; xAI signed all but safety chapter; Meta did not sign — verify current signatory list at digital-strategy.ec.europa.eu); (b) access to or summary of the training data disclosure required under Article 53(1)(d); (c) the model technical documentation referenced for downstream providers / deployers; (d) the copyright policy disclosure.

Document in your file: which model(s) you use, the GPAI provider's name, the Code of Practice signature status, the date you verified, where the upstream documentation lives. This serves your Article 26 / 27 documentation if you're a high-risk deployer, and your accountability documentation in any case.

If your GPAI provider is not a Code of Practice signer (Meta Llama as of mid-2026 example): you bear a heavier evidentiary burden. The Code of Practice is the presumed-compliant route; without it, you must document the provider's Article 53 compliance via other means (provider's published documentation, attestation, third-party assessment). This is a real cost in vendor selection.


Step 4 — high-risk deployer obligations (Article 26-29)

If your AI system is high-risk under Annex III and you are the deployer, Article 26-29 obligations apply from 2 August 2026:

Article 26 — instructions for use: use the system in accordance with the instructions for use provided by the provider. Document your use case + parameters + how you use the system.

Article 26(2) — registration in the EU database: certain high-risk systems must be registered in the EU AI database (eu-ai-database.eu). Verify whether your category requires registration.

Article 26(4) — human oversight: implement the human oversight measures specified by the provider. For an LLM-powered tool making consequential decisions, this typically means clinician / loan officer / HR officer review of AI-generated outputs.

Article 26(5) — input data: ensure that input data is relevant and sufficiently representative for the intended purpose. Document data quality controls.

Article 26(6) — monitoring + risk reporting: monitor the operation of the high-risk system; report serious incidents to the provider and competent authority.

Article 27 — fundamental rights impact assessment (FRIA): public bodies and certain private deployers of Annex III systems must conduct a FRIA before first use. Document affected categories, expected harms, mitigation measures, individuals' rights, oversight mechanisms.

Article 28 — data protection impact assessment integration: combine the GDPR DPIA with the EU AI Act FRIA where possible.

Article 29 — log retention: high-risk AI system logs must be retained for at least 6 months (longer if national law requires).

Practical: build a high-risk AI deployment runbook covering each Article 26-29 obligation. Maintain the artifacts in your regulatory file.


Step 5 — high-risk provider obligations (if you're also the provider)

If you build and place on the market an Annex III high-risk AI system (e.g., your SaaS is an Annex III system itself, not just deploying one), you are also a provider. Article 8-17 obligations apply:

Article 9 — risk management system: document risk identification, analysis, evaluation, mitigation throughout the lifecycle.

Article 10 — data governance: training/validation/test datasets meet quality criteria for representativeness, completeness, accuracy, free from errors and biases.

Article 11 — technical documentation: extensive — system design, intended purpose, architecture, training data summary, performance evaluation, controls.

Article 12 — record-keeping: logs sufficient for traceability of the system's functioning throughout its lifecycle.

Article 13 — transparency to deployers: clear and complete information to allow deployers to interpret system output and use it appropriately.

Article 14 — human oversight: design measures so that natural persons can effectively oversee.

Article 15 — accuracy, robustness, cybersecurity: declared performance levels, robustness against errors and adversarial use.

Article 16 — quality management system across development and post-market.

Article 17 — conformity assessment: high-risk systems require a conformity assessment before placing on the market. Some via internal control (Module A); others via notified body (Module B).

Annex IV — technical documentation contents.

This is a substantial undertaking. Most B2B SaaS that fall under Annex III as providers (e.g., HR-tech, credit-tech) underestimated the lift in 2024-2025; the 2026-2027 implementation is the hard year. Budget significant engineering and legal investment.


Step 6 — sectoral overlays

The EU AI Act doesn't operate in a vacuum. Sectoral regulators have AI guidance:

Medical devices (MDR / IVDR): EU AI Act high-risk + Medical Device Regulation. Conformity assessment via notified body covers both regimes typically. EMA + national health authorities supervise.

Financial services (CRD VI, MiFID II, EBA / ESMA / EIOPA): banking, insurance, securities regulators have AI guidance on top of AI Act.

Employment law: works councils and employee representation may have rights to participate in AI deployment decisions in some member states.

Consumer law: Unfair Commercial Practices Directive applies to AI-generated misleading content.

Product liability: revised Product Liability Directive includes AI systems.

Sector-specific data: GDPR + sectoral data laws (eHealth, financial data, employment data) apply on top.

Practical: maintain a regulatory map per member state per sector you operate in. Update as the EU AI Act implementation guidance + harmonized standards emerge through 2026-2027.


Step 7 — competent authority and enforcement

Enforcement under the EU AI Act is multi-tiered:

EU AI Office (Commission level): oversees GPAI provider obligations. Located in DG CONNECT.

National competent authorities: each member state designates a national competent authority (typically the existing market surveillance or data protection authority) to enforce the high-risk system provisions.

Member state coordination: European Artificial Intelligence Board (EAIB) coordinates national authorities.

Penalties (Article 99): up to €35m or 7% worldwide turnover for prohibited practices; up to €15m or 3% for high-risk non-compliance; up to €7.5m or 1.5% for information obligations.

Enforcement posture in 2026: EU AI Office is staffing up; national authorities are publishing guidance. High-profile enforcement actions are expected but sparse through 2026, ramping through 2027.

Cross-border enforcement: cooperation between national competent authorities is built into the Act. A company operating across member states may face inquiries from multiple authorities; the Act provides for coordination.


Step 8 — practical artifacts your regulatory file must contain

Minimum artifacts for a B2B SaaS shipping AI into the EU in 2026:

(1) AI system inventory — list of every AI system your SaaS deploys, with risk classification, GPAI provider, deployment region.

(2) Risk classification rationale — for each AI system, the reasoning for its Tier 0 / 1 / 2 / 3 classification with reference to specific Annex III rows or Article 5 / 50 categories.

(3) DPIA — GDPR Article 35 DPIA covering the AI processing of personal data, integrated with EU AI Act risk assessment for high-risk systems.

(4) FRIA — for Annex III high-risk systems with public-body deployment or applicable private-sector use, the Article 27 fundamental rights impact assessment.

(5) Article 50 transparency artifacts — screenshots/UX flow showing AI interaction disclosure; labels for AI-generated content.

(6) GPAI provider documentation — your provider's Code of Practice signature evidence; the upstream documentation references.

(7) Deployer Article 26-29 artifacts — for high-risk: instructions for use, human oversight design, input data quality controls, monitoring procedure, log retention configuration.

(8) Privacy notice — covering AI processing per GDPR Articles 13/14 + EU AI Act Article 50 disclosures.

(9) Workforce training records — covering AI use policy, prompt-injection awareness, incident reporting.

(10) Incident response playbook — covering AI-specific failure modes, serious-incident reporting to provider + competent authority per Article 73.

(11) Vendor inventory and DPAs — LLM vendor and other AI supplier contracts including DPA + EU SCCs.

(12) Annual refresh schedule — when each artifact is reviewed and updated.

Frequently Asked Questions

Is my B2B SaaS subject to the EU AI Act?

If your SaaS uses AI and you offer it to customers in the EU (or your AI processes data of EU residents), yes — subject to the relevant tier of obligations. Tier classification determines the depth of work.

When do EU AI Act obligations start applying?

Staged: prohibited practices (Article 5) from 2 February 2025; GPAI provider obligations from 2 August 2025; high-risk system obligations under Annex III from 2 August 2026; Annex I embedded high-risk from 2 August 2027.

What's the simplest path to Article 50 transparency?

Add a disclosure at the start of any AI interaction ('You're chatting with an AI assistant'). Label AI-generated images / videos with C2PA Content Credentials. Label AI-generated text where the content is intended to inform on matters of public interest. Document the implementation in your DPIA.

Is my chatbot high-risk?

Generally no unless it's used in an Annex III context (recruitment screening, credit scoring, education admissions, etc.). Most general-purpose B2B chatbots are limited-risk (Tier 2) with only Article 50 transparency applying. Always verify against Annex III for your specific use case.

Do I need to register in the EU AI database?

Only certain high-risk systems require registration per Article 49 + 26(2). Stand-alone Annex III high-risk AI systems generally register. Safety components of products in Annex I follow the product registration regime. Verify per your specific category.

What's the GPAI Code of Practice and why does it matter?

The Commission's Code of Practice for general-purpose AI models is the presumed-compliant route for Article 53 GPAI provider obligations. Signing implies compliance baseline. OpenAI, Anthropic, Google, Mistral signed in June 2025; xAI signed all but safety chapter; Meta did not sign. For deployers, picking a signer reduces evidentiary burden.

What are the penalties for non-compliance?

Up to €35m or 7% of worldwide turnover for prohibited practices; up to €15m or 3% for high-risk non-compliance; up to €7.5m or 1.5% for information obligations. Enforced by national competent authorities (high-risk) and the EU AI Office (GPAI providers).

How does the EU AI Act interact with GDPR?

They overlap on data processing for AI training and AI inference. GDPR is the data-protection layer; EU AI Act is the AI-specific layer. Article 28 of the AI Act expects DPIA + FRIA integration. Most artifacts (privacy notice, DPIA, transparency disclosure) can be combined to serve both regimes.

EU AI Act mapped. Now ship Act-aware prompts.

The Act picks the framework. Your prompt determines whether each compliant call earns its rate. AI Prompts Hub writes EU AI Act-aware, transparency-by-default, minimum-necessary prompts (OpenAI / Claude / Azure / Bedrock / Vertex) — so your compliance work turns into real ROI.

Browse all prompt tools →