Skip to content
Amended. Regulation (EU) 2026/1744 entered into force 27 July 2026. See what moved →
EU AI Act ChecklistIndependent reference
Industry guide · B2B SaaS

EU AI Act for B2B SaaS

SaaS breaks the Regulation’s mental model of a product placed on a market. You ship continuously, your customers configure the system, and the logs sit on your infrastructure while the obligation to retain them may sit with them. Three specific problems follow, and contracts are where all three get solved or missed.

Arts. 19, 25, 26(6), 43(4)Art. 50 live now
Classification route. You are usually the provider. Your customer is usually the deployer. Article 25 can move either of you.

What is in scope, and what is not

 Detail
You are the provider ifYou develop the AI system and place it on the EU market or put it into service under your own name or trade mark, whether for payment or free of charge
Your customer is the deployerUsing the system under their own authority. They owe Article 26 use-time obligations and, in some cases, an Article 27 FRIA
Either of you can become a providerUnder Article 25: by white-labelling, by substantial modification, or by changing the intended purpose so the system becomes high-risk

Expert analysis. Classification turns on the intended purpose of each system. This is our reading of common deployments, not an authoritative classification.

Where this usually goes next

Three situations account for most people reading this page. Each has a different answer.

A deal is blocked on an AI questionnaire

Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.

How this works for AI companies →

You need ISO/IEC 42001 documentation

23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.

Free gap assessment →
See the three tiers →

You are not sure what reaches you

Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.

Book a free 20-minute call →

This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →

Your customer can make themselves a provider using your product

You ship a general-purpose text analysis feature. A customer points it at CV screening. Under Article 25 they have modified the intended purpose so that the system becomes high-risk, and they are now the provider of a high-risk AI system, with a conformity assessment they have never heard of.

Three consequences for you.

You will be asked for the file. Where the shift happens, the original provider must supply the information reasonably needed for the new provider to comply, unless they clearly specified that the system was not to be changed into a high-risk one. That exception is a contract clause and a documentation choice you should make deliberately.

Your registered intended purpose constrains you. If you market the feature for candidate screening, you may be the provider yourself.

Customer configuration is a risk surface. Knowing what customers actually do with the product is now a compliance input, not just a product-analytics one. Role analysis →

The logs gap and the release cadence

  • “Under their control” produces a real gap. Article 19 obliges providers to retain logs under their control for at least six months; Article 26(6) obliges deployers to retain logs under theirs. In multi-tenant SaaS the provider usually holds everything and the deployer holds nothing, which leaves the deployer unable to meet an obligation they still owe. Solve it contractually: state who holds what, retention period, and how the customer obtains logs inside a two-day incident window.
  • Continuous deployment meets Article 43(4). A substantial modification triggers a fresh conformity assessment, but changes pre-determined at initial assessment and described in the technical documentation are not substantial. Your declared change envelope therefore sets your release freedom, and it must be drawn before the first assessment.
  • Article 73 clocks do not align. Your customer's two-day clock and your fifteen-day clock are different clocks. Contract the notification chain explicitly.
  • Multi-jurisdiction reporting. Serious incidents are reported to the authorities of the member state where the incident occurred. For a pan-EU customer base that can be several.

What applies before December 2027

Article 50 applies now to any in-product assistant, chatbot or generative feature, at any risk tier. Article 4 literacy applies to you and to your customers.

The deferral in Regulation (EU) 2026/1744 covers Chapter III Sections 1 to 3. It does not cover Article 5, Article 4, Chapter V general-purpose AI, Article 49 registration or Article 50 transparency. Full timeline →

Status labels on this page

Verified fact: The Annex III points, article references and dates cited above, checked against the consolidated Regulation and the Commission's AI Act Service Desk.

Expert analysis: The in-scope/out-of-scope allocation, the sector edge case, and the parallel-regulation reading.

Unsettled: Harmonised standards remain in development and the Commission's Annex III guidelines are in draft. Sector supervisory practice has not yet formed.

Next step

Answer the questionnaire before it arrives

Enterprise buyers are asking how AI is governed well ahead of any regulatory deadline. A published position, an inventory and a management system answer it once instead of per deal.

Classify before you build

Twelve questions mapping your system against Articles 5, 6, 50 and Annex III. No email required.

Run the classifier →

Frequently asked

Is a SaaS company a provider or a deployer under the EU AI Act?

A SaaS company that develops an AI system and places it on the EU market or puts it into service under its own name or trade mark is a provider. Its customers using the system under their own authority are deployers. Article 25 can move either party: a customer that modifies the intended purpose so that the system becomes high-risk becomes a provider itself.

Who keeps the logs in a SaaS deployment?

Both parties owe retention for the logs under their own control. Article 19 requires providers to retain logs automatically generated by their high-risk AI systems, to the extent under their control, for at least six months. Article 26(6) places a parallel obligation on deployers. In multi-tenant SaaS the provider typically holds the logs, which can leave the deployer unable to meet an obligation it still owes unless the contract provides access.

Does every SaaS release need a new conformity assessment?

No. Article 43(4) treats a substantial modification as triggering a fresh assessment, but changes pre-determined by the provider at the time of the initial conformity assessment and described in the technical documentation are not substantial modifications. The breadth of that declared change envelope determines release freedom and must be set before the first assessment.