EU AI Act for B2B SaaS
SaaS breaks the Regulation’s mental model of a product placed on a market. You ship continuously, your customers configure the system, and the logs sit on your infrastructure while the obligation to retain them may sit with them. Three specific problems follow, and contracts are where all three get solved or missed.
What is in scope, and what is not
| Detail | |
|---|---|
| You are the provider if | You develop the AI system and place it on the EU market or put it into service under your own name or trade mark, whether for payment or free of charge |
| Your customer is the deployer | Using the system under their own authority. They owe Article 26 use-time obligations and, in some cases, an Article 27 FRIA |
| Either of you can become a provider | Under Article 25: by white-labelling, by substantial modification, or by changing the intended purpose so the system becomes high-risk |
Expert analysis. Classification turns on the intended purpose of each system. This is our reading of common deployments, not an authoritative classification.
Where this usually goes next
Three situations account for most people reading this page. Each has a different answer.
A deal is blocked on an AI questionnaire
Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.
You need ISO/IEC 42001 documentation
23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.
You are not sure what reaches you
Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.
This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →
Your customer can make themselves a provider using your product
You ship a general-purpose text analysis feature. A customer points it at CV screening. Under Article 25 they have modified the intended purpose so that the system becomes high-risk, and they are now the provider of a high-risk AI system, with a conformity assessment they have never heard of.
Three consequences for you.
You will be asked for the file. Where the shift happens, the original provider must supply the information reasonably needed for the new provider to comply, unless they clearly specified that the system was not to be changed into a high-risk one. That exception is a contract clause and a documentation choice you should make deliberately.
Your registered intended purpose constrains you. If you market the feature for candidate screening, you may be the provider yourself.
Customer configuration is a risk surface. Knowing what customers actually do with the product is now a compliance input, not just a product-analytics one. Role analysis →
The logs gap and the release cadence
- “Under their control” produces a real gap. Article 19 obliges providers to retain logs under their control for at least six months; Article 26(6) obliges deployers to retain logs under theirs. In multi-tenant SaaS the provider usually holds everything and the deployer holds nothing, which leaves the deployer unable to meet an obligation they still owe. Solve it contractually: state who holds what, retention period, and how the customer obtains logs inside a two-day incident window.
- Continuous deployment meets Article 43(4). A substantial modification triggers a fresh conformity assessment, but changes pre-determined at initial assessment and described in the technical documentation are not substantial. Your declared change envelope therefore sets your release freedom, and it must be drawn before the first assessment.
- Article 73 clocks do not align. Your customer's two-day clock and your fifteen-day clock are different clocks. Contract the notification chain explicitly.
- Multi-jurisdiction reporting. Serious incidents are reported to the authorities of the member state where the incident occurred. For a pan-EU customer base that can be several.
What applies before December 2027
Article 50 applies now to any in-product assistant, chatbot or generative feature, at any risk tier. Article 4 literacy applies to you and to your customers.
The deferral in Regulation (EU) 2026/1744 covers Chapter III Sections 1 to 3. It does not cover Article 5, Article 4, Chapter V general-purpose AI, Article 49 registration or Article 50 transparency. Full timeline →
Status labels on this page
Verified fact: The Annex III points, article references and dates cited above, checked against the consolidated Regulation and the Commission's AI Act Service Desk.
Expert analysis: The in-scope/out-of-scope allocation, the sector edge case, and the parallel-regulation reading.
Unsettled: Harmonised standards remain in development and the Commission's Annex III guidelines are in draft. Sector supervisory practice has not yet formed.
Answer the questionnaire before it arrives
Enterprise buyers are asking how AI is governed well ahead of any regulatory deadline. A published position, an inventory and a management system answer it once instead of per deal.
Classify before you build
Twelve questions mapping your system against Articles 5, 6, 50 and Annex III. No email required.
Frequently asked
Is a SaaS company a provider or a deployer under the EU AI Act?
A SaaS company that develops an AI system and places it on the EU market or puts it into service under its own name or trade mark is a provider. Its customers using the system under their own authority are deployers. Article 25 can move either party: a customer that modifies the intended purpose so that the system becomes high-risk becomes a provider itself.
Who keeps the logs in a SaaS deployment?
Both parties owe retention for the logs under their own control. Article 19 requires providers to retain logs automatically generated by their high-risk AI systems, to the extent under their control, for at least six months. Article 26(6) places a parallel obligation on deployers. In multi-tenant SaaS the provider typically holds the logs, which can leave the deployer unable to meet an obligation it still owes unless the contract provides access.
Does every SaaS release need a new conformity assessment?
No. Article 43(4) treats a substantial modification as triggering a fresh assessment, but changes pre-determined by the provider at the time of the initial conformity assessment and described in the technical documentation are not substantial modifications. The breadth of that declared change envelope determines release freedom and must be set before the first assessment.