EU AI Act Guide

EU AI Act Compliance Checklist for SaaS Founders (2026)

Last updated: 2026-07-09

If you sell AI-powered software into the EU, do not treat every obligation as one 2 August 2026 deadline. Article 50 transparency duties point to 2 August 2026; current Commission implementation material points to 2 December 2027 for Annex III high-risk systems. This checklist walks a SaaS team from “we should look into this” to a defensible compliance position, in the order that actually works.

It is written for founders and CTOs without in-house counsel. Each step ends with a concrete artifact — something you can show a buyer, an investor or a market surveillance authority.

Not sure which tier applies to you? Check your system in 2 minutes — free and rule-based.

Quick shortcut

Already know you need documents? Skip straight to the Doc Pack — your classification is done for you.

Get Doc Pack ($229$499)

Step 1 — Classify every AI system you ship

Everything downstream depends on your risk tier, so start here. For each AI feature or system, answer: does it do anything in Article 5 (prohibited practices)? Does it operate in an Annex III area — hiring, credit, education, biometrics, essential services, law enforcement? Does it interact with people or generate content (Article 50)? If none apply, you land in minimal risk.

Classify per system, not per company. A SaaS product with an AI resume screener and a support chatbot has one high-risk system and one limited-risk system — different obligations, different deadlines for effort.

Artifact: a one-page risk classification memo per system, stating the tier and the reasoning with article references. This is the document enterprise procurement asks for first.

Step 2 — Put the deadlines in your calendar

Prohibited practices and AI literacy duties have applied since 2 February 2025. GPAI model obligations since 2 August 2025. Article 50 transparency duties apply from 2 August 2026. Annex III high-risk systems point to 2 December 2027, and Annex I product-embedded systems to 2 August 2028.

Work backwards from your tier: a high-risk system needs its technical documentation, risk management system and conformity assessment ready before the applicable high-risk date - and documentation alone routinely takes weeks. Put an internal deadline at least a quarter before 2 December 2027.

Step 3 — Produce the documents buyers ask for

In practice, compliance is evidenced by documents. The core set: a risk classification memo as a practical baseline across tiers, technical documentation per Annex IV for high-risk systems, a model card summarising capabilities and limitations, an internal AI usage policy that supports Article 4 AI-literacy measures, and a compliance roadmap with dated milestones.

These are practical baseline artifacts for defensibility and buyer review, even where the Act does not prescribe them as named documents. Write the classification memo and AI usage policy first because they are short and unblock sales conversations.

Step 4 — Stand up the processes behind the documents

For high-risk systems, documents describe processes that must actually exist: risk management (Art. 9), data governance (Art. 10), logging (Art. 12), human oversight (Art. 14), accuracy and robustness testing (Art. 15), post-market monitoring (Art. 72). A document describing a process you do not run is worse than no document — it is evidence of misrepresentation.

Most of these map onto engineering practices you may partly have: incident tracking, evaluation suites, access controls, release review. The work is formalising and recording them, not inventing them from zero.

Step 5 — Answer the AI questions in vendor reviews

Enterprise security questionnaires increasingly include an AI section: what models do you use, what data trains them, are you in scope of the EU AI Act, what tier, where is your documentation. Teams with Steps 1–3 done answer in minutes; teams without lose deal momentum for weeks.

Keep a standing answer sheet next to your SOC 2 or ISO 27001 material. If you use a compliance platform, add the AI Act controls to the same workspace so evidence collection stays in one place.

Step 6 — Re-check when anything changes

Classification is not permanent. A new feature, a new customer segment, a new data source or a substantial model change can move a system across tiers — and a substantial modification can restart conformity obligations. Re-run classification at every major release, and log the result even when nothing changes.

Where does your system land?

Check your AI system against the actual Annex I/III rules in 2 minutes. Free, rule-based, no signup.

Start the free risk check →

Frequently asked questions

Does this apply if my company is not based in the EU?

Yes, if your system is placed on the EU market or its output is used in the EU. The Act follows the market, not your place of incorporation — a US or Asian SaaS with EU customers is in scope.

We just call the OpenAI API. Do we still need all this?

Calling a third-party model does not make you a GPAI provider, but it does not exempt your application either. Your product is classified by what it does — an AI hiring tool built on an API is still an Annex III high-risk system.

How long does the whole checklist take?

For a typical 10–50 person SaaS: classification in a day, core documents in 2–4 weeks of part-time effort, processes over a quarter. Starting from templates instead of blank pages compresses the documentation phase to days.

About these guides

Written by the TrustPacket team. We track Regulation (EU) 2024/1689, Commission guidance, and enforcement developments to keep these guides current. Not legal advice — when in doubt, consult qualified counsel.

Last updated: 2026-07-09 · Content review: 11 July 2026 · Questions? Email us

This is informational editorial content based on Regulation (EU) 2024/1689 and cited official implementation material. It is not legal advice, not a conformity assessment, and does not create a lawyer-client relationship. Application depends on facts this guide cannot verify. Consult qualified counsel for a binding assessment.