Use case · SaaS & product teams

The EU AI Act for SaaS products

The question isn't whether the Act applies — it's which features carry duties, whose duties they are, and which are enforceable now.

Last updated 8 August 2026 · Regulation (EU) 2024/1689 as amended by the June 2026 Omnibus · Self-assessment, not legal advice

Most SaaS teams added AI features in the last three years: a copilot, a summariser, a support bot, a scoring model. The EU AI Act question for SaaS is rarely "does it apply" — if your users are in the EU, it almost certainly does, wherever you're incorporated. The real questions are which features carry duties, whose duties they are, and which are enforceable now.

Feature-level, not company-level

The Act regulates AI systems, not companies. A typical SaaS product is several systems with different tiers:

FeatureLikely tierWhat attaches
In-app support / onboarding chatbotLimitedArticle 50 disclosure — live now
Text / image generation for usersLimitedMachine-readable content marking (Art 50(2)) — usually your model vendor's duty if you're on an API, but check
Search, summarisation, internal copilotsMinimalArticle 4 literacy, little else
Lead scoring (companies)MinimalScoring businesses isn't scoring people
Anything scoring individual people's access to work, credit, education, essential servicesHigh-riskChapter III by Dec 2027 — see HR / fintech

Inventory first: list your AI features, who each affects, and whether the subject of any evaluation is a natural person. Most SaaS products land in Limited/Minimal across the board — a defensible written position that takes a day to produce, and that enterprise procurement will eventually ask for.

"We just call OpenAI/Anthropic" — what that actually means

Calling a model through an API keeps Article 53 (GPAI duties) with the model provider, not you — including the training-data summary and copyright policy everyone worries about. A light in-domain fine-tune ordinarily keeps you downstream too. What API use does not do is remove your own system-level duties: your chatbot still discloses (Art 50(1)), your product still gets classified by what it does to its users, and a substantial retrain or new task domain can make you a GPAI provider after all. The threshold, in detail.

Role-wise, shipping AI features under your own brand makes you the provider of those features even though the model underneath is someone else's. Your customers are typically deployers — which means your documentation is their compliance input, and "AI Act position available on request" is quietly becoming a procurement filter. Provider vs deployer.

Live now vs December 2027

Since 2 August 2026: Article 50 (your user-facing bot says it's a bot, at first contact, not in the privacy policy), Article 4 (a recorded AI-literacy session for staff touching the systems), Article 5 (no emotion inference on employees or users in prohibited contexts). Deferred to 2 December 2027: the heavy Chapter III set, only if something you ship is genuinely high-risk — and check the Article 6(3) exemption before assuming it is.

US and UK SaaS selling into the EU: Article 2 reaches providers wherever established, when output is used in the EU. Delaware doesn't help. What the Act asks of a typical B2B SaaS is smaller than feared — but "we looked, here's our position, dated" is the deliverable, and its absence is what stalls enterprise deals.

The 90-minute version

When a prospect's legal team wants more than a page, the full gap report is the defensible version: role, tier, obligations, deadlines and a fix list, referenced to your actual product — €59, once.

Classify your features in minutes

Run the free check per user-facing feature. The full report turns it into the written position enterprise procurement keeps asking for.

Start the free scan

No card, no account. Full gap report from €59. See a real report first.

Self-assessment, not legal advice. This page and the Reglynn report are a structured self-assessment based on the EU AI Act (Regulation 2024/1689, as amended by the June 2026 Omnibus). They indicate where you likely stand and what to verify with a qualified advisor. Reglynn is not a notified body and issues no certification.

How this was made. Reglynn reports are generated by an AI system and reviewed before delivery. Reglynn is a Limited Risk AI system under Article 50; we disclose AI involvement wherever it occurs, including in our chat assistant. Our own self-assessment.