Is your SaaS high-risk under the AI Act?
The AI Act (Regulation (EU) 2024/1689) does not classify the SaaS model as a high-risk category per se. Classification depends on the intended use of the AI system, not the delivery model. A SaaS may be high-risk, limited, minimal or none, depending on what the AI is used for.
When a SaaS is high-risk:
- If used as a safety component in critical digital infrastructure (Annex III, point 2)
- If used for an Annex III purpose by the customer (credit scoring, HR, education, health, insurance, etc.)
- If covered as a product under Annex I harmonised legislation (e.g. medical device) and requires third-party conformity assessment (Art. 6(1))
GPAI models in SaaS: General-purpose AI models used in SaaS may trigger obligations under Chapter V of the AI Act, depending on systemic risk. Systemic-risk GPAI (>10²⁵ FLOPs) have additional obligations for risk assessment and incident notification.
Chatbots in SaaS: If your SaaS includes a chatbot interacting with natural persons, Art. 50(1) requires informing users that they are interacting with an AI system, unless it is obvious.
Prohibited practices: Art. 5(1)(a) prohibits AI systems deploying subliminal, manipulative or deceptive techniques to materially distort behaviour. A SaaS using dark patterns with AI may fall under this prohibition.
- Intended-use classification — We determine whether your SaaS is high-risk under Annex III
- Art. 50 transparency — We implement information obligations for chatbots and synthetic content
- GPAI model analysis — We assess whether your AI model is systemic-risk (>10²⁵ FLOPs)
- Prohibited practices audit — We verify your SaaS does not engage in AI dark patterns (Art. 5(1)(a))
- Technical documentation — We prepare the documentation required by Art. 11 for high-risk SaaS
AI Act obligations for SaaS by classification
AI Act obligations for a SaaS depend on its risk classification:
High-risk SaaS (Annex III):
- Risk management system (Art. 9)
- Training data quality (Art. 10)
- Technical documentation and record-keeping (Art. 11)
- Transparency for deployers (Art. 13)
- Human oversight (Art. 14)
- Accuracy, robustness and cybersecurity (Art. 15)
- Conformity assessment (Art. 6 + Annex III)
- EU database registration (Art. 49)
SaaS with chatbots (limited risk):
- Inform users they are interacting with AI (Art. 50(1))
- Mark AI-generated synthetic content (Art. 50(2))
SaaS with GPAI models:
- Model documentation (Art. 53)
- Acceptable use policy
- Training data summary
- If systemic-risk: risk assessment, serious incident notification (Art. 55)
Minimal-risk SaaS:
- No specific obligations
- Voluntary codes of conduct
Timeline: Art. 50 transparency obligations enter into force on 2 August 2026. Prohibited practices under Art. 5 have been in force since 2 February 2025. High-risk systems under Annex III must comply before 2 December 2027.
AI use cases in SaaS and their classification
| Use case | AI Act classification | Applicable rule |
|---|---|---|
| SaaS for credit scoring | High risk | Annex III, point 5(b) |
| SaaS for HR (recruitment) | High risk | Annex III, point 4 |
| SaaS for education (assessment) | High risk | Annex III, point 3 |
| SaaS for health (medical device) | High risk | Art. 6(1) + Annex I |
| SaaS with customer chatbot | Limited risk | Art. 50(1) transparency |
| SaaS with content generation | Limited risk | Art. 50(2) marking |
| SaaS with GPAI model | Chapter V obligations | Arts. 53-55 |
| Data analytics SaaS | Minimal (generally) | GDPR |
| SaaS with dark patterns | Prohibited | Art. 5(1)(a) |
Official guidance for SaaS
- AEPD — Guide for clients contracting cloud computing: AEPD
- AEPD — Guidance for cloud computing providers: AEPD
- EDPB — Guidelines 07/2020 on controller and processor concepts: EDPB
- AEPD — GDPR compliance for AI processing (2020): AEPD
- European Commission — Art. 50 transparency obligations: Digital Strategy
AI Act compliance checklist for SaaS
- Identify all AI uses in the SaaS
- Classify each use under Annex III
- Verify no prohibited practices under Art. 5
- Implement chatbot transparency (Art. 50(1))
- Mark AI-generated synthetic content (Art. 50(2))
- If high-risk: risk management system (Art. 9)
- If high-risk: technical documentation (Art. 11)
- If high-risk: conformity assessment and EU database registration
- If using GPAI: model documentation (Art. 53)
- If systemic-risk GPAI: risk assessment (Art. 55)
- Designate EU representative if not established (Art. 22)
- Coordinate with GDPR: processor contract (Art. 28), security (Art. 32), DPIA (Art. 35)
Related resources
- AI Act Hub — Resource centre on the European AI Regulation
- AI Act Glossary — 45+ key terms with article references
- AI Act vs GDPR — Comparative table of both regulations
- AI Act Compliance Checker — Self-assess your AI system
- AI & Data Regulation Service — Integrated advisory
- GDPR for SaaS — Sectoral GDPR guide for SaaS
- DPO as a Service — External Data Protection Officer
This page is general information, not legal advice. Each AI system must be analysed individually. Fines and deadlines cited are based on Regulation (EU) 2024/1689 in force at the date of publication.