AI Act · SaaS

AI Act for SaaS: Classification, Transparency and Compliance

The SaaS model is not itself a high-risk category under the AI Act. Classification depends on the intended use. Learn the Art. 50 transparency obligations, GPAI models and how to classify your product.

Is your SaaS high-risk under the AI Act?

The AI Act (Regulation (EU) 2024/1689) does not classify the SaaS model as a high-risk category per se. Classification depends on the intended use of the AI system, not the delivery model. A SaaS may be high-risk, limited, minimal or none, depending on what the AI is used for.

When a SaaS is high-risk:

  • If used as a safety component in critical digital infrastructure (Annex III, point 2)
  • If used for an Annex III purpose by the customer (credit scoring, HR, education, health, insurance, etc.)
  • If covered as a product under Annex I harmonised legislation (e.g. medical device) and requires third-party conformity assessment (Art. 6(1))

GPAI models in SaaS: General-purpose AI models used in SaaS may trigger obligations under Chapter V of the AI Act, depending on systemic risk. Systemic-risk GPAI (>10²⁵ FLOPs) have additional obligations for risk assessment and incident notification.

Chatbots in SaaS: If your SaaS includes a chatbot interacting with natural persons, Art. 50(1) requires informing users that they are interacting with an AI system, unless it is obvious.

Prohibited practices: Art. 5(1)(a) prohibits AI systems deploying subliminal, manipulative or deceptive techniques to materially distort behaviour. A SaaS using dark patterns with AI may fall under this prohibition.

  • Intended-use classification — We determine whether your SaaS is high-risk under Annex III
  • Art. 50 transparency — We implement information obligations for chatbots and synthetic content
  • GPAI model analysis — We assess whether your AI model is systemic-risk (>10²⁵ FLOPs)
  • Prohibited practices audit — We verify your SaaS does not engage in AI dark patterns (Art. 5(1)(a))
  • Technical documentation — We prepare the documentation required by Art. 11 for high-risk SaaS

AI Act obligations for SaaS by classification

AI Act obligations for a SaaS depend on its risk classification:

High-risk SaaS (Annex III):

  • Risk management system (Art. 9)
  • Training data quality (Art. 10)
  • Technical documentation and record-keeping (Art. 11)
  • Transparency for deployers (Art. 13)
  • Human oversight (Art. 14)
  • Accuracy, robustness and cybersecurity (Art. 15)
  • Conformity assessment (Art. 6 + Annex III)
  • EU database registration (Art. 49)

SaaS with chatbots (limited risk):

  • Inform users they are interacting with AI (Art. 50(1))
  • Mark AI-generated synthetic content (Art. 50(2))

SaaS with GPAI models:

  • Model documentation (Art. 53)
  • Acceptable use policy
  • Training data summary
  • If systemic-risk: risk assessment, serious incident notification (Art. 55)

Minimal-risk SaaS:

  • No specific obligations
  • Voluntary codes of conduct

Timeline: Art. 50 transparency obligations enter into force on 2 August 2026. Prohibited practices under Art. 5 have been in force since 2 February 2025. High-risk systems under Annex III must comply before 2 December 2027.

AI use cases in SaaS and their classification

Use caseAI Act classificationApplicable rule
SaaS for credit scoringHigh riskAnnex III, point 5(b)
SaaS for HR (recruitment)High riskAnnex III, point 4
SaaS for education (assessment)High riskAnnex III, point 3
SaaS for health (medical device)High riskArt. 6(1) + Annex I
SaaS with customer chatbotLimited riskArt. 50(1) transparency
SaaS with content generationLimited riskArt. 50(2) marking
SaaS with GPAI modelChapter V obligationsArts. 53-55
Data analytics SaaSMinimal (generally)GDPR
SaaS with dark patternsProhibitedArt. 5(1)(a)

Official guidance for SaaS

  • AEPD — Guide for clients contracting cloud computing: AEPD
  • AEPD — Guidance for cloud computing providers: AEPD
  • EDPB — Guidelines 07/2020 on controller and processor concepts: EDPB
  • AEPD — GDPR compliance for AI processing (2020): AEPD
  • European Commission — Art. 50 transparency obligations: Digital Strategy

AI Act compliance checklist for SaaS

  • Identify all AI uses in the SaaS
  • Classify each use under Annex III
  • Verify no prohibited practices under Art. 5
  • Implement chatbot transparency (Art. 50(1))
  • Mark AI-generated synthetic content (Art. 50(2))
  • If high-risk: risk management system (Art. 9)
  • If high-risk: technical documentation (Art. 11)
  • If high-risk: conformity assessment and EU database registration
  • If using GPAI: model documentation (Art. 53)
  • If systemic-risk GPAI: risk assessment (Art. 55)
  • Designate EU representative if not established (Art. 22)
  • Coordinate with GDPR: processor contract (Art. 28), security (Art. 32), DPIA (Art. 35)

This page is general information, not legal advice. Each AI system must be analysed individually. Fines and deadlines cited are based on Regulation (EU) 2024/1689 in force at the date of publication.

Featured Services

Frequently Asked Questions

Is the SaaS model itself a high-risk category?

No. The AI Act does not classify the SaaS model as a high-risk category. Classification depends on the intended use of the AI system. A SaaS is high-risk if used as a safety component in critical infrastructure (Annex III point 2), if used for an Annex III purpose by the customer (credit scoring, HR, education, health, insurance) or if covered as a product under Annex I harmonised legislation.

What obligations does a SaaS with a chatbot have?

Art. 50(1) of the AI Act requires that users be informed that they are interacting with an AI system, unless it is obvious. If the chatbot generates synthetic content (text, images, audio), Art. 50(2) requires that such content be marked in a machine-readable way as artificially generated. These obligations enter into force on 2 August 2026.

When is an AI model in my SaaS a systemic-risk GPAI?

A general-purpose AI model (GPAI) is considered systemic-risk when it has significant capabilities and the compute used for its training exceeds 10²⁵ FLOPs. The Commission may designate other models as systemic-risk on a case-by-case basis. Systemic-risk GPAI have additional obligations: risk assessment, mitigation, serious incident notification and cybersecurity (Art. 55).

Can AI dark patterns be a prohibited practice?

Yes. Art. 5(1)(a) of the AI Act prohibits AI systems deploying subliminal, manipulative or deceptive techniques to materially distort a person's behaviour in a way that causes or is likely to cause significant harm. A SaaS using AI to design dark patterns that manipulate user behaviour may fall under this prohibition, in force since 2 February 2025.

What fines does the AI Act provide for SaaS?

Maximum fines are: up to €35 million or 7% of global turnover for prohibited practices; up to €15 million or 3% for breach of high-risk obligations; up to €7.5 million or 1.5% for incorrect information to authorities. For SMEs and startups, the lower absolute amount applies.

Do I need an EU representative if my SaaS is not in Europe?

Yes, if you are a provider of an AI system not established in the EU. Art. 22 of the AI Act requires designating an authorised representative in a Member State before placing the system on the EU market. The representative acts before national authorities and is responsible for compliance.

How does the AI Act relate to the GDPR in a SaaS?

Both regulations apply simultaneously. The AI Act regulates the AI system (the product), while the GDPR regulates the processing of personal data. A SaaS processing personal data with AI must comply with both. The GDPR requires a processor contract (Art. 28), security measures (Art. 32) and, in high-risk cases, DPIA (Art. 35). The AI Act requires conformity assessment and FRIA in high-risk cases.

Which authority supervises the AI Act in Spain for SaaS?

The AESIA (Spanish Agency for the Supervision of Artificial Intelligence) is the competent authority in Spain. The European AI Office coordinates enforcement between Member States and directly supervises systemic-risk GPAI models. The AEPD intervenes when there is intersection with the GDPR.

Contact

If you want to talk about intellectual property protection, AI and data regulation, startup formation or international expansion, write us a few lines and schedule a conversation with the team.

A2 Estudio Legal
María de Molina, 41
28006 Madrid · Spain

Tel: +34 913 451 406
Email: info@a2estudiolegal.com

Tell us briefly about your project, development stage and target countries. We will respond with the next steps to start working together.

Let's talk
Contact us