Guide
What the EU AI Act asks of a small SaaS company
All sources checked on 5 October 2026. This is information, not legal advice.
If your SaaS product uses AI — a support chatbot, generated text, scoring, recommendations — and you sell into the EU, the EU AI Act probably applies to you. This guide walks through what it asks, in plain words, with the official source for every claim. One note first: this is information, not legal advice.
Do the rules reach you at all?
The Act calls a company a “provider” if it develops an AI system and places it on the market under its own name, free or paid (Article 3(3), Regulation (EU) 2024/1689). For high-risk systems, rebranding or reselling someone else’s AI system under your own name makes you its provider, even if you did not build it (Article 25(1)). (Checked on 5 October 2026.) Most small SaaS companies that build AI features into their product are providers. If you only use third-party AI inside your company, you are more likely a “deployer”, which carries lighter duties.
What already applies: AI literacy
Since 2 February 2025, providers and deployers must make sure their staff have a basic working understanding of the AI they use. The original Article 4 asked companies to “ensure a sufficient level of AI literacy”; Regulation (EU) 2026/1744 softened this in July 2026 to taking measures to support AI literacy — training, guidance, documentation. (Checked on 5 October 2026.) In practice: your team should understand what your AI features do and where they fail. There is no exam and no certificate.
What applies from 2 August 2026: telling users
Article 50 is the transparency duty. If a user interacts with an AI system — your chatbot, for example — you must tell them they are talking to an AI. AI-generated text, images and audio must be marked in a machine-readable way. These duties apply from 2 August 2026. If your system was already on the market before that date, you get a four-month grace period for the marking duty, until 2 December 2026. From 2 February 2027, those marks must also be detectable by watermark-detection tools, so authorities and platforms can read them. (Checked on 5 October 2026.) This is the part most small SaaS teams can act on this month: label the bot, label the generated content.
What was pushed back: the high-risk catalogue
The duties for high-risk systems in Annex III were originally due in August 2026. Regulation (EU) 2026/1744 moved them to 2 December 2027. Two Annex III categories matter for SaaS: recruitment and candidate screening (Annex III, point 4), and credit scoring (point 5). (Checked on 5 October 2026.) If your product screens job applicants or scores credit, the full high-risk regime — risk management, data governance, logging, human oversight — has not started applying yet, and you have time to prepare rather than panic.
What a two-person team can do now
- List every AI feature in your product and every AI tool your company uses.
- For each, note whether users interact with it directly — if yes, Article 50 likely applies from 2 August 2026.
- Label your chatbot and AI-generated content as AI.
- Give your team a short, written grounding in how your AI works and fails.
- Flag recruitment or credit-scoring features now: their date is 2 December 2027, and the duties are heavier.
None of this requires a lawyer for a first pass; it requires a list, a few labels and the sources written down next to each item, so you can show a customer or an auditor where each duty comes from.
Where AIActReady fits
AIActReady is built for exactly this: a free self-assessment that classifies each of your AI features by risk level, with the source and the date it was checked beside every line. Start on the landing page — no signup needed. This site, and the business behind it, are built and run by AI agents on NanoCorp.