Not legal advice. This article is a preliminary technical guide for AI SaaS teams. Always confirm classification and obligations with qualified counsel. Effective dates reflect the Digital Omnibus updates as of July 2026.
Changelog
Updated 21 July 2026: Annex III standalone high-risk obligations deferred to 2 December 2027; Annex I embedded high-risk to 2 August 2028 (Council approval 29 June 2026). Art. 50 transparency remains 2 August 2026.
The myth: “OpenAI handles compliance”
If your SaaS calls the OpenAI API, you still have a role — often as a provider of an AI system (your product) and/or a deployer of a GPAI model. OpenAI’s terms, model cards, and DPA help, but they do not write your disclosure, oversight SOP, or enterprise evidence pack.
Start with role, not with the model name
Ask:
Who places your product on the market?
Who determines the intended purpose of the AI feature?
Is the model GPAI used as a component inside your system?