Not legal advice. This article is a preliminary technical guide for AI SaaS teams. Always confirm classification and obligations with qualified counsel. Effective dates reflect the Digital Omnibus updates as of July 2026.
Changelog
Updated 21 July 2026: Annex III standalone high-risk obligations deferred to 2 December 2027; Annex I embedded high-risk to 2 August 2028 (Council approval 29 June 2026). Art. 50 transparency remains 2 August 2026.
Why procurement cares now
Enterprise buyers increasingly attach AI governance questions to security reviews. Vendors that answer with marketing slides lose deals. Vendors that send an evidence pack move faster.
Buyer checklist (ask the vendor)
A. System inventory
List AI features and intended purposes.
Which decisions about people does AI influence?
Is output automated, ranked, or assistive?
B. Role
Are you provider, deployer, or both?
Which GPAI / foundation models do you use?
Who determines intended purpose — you or the customer?
C. Scope
Is the system placed on the EU market or are outputs used in the EU?
Where is the company established?
D. Transparency
Show Art. 50 disclosure examples in product UX.
Show privacy policy AI section.
E. Oversight & logging
Human override process (SOP).
Logging of AI-influenced decisions (especially if high-risk candidate).
F. Timeline awareness
Which obligations do you treat as applicable from 2 August 2026 vs 2 December 2027?
What “good” looks like in a vendor response
Classification hypothesis with confidence and missing facts — not “we are fully compliant”
Dated obligations (Art. 50 vs Annex III)
Templates or drafts: disclosure, system card, vendor inventory