AI Act Compliance Checklist
for SaaS — 2026

The primary EU AI Act compliance checklist for AI SaaS founders: understand scope, classify risk, document gaps, and hand off to counsel or a buyer — not a fake “compliant” badge.

Last updated 27 Aug 2026 · Article 50 in force since 2 August 2026 · Annex III from 2 December 2027 · Written by ActBrief Editorial · External legal review pending — see methodology

A useful SaaS AI Act checklist starts with scope and role, screens prohibited and potentially high-risk uses, then maps Article 50 transparency before assembling evidence for counsel or procurement. Article 50 applies from 2 August 2026; this checklist is a preliminary technical reference, not legal advice.

Primary sources: EU AI Act (Regulation (EU) 2024/1689) — EUR-Lex · European Commission — AI Act overview · AI Act Service Desk — implementation timeline

Article 50 hub · Chatbot checklist · 2026 dates

Copy this checklist · then personaliseWalk steps 0–10 below. Unsure what applies to your product? Run the free scan (email optional).
Run free AI Act scan
0

Step 0 — Determine whether you are in scope

Map territorial scope before classifying risk

Ask: Is the system placed on the EU market, put into service in the Union, or is its output used in the Union? Who is the provider vs deployer? What is the exact intended purpose? Who are affected persons? EU users or EU market? Remember: the model provider (OpenAI, Anthropic, etc.) is not automatically the system provider of your chatbot. See OpenAI-powered SaaS role and US companies.
1

Step 1 — Role

Record provider / deployer / importer / distributor / GPAI (or mixed)

Role drives which duties apply. A SaaS that ships a chatbot often places an AI system on the market (provider of that system) while also using a GPAI model as a component. Document the facts; do not guess from a vendor logo. Provider vs deployer vs GPAI.
2

Step 2 — Prohibited-use screening (Art. 5)

Confirm the product does not fall under prohibited practices

Short screen: social scoring, exploitative manipulation, untargeted facial scraping, real-time remote biometric ID in public (with narrow exceptions), and related Art. 5 cases. If anything is ambiguous, stop and escalate to counsel before launch.
3

Step 3 — Annex III screening

Flag potential high-risk categories by intended purpose

Classic SaaS signals: employment / CV ranking (III.4), education assessment (III.3), credit / essential services (III.5), certain biometric / health uses. Standalone Annex III duties apply from 2 December 2027 (Digital Omnibus). This is a hypothesis until Art. 6(3) facts are confirmed.
4

Step 4 — Article 6(3) (if Annex III may apply)

Test material influence, profiling, and narrow / preparatory use

Ask: Does output materially influence a decision about a person? Does the system profile natural persons? Is use narrow or only preparatory for a human? Profiling usually blocks the Art. 6(3) exception. Record answers as missing facts until counsel confirms.
5

Step 5 — Article 50 transparency (in force)

Map every AI touchpoint to the right Article 50 paragraph and keep evidence

In force since 2 August 2026 (Commission guidelines 20 July 2026). Separate cases: human↔AI interaction; generated / manipulated content marking; deepfakes; public-interest text; emotion / biometric notice where relevant; provider vs deployer duties; screenshots + product version + owner as evidence. Deep dive: Article 50 hub · Chatbot disclosure guide · Article 50 checklist.
6

Step 6 — Documentation stack

Assemble system inventory, purpose statements, and gap list

One card per AI feature: system card. Intended purpose paragraph, affected persons, automation level, data categories. Label legal duties vs recommended readiness practice.
7

Step 7 — Human oversight

Define who reviews, when, and how overrides are logged

Legal for confirmed high-risk (Art. 14); still a top buyer diligence ask for other AI SaaS. Use the human–AI collaboration SOP.
8

Step 8 — Logging and data governance

Map data flows; plan Art. 12 logging if high-risk is confirmed

Article 12 logging is a legal requirement for high-risk systems. For other SaaS, logging and data-flow docs are recommended readiness practice for diligence — do not treat them as universal AI Act duties for every product.
9

Step 9 — Vendor / model inventory

List models, subprocessors, regions, and DPA status

Provider name, model / version, data sent, region, training opt-out, owner, last reviewed. Template: AI vendor inventory.
10

Step 10 — Legal / buyer evidence pack

Hand counsel or procurement a structured file, not slides

Include: role hypothesis, Art. 50 evidence, Annex III / 6(3) open facts, gap list, lawyer questions, dated next steps. Free: readiness scan. Product-specific Art. 50 file: Evidence Pack (€199). Diligence prep: readiness checklist for audit / procurement.

Article 50 checklist (not one checkbox)

Transparency is in force since 2 August 2026. Map each AI surface to a paragraph, then keep evidence. Full hub: /article-50.

Checklist by product type

Same Act — different first steps. Use the deep page for your product; come back here for the full stack.

ProductFirst focusDeep page
Chatbot / support AIUsually Art. 50 first; high-risk only if it decides about peopleOpen →
AI agentsAutonomy + outbound messages raise disclosure and oversight questionsOpen →
Recruiting AIOften Annex III.4 signal — confirm material influenceOpen →
Copilot (employee / customer)Interaction disclosure + generated-content casesOpen →
Content generatorArt. 50(2)/(4) marking and publication duties may applyOpen →
Recommendation / rankingDepends on whether scores drive person-level decisionsOpen →

AI Act compliance checklist FAQ

What is an EU AI Act compliance checklist?

A structured list of obligations and readiness steps for SaaS: scope, role, prohibited uses, Annex III screening, Art. 6(3), Article 50 transparency, documentation, oversight, logging, vendor inventory, and lawyer handoff — before selling AI products with EU users or EU-used output.

Who needs an AI Act compliance checklist?

Teams that may be in scope under Article 2: if you place or deploy an AI system in the EU, or its output is used in the EU. Provider and deployer roles both can have obligations — “accessible from the EU” alone is not the full legal test.

Is every SaaS product high-risk under the AI Act?

No. Potentially high-risk depends on intended purpose and material influence. Annex III signals are hypotheses — Art. 6(3) can change the outcome. Standalone Annex III duties apply from 2 Dec 2027. Article 50 transparency has applied since 2 Aug 2026 for relevant surfaces.

How is this different from a SaaS impact analysis checklist?

Impact analysis maps who is affected and what decisions AI influences. This compliance checklist maps those impacts to Act obligations and readiness artefacts so you know what to fix before legal review.

How is this different from the SaaS readiness checklist?

This page is the primary general EU AI Act compliance checklist. The readiness checklist is for audit / procurement prep and lawyer handoff sequencing — not a second general compliance checklist.

Can I get a personalized checklist for my product?

Yes. Run the free ActBrief scanner with your product URL and intended purpose. You get risk signals, missing documentation, and lawyer questions in about two minutes. Email optional.

Not sure which checklist items apply to your product?

Run a free AI Act readiness scan. We map your product to risk signals, missing documentation, and questions for your lawyer — about 2 minutes.

Scan my product — it's free

Next: Article 50 hub · Evidence Pack · 2026 dates

2 minutes · Email optional · No credit card