Blog / High-risk
Not legal advice. This article is a preliminary technical guide for AI SaaS teams. Always confirm classification and obligations with qualified counsel. Effective dates reflect the Digital Omnibus updates as of July 2026.
The headline numbers are scary: €35 million or 7% of global annual turnover. But the reality is more nuanced — and in some ways more concerning for SaaS founders.
| Violation | Max fine | Compared to GDPR |
|---|---|---|
| Prohibited AI practices (Art. 5) | €35M or 7% turnover | Same as GDPR top tier |
| Non-compliance with high-risk obligations | €15M or 3% turnover | GDPR mid tier |
| Providing incorrect info to authorities | €7.5M or 1% turnover | GDPR low tier |
| Date | Milestone |
|---|---|
| Feb 2025 | AI Act entered into force |
| Feb 2025 | Prohibited practices (Art. 5) apply |
| Aug 2025 | GPAI provider obligations apply |
| 2 Aug 2026 | Transparency / disclosure (Art. 50) applies |
| 2 Dec 2027 | Standalone high-risk systems (Annex III) — deferred by Digital Omnibus |
| 2 Aug 2028 | High-risk AI embedded in Annex I regulated products |
Key: Do not treat August 2026 as a blanket “high-risk enforcement” date. The Council gave final approval to the Digital Omnibus on AI on 29 June 2026, deferring standalone Annex III high-risk duties to 2 December 2027 and embedded Annex I high-risk duties to 2 August 2028. Article 50 transparency still matters in 2026.
Key for SaaS founders: Transparency and prohibited-practices risk are near-term. Full Annex III conformity / registration pressure is a 2027 planning problem — still start the evidence pack early, but don’t invent false urgency.
National regulators (each EU member state designates one) will prioritize:
If you're a B2B AI SaaS without AI disclosure on your website, you're in category 3 — and that's the easiest fix.
The fine itself is usually not the biggest risk. What hurts more:
The EU AI Act is enforced by each member state's market surveillance authority. In practice:
| Your situation | Estimated risk | What to do |
|---|---|---|
| No AI disclosure (user-facing / Art. 50) | Rising into Aug 2026 | Draft disclosure this month |
| Potential Annex III, no evidence pack | High for diligence; duties largely from Dec 2027 | Scan + confirm Art. 6(3) + legal review |
| Limited risk, basic docs | Lower regulatory near-term | Maintain Art. 50 + inventory |
| Minimal risk, some docs | Low | Re-check when use case changes |
Parts of the AI Act are already enforceable (notably prohibited practices and, from 2 August 2026, Article 50 transparency). Standalone Annex III high-risk duties were deferred to 2 December 2027. Fines are real for what is in force — but most SaaS teams should prioritize an evidence pack and Art. 50 work now, not invent a false 2026 high-risk registration deadline.
The worst position is not knowing which obligations apply when.
Get a free readiness brief for your product — not a commodity risk label.
Get a free readiness brief for your product