Not legal advice. This article is a preliminary technical guide for AI SaaS teams. Always confirm classification and obligations with qualified counsel. Effective dates reflect the Digital Omnibus updates as of July 2026.
Changelog
Updated 21 July 2026: Annex III standalone high-risk obligations deferred to 2 December 2027; Annex I embedded high-risk to 2 August 2028 (Council approval 29 June 2026). Art. 50 transparency remains 2 August 2026.
Use this before audit or enterprise diligence
This is a readiness checklist for legal review and buyer questionnaires — not the general primary compliance checklist. Goal: walk in with facts, not vibes.
1. Inventory
[ ] List AI features + intended purpose
[ ] List models / vendors
[ ] Note whether outputs affect people
2. Role & scope
[ ] Provider / deployer / both (per feature)
[ ] Company establishment country
[ ] EU market placement or EU output use?
3. Near-term transparency
[ ] Art. 50 disclosure draft (target 2 August 2026 where applicable)
[ ] Privacy policy AI section
4. High-risk signals
[ ] Annex III category candidates (HR, education, credit, etc.)
[ ] Material influence? Profiling?
[ ] Art. 6(3) facts captured
5. Oversight & logging
[ ] Human oversight SOP draft
[ ] Logging plan (legal if high-risk; recommended otherwise)