EU AI ACT · OPERATING ENVIRONMENTKnow what applies · prove why · preserve change? LEARN THIS PAGE
EU AI ACT · SAAS · CLOUD AI · EMBEDDED AI
SELLING AI FEATURES INTO EUROPE? KNOW YOUR ROLE BEFORE YOU SCALE.
SaaS companies often sit in the middle of the AI value chain: a third-party model underneath, your product and brand in the middle, and customer use cases downstream. The commercial risk is assuming that someone else’s model documentation answers your own system-level obligations.
BOUNDARYThis page is educational and operational guidance. It is not legal advice, certification, conformity assessment or regulatory approval.
CURRENT SOURCE ANCHOR
EUR-Lex · Regulation (EU) 2024/1689 · Articles 2 and 3
The Regulation applies to providers placing AI systems or GPAI models on the Union market even when they are established outside the EU. Article 3 defines provider, deployer, importer, distributor, placing on the market, and making available on the market.
Start with the actual system, role, use case and evidence boundary. The same regulation can produce different obligations for different actors and systems.
01
ARE YOU THE PROVIDER OR JUST USING SOMEONE ELSE’S AI?
A SaaS company can become the provider of an AI system it develops or has developed and places on the market under its own name or trademark. Using a third-party model does not automatically eliminate provider responsibilities at the system level.
02
IS THE AI FEATURE BEING MADE AVAILABLE IN THE EU?
The Act can apply when AI systems or models are placed on the Union market. Availability can occur through software, APIs, cloud services, integrations, or other commercial delivery paths.
03
DO YOUR CUSTOMERS RELY ON YOUR SYSTEM FOR CONSEQUENTIAL USES?
A general SaaS feature can move into a more demanding governance route when customers use it for employment, credit, essential services, biometric, safety, transparency-sensitive, or other regulated purposes.
04
WHAT DO YOU NEED TO PASS DOWN TO CUSTOMERS?
Preserve instructions, intended purpose, limitations, version history, change notices, technical information, transparency measures, human-oversight expectations, and other evidence customers need to use the system within a supportable boundary.
THE TA-14 OPERATING ROUTE
Turn the question into a governed record.
The goal is not merely to reach an answer. It is to preserve what facts, evidence, scope and limitations supported that answer at that time.
01
Identify the commercial AI system boundary
Separate the underlying model, your SaaS application, embedded AI features, customer-configured workflows, and downstream use cases. Different layers can carry different roles and obligations.
02
Determine your operator role and EU exposure
Establish whether you are acting as provider, deployer, importer, distributor, product manufacturer, GPAI provider, or another operator for each relevant layer. Preserve the facts supporting that role.
03
Map customer-facing obligations to evidence
Connect transparency, technical documentation, instructions, logs, risk controls, system versions, human oversight, support boundaries, and change notices to the claims your SaaS business makes to customers.
04
Revalidate when features, models, or use cases change
Model swaps, new autonomous features, expanded decision authority, new customer sectors, EU market entry, or changes in intended purpose can change both role and obligation state.
READY TO OPERATE · START PAID ACCESS NOW
Move from reading about the EU AI Act to maintaining the record.
Choose the smallest operating tier that fits the portfolio today. Upgrade when system count, team size or governance scope actually requires it.
1–3 AI systems
Evidence Passport
$19/MO
Keep a living system-level evidence record with obligations, gaps, versions and revalidation state.
Use the free classifier to establish the system, intended purpose, possible actor role, EU exposure and unresolved facts. When continuing evidence infrastructure is needed, paid access begins at $19 per month. Independent human readiness review remains a separate service.
Does the EU AI Act apply to SaaS companies outside Europe?
It can. Article 2 applies to providers placing AI systems or general-purpose AI models on the Union market regardless of whether the provider is established in the EU, and it can also apply where outputs from a third-country provider or deployer are used in the Union.
If we use OpenAI or another third-party model, are we automatically only a deployer?
No. Role depends on the actual system and how it is developed, branded, placed on the market, and used. A SaaS company can still be the provider of its own AI system even when that system incorporates a third-party model.
Does offering an AI feature through an API or cloud service count as placing it on the market?
The Commission’s current GPAI guidance expressly notes that first availability on the Union market can occur through APIs, downloads, cloud services, integrations into applications, or other means. System-level analysis should still be done separately from model-level analysis.
What if our SaaS is low-risk?
Low-risk does not mean “no obligations.” Depending on the system, provider/deployer role, transparency features, AI literacy duties, customer use, and other legal layers may still matter. The first step is classification, not assumption.
What evidence should a SaaS vendor preserve?
At minimum: system identity, version, intended purpose, operator role, model/provider dependencies, customer instructions, transparency measures, change history, limitations, testing, incident records, and the evidence supporting any classification or exclusion claim.
Does TA-14 certify our SaaS platform as EU AI Act compliant?
No. TA-14 can preserve role analysis, system identity, evidence, gaps, changes and revalidation history. It does not itself provide legal advice, conformity assessment, certification or regulatory approval.
EU AI ACT WORLD · TA-14 AUTHORITY GOVERNANCE INSTITUTION
Understand the requirement. Preserve the evidence. Revalidate when reality changes.