EU AI ACT · OPERATING ENVIRONMENTKnow what applies · prove why · preserve change? LEARN THIS PAGE
EU AI ACT · SAAS · CLOUD AI · EMBEDDED AI

SELLING AI FEATURES INTO EUROPE?
KNOW YOUR ROLE BEFORE YOU SCALE.

SaaS companies often sit in the middle of the AI value chain: a third-party model underneath, your product and brand in the middle, and customer use cases downstream. The commercial risk is assuming that someone else’s model documentation answers your own system-level obligations.

BOUNDARYThis page is educational and operational guidance. It is not legal advice, certification, conformity assessment or regulatory approval.
CURRENT SOURCE ANCHOR

EUR-Lex · Regulation (EU) 2024/1689 · Articles 2 and 3

The Regulation applies to providers placing AI systems or GPAI models on the Union market even when they are established outside the EU. Article 3 defines provider, deployer, importer, distributor, placing on the market, and making available on the market.

OPEN OFFICIAL EU SOURCE ↗
WHAT BUSINESSES NEED TO ESTABLISH

Do not start with a generic checklist.

Start with the actual system, role, use case and evidence boundary. The same regulation can produce different obligations for different actors and systems.

01

ARE YOU THE PROVIDER OR JUST USING SOMEONE ELSE’S AI?

A SaaS company can become the provider of an AI system it develops or has developed and places on the market under its own name or trademark. Using a third-party model does not automatically eliminate provider responsibilities at the system level.

02

IS THE AI FEATURE BEING MADE AVAILABLE IN THE EU?

The Act can apply when AI systems or models are placed on the Union market. Availability can occur through software, APIs, cloud services, integrations, or other commercial delivery paths.

03

DO YOUR CUSTOMERS RELY ON YOUR SYSTEM FOR CONSEQUENTIAL USES?

A general SaaS feature can move into a more demanding governance route when customers use it for employment, credit, essential services, biometric, safety, transparency-sensitive, or other regulated purposes.

04

WHAT DO YOU NEED TO PASS DOWN TO CUSTOMERS?

Preserve instructions, intended purpose, limitations, version history, change notices, technical information, transparency measures, human-oversight expectations, and other evidence customers need to use the system within a supportable boundary.

THE TA-14 OPERATING ROUTE

Turn the question into a governed record.

The goal is not merely to reach an answer. It is to preserve what facts, evidence, scope and limitations supported that answer at that time.

01

Identify the commercial AI system boundary

Separate the underlying model, your SaaS application, embedded AI features, customer-configured workflows, and downstream use cases. Different layers can carry different roles and obligations.

02

Determine your operator role and EU exposure

Establish whether you are acting as provider, deployer, importer, distributor, product manufacturer, GPAI provider, or another operator for each relevant layer. Preserve the facts supporting that role.

03

Map customer-facing obligations to evidence

Connect transparency, technical documentation, instructions, logs, risk controls, system versions, human oversight, support boundaries, and change notices to the claims your SaaS business makes to customers.

04

Revalidate when features, models, or use cases change

Model swaps, new autonomous features, expanded decision authority, new customer sectors, EU market entry, or changes in intended purpose can change both role and obligation state.

READY TO OPERATE · START PAID ACCESS NOW

Choose the smallest operating tier that fits the portfolio today. Upgrade when system count, team size or governance scope actually requires it.

1–3 AI systems

Evidence Passport

$19/MO

Keep a living system-level evidence record with obligations, gaps, versions and revalidation state.

START EVIDENCE PASSPORT
Up to 10 AI systems

Compliance Workspace

$49/MO

Coordinate evidence, owners, documentation, incidents and team compliance work in one governed workspace.

START COMPLIANCE WORKSPACE
Up to 25 AI systems

Governance Pro

$99/MO

Operate broader high-risk, GPAI, FRIA, post-market and material-change governance across a growing portfolio.

START GOVERNANCE PRO
Up to 50 AI systems

Institution

$499/MO

Run institutional governance with expanded users, authority workflows, examiner rooms and portfolio reporting.

START INSTITUTION
Need an independent human readiness examination?A governed readiness review is separate from software access and starts at $750.
REQUEST READINESS REVIEW →
START WITH ONE SYSTEM

Not ready to subscribe? Classify first.

Use the free classifier to establish the system, intended purpose, possible actor role, EU exposure and unresolved facts. When continuing evidence infrastructure is needed, paid access begins at $19 per month. Independent human readiness review remains a separate service.

COMMON QUESTIONS

Questions businesses are asking now.

Does the EU AI Act apply to SaaS companies outside Europe?

It can. Article 2 applies to providers placing AI systems or general-purpose AI models on the Union market regardless of whether the provider is established in the EU, and it can also apply where outputs from a third-country provider or deployer are used in the Union.

If we use OpenAI or another third-party model, are we automatically only a deployer?

No. Role depends on the actual system and how it is developed, branded, placed on the market, and used. A SaaS company can still be the provider of its own AI system even when that system incorporates a third-party model.

Does offering an AI feature through an API or cloud service count as placing it on the market?

The Commission’s current GPAI guidance expressly notes that first availability on the Union market can occur through APIs, downloads, cloud services, integrations into applications, or other means. System-level analysis should still be done separately from model-level analysis.

What if our SaaS is low-risk?

Low-risk does not mean “no obligations.” Depending on the system, provider/deployer role, transparency features, AI literacy duties, customer use, and other legal layers may still matter. The first step is classification, not assumption.

What evidence should a SaaS vendor preserve?

At minimum: system identity, version, intended purpose, operator role, model/provider dependencies, customer instructions, transparency measures, change history, limitations, testing, incident records, and the evidence supporting any classification or exclusion claim.

Does TA-14 certify our SaaS platform as EU AI Act compliant?

No. TA-14 can preserve role analysis, system identity, evidence, gaps, changes and revalidation history. It does not itself provide legal advice, conformity assessment, certification or regulatory approval.

EU AI ACT WORLD · TA-14 AUTHORITY GOVERNANCE INSTITUTION

Understand the requirement. Preserve the evidence. Revalidate when reality changes.

TA-14 Exchange Activity

Public network activity

Live cumulative activity recorded across the public Exchange surface.

Refreshing public totals

···

Visitors

Recorded public visitors

···

Page Views

Recorded Exchange views