Articles 6 / 16 / 25 / 53
EU AI Act for SaaS — Are You a Provider, Deployer, or Both?
A pillar guide for B2B SaaS vendors and buyers under Regulation (EU) 2024/1689. Provider vs deployer decision tree, GPAI integration, Article 25 promotion, the August 2026 deadlines.
Source: Regulation (EU) 2024/1689 on EUR-Lex · Last published 2026-04-28 · Hand-edited 2026-04-28
Why SaaS is the awkward case
The EU AI Act was drafted with three actors in mind: providers (who build), deployers (who use), and importers / distributors (who sell). SaaS is all three at once, sometimes for the same product. A B2B SaaS vendor delivering an HR-tech product to a French law firm:
- builds the AI feature (provider duties),
- operates it on hosted infrastructure (provider-as-operator),
- sells it as a service into the EU (importer/distributor concerns), and
- the buyer law firm becomes the deployer.
Most of the time, the vendor is the provider under Article 3(3) and the buyer is the deployer under Article 3(4). But there are four edge cases — and most SaaS products hit at least one.
This pillar walks the decision tree, names the obligations on each side, calls out the GPAI integration question, flags Article 25 promotion risks, and gives you the August 2026 deadline map.
Decision tree — provider vs deployer in five questions
1. Is the AI system high-risk under Article 6?
Article 6 classifies a system as high-risk if it falls under either:
- Annex I path — the system is a safety component of, or itself constitutes, a product covered by the Union harmonisation legislation in Annex I, AND that product requires a third-party conformity assessment.
- Annex III path — the system is intended for one of the use cases in Annex III: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice and democratic processes.
Most B2B SaaS triggers Annex III. HR-tech triggers §4(a) recruitment + §4(b) employee management. Credit-tech triggers §5(b). Edu-tech triggers §3. Customer-service AI triggers §5(a) for public-administration access to essential services. If you're in regulated B2B, run through Annex III line by line.
If the system is not high-risk, Article 11 / Annex IV does not apply. You may still owe Article 50 transparency obligations (deepfakes, AI-generated content disclosure) and, if your product is a GPAI, Article 53 duties. But you are out of the heavyweight regime.
2. Are you the provider or the deployer?
You are the provider (Article 3(3)) if you develop the system or have it developed and place it on the market or put it into service under your own name or trademark. SaaS vendors are almost always providers of their AI features.
You are the deployer (Article 3(4)) if you use the system under your authority. SaaS buyers are almost always deployers.
You are both if you build a feature using a third-party model and your customer uses it under their authority. This is the typical SaaS shape: vendor = provider, buyer = deployer.
3. Could you be promoted under Article 25?
Article 25 promotes a deployer (or distributor or importer) into a provider when any of three things happen:
- (a) They put their name or trademark on a high-risk system already placed on the market, unless the original provider has agreed by contract to retain the provider duties.
- (b) They make a substantial modification to a high-risk system already on the market, in such a way that it remains high-risk under Article 6.
- (c) They modify the intended purpose of a system that was not classified as high-risk in such a way that it becomes high-risk under Article 6.
For SaaS, this is the most common trap. A consultancy white-labels your AI feature and rebrands it — that consultancy may now be a provider for that variant under Article 25(a). A buyer fine-tunes your model on their data — they may now be a provider for that fine-tuned variant under Article 25(b). Document the Article 25 boundary in your contracts. The EU AI Office is expected to publish Article 25 contractual-allocation guidance in 2026.
4. Is there a GPAI model in the chain?
If your AI feature uses a general-purpose AI model — a third-party LLM, a third-party foundation vision model — the GPAI provider has separate duties under Article 53 (and Article 55 for systemic-risk GPAI). Your duties as the integrating provider of the high-risk system are unchanged: Article 11 Annex IV file, Article 9 risk management, Article 14 human oversight, Article 15 accuracy.
The GPAI provider's Annex XI training-data summary is an input to your Annex IV §2(d) data documentation, not a substitute for it. You still owe data-governance evidence at the integrated-system level.
5. Are you established outside the EU?
Article 16(b) requires non-EU providers to designate an authorised representative established in the Union by written mandate before placing the system on the market. This is not optional and not something to leave for the last week.
Article 22 lists the representative's duties. Article 49 registration in the EU Database is the place where most non-EU providers first realise they need a representative.
Provider obligations cheat-sheet (high-risk SaaS)
If you are a SaaS provider of a high-risk AI feature, you owe:
- Article 9 — continuous risk management system.
- Article 10 — data and data governance.
- Article 11 — technical documentation per Annex IV.
- Article 12 — automatic logging.
- Article 13 — transparency, instructions for use.
- Article 14 — human oversight measures designed in.
- Article 15 — accuracy, robustness, cybersecurity.
- Article 16 — provider obligations (QMS, conformity assessment, EU Database registration, post-market monitoring, corrective actions, cooperation).
- Article 17 — quality management system.
- Article 18 — 10-year retention of technical documentation.
- Article 19 — at-least-six-month log retention.
- Article 20 — corrective-action duty with distributors.
- Article 22 — authorised representative if non-EU.
- Article 47 — EU declaration of conformity.
- Article 49 — EU Database registration.
- Article 73 / 79 — serious-incident reporting, post-market monitoring.
Deployer obligations cheat-sheet (SaaS buyer)
If you buy a high-risk AI feature, you owe under Article 26:
- Use the system in accordance with the instructions for use.
- Assign competent, trained, authorised human oversight (Article 26(2)).
- Ensure deployer-controlled input data is relevant and representative of the intended purpose (Article 26(4)).
- Monitor operation in line with the IFU; inform the provider of any serious incident or risk (Article 26(5)).
- For deployers covered by Article 27 — public-sector bodies, private entities providing public services, credit-decision deployers, life/health insurance pricing — perform a FRIA.
- Cooperate with market surveillance authorities under Article 21.
A SaaS buyer's compliance burden is real but smaller than the provider's. The buyer relies on the provider's Article 13 instructions for use and Article 11 technical documentation as the foundation; their own duty is to use the system competently and to feed back operational reality.
The August 2026 deadline map
- 2 February 2025 — prohibited practices (Article 5) and AI literacy (Article 4) became applicable.
- 2 August 2025 — GPAI obligations (Article 53), governance (AI Office), and confidentiality regime applicable.
- 2 August 2026 — main applicability: high-risk AI systems under Annex III, transparency obligations (Article 50), penalties (Article 99). This is the date most SaaS providers must hit.
- 2 August 2027 — high-risk AI systems under Annex I (safety-component path) become applicable.
- Existing GPAI models on the market by 2 August 2025 had until 2 August 2027 to comply with Article 53.
If you are a SaaS provider with a high-risk Annex III feature, August 2026 is the date that matters. Backwards-plan: 12 weeks for Annex IV, 8 weeks for Article 17 QMS, 4 weeks for Article 47 / 49 paperwork. Start by Q1 2026 if you haven't.
What buyers ask SaaS vendors in due diligence
EU buyers (especially in regulated industries — banking, insurance, healthcare, public sector) increasingly run an AI-Act-specific due diligence pass. The questions you'll see:
- "Is your system high-risk under Annex III? Which point?"
- "Where is your Article 11 / Annex IV technical file? Can we have a redacted copy under NDA?"
- "What is your risk management cadence under Article 9?"
- "What is your bias-detection methodology under Article 10(2)(f)–(g)?"
- "What human oversight does the system support? Where is the stop control?"
- "What is your accuracy disaggregated by sub-group? (Article 15(3) + Annex IV(2)(b))"
- "What is your cybersecurity testing regime? (Article 15 + Annex IV(2)(g))"
- "Where are you registered in the EU Database under Article 49?"
- "Is your declaration of conformity under Article 47 current?"
- "Who is your authorised representative under Article 22 if you're non-EU?"
Vendors who can answer these in a single PDF win the deal. Vendors who can't, lose to a competitor who can.
What we ship
Governancer is a SaaS for SaaS — a compliance platform for B2B vendors and buyers under the EU AI Act. The Free tier includes the 30-question quiz and a gap-report email. The Starter tier ships the Article 11 technical-documentation template (.docx) and the 12-item compliance checklist. The Pro tier ships the LLM-assisted Article 11 drafting tool, the 30-item extended checklist, the FRIA template, ISO 42001 / NIST AI RMF crosswalks, per-system gap reports, regulatory digest, audit trail and exportable compliance file.
If you're 90 days from August 2026 and have nothing in place, start with the quiz. It is the smallest defensible step.
Internal links
- Article 11 step-by-step — the eight-section build, in order.
- FRIA explained — for deployers covered by Article 27.
- GPAI compliance — if your stack uses third-party LLMs.
- EU AI Act vs NIST AI RMF — for buyers asking for both.
- EU AI Act vs ISO 42001 — same.
Disclaimer. This page is a reference summary of how the EU AI Act applies to B2B SaaS. It is not legal advice. Verify with qualified counsel before relying on it for compliance decisions. Reg text from Regulation (EU) 2024/1689.
Reference checklist
From the Governancer 30-item EU AI Act checklist. Each item joins to the ISO 42001 + NIST AI RMF crosswalk table below.
Article 11 · Starter tier · critical
Draft technical documentation (system purpose, design, risk)
Required for all high-risk AI systems before market placement. Our template covers the eight mandatory sections in one .docx.
Article 16 · Pro tier · critical
Appoint authorised representative in EU (non-EU providers)
Article 22 requires non-EU providers to designate a written-mandate representative established in the Union before placement on market.
Article 26 · Pro tier · high
Deployer-side monitoring plan; report serious issues to provider
Article 26(5) requires deployers to monitor operation in line with the instructions for use and inform the provider of any serious incident or risk.
Article 26 · Pro tier · high
Assign human oversight to competent, trained, and authorised persons
Article 26(2) requires deployers to assign human oversight to natural persons with the necessary competence, training, authority, and support.
ISO 42001 + NIST AI RMF crosswalk
Pulled live from the Governancer crosswalk module. Mapping reference; not a substitute for ISO 42001 certification audit or NIST AI RMF self-attestation.
ISO/IEC 42001:2023
| Checklist item | ISO 42001 control | Rationale |
|---|---|---|
art11-tech-docs | ISO/IEC 42001:2023 Clause 7.5 — Documented information | Article 11 technical file is the AIMS-required documented information evidencing AI system design, purpose, and risk decisions. |
art11-tech-docs | ISO/IEC 42001:2023 Annex A.6.2 — AI system life cycle documentation | Annex A.6.2 requires lifecycle documentation; the Article 11 technical file is its EU AI Act manifestation. |
art16-registered-office | ISO/IEC 42001:2023 Annex A.10.2 — Allocation of responsibilities with suppliers and partners | A written-mandate EU representative is the allocation-of-responsibilities control in Annex A.10 third-party relationships. |
art26-deployer-monitoring | ISO/IEC 42001:2023 Annex A.6.2.8 — Operation and monitoring of AI systems | Deployer-side monitoring with provider escalation is the operational monitoring control in Annex A.6.2.8. |
art26-deployer-human-oversight | ISO/IEC 42001:2023 Annex A.9.2 — Human oversight of AI systems | Article 26(2) competent and trained oversight by deployers is the human-oversight control of Annex A.9.2. |
NIST AI RMF 1.0
| Checklist item | NIST AI RMF subcategory | Rationale |
|---|---|---|
art11-tech-docs | NIST AI RMF MAP 4.1 — Approaches and metrics for measurement of AI risks are followed; documentation includes purpose, intended use, users, and limitations | Article 11 technical file documents purpose, design and limitations — the system-context output expected by MAP 4.1. |
art11-tech-docs | NIST AI RMF GOVERN 1.4 — The risk management process is documented and is regularly reviewed | Maintaining a living technical file is the documented and regularly reviewed risk-management evidence under GOVERN 1.4. |
art16-registered-office | NIST AI RMF GOVERN 6.1 — Policies and procedures are in place to address AI risks and benefits arising from third-party software and data | Designating a written-mandate EU representative is part of the third-party-relationship governance GOVERN 6.1 covers. |
art26-deployer-monitoring | NIST AI RMF MANAGE 4.1 — Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing and evaluating input from users and other relevant AI Actors | Article 26(5) deployer monitoring with provider escalation is the deployer-side leg of MANAGE 4.1 monitoring. |
art26-deployer-human-oversight | NIST AI RMF GOVERN 3.2 — Policies and procedures define and differentiate roles and responsibilities for human-AI configurations | Assigning competent and trained oversight personnel is the human-AI role differentiation GOVERN 3.2 mandates. |
Related
Article 11
EU AI Act Article 11 — Technical Documentation Requirements
Article 26
EU AI Act Article 26 — Deployer Obligations
Article 53
EU AI Act Article 53 — General-Purpose AI Model Provider Obligations
Article 16
EU AI Act Article 16 — Provider Obligations Checklist
Articles 51 / 53 / 55
GPAI Compliance — Obligations for General-Purpose AI Model Providers
Article 11 + Annex IV
EU AI Act Article 11 Step-by-Step — How to Build the Annex IV File
Article 27
FRIA Explained — Fundamental Rights Impact Assessment Under Article 27
Pro feature
Generate Article 11 with AI
LLM-assisted draft of all eight Annex IV sections, pre-filled from your system intake. 5 drafts/month on Pro.
Pro template
Download FRIA template
15-page Article 27 FRIA template (.docx) with the six elements pre-structured and a worked example.
Get the 30-item EU AI Act compliance checklist
Free PDF. No spam. Maps every Article and Annex IV section we ship to a ready-to-action checklist row.
Reference; not legal advice. Verify with qualified counsel before relying on it for compliance decisions. Reg text quoted from the Official Journal version of Regulation (EU) 2024/1689. Published by Agonist Development AB.