Disclosure: This article contains affiliate links. We may earn a commission if you make a purchase through them.
If you're a CTO, VP Engineering, or compliance lead evaluating SaaS vendors, most EU AI Act content on the web is written for the wrong audience. It explains what AI providers must build. It rarely explains what you, as the buyer, should actually verify before you sign a contract, and it almost never accounts for the biggest change to the Act's timeline in its history — a deadline delay that only became binding law in the last few weeks.
This checklist is written for the procurement side of the table: what to ask a vendor, what to put in the contract, and which 2026 deadlines still apply to you even though the headline "August 2026" enforcement date most articles cite no longer means what it used to.
Quick Answer
Full high-risk obligations under the EU AI Act were pushed back to December 2, 2027 (stand-alone systems) and August 2, 2028 (AI embedded in regulated products) after the EU Council gave final approval to the "Digital Omnibus" simplification package on June 29, 2026. But the August 2, 2026 transparency rules (Article 50 — chatbot disclosure, labeling of AI-generated content) were not delayed and still apply. Here's what that means for a checklist:
- Get the vendor's AI Act risk classification in writing — don't assume "minimal risk" without asking.
- Add an AI Act compliance warranty and audit-rights clause to the master services agreement, not a side letter.
- Confirm whether the tool discloses AI interaction to end users and labels AI-generated content (required from August 2, 2026, regardless of the high-risk delay).
- Ask which foundation model sits underneath the product and whether that model provider has met its GPAI obligations (in force since August 2, 2025).
- Document your own staff's AI literacy training — this is an obligation on your organization too, not just the vendor.
- Don't treat the December 2027 delay as "nothing to do until 2027" — contract terms, data rights, and vendor due diligence should be locked down now, while you have leverage.
On this page
1Why This Matters Now: The Timeline Just Changed
Until this summer, the working assumption — repeated across most EU AI Act explainers, including several currently ranking for this exact keyword — was that high-risk AI system obligations would become enforceable on August 2, 2026, alongside the Act's general transparency rules. That assumption is now out of date.
On November 19, 2025, the European Commission proposed a "Digital Omnibus on AI" to defer several high-risk compliance deadlines, citing delays in Member States designating market-surveillance authorities and the slow finalization of harmonized technical standards. The European Parliament and Council reached a provisional political agreement on May 7, 2026. Parliament formally endorsed it on June 16, 2026 (423 votes in favor, 57 against, 174 abstentions), and the Council of the EU gave its final green light on June 29, 2026. At the time of writing, the amended regulation was awaiting formal publication in the EU's Official Journal — expected imminently, ahead of the original August 2, 2026 deadline — after which it enters into force three days later.
The net effect for a B2B SaaS buyer: the deadline that generates headlines — full high-risk conformity assessment — is no longer this August. But two other tracks are unaffected and land on schedule. Here's the current state of play, as verified this month:
| Deadline | What Applies | Who It Affects | Buyer Action |
|---|---|---|---|
| Feb 2, 2025 (in force) |
Article 5 prohibited-practice ban; Article 4 AI literacy obligation | All providers and deployers | Confirm the vendor doesn't use banned techniques (subliminal manipulation, untargeted biometric scraping, workplace emotion inference, social scoring) |
| Aug 2, 2025 (in force) |
GPAI model obligations (Art. 51–56); penalty provisions become enforceable | Foundation-model providers underlying your vendor's product | Ask which base model powers the tool and whether that model's provider has published its GPAI documentation |
| Aug 2, 2026 | Article 50 transparency: chatbot disclosure, AI-content labeling for newly placed systems | Any vendor product with a chatbot, generative output, or biometric/emotion feature | Confirm the product discloses AI interaction and marks synthetic content |
| Dec 2, 2026 | Labeling grace period ends for pre-existing systems; new ban on non-consensual intimate-imagery ("nudifier") AI | Systems already on the market before Aug 2026 | Confirm labeling is complete for any legacy AI feature by this date |
| Dec 2, 2027 (delayed from Aug 2026) |
High-risk obligations for stand-alone Annex III systems | Vendor tools used for hiring/HR scoring, credit or insurance decisioning, biometric ID, critical-infrastructure monitoring | Get the vendor's roadmap toward conformity assessment — and a written compliance warranty now, even though the hard deadline moved |
| Aug 2, 2028 (delayed from Aug 2027) |
High-risk obligations for AI embedded in Annex I regulated products | Medical devices, machinery, vehicles with embedded AI components | Relevant mainly if you're procuring regulated hardware/software combinations |
One nuance worth flagging: the AI literacy obligation under Article 4 technically started on February 2, 2025, but meaningful enforcement depends on the national market-surveillance authorities that Member States are only now finishing standing up — so don't assume "in force since 2025" means "actively audited since 2025." It's a live obligation with enforcement catching up to it.
2Are You Even in Scope? Provider vs. Deployer vs. Buyer
Most competing content on this keyword is written from the perspective of the company building the AI system. If you're buying or evaluating a SaaS tool that happens to use AI, your legal role under the Act is almost always deployer, not provider. That distinction changes what you're actually on the hook for:
- Providers (typically your vendor, or the foundation-model company behind your vendor's product) carry the heavy compliance lift: risk classification, conformity assessment, technical documentation, and registration in the EU database for high-risk systems.
- Deployers (typically you, the buyer, if you use the tool in your own operations) have a narrower but real set of duties: use the system per its instructions, ensure human oversight where required, monitor for and report serious incidents, and maintain your own staff's AI literacy.
- The Act applies extraterritorially, the same way GDPR does. If your company has EU customers, EU employees, or an AI system's output affects people in the EU, scope questions apply even if you're headquartered outside Europe.
The practical upshot: your direct legal exposure as a buyer is usually smaller than a vendor's, but not zero, and it doesn't disappear just because the high-risk deadline moved to December 2027. Deployer obligations for prohibited practices and (from August 2026) transparency are unaffected by the delay.
3The B2B SaaS Buyer's EU AI Act Checklist
Work through these six areas before signing or renewing a contract with a vendor whose product uses AI in any customer-facing or decision-influencing way.
1. Get the Vendor's Risk Classification in Writing
Ask the vendor directly: "What is this product's classification under Article 6 of the EU AI Act, and on what basis?" A vendor that can't answer, or answers with marketing language instead of a specific tier, is a signal to dig deeper, not a reason to stop asking.
An AI system is high-risk under Article 6 through one of two routes: it's a safety component of (or is) a product covered by Annex I product-safety legislation requiring third-party conformity assessment, or it falls into an Annex III use case — biometrics, critical-infrastructure management, education and vocational training, employment and worker management, access to essential private or public services (including credit scoring and insurance risk pricing), law enforcement, migration and border control, or the administration of justice. A narrow carve-out exists for systems performing purely procedural tasks or improving the result of an already-completed human decision without materially affecting the outcome — but don't take a vendor's word for that exemption without seeing their reasoning.
For B2B SaaS buyers specifically, the categories that come up most often are HR and applicant-tracking tools (employment/worker management), fintech underwriting and collections tools (credit and essential-services access), and any product with biometric or emotion-recognition features bolted onto a support or security workflow.
2. Lock Down Contract Terms Before You Sign
The Digital Omnibus delay is a reason to negotiate contract language now, not a reason to wait. Vendors have more room to make commitments while the hard compliance deadline is still 17+ months out, and locking in terms early avoids a renegotiation fight closer to December 2027.
| Contract Clause | Why It Matters | Red Flag |
|---|---|---|
| AI Act compliance warranty | Vendor formally states its classification and commits to meeting applicable obligations by the correct (post-Omnibus) deadline | Warranty only references "applicable law" generically, with no named classification |
| Documentation access | You need instructions for use, and (for high-risk systems) technical documentation and a declaration of conformity, on request | Documentation gated behind a paid "enterprise tier" or not contractually guaranteed |
| Data and model rights | Clarifies who owns your input data, any fine-tuned model built on it, and generated outputs | Broad, one-sided rights for the vendor to reuse your data for model training by default |
| Incident notification | Serious-incident reporting timelines for high-risk systems, and general security-incident SLAs | No defined notification window, or one longer than your own regulatory reporting deadlines |
| Subprocessor / model disclosure | You need to know which foundation model(s) sit underneath the product for your own GPAI due diligence | Vendor treats the underlying model as confidential with no disclosure mechanism |
| Audit rights | Right to request evidence of compliance status, not just a self-attestation | No audit or evidence-request mechanism beyond the vendor's own marketing claims |
If your vendor already uses a GRC platform to manage its own compliance posture, ask to see the relevant evidence directly — most modern platforms, including the compliance-automation tools we compared here, generate shareable trust-center pages or evidence packets specifically for this kind of vendor due-diligence request.
3. Demand Documentation and an Audit Trail
Even with the high-risk deadline pushed to December 2027, providers of systems that will eventually fall into that tier should already be building the paper trail: technical documentation describing the system's purpose, logic, and data governance; instructions for use covering intended purpose and known limitations; and, once the deadline lands, a declaration of conformity and CE marking for qualifying systems.
As a buyer, you don't need to independently verify a vendor's entire conformity file today. What you should confirm is that the vendor is building toward it and can produce interim evidence — a documented risk-management process, a data-governance policy, and logging sufficient to support human oversight — rather than starting from zero when 2027 arrives. Frameworks like ISO/IEC 42001 are becoming the de facto way vendors demonstrate this readiness; if the tool you're evaluating claims 42001 alignment, ask for the certificate scope, not just the logo on their trust page (we'll cover how ISO 42001 maps to EU AI Act documentation requirements in a dedicated guide).
4. Check What's Under the Hood: GPAI-Specific Items
Most B2B SaaS AI features aren't built on a proprietary model from scratch — they're a workflow layered on top of a general-purpose AI (GPAI) model from a foundation-model provider. Those obligations have applied since August 2, 2025, independent of the high-risk delay.
Under the Act, a GPAI model is one trained with more than 1023 floating-point operations that can generate language, image, audio, or video output. Models trained at or above 1025 FLOPs carry a presumption of "systemic risk," triggering additional obligations, and providers must notify the European Commission within two weeks of reasonably foreseeing they'll cross that threshold. GPAI providers generally must maintain technical documentation, publish a summary of training content using the Commission's template, and demonstrate compliance with EU copyright law.
Ask your vendor: which foundation model (or models) power this feature, and has that provider published its GPAI documentation and training-data summary? If the vendor can't answer, that's a gap worth flagging — not necessarily disqualifying, but worth tracking against their roadmap. (We're planning a full breakdown of how the NIST AI RMF maps to EU AI Act GPAI obligations for teams running dual frameworks.)
5. Verify Transparency Compliance (Article 50)
This is the one deadline in this checklist that wasn't touched by the Digital Omnibus. From August 2, 2026, any AI system that interacts directly with people must disclose that fact in plain, accessible terms — this covers customer-facing chatbots, AI sales/support assistants, and voice agents. Generative systems producing text, image, audio, or video must mark that output as artificially generated or manipulated in a machine-readable format. Systems already on the market before August 2, 2026 get a grace period on the labeling requirement specifically, extending to December 2, 2026.
For procurement purposes: if the tool you're buying includes a chatbot, AI writing assistant, voice feature, or any generative output shown to your customers or the public, confirm the disclosure and labeling behavior is either already built in or on a committed roadmap for August 2026.
6. Don't Forget Your Own AI Literacy Obligation
Article 4 doesn't just apply to your vendor — it applies to you as a deployer, too. Your organization is expected to take reasonable measures to ensure staff operating or using AI systems on your behalf have a sufficient level of AI literacy, calibrated to their role and the context in which the system is used. There's no mandated test or certification, but regulators expect documented evidence of training, not just a policy statement sitting in a wiki.
Practically: keep a record of who uses AI-powered vendor tools, what training they've received (even a recorded session plus a sign-off), and revisit it when you adopt a new AI feature. This overlaps meaningfully with GDPR training obligations many compliance teams already run — a topic covered in more depth in our GDPR vs. EU AI Act overlap guide.
4What's Actually at Stake: Penalties and Exposure
The Act's penalty structure, under Article 99, is tiered by severity, and it's worth understanding who typically bears each type of exposure in a vendor relationship:
- Prohibited practices (Article 5): up to €35 million or 7% of total worldwide annual turnover, whichever is higher — the most severe tier, covering things like subliminal manipulation, untargeted facial-recognition scraping, and social scoring.
- High-risk system and most other obligations: up to €15 million or 3% of worldwide turnover, whichever is higher. This is the tier that will matter for Annex III systems once the December 2027 (or August 2028) deadlines land.
- GPAI provider violations (Article 101): up to €15 million or 3% of worldwide turnover, enforced by the EU AI Office rather than national authorities.
- Supplying incorrect or misleading information to authorities: up to €7.5 million or 1% of turnover.
- SMEs and startups benefit from a cap based on whichever figure — the fixed amount or the percentage — is lower, rather than higher, reversing the calculation used for larger undertakings.
In practice, most of this liability sits with the provider (your vendor or its underlying model provider), not with you as a deployer — unless you materially modify the system, use it outside its documented intended purpose, or fail your own deployer obligations (human oversight, incident reporting, AI literacy). That's exactly why the contract clauses in the checklist above matter: they determine who actually absorbs the risk if your vendor gets it wrong.
5Recommended AI Governance and Compliance Tooling
Two categories of tooling are relevant here, and buyers frequently conflate them. General GRC platforms treat the EU AI Act as one framework alongside SOC 2, ISO 27001, and GDPR — a good fit if AI risk is one line item in a broader compliance program. Dedicated AI governance platforms are built around Annex III risk classification and Annex IV technical documentation as their core product, which tends to matter more once your organization runs multiple AI systems across teams.
Vanta has built a specific EU AI Act module on top of its GRC platform: system and team scoping tools, guided workflows spanning more than 150 controls and 16 policies, incident and model monitoring, and evidence mapping across ISO 42001 and the NIST AI RMF so teams running multiple frameworks aren't duplicating work.
Evaluating Vanta for AI Act readiness?
See their EU AI Act module, control mapping, and evidence workflows.
Get a Vanta QuoteDrata and Secureframe take a similar GRC-plus-AI approach, with Secureframe notably early in adding AI-specific frameworks (including NIST AI RMF and ISO 42001-adjacent controls) and automation features aimed at drafting remediation steps and readiness reports, while Drata leans into AI-assisted control mapping and vendor-risk workflows across its broader platform. We covered all three vendors, including pricing structure and where each one is strongest, in our full Secureframe vs. Vanta vs. Drata comparison.
Comparing Secureframe against the field?
Check current plans and see if their AI compliance automation fits your stack.
Get a Secureframe QuoteIf your organization is managing a larger AI portfolio — multiple internal AI systems, several vendor tools with embedded AI, or you need Annex III/IV documentation as a system of record rather than an add-on — dedicated AI governance platforms such as OneTrust, Credo AI, and Holistic AI are built specifically around discovery, risk classification, and impact assessments at that scale, rather than treating the Act as one framework among several.
Need dedicated AI governance, not just a GRC add-on?
Compare Drata's AI-assisted control mapping and vendor-risk tooling.
Whichever direction you go, verify current pricing and feature scope directly with each vendor before deciding — AI-compliance modules are one of the fastest-moving product categories in the GRC space right now, and tiers change often.
6FAQ
Does the EU AI Act apply if my company isn't based in the EU?
Yes, in most cases. Like GDPR, the Act applies extraterritorially: if your AI system's output is used in the EU, or you have EU-based customers, employees, or users interacting with the system, scope questions apply regardless of where your company is headquartered.
Is my SaaS vendor's tool "high-risk" under the Act?
Only if it fits one of the specific Annex III use cases (biometrics, employment and worker management, credit or essential-services access, critical infrastructure, law enforcement, migration, or justice administration) or is a safety component of an Annex I regulated product. Most general productivity, analytics, and support-tooling AI features fall into the limited- or minimal-risk tiers instead — but don't assume that without asking the vendor for their specific classification and reasoning.
Now that high-risk deadlines are delayed to December 2027, do I still need to worry about EU AI Act compliance in 2026?
Yes. The August 2, 2026 transparency obligations (Article 50 — chatbot disclosure and AI-content labeling) were not delayed, GPAI obligations have applied since August 2025, and your own organization's AI literacy obligation under Article 4 has technically applied since February 2025. The delay affects the heaviest compliance lift — high-risk conformity assessment — not the full Act.
What's the difference between being an AI "provider" and a "deployer" — which one is my company?
A provider builds and places the AI system on the market; a deployer uses it under its own authority. As a company buying and using a SaaS tool with AI features, you're almost always a deployer for that specific system, even if you're a provider for AI features you build yourselves.
Can I be fined for a compliance failure by my AI vendor?
Direct liability generally sits with the provider, but as a deployer you can face exposure if you materially modify the system, use it outside its documented intended purpose, skip required human oversight, or fail to report a serious incident. This is exactly why the contract clauses covering compliance warranties, documentation access, and audit rights matter — they determine how risk is allocated between you and the vendor if something goes wrong.
7Methodology
This checklist was compiled from the EU AI Act's official text (Articles 4, 5, 6, 50, 51–56, 99, 101, and Annexes I and III), the European Commission's Digital Omnibus on AI proposal and the resulting co-legislator agreement finalized by the European Parliament (June 16, 2026) and the Council of the EU (June 29, 2026), and current public product documentation from Vanta, Drata, and Secureframe, cross-checked against independent legal-industry analysis published in the weeks following the Omnibus vote. All dates and figures were verified as of July 2026; given the pace of change on this file, confirm current deadlines directly with the European Commission's AI Act Service Desk before finalizing any compliance program.