# SaaS with Integrated AI: AI Act Provider Obligations

> Any SaaS provider integrating AI, even via a third-party API, is considered a provider under the AI Act. It must classify the system, produce technical documentation if it is high-risk, and inform its clients in accordance with Article 50. Compliance becomes essential by 2026.

- Tags: AI Act SaaS, obligations fournisseur IA, conformité IA SaaS B2B, documentation technique IA, transparence IA Article 50, GPAI SaaS, classification système IA
- Main keyword: obligations fournisseur AI Act SaaS

## Key points

- 85% of B2B SaaS providers use AI without official declaration.
- Transparency regarding AI becomes mandatory starting November 2, 2026 (Article 50).
- HR scoring systems are classified as high-risk according to Annex III.
- By 2026, 30% of tenders will require AI Act guarantees.

## Introduction

_If your SaaS uses an AI API to offer recommendations, scoring, or automation, you are legally considered a provider under the AI Act. Here is how to structure your compliance process and avoid being excluded from public or private markets._

## Content

## Why your SaaS is subject to the AI Act, even without internally developed AI

As soon as a SaaS provider integrates an artificial intelligence API to enhance its features (recommendation, scoring, automation), it assumes the status of a provider under the European regulation. **Article 3(3)** specifies that if an AI system is incorporated into a product marketed under the provider's brand, the latter bears the responsibility of the provider. It does not matter if the model comes from OpenAI, Mistral, or Anthropic: what matters is the final use offered to the client.

**Typical examples:**
- A project management tool that generates meeting minutes via the OpenAI API.
- A marketing platform that uses a third-party library to score leads.
- HR software that recommends training using a language model.

In all these cases, the provider must apply the provider obligations: classify the AI system and compile technical documentation if the use is high-risk.

[Article 3(3) AI Act](https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX%3A32024R1689) — Definition of provider

[Compaia Glossary](https://compaia.eu/glossaire) — Difference between provider/deployer

## Three essential steps to comply with the AI Act

Compliance with the AI Act for a B2B SaaS relies on three major pillars: classification, documentation, and transparency.

### 1. Determine the risk category of your AI system

The first step is to verify if the integrated AI feature falls into the high-risk category. **Annex III** of the text lists, among others:
- HR uses (candidate scoring, performance evaluation).
- Access to essential services (credit scoring, insurance).
- Education and training (automated grading).

If your system falls into these areas, it is mandatory to produce technical documentation compliant with **Annex IV**.

### 2. Draft the required technical documentation

For systems classified as high-risk, **Annex IV** requires detailed documentation, including:
- A precise description of the system's functionalities and limitations.
- The sources and types of training data.
- Cybersecurity and robustness measures implemented.
- Post-market monitoring procedures.

This documentation must be available to competent authorities at any time.

### 3. Respect transparency rules

**Article 50** of the regulation requires clearly informing end-users that they are interacting with an AI. For a B2B SaaS provider, this implies:
- Warning clients that certain features rely on AI.
- Presenting the system's capabilities and limitations in an information document (in accordance with **Article 13**).
- Specifying if the system is classified as high-risk.

[Annex III AI Act](https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX%3A32024R1689#d1e32-1-1) — Full list of high-risk systems

[Annex IV AI Act](https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX%3A32024R1689#d1e32-1-1) — Technical documentation requirements

[Guide to obligations by system type](https://compaia.eu/obligations) — compaia

## Case study: Compliance of an HR SaaS with automated scoring

Let's take the case of an HR software provider that integrates an AI API for automatic CV analysis. Here are the essential steps to ensure compliance.

**Use case:** an HR SaaS offers a premium module for automatic candidate scoring, powered by the OpenAI API.

### Step 1: System categorization

Candidate scoring falls under HR management, explicitly covered by **Annex III**. This system must therefore be treated as high-risk.

### Step 2: Development of technical documentation

The provider must compile a file compliant with **Annex IV**, including:
- Scoring criteria and their weighting.
- Datasets used for training (e.g., CV history, job offers).
- Measures to prevent discriminatory bias.
- Post-deployment monitoring methods (e.g., regular audits).

### Step 3: Transparent communication with clients

It is mandatory to:
- Inform clients that the scoring feature relies on AI.
- Provide a notice detailing the system's capabilities and limitations (in accordance with **Article 13**).
- Explicitly state that the system is classified as high-risk.

_An HR SaaS that neglects these obligations risks being excluded from tenders, particularly by large companies that now require AI Act compliance._

[CNIL — AI Act Guide](https://www.cnil.fr/fr/intelligence-artificielle/reglement-europeen-sur-lia) — Practical examples

[Compaia Diagnostic](https://compaia.eu/diagnostic) — Check if your system is high-risk

## Article 50: Concrete expectations of B2B clients

Corporate clients, especially large accounts, are demanding increased transparency regarding the use of AI in SaaS solutions.

**Article 50** of the AI Act requires providers to clearly inform end-users of the use of AI. This translates into:
- An explicit mention in the Terms of Service or technical documentation.
- An easily accessible information notice detailing:
  - Integrated AI features.
  - System limitations (error rates, potential biases).
  - Planned protection measures.
- A contact channel for any AI-related questions.

In regulated sectors (banking, insurance, health), AI Act clauses are becoming the standard in tenders. A SaaS provider without compliant documentation will be systematically rejected.

[AI Office — Transparency](https://digital-strategy.ec.europa.eu/en/policies/ai-act) — Official explanations

[Article 50 AI Act](https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX%3A32024R1689#d1e32-1-1) — Full text of transparency obligations

## Special case: Integration of a General Purpose AI (GPAI) model in your SaaS

If your SaaS relies on a general-purpose language model (GPAI) like GPT-4 or Mistral, additional obligations apply.

**Article 25(4)** of the regulation requires:
- Explicitly informing your clients that the system uses a GPAI model.
- Providing technical documentation on the model, including:
  - The capabilities and limitations of the model used.
  - Training data (to the extent available).
  - Associated cybersecurity measures.
- Complying with all transparency requirements set out in **Article 50**.

**Example:** a content generation SaaS using the Mistral API must inform its clients that it relies on a GPAI model, detailing the limitations (biases, risks of hallucination, etc.).

[Article 25(4) AI Act](https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX%3A32024R1689#d1e32-1-1) — GPAI obligations

[AI Act Explorer](https://www.ai-act.eu/) — Interactive guide

## Sanctions provided by the AI Act: amounts and percentages

Sanctions for non-compliance with the AI Act can reach **35 million euros** or **7%** of global annual turnover, whichever is higher. For SMEs, the cap is set at **15 million euros** or **3%** of turnover. Competent authorities may also order the withdrawal of the system from the market.

## Leveraging AI Act compliance in your SaaS offering

Compliance can become a real commercial asset, especially when responding to tenders.

Large companies and mid-sized enterprises now systematically include clauses related to the AI Act in their specifications. Providers unable to provide compliant documentation are automatically eliminated.

### Best practices for highlighting compliance:
- **Premium option**: Offer AI Act documentation as an add-on for large account clients.
- **Enterprise tier**: Reserve compliant features for the enterprise segment.
- **Sales pitch**: Highlight compliance in your presentations and marketing materials ("Our SaaS is compliant with the AI Act, ensuring transparency and security").
- **Certification**: Obtain third-party certification (CNIL label, ISO 42001) to build trust.

Example: a credit scoring SaaS can market AI Act documentation as a premium option, with a **20%** surcharge compared to the standard rate. Clients subject to strict regulatory constraints are willing to pay this supplement to reduce their risk exposure.

### Test your regulatory exposure in 3 minutes

A free diagnostic allows you to know if your SaaS is affected by the AI Act and to identify the key steps to achieve compliance.

[Compaia Diagnostic](https://compaia.eu/diagnostic)

## Official resources and practical guides

- [AI Act Regulation — full text](https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX%3A32024R1689)
- [AI Act Glossary — compaia](https://compaia.eu/glossaire)
- [Guide to obligations by system](https://compaia.eu/obligations)
- [AI Act Explorer](https://www.ai-act.eu/)
- [CNIL Guide on the AI Act](https://www.cnil.fr/fr/intelligence-artificielle/reglement-europeen-sur-lia)
- [AI Office — transparency](https://digital-strategy.ec.europa.eu/en/policies/ai-act)

---

_Jérémy Pierre_

Founder compaia.eu · AI Act Compliance Expert

Supporting AI providers and deployers on operational and regulatory compliance.

**35 million euros**, **15 million euros**, **85%**, **30%**, **20%**, **7%**, **3%**, **Article 50**, **Annex III**, **article 3(3)**, **Article 3(3)**, **annexe III**, **annexe IV**, **article 50**, **article 13**, **Annexe IV**, **article 25(4)**, **Article 25(4)**, **2026**

## Official source
- [Source](https://www.aiacto.eu/fr/blog/votre-saas-integre-ia-obligations-fournisseur-ai-act)
