Answer guide

Are you compliant with the EU AI Act?

It sits in the questionnaire as a yes/no field. It is not a yes/no question — and the vendors who treat it as one either under-claim (and look unprepared) or over-claim (and hand the buyer's counsel something to dismantle in due diligence). Here is how to answer it honestly and well.

Why buyers ask this

Regulation (EU) 2024/1689 is in force and its obligations are landing in stages: the prohibitions of Article 5 and the AI-literacy measures of Article 4 have applied since 2 February 2025, the Article 50 transparency duties apply from 2 August 2026 (the Digital Omnibus did not postpone them), and the high-risk regime of Chapter III applies from 2 December 2027 for the Annex III use cases (Article 6(2)) and from 2 August 2028 for the Annex I regulated-product route (Article 6(1)). Breaching Article 50 can draw fines of up to €15,000,000 or 3% of total worldwide annual turnover, whichever is higher — for SMEs and startups, the lower of the two (Article 99). Your buyer's legal team wants to know whether any of that exposure sits in your product. And the question doubles as a competence test: a vendor who answers "yes, fully compliant" is telling the reviewer they haven't read the Regulation closely.

The honest answer structure

Four parts, in this order — the same structure we use in our full method for AI sections:

  1. Classification. Where your system sits in the Regulation's risk tiers. Most B2B SaaS is limited or minimal risk — outside both high-risk routes of Article 6: the Annex I regulated-product route (Article 6(1)) and the Annex III use-case list (Article 6(2)). Rule out both explicitly, and check before you say it.
  2. Obligations that apply to you. For a limited-risk system, typically Article 50 transparency plus Article 4 AI literacy. Mind the role trap: if you ship a third-party model under your own brand, you are the provider of the resulting system for Article 50(1) purposes — the duty to disclose the AI does not stay with the model vendor. The only carve-out is where the AI interaction is obvious to a person who is "reasonably well-informed, observant and circumspect". Full map of who owes what under Article 50.
  3. Status per obligation. What is actually in place today, stated factually — one line per obligation.
  4. Gaps, each with a plan. Current state, compensating control, "in progress", realistic target date that someone in your company actually approved.

Template — for orientation only. Replace every bracket with facts you have verified for your own product before sending. If your product touches Annex III territory (biometrics, employment decisions, credit scoring, and similar), or ships inside a product regulated under Annex I (medical devices, machinery and the rest), stop and take legal advice instead of adapting this.

"Classification: based on its current intended use, [your product] is not high-risk under either route of Article 6 of Regulation (EU) 2024/1689 — it is neither a product nor a safety component of a product covered by the Union harmonisation legislation listed in Annex I and subject to third-party conformity assessment (Article 6(1)), and it does not fall within the high-risk use cases of Annex III (Article 6(2)) — and is therefore a limited-risk AI system. Applicable obligations: because [your product] offers [an AI assistant] under our own brand, the transparency obligations of Article 50 apply to us as provider from 2 August 2026, alongside the Article 4 AI-literacy measures (applicable since 2 February 2025). Status: users are informed they are interacting with an AI system at first interaction [state where]; staff operating the system complete [your AI training], with completion records kept. In progress: [machine-readable marking of AI-generated content] is being implemented, targeted for [approved date]. We review this assessment as the Regulation's remaining provisions phase in."

Note what the template never says: "fully compliant". Under this Regulation, compliance is per obligation and per date — an unqualified claim is one the buyer can test.

The mistake that costs deals

The blanket "yes". It feels like the strong answer and it is the weak one: it is a warranty-shaped claim about a regulation whose obligations are still phasing in, made in a document you may later be asked to stand behind contractually. When one over-claim surfaces in due diligence, every other answer in your questionnaire gets re-read with suspicion.

The quieter version of the same mistake is over-claiming obligations you do not have — for example, presenting your human-review measures as satisfying the Regulation's human-oversight requirements. Article 14 human oversight binds high-risk systems only; for a limited-risk system, describe such measures as voluntary good practice that supports the buyer's risk management, not as AI Act compliance.

Mini-FAQ

Can we just answer "yes, we are compliant"?

No. Obligations phase in on staggered dates and differ by risk class and role, so "compliant" is only meaningful per obligation. Reviewers treat a blanket yes as a red flag — and by contract stage you may be asked to warrant it.

Which obligations apply to a typical B2B SaaS vendor?

Most B2B SaaS is limited or minimal risk: typically Article 50 transparency (from 2 August 2026) and Article 4 AI literacy (since 2 February 2025). The high-risk regime applies from 2 December 2027 for Annex III use cases (Article 6(2)) and from 2 August 2028 for the Annex I regulated-product route (Article 6(1)) — rule out both before calling yourself limited risk. For content-marking under Article 50(2), systems placed on the market before 2 August 2026 have a transition until 2 December 2026.

We use a third-party model — isn't compliance their problem?

Not entirely. Ship a model under your own name or trademark and you are the provider of the resulting system: the Article 50(1) disclosure duty is yours. Our free Article 50 checker maps which duties hit your product in seven questions.

Related: "Is our data used to train your AI models?" — usually the question next to it — and the first-24-hours playbook if the questionnaire just landed.

This exact question is sitting in your questionnaire?

Send it — first 3 answers free within 24h, full delivery in 48h for $490 flat up to 60 questions, paid after delivery. Every legal claim cited to its article. Judge the work on the public sample first.

Send your questionnaire →