Are you compliant with the EU AI Act?
It sits in the questionnaire as a yes/no field. It is not a yes/no question — and the vendors who treat it as one either under-claim (and look unprepared) or over-claim (and hand the buyer's counsel something to dismantle in due diligence). Here is how to answer it honestly and well.
Why buyers ask this
Regulation (EU) 2024/1689 is in force and its obligations are landing in stages: the prohibitions of Article 5 and the AI-literacy measures of Article 4 have applied since 2 February 2025, the Article 50 transparency duties apply from 2 August 2026 (the Digital Omnibus did not postpone them), and the high-risk regime for Annex III use cases applies from 2 December 2027. Breaching Article 50 can draw fines of up to €15,000,000 or 3% of total worldwide annual turnover, whichever is higher — for SMEs and startups, the lower of the two (Article 99). Your buyer's legal team wants to know whether any of that exposure sits in your product. And the question doubles as a competence test: a vendor who answers "yes, fully compliant" is telling the reviewer they haven't read the Regulation closely.
The honest answer structure
Four parts, in this order — the same structure we use in our full method for AI sections:
- Classification. Where your system sits in the Regulation's risk tiers. Most B2B SaaS is limited or minimal risk — outside the high-risk use cases of Annex III. Say so explicitly, and check before you say it.
- Obligations that apply to you. For a limited-risk system, typically Article 50 transparency plus Article 4 AI literacy. Mind the role trap: if you ship a third-party model under your own brand, you are the provider of the resulting system for Article 50(1) purposes — the duty to disclose the AI does not stay with the model vendor. The only carve-out is where the AI interaction is obvious to a person who is "reasonably well-informed, observant and circumspect". Full map of who owes what under Article 50.
- Status per obligation. What is actually in place today, stated factually — one line per obligation.
- Gaps, each with a plan. Current state, compensating control, "in progress", realistic target date that someone in your company actually approved.
Template — for orientation only. Replace every bracket with facts you have verified for your own product before sending. If your product touches Annex III territory (biometrics, employment decisions, credit scoring, and similar), stop and take legal advice instead of adapting this.
"Classification: based on its current intended use, [your product] does not fall within the high-risk use cases of Annex III of Regulation (EU) 2024/1689 and is a limited-risk AI system. Applicable obligations: because [your product] offers [an AI assistant] under our own brand, the transparency obligations of Article 50 apply to us as provider from 2 August 2026, alongside the Article 4 AI-literacy measures (applicable since 2 February 2025). Status: users are informed they are interacting with an AI system at first interaction [state where]; staff operating the system complete [your AI training], with completion records kept. In progress: [machine-readable marking of AI-generated content] is being implemented, targeted for [approved date]. We review this assessment as the Regulation's remaining provisions phase in."
Note what the template never says: "fully compliant". Under this Regulation, compliance is per obligation and per date — an unqualified claim is one the buyer can test.
The mistake that costs deals
The blanket "yes". It feels like the strong answer and it is the weak one: it is a warranty-shaped claim about a regulation whose obligations are still phasing in, made in a document you may later be asked to stand behind contractually. When one over-claim surfaces in due diligence, every other answer in your questionnaire gets re-read with suspicion.
The quieter version of the same mistake is over-claiming obligations you do not have — for example, presenting your human-review measures as satisfying the Regulation's human-oversight requirements. Article 14 human oversight binds high-risk systems only; for a limited-risk system, describe such measures as voluntary good practice that supports the buyer's risk management, not as AI Act compliance.
Mini-FAQ
Can we just answer "yes, we are compliant"?
No. Obligations phase in on staggered dates and differ by risk class and role, so "compliant" is only meaningful per obligation. Reviewers treat a blanket yes as a red flag — and by contract stage you may be asked to warrant it.
Which obligations apply to a typical B2B SaaS vendor?
Most B2B SaaS is limited or minimal risk: typically Article 50 transparency (from 2 August 2026) and Article 4 AI literacy (since 2 February 2025). The Annex III high-risk regime applies from 2 December 2027. For content-marking under Article 50(2), systems already on the market have a transition until 2 December 2026.
We use a third-party model — isn't compliance their problem?
Not entirely. Ship a model under your own name or trademark and you are the provider of the resulting system: the Article 50(1) disclosure duty is yours. Our free Article 50 checker maps which duties hit your product in six questions.
Related: "Is our data used to train your AI models?" — usually the question next to it — and the first-24-hours playbook if the questionnaire just landed.