Enterprise prospects are now asking: "Are you EU AI Act compliant?" Get your documentation, DPAs, and AI risk register in order before your next enterprise procurement — without hiring a compliance team.
Rising
share of enterprise procurement that asks for AI compliance docs
2025
EU AI Act obligations live for GPAI providers
€35M
GPAI max fine for prohibited AI
30 days
DSAR response deadline for SaaS users
B2B SaaS companies using AI features face a fast-moving compliance landscape: the EU AI Act imposes provider obligations for AI systems deployed in the EU, GDPR governs data processing, and enterprise buyers increasingly require SOC 2 and EU AI Act attestation in procurement questionnaires.
GPAI model provider obligations
If your SaaS product includes a general-purpose AI model you built or fine-tuned, you are a GPAI model provider under EU AI Act Chapter V. Technical documentation and transparency measures are mandatory from August 2025.
EU AI Act deployer obligations
If you use third-party AI APIs (OpenAI, Anthropic, Google) in your product, you are a deployer of an AI system under the Act. You must ensure provider compliance documentation exists and implement required transparency measures for your users.
Enterprise procurement questionnaires
Large enterprise customers now require EU AI Act compliance documentation, AI vendor agreements, and DPAs as part of procurement. Failing to provide these delays or loses deals.
GDPR Article 28 DPAs for every customer
As a data processor for your customers, you must have an Article 28 DPA in place with every customer who is in the EU/UK. Missing DPAs block sales and create GDPR liability.
AI feature transparency for users
EU AI Act Article 50 requires that users are told when they interact with an AI system. Undisclosed AI features — chatbots, recommendation engines, content generation — are a violation.
Sub-processor notification obligations
When you add or change AI providers (sub-processors), GDPR requires notifying customers who have DPAs with you. Many SaaS companies manage this poorly, creating retroactive compliance debt.
EU AI Act documentation kit
Generate the technical documentation required for GPAI model providers and deployers — model cards, risk assessments, transparency notices — ready to share with enterprise procurement teams.
Customer DPA builder
Generate GDPR Article 28 DPAs automatically for every new customer. Send for e-signature in one click. Track signing status in your compliance dashboard.
Sub-processor register and notifications
Maintain a live sub-processor register. When you add or change AI vendors, Aegis Firma generates the required customer notifications in bulk.
AI transparency notices for your product
Generate and update the in-product transparency notices required when users interact with AI features — ready to drop into your Terms of Service and feature UI.
Enterprise trust page toolkit
Generate a compliance trust page you can share with enterprise prospects — showing your GDPR documentation, AI Act status, sub-processor list, and security posture.
SOC 2 policy templates
Pre-built information security policies for all 5 SOC 2 Trust Service Categories, ready to publish and use as evidence in your Type I or Type II audit.
When do EU AI Act obligations apply to SaaS providers?
GPAI model providers had their first obligations from August 2025 (transparency, copyright policy, technical documentation for systemic risk models). Article 50 transparency duties apply from August 2, 2026. Deployer obligations for high-risk AI systems (Annex III) were deferred by the 2025 Digital Omnibus to December 2, 2027. However, enterprise procurement is already requiring compliance documentation now — companies that prepare early win deals competitors lose.
We use OpenAI/Anthropic APIs — are we a "provider" or "deployer" under the EU AI Act?
If you use an existing AI model via API and build your own product on top, you are generally a deployer. Your obligations are lighter than a provider's but still include: using the system within its intended purpose, implementing required transparency for users, maintaining usage logs, and ensuring your use does not cause harm. You are not responsible for the model's underlying compliance — that is OpenAI/Anthropic's responsibility as the provider.
What do enterprise procurement teams actually ask for?
Common requests include: (1) your Data Processing Agreement, (2) your sub-processor list, (3) a Data Protection Impact Assessment summary for your AI features, (4) your security policies (ISO 27001 / SOC 2 / equivalent), and increasingly (5) your EU AI Act compliance documentation and risk assessment. Aegis Firma generates all of these.
How do we handle sub-processor changes when we switch AI providers?
GDPR Article 28(2) requires you to give customers advance notice of sub-processor changes and a right to object. Aegis Firma maintains your sub-processor register and can generate bulk notification emails whenever you add or remove an AI vendor.
Cancel anytime · 7-day refund eligibility · no contracts