Define the system
Start by naming the AI feature, users, decision impact, data categories, vendors, and the team member responsible for maintaining the review record.
US SaaS guide
A US company can still have EU AI Act exposure when it places an AI system on the EU market, serves EU customers, supports EU deployers, or produces outputs used in the EU. Start with scope, then classify the use case.
| Question | Why it matters |
|---|---|
| Do you offer the AI feature to EU customers or users? | EU market availability can create review needs even when the company is incorporated in the United States. |
| Do EU-based customers deploy the feature inside their workflows? | Your customer may be a deployer, while your company may still have provider or supplier duties depending on the product role. |
| Are AI outputs used in the EU? | Article 2 includes certain providers and deployers outside the EU when output produced by the AI system is used in the Union. |
| Do you control the model, intended purpose, or key product behavior? | Control over intended purpose and system design is important when assigning provider, deployer, importer, or distributor roles. |
| Do you sell through partners, marketplaces, or enterprise resellers? | Distribution channels can add role-mapping and documentation requests. |
| Feature | Review focus |
|---|---|
| AI support chatbot | Transparency notice, escalation to human support, limitation language, and data handling. |
| AI hiring assistant | Employment high-risk signal, human oversight, documentation, evaluation, and vendor role mapping. |
| Lead scoring or fraud scoring | Whether the score affects access, eligibility, pricing, services, or treatment of individuals. |
| Document summarization | Transparency, accuracy warnings, review path, and whether summaries are used for consequential decisions. |
| Generated marketing media | AI-generated content disclosure and deepfake or synthetic media rules where relevant. |
Last reviewed: July 3, 2026.
practical AI compliance self-assessment
EU AI Act for US SaaS Companies | Practical Scope Guide is maintained for founders, product managers, compliance owners, agencies, and small teams building AI workflows who need AI governance workflow. The goal is to help visitors complete a real task and leave with an AI inventory, risk note, disclosure draft, vendor question set, policy outline, or review workflow report, not only read a generic summary.
Start by naming the AI feature, users, decision impact, data categories, vendors, and the team member responsible for maintaining the review record.
Use the generated output as first-pass operational triage. Legal, medical, hiring, credit, education, biometric, and public-sector uses still need specialist review.
Save the output, assumptions, date, source links, and reviewer notes so the team can explain why a risk level, disclosure, or vendor question set was chosen.
Review record
A compliance tool is useful when it leaves a traceable record. The output should name the AI system, explain the assumptions, and show what the team still needs to verify with product, legal, security, or vendor owners.
Record the feature name, user group, decision impact, data sources, vendor dependencies, and the human owner. A generic "chatbot" label is rarely enough. A hiring assistant, support summarizer, medical triage bot, and product recommender can have very different risk profiles even if they all use language models.
Treat this page as first-pass triage. It can flag high-risk areas, transparency duties, missing evidence, and questions to ask a vendor. It should not be treated as legal approval, clinical advice, hiring approval, credit approval, or permission to launch without human review.
Save the generated result with the date, reviewer, source links, and unresolved questions. Update the record when the model, data, users, product flow, vendor, or region changes. This keeps the site useful for actual operators rather than only being a static explanation page.