Observed Signal · Jun 2, 2026 · Guidance · Source: DEV Community · Impact: 3/5 · Sentiment: Neutral

Decision Tree to Classify SaaS Features Under EU AI Act

Executive Signal Summary

A Dev.to post from Disclos explains how to determine whether a SaaS AI feature is high-risk under Annex III of the EU AI Act. The author provides a three-question decision tree used in audits, eight anonymised real-world SaaS examples, time/cost estimates for compliance, and an open-source Python classifier (github.com/GatisOzols/eu-ai-act-checklist). High-risk systems (Annex III) require conformity assessment, a technical file, human oversight policies, post-market monitoring and EU database registration; limited/minimal-risk features mainly need Article 50 transparency disclosures. The post highlights penalties for misclassification (Article 99(3): up to €15M or 3% of worldwide turnover), and offers paid audits via Disclos (5 business days, €997, refund if not compliant by 2026-08-02).

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

Practical classification guidance and an open-source classifier help SaaS vendors assess EU AI Act obligations; misclassification carries major financial and operational consequences relevant to software vendors and MarTech/AdTech SaaS providers.

SIGNAL RADAR

Track Real-Time Regulation Signals & Market Shifts

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • Annex III of the EU AI Act lists eight high-risk application areas; if an AI feature falls into any, heavier obligations apply.
  • The author provides a three-question decision tree to classify SaaS AI features as prohibited / high-risk / limited-risk / minimal-risk.
  • High-risk classification requires conformity assessment, a technical file (Article 11), human oversight policy, post-market monitoring, and EU database registration.
  • An open-source classifier (python script) is available at https://github.com/GatisOzols/eu-ai-act-checklist to run the checklist automatically.
  • Article 99(3) sets penalties for non-compliance with high-risk obligations: up to €15 million or 3% of worldwide annual turnover.
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: DEV Community•Published: Jun 2, 2026
Original Coverage Title: “When is your SaaS feature actually high-risk under the EU AI Act? The Annex III decision tree.”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

RegulationJun 6, 2026

EU AI Act Checklist for ChatGPT Wrappers

A DEV.to article explains how the EU AI Act applies to SaaS founders who build AI 'wrappers' (e.g., ChatGPT front-ends). It breaks obligations into four risk tiers — prohibited, high-risk, limited-risk (transparency), and minimal-risk — and stresses that Article 12 logging (timestamped decision logs and rationales) applies only to high-risk systems that meet Article 6(1) or Annex III gates (biometrics, employment, credit, law enforcement, etc.). Most marketing, support, or content-generation wrappers are limited- or minimal-risk and only need a disclosure under Article 52 when interacting with users. The piece highlights key deadlines (Aug 2, 2026 for high-risk enforcement; December 2026 for watermarking), recommends classifying your system before building logging infrastructure, and links to a free classification tool at eu-ai-act-compliance.progenix.ai. Publication date: 2026-06-06.

Read assessment
RegulationApr 28, 2026

EU AI Act 2026 Cheat Sheet for Developers

This developer-focused cheat sheet summarizes the EU AI Act obligations and timelines relevant to teams shipping LLM features, recommenders, recruitment filters, or other AI scoring systems to EU users. Enforcement began in August 2025, with major obligations from 2 August 2026 and full enforcement for high-risk systems from 2 August 2027. The Act establishes a four-tier risk pyramid (Unacceptable, High-risk, Limited, Minimal), prescribes transparency rules under Article 50 (machine-readable AI labels and in-UI disclosure), and defines steep fines for breaches. The post gives a practical 30-minute audit checklist (risk classification, data governance, human oversight, post-market monitoring, documentation, incident reporting within 15 days) and a starter AI transparency template. The author notes recurring compliance gaps found in SaaS audits and describes CompliPilot, a tool they built to automate checks and generate reports.

Read assessment
Market IntelligenceAug 17, 2026

10-Step EU AI Act Compliance Checklist for AI Companies in 2026

A practical EU AI Act compliance checklist for AI companies in 2026, covering risk classification, documentation, deadlines, and what the Omnibus changes mean for you.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.