Guide

The EU AI Act for B2B SaaS, explained simply.

By the Mitravan team · Updated May 2026

The EU AI Act is the world’s first comprehensive AI law, and it is risk-based: what you must do depends on what your AI does. Here is a plain-language guide for SaaS teams - and how to answer it when it appears in a security questionnaire.

Note: general information, not legal advice. Confirm current obligations and dates with official EU sources and your counsel.

The four risk tiers

Unacceptable risk
Banned outright (e.g. social scoring, certain manipulation). Most SaaS never touches this.
High risk
AI in sensitive areas (e.g. employment, credit, critical infrastructure). Heaviest obligations: risk management, data governance, documentation, human oversight.
Limited risk
Transparency duties - tell people they are interacting with AI or seeing AI-generated content.
Minimal risk
Most AI features. Few or no obligations, but good governance still helps in buyer reviews.

How to get ready (5 steps)

  1. 1
    Inventory your AI systems
    List every AI system and vendor you build or use, and what each does.
  2. 2
    Classify each by risk tier
    Map each system to unacceptable / high / limited / minimal risk under the Act.
  3. 3
    Meet the transparency duties
    Disclose AI interaction and AI-generated content where required.
  4. 4
    Document high-risk systems
    For anything high-risk: technical documentation, data governance, logging, and human oversight.
  5. 5
    Map to ISO 42001 & reuse evidence
    Reuse one set of controls across the EU AI Act, ISO 42001, DPDP and SOC 2.

How Mitravan helps

Mitravan’s AI Inventory auto-discovers your AI vendors and classifies each by EU AI Act risk tier, the Framework Mapper reuses one control across the EU AI Act, ISO 42001, DPDP, NIST AI RMF and SOC 2, and the Questionnaire Engineanswers EU AI Act questions in security reviews in minutes - cited, and approved by your team.

FAQ

When does the EU AI Act apply?
It entered into force in 2024 and applies in phases. Obligations for general-purpose AI (GPAI) models began in August 2025, and the heavier obligations for high-risk systems are phased in later (currently targeted around 2026–2027). Confirm current dates with official EU sources.
What is a "high-risk" AI system?
AI used in sensitive contexts - such as employment, credit scoring, education, or critical infrastructure. High-risk systems carry the heaviest obligations: risk management, data governance, technical documentation, logging, and human oversight.
Does it apply to companies outside the EU?
It can. The Act has extraterritorial reach: if your AI system is placed on the EU market or its output is used in the EU, obligations can apply regardless of where you are based.
Does Mitravan make me EU AI Act compliant?
Compliance is a legal outcome, not a single tool. Mitravan’s AI Inventory classifies each AI vendor by EU AI Act risk tier, the Framework Mapper reuses evidence across frameworks, and the Questionnaire Engine answers EU AI Act questions in security reviews. It does not replace legal counsel.

Classify your AI, answer the questionnaire

See how Mitravan classifies your AI by EU AI Act risk tier and answers it in security reviews. Book a 15-minute call.

Book a 15-min call