The EU AI Act Classification Checklist Most B2B SaaS Companies Are Skipping
AI Governance

The EU AI Act Classification Checklist Most B2B SaaS Companies Are Skipping

JU
By John Utley|3 IPOs
August 17, 2026
If you sell into the EU and have not formally classified every AI system in your stack against the Article 6 decision tree, you are exposed. Here is the five-gate classification process most B2B SaaS operators are still avoiding, and the cost of getting it wrong.

The EU AI Act Classification Checklist Most B2B SaaS Companies Are Skipping

The common executive position is that the EU AI Act is a problem for foundation model providers, not B2B SaaS. That position is wrong. Confidence: high. The Act applies to deployers of AI systems whose outputs are used in the EU, regardless of where you are headquartered or where your servers sit. If your CRM uses AI lead scoring on EU prospects, you are a deployer. If your sales engagement platform writes AI emails to EU buyers, you are a deployer. The deployer obligations are not optional and they are not light.

What most teams are still missing is the classification step. You cannot decide what controls to implement until you know the tier of every AI system you operate. Article 6 of the Act provides the decision tree. The Sophizo SOPHIZO-GOV-001 checklist runs that decision tree as five gates so you produce a defensible classification rationale per system, not a verbal hand-wave.

Why Classification is the Step Most Operators Skip

The reason classification gets skipped is not laziness. It is that the classification process forces you to first inventory every AI system you actually operate, including the ones embedded in tools you bought thinking they were CRMs and sales engagement platforms. Salesforce Einstein lead scoring is an AI system under Article 3(1). HubSpot Breeze is an AI system. Gong call analysis is an AI system. Clay enrichment is an AI system. Outreach AI is an AI system. Inventory those honestly and most B2B SaaS companies discover they are operating between fifteen and forty AI systems they have never formally documented.

Every one of those systems needs to pass through the same five-gate classification process. That work cannot be delegated to a vendor. It is a deployer obligation.

The Five Gates

Gate 1. Article 3(1) qualification. Does the system meet the EU AI Act definition of an AI system? "A machine-based system designed to operate with varying levels of autonomy, that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions, that can influence physical or virtual environments." Most modern RevOps tooling clears this bar.

Gate 2. Article 5 prohibited practice check. Does the system perform any of the eight prohibited practices listed in Article 5? Manipulation, exploitation of vulnerabilities, social scoring, real-time remote biometric identification, untargeted facial recognition scraping, emotion inference in workplaces or schools, biometric categorization for sensitive attributes, predictive policing for individuals. If yes, the system is illegal in the EU and must be retired. No remediation path exists.

Gate 3. Annex I product check. Is the system a safety component in a product covered by EU sector legislation listed in Annex I? Medical devices, machinery, vehicles, toys, lifts, radio equipment. Pure B2B SaaS rarely triggers this gate.

Gate 4. Annex III domain check. Does the system operate in one of the eight Annex III high-risk domains? Biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential private and public services, law enforcement, migration and border control, administration of justice and democratic processes. Employment and worker management is the gate that catches most RevOps stacks. SDR performance scoring used in compensation decisions, AE quota attainment AI used in promotion decisions, and any AI involved in hiring decisions are high-risk.

Gate 5. Exception assessment. Annex III systems can drop out of the high-risk tier if they perform only narrow procedural tasks, improve a previously completed human activity, detect deviation from decision patterns without replacing human assessment, or perform purely preparatory work. The exception bar is high. The default position should be that an Annex III system is high-risk unless you can defend an exception in writing.

After the five gates, the system lands in one of four tiers: prohibited, high-risk, limited-risk with transparency obligations, or minimal-risk. The obligations diverge sharply by tier.

What Each Tier Costs You

High-risk systems carry the full Article 9 through 15 obligation stack (see the agentic governance overlap matrix for the NIST and ISO 42001 controls that satisfy each article). Risk management system, data governance, technical documentation, automatic logging, human oversight, accuracy and robustness, cybersecurity. Plus EU AI database registration before deployment. Plus, for non-EU providers, an EU-based legal representative. Build cost: realistically six to twelve months for a system already in production, depending on vendor cooperation.

Limited-risk systems require transparency disclosures. AI-generated content must be labeled. Chatbots must disclose they are AI. The Article 50 transparency obligations apply.

Minimal-risk systems carry the Article 4 AI literacy obligation and the Article 5 prohibited practice prohibition. Both already in force as of February 2, 2025. If your staff cannot pass an AI literacy benchmark, you are already non-compliant.

The Penalty Structure That Actually Matters

The headline penalty number is 35 million EUR or 7 percent of global annual turnover for prohibited practices. That figure gets quoted in every press release and almost never applied to B2B SaaS, because most B2B SaaS operators are not running prohibited systems.

The number that should worry you is the 15 million EUR or 3 percent of global turnover penalty for non-compliance with high-risk system obligations. That is the bucket that catches deployer failures. Misclassification, missing technical documentation, no logging, no human oversight protocol. A US-headquartered SaaS company doing 50 million USD ARR in the EU could face a 15 million EUR fine for one inadequately governed high-risk system. The math is not theoretical.

How to Run the Classification This Quarter

Three weeks of focused work, not six months of program management.

Week one: full AI system inventory. Every product feature, every SaaS-embedded AI, every internal model. The deliverable is a register with vendor, version, intended use, output type, EU exposure, and business owner per system.

Week two: classification worksheets for every system in the inventory using the five gates. Document the rationale at every gate, because the documentation is the audit defense. A correct classification with no documented rationale is indistinguishable from a wrong classification under enforcement.

Week three: tier-grouped remediation plan. Prohibited systems get a retirement schedule. High-risk systems get a build plan against Articles 9 through 15. Limited-risk systems get a transparency disclosure rollout. Minimal-risk systems get an AI literacy curriculum.

You can do this internally. You can also accelerate it with the SOPHIZO-GOV-001 checklist, which gives you the five-gate worksheet pre-built and the Annex III table pre-mapped to the most common B2B SaaS use cases.

The Position to Hold in the Boardroom

The narrative that "we are watching the EU AI Act before we act" is the same narrative that produced GDPR remediation costs of 3 to 8 million USD per non-compliant company in 2018 and 2019. The Act is in force. The classification work is bounded. The cost of being wrong is asymmetric. Do the classification.

Get the EU AI Act Classification Checklist (free).

Related reading

This article is part of the Sophizo AI governance series.

JU
John Utley

Founder & Fractional AI & RevOps Leader

SalesforceIBM3 IPOs
Content Upgrade

Want All 12 Frameworks?

Get the complete 2026 Revenue Leader's Playbook with consulting-grade issue trees, first principles thinking, and agentic AI deployment templates.

12 Frameworks
MECE Thinking
AI Templates

Keep reading

Related articles

Ready to Transform Your Business with AI?

Schedule a free discovery call to discuss your AI strategy

Schedule Free Call