The EU AI Act Registration Playbook for B2B SaaS: Eight Steps, Four Markets, Two Years to Aug 2026
AI Governance

The EU AI Act Registration Playbook for B2B SaaS: Eight Steps, Four Markets, Two Years to Aug 2026

JU
By John Utley|3 IPOs
August 17, 2026
If you sell into Germany, France, Netherlands, Spain, or Ireland and operate any high-risk AI system, EU AI database registration is binding by August 2, 2026. The eight-step process, the national competent authority contacts, and the deadlines you cannot move.

The EU AI Act Registration Playbook for B2B SaaS: Eight Steps, Four Markets, Two Years to Aug 2026

The dominant US-headquartered B2B SaaS position is that EU AI Act registration is something to revisit in late 2025 once enforcement structures are clearer. That position is wrong. Confidence: high. Two obligations are already in force as of February 2, 2025. The high-risk system registration deadline is August 2, 2026. Standing up the registration capability takes between nine and fourteen months for a typical B2B SaaS operator with vendor cooperation. If you start in Q4 2025, you ship on time. If you start in 2026, you do not.

The SOPHIZO-GOV-006 EU AI Act Registration Playbook compresses this into an eight-step process with named deliverables, current national competent authority contacts for the five largest EU markets, and the binding enforcement timeline.

The Master Enforcement Timeline

Feb 2, 2025. In force. Prohibited AI practices ban under Article 5. AI literacy obligation under Article 4. Both apply to all providers and deployers regardless of risk tier. If you have not audited your AI stack against the Article 5 prohibited list and trained your staff on AI literacy, you are already out of compliance.

Aug 2, 2025. In force. General-purpose AI model obligations. If you build on top of an OpenAI, Anthropic, Google, Mistral, or other foundation model API, your vendor must provide adequate documentation under these provisions. Request model cards and training data summaries from your LLM providers. Review contracts for AI value chain compliance clauses. The vendor obligation does not relieve your deployer obligation.

Aug 2, 2026. Approaching. High-risk AI obligations under Annex III. Providers and deployers of high-risk systems must implement risk management, data governance, logging, human oversight, and register the system in the EU AI database. Fourteen months from May 2025. The window is finite.

Aug 2, 2027. Future. High-risk AI embedded in regulated products under Annex I. Mostly relevant to medical devices, vehicles, machinery. Pure B2B SaaS operators are usually out of scope on this track.

The Eight-Step Process

Step 1. Full AI System Inventory. Two to four weeks for a typical $10M to $100M ARR B2B SaaS stack. Cover every AI feature in your own product, every AI-enabled SaaS tool you have deployed, and any internal ML models. The most common miss: AI features embedded in SaaS tools. Salesforce Einstein. HubSpot AI. Gong. Clay. 6sense. Outreach. They are AI systems under Article 3(1).

Step 2. Classify Each System Using Article 6. Apply the SOPHIZO-GOV-001 five-gate classification process. Document the rationale per system. Borderline cases default to high-risk. The penalty for under-classification is 15 million EUR or 3 percent of global turnover. The penalty for over-classification is excess documentation burden. The asymmetry is one-sided.

Step 3. Implement High-Risk Obligations. For any system classified as high-risk, build the Article 9 risk management system, Article 10 data governance, Article 11 technical documentation per Annex IV, Article 12 automatic logging with minimum 6-month retention, Article 14 human oversight protocol, and Article 15 accuracy and cybersecurity measures. This is the substantive build. Six to twelve months of work depending on vendor cooperation.

Step 4. Complete EU AI Database Registration. The database is operated by the European AI Office. Provider registers the system. Deployer registers their use of the system. Both entries required. Information needed: provider name and contact, member state of establishment, system name and version, intended purpose, risk classification, conformity assessment body if applicable, EU declaration of conformity reference, system status. Registration must be complete before the system is put into service in the EU.

Step 5. Prepare the Documentation Package. Even for non-high-risk systems, build the documentation infrastructure now. AI literacy training records under Article 4. Internal AI acceptable use policy. Vendor data processing agreements covering AI-specific data use. AI system inventory. The enforcement architecture rewards documented processes and penalizes verbal governance.

Step 6. Implement Post-Market Monitoring. Article 72 obligation. Continuous monitoring of system performance in operation. Incident logging. Periodic review against intended purpose. Reporting to national competent authority on serious incidents.

Step 7. Appoint EU Legal Representative. Required for non-EU providers. The representative can be a law firm, an EU subsidiary, or a designated third party. The representative shares legal responsibility. Pricing: typically $30K to $100K per year depending on scope and provider.

Step 8. Engage National Competent Authorities. The Act is enforced through national competent authorities, not centrally. You will engage between one and five NCAs depending on your EU market footprint.

The National Competent Authorities for the Five Largest EU Markets

Germany. Bundesnetzagentur (BNetzA) is the central market surveillance authority. BaFin handles financial services AI. The German enforcement structure is the most mature in the EU as of mid-2025.

France. ARCOM is the central authority. CNIL handles AI systems processing personal data. The French structure formally couples AI Act enforcement with GDPR enforcement, which materially increases scrutiny.

Netherlands. RDI (Rijksinspectie Digitale Infrastructuur) is the central authority. The Dutch structure is the most operationally aggressive in the EU as of mid-2025, with the most pre-Aug-2026 enforcement guidance published.

Spain. AESIA (Agencia Española de Supervisión de la Inteligencia Artificial) is the most developed national AI authority in the EU. Stood up specifically to enforce the AI Act. The Spanish structure should be considered the leading indicator for what other NCAs will adopt.

Ireland. Multiple authorities under coordination. The Data Protection Commission carries significant influence given the concentration of US tech subsidiaries headquartered in Ireland for EU operations. Enforcement here will set precedent for US-headquartered B2B SaaS.

Verify NCA contacts quarterly. Enforcement structures are still being finalized as of Q2 2025.

The Position to Hold

This is not a 2027 problem. The substantive build for a single high-risk system takes longer than the time remaining to August 2026 if you have not started. The cost of starting late compounds because the EU legal representative market, the conformity assessment body market, and the AI governance consultant market are all capacity-constrained. Pricing is rising and will rise faster as Aug 2026 approaches. Confidence: high.

Start with the inventory. Without an inventory you cannot classify. Without classification you cannot scope. Without scope you cannot stage the build.

License the EU AI Act Registration Playbook (email gated).

Related reading

This article is part of the Sophizo AI governance series.

JU
John Utley

Founder & Fractional AI & RevOps Leader

SalesforceIBM3 IPOs
Content Upgrade

Want All 12 Frameworks?

Get the complete 2026 Revenue Leader's Playbook with consulting-grade issue trees, first principles thinking, and agentic AI deployment templates.

12 Frameworks
MECE Thinking
AI Templates

Keep reading

Related articles

Ready to Transform Your Business with AI?

Schedule a free discovery call to discuss your AI strategy

Schedule Free Call