The EU AI Act Registration Playbook for B2B SaaS: Eight Steps, Four Markets, Two Years to Aug 2026
The EU AI Act Registration Playbook for B2B SaaS: Eight Steps, Four Markets, Two Years to Aug 2026
The dominant US-headquartered B2B SaaS position is that EU AI Act registration is something to revisit in late 2025 once enforcement structures are clearer. That position is wrong. Confidence: high. Two obligations are already in force as of February 2, 2025. The high-risk system registration deadline is August 2, 2026. Standing up the registration capability takes between nine and fourteen months for a typical B2B SaaS operator with vendor cooperation. If you start in Q4 2025, you ship on time. If you start in 2026, you do not.
The SOPHIZO-GOV-006 EU AI Act Registration Playbook compresses this into an eight-step process with named deliverables, current national competent authority contacts for the five largest EU markets, and the binding enforcement timeline.
The Master Enforcement Timeline
Feb 2, 2025. In force. Prohibited AI practices ban under Article 5. AI literacy obligation under Article 4. Both apply to all providers and deployers regardless of risk tier. If you have not audited your AI stack against the Article 5 prohibited list and trained your staff on AI literacy, you are already out of compliance.
Aug 2, 2025. In force. General-purpose AI model obligations. If you build on top of an OpenAI, Anthropic, Google, Mistral, or other foundation model API, your vendor must provide adequate documentation under these provisions. Request model cards and training data summaries from your LLM providers. Review contracts for AI value chain compliance clauses. The vendor obligation does not relieve your deployer obligation.
Aug 2, 2026. Approaching. High-risk AI obligations under Annex III. Providers and deployers of high-risk systems must implement risk management, data governance, logging, human oversight, and register the system in the EU AI database. Fourteen months from May 2025. The window is finite.
Aug 2, 2027. Future. High-risk AI embedded in regulated products under Annex I. Mostly relevant to medical devices, vehicles, machinery. Pure B2B SaaS operators are usually out of scope on this track.
The Eight-Step Process
Step 1. Full AI System Inventory. Two to four weeks for a typical $10M to $100M ARR B2B SaaS stack. Cover every AI feature in your own product, every AI-enabled SaaS tool you have deployed, and any internal ML models. The most common miss: AI features embedded in SaaS tools. Salesforce Einstein. HubSpot AI. Gong. Clay. 6sense. Outreach. They are AI systems under Article 3(1).
Step 2. Classify Each System Using Article 6. Apply the SOPHIZO-GOV-001 five-gate classification process. Document the rationale per system. Borderline cases default to high-risk. The penalty for under-classification is 15 million EUR or 3 percent of global turnover. The penalty for over-classification is excess documentation burden. The asymmetry is one-sided.
Step 3. Implement High-Risk Obligations. For any system classified as high-risk, build the Article 9 risk management system, Article 10 data governance, Article 11 technical documentation per Annex IV, Article 12 automatic logging with minimum 6-month retention, Article 14 human oversight protocol, and Article 15 accuracy and cybersecurity measures. This is the substantive build. Six to twelve months of work depending on vendor cooperation.
Step 4. Complete EU AI Database Registration. The database is operated by the European AI Office. Provider registers the system. Deployer registers their use of the system. Both entries required. Information needed: provider name and contact, member state of establishment, system name and version, intended purpose, risk classification, conformity assessment body if applicable, EU declaration of conformity reference, system status. Registration must be complete before the system is put into service in the EU.
Step 5. Prepare the Documentation Package. Even for non-high-risk systems, build the documentation infrastructure now. AI literacy training records under Article 4. Internal AI acceptable use policy. Vendor data processing agreements covering AI-specific data use. AI system inventory. The enforcement architecture rewards documented processes and penalizes verbal governance.
Step 6. Implement Post-Market Monitoring. Article 72 obligation. Continuous monitoring of system performance in operation. Incident logging. Periodic review against intended purpose. Reporting to national competent authority on serious incidents.
Step 7. Appoint EU Legal Representative. Required for non-EU providers. The representative can be a law firm, an EU subsidiary, or a designated third party. The representative shares legal responsibility. Pricing: typically $30K to $100K per year depending on scope and provider.
Step 8. Engage National Competent Authorities. The Act is enforced through national competent authorities, not centrally. You will engage between one and five NCAs depending on your EU market footprint.
The National Competent Authorities for the Five Largest EU Markets
Germany. Bundesnetzagentur (BNetzA) is the central market surveillance authority. BaFin handles financial services AI. The German enforcement structure is the most mature in the EU as of mid-2025.
France. ARCOM is the central authority. CNIL handles AI systems processing personal data. The French structure formally couples AI Act enforcement with GDPR enforcement, which materially increases scrutiny.
Netherlands. RDI (Rijksinspectie Digitale Infrastructuur) is the central authority. The Dutch structure is the most operationally aggressive in the EU as of mid-2025, with the most pre-Aug-2026 enforcement guidance published.
Spain. AESIA (Agencia Española de Supervisión de la Inteligencia Artificial) is the most developed national AI authority in the EU. Stood up specifically to enforce the AI Act. The Spanish structure should be considered the leading indicator for what other NCAs will adopt.
Ireland. Multiple authorities under coordination. The Data Protection Commission carries significant influence given the concentration of US tech subsidiaries headquartered in Ireland for EU operations. Enforcement here will set precedent for US-headquartered B2B SaaS.
Verify NCA contacts quarterly. Enforcement structures are still being finalized as of Q2 2025.
The Position to Hold
This is not a 2027 problem. The substantive build for a single high-risk system takes longer than the time remaining to August 2026 if you have not started. The cost of starting late compounds because the EU legal representative market, the conformity assessment body market, and the AI governance consultant market are all capacity-constrained. Pricing is rising and will rise faster as Aug 2026 approaches. Confidence: high.
Start with the inventory. Without an inventory you cannot classify. Without classification you cannot scope. Without scope you cannot stage the build.
License the EU AI Act Registration Playbook (email gated).
Related reading
This article is part of the Sophizo AI governance series.
Want All 12 Frameworks?
Get the complete 2026 Revenue Leader's Playbook with consulting-grade issue trees, first principles thinking, and agentic AI deployment templates.
Keep reading
Related articles
The EU AI Act Classification Checklist Most B2B SaaS Companies Are Skipping
If you sell into the EU and have not formally classified every AI system in your stack against the Article 6 decision tree, you are exposed. Here is the five-gate classification process most B2B SaaS operators are still avoiding, and the cost of getting it wrong.
NIST AI Actor and Harm Mapping for RevOps: Who Owns the Failure When the Agent Misfires
Most enterprise AI governance failures happen in the gaps between roles, not inside any single role. NIST AI RMF 1.0 defines the actors. We map them to the agents you have already deployed and to the three harm categories you will be measured against.
The Agentic Governance Overlap Matrix: How NIST, ISO 42001, and the EU AI Act Stack Into One Operating System
Stop running three parallel governance programs. NIST AI RMF, ISO/IEC 42001, and the EU AI Act overlap by design. The crosswalk that lets you build once and certify against all three, with the high-performer revenue lever per row.
Ready to Transform Your Business with AI?
Schedule a free discovery call to discuss your AI strategy
Schedule Free Call