Regulation archetype
EU SaaS company building or embedding AI
An EU SaaS company using AI should plan for GDPR, AI governance, security controls, and EU AI Act readiness. High-risk AI use requires deeper risk management, documentation, monitoring, and human oversight than ordinary productivity AI features.
- Likely now
- 4 planning items
- Possible later
- 3 to watch
- Next steps
- 3 to run
- Last reviewed
- May 2026
Company profile
A B2B software company that provides, deploys, or embeds AI features in customer-facing workflows.
Likely planning items
Framework
Planning weight
- GDPRPlan now
- EU AI Act readinessPlan now
- ISO 27001Plan now
- AI governance controlsPlan now
Possible additional pressure
Framework
Planning weight
- ISO 42001Watch
- NIS2Watch
- Cyber Resilience ActWatch
Next steps
- 01List AI systems, data inputs, model providers, and customer-facing decisions.
- 02Classify AI use cases by impact, transparency needs, and prohibited or high-risk categories.
- 03Connect AI risk work to existing security and privacy controls.
This page is a practical planning guide, not legal or audit advice. Use it to scope questions before confirming obligations with legal, audit, or regulatory specialists.
Other company profiles
- EU B2B SaaS company with 15-100 employeesLikely now: GDPR, ISO 27001, SOC 2, NIS2 supply-chain pressure.
- EU fintech or software supplier to financial customersLikely now: GDPR, ISO 27001, SOC 2, DORA due diligence.
- Finnish public-sector software supplierLikely now: GDPR, ISO 27001, Julkri, NIS2 supply-chain pressure.