EU AI Act compliance software for B2B SaaS
Govarna classifies each of your AI systems against Article 6 and Annex III with the reasoning recorded, tracks Article 50 transparency duties as per-system obligations, and exports audit-ready evidence packs whenever a buyer, auditor, or counsel asks. Self-serve, from $499/month.
14-day free trial · no card required · no sales call · not legal advice
The EU AI Act timeline for B2B SaaS
The Act applies in phases. Some duties are already in force, Article 50 transparency duties apply from 2 August 2026, and the high-risk rules have a later, status-sensitive schedule.
- 2 February 2025In forceAI literacy & prohibited practices
AI literacy duties and the ban on prohibited AI practices have applied since 2 February 2025.
- 2 August 2025In forceGeneral-purpose AI obligations
Obligations for general-purpose AI models have applied since 2 August 2025.
- 2 August 2026AdoptedArticle 50 transparency
Duties covering AI-interaction disclosure, machine-readable marking of synthetic content, biometric notices, and deepfake labels apply from 2 August 2026.
- 2 December 2027Scheduled — adoption pendingAnnex III high-risk rules
Under the May 2026 political agreement, rules for certain Annex III high-risk systems are scheduled for 2 December 2027. The legal adoption process is not yet complete.
- 2 August 2028Scheduled — adoption pendingProduct-integrated high-risk rules
Rules for high-risk AI embedded in regulated products are scheduled for 2 August 2028 under the same agreement, pending legal adoption.
Regulatory facts reviewed 13 July 2026. Sources: Commission overview, Article 50 FAQ, and draft high-risk guidance. Informational only, not legal advice; verify the current legal position with qualified counsel.
What Govarna does under the EU AI Act
One workspace for the operational work: knowing which systems trigger which duties, who owns each one, and what evidence exists that it was done.
A deterministic classification wizard assesses each AI system against Article 6 and Annex III — same inputs, same result, reasoning recorded. Provider vs deployer role is determined per system, and the dated, versioned classification report is exportable for counsel.
Applicable Article 50 duties become discrete, per-system obligations with an owner, implementation status, and the reasoning for why each applies or does not.
Inventory, classifications, policies, control mappings, and change history compiled into a dated PDF and JSON package — generated from live data whenever a buyer, auditor, or counsel asks.
Govarna drafts AI security questionnaire answers from your indexed policies and AI system register, cites the source on each answer, and banks every approved answer for reuse.
Provider, deployer — or both?
Govarna is built for mid-market B2B SaaS teams that use AI, sell to enterprise buyers, or serve European customers. Under the Act, a provider develops or offers an AI system under its own name; a deployeruses an AI system under its authority in a professional context. Which role you hold — and which obligations attach — is decided system by system, and using a third-party model API does not by itself determine the answer. Most B2B SaaS companies are deployers for some systems and providers for others.
Not sure which role you hold? Take the free deployer assessment — 7 questions, instant suggested classification, no signup needed to see your result. If any of your systems may fall in a high-risk category, start with the Annex III high-risk guide.
EU AI Act guides
EU AI Act Article 50: Transparency Requirements Explained
A practical guide to chatbot disclosures, machine-readable marking, biometric notices, and deepfake labelling—with adaptable wording and a 10-step checklist.
Read the guideEU AI Act Annex III: Every High-Risk Category Explained (With Real SaaS Examples)
Complete breakdown of all 8 Annex III high-risk AI categories, the Article 6(3) derogation, and the revised schedule under the May 2026 political agreement.
Read the guideEU AI Act Fines and Penalties: What You Actually Risk (2026)
The three fine tiers under Article 99, what an Article 50 transparency breach can cost, how national authorities set penalties, and what enforcement realistically looks like for B2B SaaS.
Read the guideThe EU AI Act Compliance Checklist for B2B SaaS (2026)
A 10-step EU AI Act roadmap covering Article 50, revised high-risk dates, Article 26 deployer duties, the Article 6(3) derogation, and tiered fines.
Read the guideEU AI Act compliance questions teams ask
Does the EU AI Act apply to US companies?
It can. The Act covers providers placing AI systems on the EU market or putting them into service in the EU, and certain providers or deployers outside the EU where AI-system output is used in the EU. Scope depends on the company role and specific deployment — and US enterprise buyers are adopting the same questions in vendor reviews regardless.
What applies on 2 August 2026, and what comes later?
Article 50 transparency obligations apply from 2 August 2026 — AI systems interacting with people or generating synthetic content must disclose it. AI literacy and prohibited-practice rules have applied since 2 February 2025, and general-purpose AI model obligations since 2 August 2025. Under the May 2026 political agreement, Annex III high-risk rules are scheduled for 2 December 2027 and product-integrated high-risk rules for 2 August 2028, subject to legal adoption.
Are we a provider or a deployer?
Broadly: build an AI system or place it on the EU market under your name, and you're likely a provider with heavier obligations. Use AI systems built by others, and you're likely a deployer with lighter but real obligations. Many SaaS companies are both, for different systems — which is why Govarna classifies per system and records the reasoning.
What evidence do we actually need?
Buyers and reviewers typically ask for an AI system inventory, risk classifications with the reasoning behind them, the policies that govern AI use, and records showing disclosures and controls were implemented. Govarna compiles these — with change history — into a dated PDF and JSON evidence pack generated from live workspace data.
Is the classification legally binding?
No. Govarna provides suggested, auditable classifications and per-system obligation tracking for you to review with qualified counsel. It is a governance workspace, not legal advice or a legal determination.
Do we need a sales call to start?
No. Pricing is public from $499 per month, every plan starts with a 14-day self-serve trial with no credit card required, and a sample audit package is downloadable. If you want a human, email sales@govarna.com — but a call is never required to evaluate or buy Govarna.
Start the EU AI Act record before the next review asks for it.
14-day self-serve trial of the full product. Public pricing from $499/month. No sales call required.