Wednesday, July 22, 2026 · Week 30 DE · EN · FR · ES Dark
Success Stories

High-Risk AI Hits Education Platforms This August

EU AI Act high-risk from August 2026: Annex IV documentation, conformity assessment, and EU registration for SaaS providers with AI features.

By Alec Chizhik April 29, 2026 5 min read
High-Risk AI Hits Education Platforms This August

Those who have integrated AI into a SaaS app and thought it was “just a feature” until now: as of August 2, 2026, the high-risk classification of the EU AI Act will apply strictly to certain AI systems. Those who realize too late that they are affected will have a compliance problem, not a technical one.

Key Takeaways

  • As of August 2, 2026, providers of high-risk AI systems must provide technical documentation according to Annex IV – not a summary, but auditable documents.
  • High-risk classification directly affects many SaaS categories: HR software with AI scoring, educational platforms with adaptive assessment, and AI-supported credit decisions.
  • Annex IV prescribes 11 mandatory sections for technical documentation – plus a risk management system, data governance, and conformity assessment.
  • Those who use GPAI models (GPT-4o, Claude, Gemini) as a foundation share responsibility with the model provider – but only if their own use case serves a high-risk context.
  • Registration in the EU AI database before the first deployment is mandatory and cannot be done retroactively.

What is a high-risk AI system according to the EU AI Act? High-risk AI systems are, according to Annex III of the EU AI Act, AI applications in eight regulated areas: biometric identification, critical infrastructure, education and training, employment and personnel management, access to essential services (credit, insurance, public services), law enforcement, migration and border control, and justice. Within these areas, it is the specific function that matters – not the product name.

The EU AI Act has been in force since August 2024. What happens on August 2, 2026, is not a new law, but the end of the transition period for high-risk systems. From this date on, all obligations will be fully applicable. Those who are not ready by then will be operating non-compliantly.

For SaaS providers, this is not a theoretical question. Three product categories deserve special attention:

HR software with AI-supported screening or ranking of applications falls directly under Annex III, point 4 (employment). Educational platforms that use adaptive learning paths or automated assessment fall under point 3. And any type of AI-supported credit scoring function – also marketed as “AI-powered insight” – falls under point 5.

11
Mandatory sections in Annex IV
technical documentation

3
Years of retention obligation
after last deployment

30 Mio €
Maximum fine
or 6% of annual turnover

What Annex IV specifically requires: the eleven mandatory sections

This is the part that many SaaS teams underestimate. Annex IV is not a checklist that can be ticked off in an afternoon. There are eleven documentation elements that must be demonstrably available for every high-risk model:

  1. General description: Purpose, version, development context, and change history of the AI system
  2. System design: Architecture, training logic, decision logic – machine-readable where possible
  3. Training data: Description of data sets, data origin, preprocessing steps, and quality assurance
  4. Validation and test data: How was the model tested for bias, accuracy, and robustness?
  5. Performance metrics: Accuracy, precision, and recall metrics for all relevant population groups
  6. Risk management system: Documentation of the risk identification and mitigation process
  7. Change log: Every model change that is relevant to conformity is tracked and documented
  8. Quality management: Processes for testing, monitoring, and post-market surveillance
  9. Cybersecurity: Measures against adversarial inputs, data poisoning, and prompt injection
  10. Instructions for use: Documentation that is understandable for deployers, outlining what the system can and cannot do
  11. EU declaration of conformity: Formally signed document according to Article 47

Point 5 is the one that requires the most work in practice: fairness evaluation across population groups. Those who build application scoring and do not have stratified test sets by gender, origin, and age will not be able to catch up on this in a week.

KEY FIGURE
30 Mio €
maximum fine or 6% of annual turnover
KEY FIGURE
6%
of annual turnover

Self-assessment or third-party audit: what SaaS providers can choose

Self-assessment (Art. 43 Para. 2) Third-party audit (Art. 43 Para. 1)
Possible if harmonized standards are applied Mandatory for biometric remote identification
Can be carried out internally, own QM system Notified Body required (still few accredited)
Faster and more cost-effective Higher credibility towards supervisory authority
Complete Annex IV documentation still mandatory Also complete documentation + external review required

For most SaaS providers that are not involved in biometric identification, self-assessment is the more realistic path – provided that the harmonized standards (EN standards that are still being developed) are available in time.

// Key point

Anyone who has integrated AI into a SaaS app and thought ‘this is just a feature’: From 2.

What GPAI Foundation Users Need to Consider

Anyone using GPT-4o, Claude, or Gemini as the foundation for a high-risk product shares responsibility with the model provider. OpenAI, Anthropic, and Google must fulfill their GPAI documentation obligations (Art. 53) by August 2025. For SaaS providers, this means they can rely on this documentation – but must fully document their own use case layer themselves. The model is not within the scope, but the application area is.

Frequently Asked Questions

Does the EU AI Act also apply to SaaS providers outside the EU that serve EU customers?

Yes. The AI Act has extraterritorial scope, similar to the GDPR. What matters is not the provider’s location, but whether the AI system is used in the EU or its outputs are utilized in the EU. A US SaaS with German enterprise customers is affected.

Do I need to perform a high-risk assessment for every AI feature in my product?

No. The scope is the use case, not the technology. An LLM-powered chatbot feature that answers general questions is not a high-risk system. The same technology used in a credit decision workflow would be. The classification depends on the specific function the system performs in the regulated context.

What happens if I miss the deadline on August 2, 2026?

National market supervisory authorities can impose warnings, fines of up to 30 million Euro or 6% of global annual turnover. Additionally, they can order the system to be removed from the market. A delay due to “we are working on it” is not a recognized compliance status.

Do I need to retrain my AI system if the training data documentation is missing?

Not necessarily. The documentation requirement under Annex IV demands descriptions of the training data, not the complete dataset. If the origin, preprocessing, and quality assurance are traceable – even if reconstructed and documented retrospectively – that is sufficient. What is missing can often be documented without modifying the model.

What is the EU AI database, and how do I register my system there?

The EU database under Article 71 of the AI Act is operated by the EU AI authority. Providers of high-risk systems must register their system before the first deployment in the EU. Registration includes the provider’s contact details, system description, geographical scope, and information on the conformity assessment. The portal is accessible at eudatabase.eu; specific steps will be communicated by the responsible national authority.

More from the MBF Media Network

Source: Title image from Pexels

Image source: AI-generated (Juli 2026)

Also available in

FrançaisEspañolDeutsch
MBF Media Newsletter

The monthly briefing for decision-makers

Once a month, the MBF Media Newsletter gathers what matters from cloudmagazin, MyBusinessFuture, Digital Chiefs and SecurityToday, curated by the editorial team.

25,000 IT and business decision-makers read this newsletter. Read along.

Subscribe for free
MBF Media Newsletter, aktuelle Ausgabe auf dem iPhone
Ein Magazin der Evernine Media GmbH