B2B SaaS providers · AI features & EU AI Act

AI features in your SaaS: EU AI Act, GPAI and AI security, legally led

The moment your SaaS ships a copilot, a chatbot, scoring or an agent, the AI questions land in the vendor security review. We inventory and classify your AI features under the EU AI Act, clarify transparency and GPAI duties, test the LLM, RAG and agent layer and interlock all of it with GDPR/nFADP and your DPA.

legally led (Dr. iur., CIPP/E) three dedicated AI services DE · FR · EN
AI features in B2B SaaS under the EU AI Act

For SaaS product owners shipping AI features: copilots, chatbots, scoring, agents

Legally led Dr. iur. · CIPP/E
EU AI Act Art. 50, Annex III, GPAI
AI security OWASP-LLM · MITRE ATLAS
DPA-interlocked GDPR · nFADP
CH · EU multilingual DE/FR/EN
Dr. Dominic Staiger

Responsible for this mandate

Dr. Dominic Staiger

LL.M., Dr. iur., CIPP/E · Attorney at Law (New York) · Solicitor (UK)

LinkedIn

AI features are now part of the vendor security review

Your enterprise customers no longer ask only about ISO 27001, the DPA and a pentest. They ask what your AI features do, on which data they are trained and run and how you meet the EU AI Act.

AI questions are moving into the security questionnaires: which models you use, whether customer data is used for training, whether there is human oversight, how data residency works and whether the EU AI Act applies. A SaaS vendor without clean answers here stalls in procurement.

Under the EU AI Act, most SaaS AI features carry transparency duties under Art. 50: users must be able to tell they are interacting with an AI system, and AI-generated or manipulated content must be marked. This reaches chatbots, assistants and generators broadly.

Some features may fall into the high-risk category under Annex III, for example AI used in creditworthiness, recruitment, education or critical services. There, far stricter duties apply: risk management, data quality, logging, human oversight and technical documentation. Classification is done case by case.

If you build on your own or a fine-tuned model, duties for providers of general-purpose AI models (GPAI) may apply on top, from technical documentation to copyright and training-data transparency. You can be provider and deployer at the same time, depending on whether you supply a model or merely use a third-party one. We clarify your role per feature.

The application dates for high-risk duties fall from 2026/2027 and are politically under revision via the Digital Omnibus. We verify the deadlines relevant to you case by case and align the measures accordingly.

How we bring your AI features into an audit-ready state

One continuous path from inventory through classification to testing and ongoing governance, with clear fixed fees at entry.

We start with the AI Governance Check (from CHF 3'900): an AI use-case inventory and classification of each feature under the EU AI Act, role determination (provider and deployer), transparency and GPAI review, plus a prioritised action plan you can cite directly in the vendor review.

For ongoing steering, our AI Officer (from CHF 500/month) runs your AI governance as a fixed point of contact: maintaining the AI inventory, accompanying new features, updating for shifting deadlines and answering your customers' AI questions, reusable in your trust center.

On the technical side, AI Security (from CHF 8'000) tests your LLM, RAG and agent layer against prompt injection, jailbreaks, context data leakage, unsafe tool and agent actions and model and training-data risks, methodically along the OWASP Top 10 for LLM applications and MITRE ATLAS. The result is a report you can put in front of your security reviewers.

All three building blocks are interlocked with your data protection. Where AI processes personal data, we run GDPR and nFADP plus your DPA and sub-processor list cleanly through, including data residency and the question of whether customer data is used for training. So the legal, governance and technical layers fit together.

Why SIDD for AI features in your SaaS

With the EU AI Act, legal classification drives the obligation. That is exactly where we start, backed by three dedicated AI services and an in-house technical team.

Legally led

Your AI classification is led by doctorate-level lawyers with CIPP/E. Whether a feature falls under Art. 50, Annex III or GPAI and whether you are provider or deployer is first a legal question. We answer it robustly and on the record.

Three dedicated AI services

AI Governance Check, AI Officer and AI Security mesh together: classification, ongoing steering and technical testing of the LLM, RAG and agent layer. You get law, governance and security from one partner, without friction between several providers.

AI security on recognised models

We test along the OWASP Top 10 for LLM applications and MITRE ATLAS, from prompt injection to unsafe agent actions. The report is structured so you can hand it into the vendor review without translation.

Interlocked with data protection and the DPA

Where AI processes personal data, we run GDPR, nFADP, your DPA and the sub-processor list consistently through. So your AI answers and your data-protection answers in the questionnaire do not contradict each other.

Security as a sales enabler

We deliver your AI answers in a form that speeds up deals: classified use cases, documented measures and a test report that move straight into your trust center and questionnaire. Compliance becomes a selling point, not a cost block.

Multilingual & independent

We work in German, French and English, matching customers in CH, EU and the UK. Because we do not sell an in-house SOC, our recommendations on models, hosting and measures stay independent.

Getting started with your SaaS AI compliance

AI Officer

from CHF 500/month ongoing

A fixed point of contact for your AI governance who maintains the inventory and accompanies new features.

  • Ongoing maintenance of the AI inventory and classification
  • Accompanying new AI features before release
  • Updates as deadlines shift (Digital Omnibus)
  • Answers to your customers' AI questions, reusable in your trust center

AI Security

from CHF 8,000 Fixed fee

Technical security test of your LLM, RAG and agent layer along OWASP-LLM and MITRE ATLAS.

  • Prompt injection, jailbreaks and context data leakage
  • Unsafe tool and agent actions plus model risks
  • Methodology along the OWASP Top 10 for LLM applications and MITRE ATLAS
  • Test report you can present in the vendor security review

Our tool: LexCommand

Why we work with LexCommand, our own Swiss legal AI

LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.

Sovereign in Switzerland

The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.

No citation, no claim

Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.

From effort to judgement

LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.

Three disciplines, one picture

We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.

For the AI Governance Check, concretely: LexCommand backs every classification of your AI feature under Art. 50, Annex III or GPAI with the exact source in the EU AI Act, reads the deadline at the chosen Digital Omnibus reference date and sets GDPR, nFADP and DPA duties alongside, so the citable action plan stays consistent in the vendor review.

Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.

Frequently asked questions

We only use a third-party model via an API. Does the EU AI Act still apply?

Most likely yes. Anyone deploying an AI system is a deployer and may have to meet transparency duties under Art. 50, for example. Depending on how you embed, adapt or ship the model under your own name, further duties can apply. We determine your exact role per feature in the AI Governance Check.

Aren't the high-risk AI deadlines being postponed anyway?

The application dates for high-risk duties fall from 2026/2027 and are politically under revision via the Digital Omnibus. We frame this deliberately cautiously and verify the deadlines relevant to you case by case. Transparency and inventory measures pay off regardless, because your customers are already asking the AI questions today.

What is GPAI and does it concern us?

GPAI stands for general-purpose AI models. If you build on your own or a fine-tuned model, provider duties can apply, such as technical documentation and transparency on copyright and training data. If you only use a third-party model, those duties sit primarily with the model provider. We clarify which role you carry in the check.

Is the AI Governance Check enough for our vendor review?

For the legal and organisational side, yes: you get classified use cases, documented roles and an action plan you can put straight into questionnaires and your trust center. If customers additionally demand technical evidence of the AI layer, we add AI Security with a presentable test report.

How does this connect to our DPA and data protection?

Closely. Where AI processes personal data, your statements on training, data residency and sub-processors must match your DPA and sub-processor list. We run GDPR and nFADP consistently through, so AI answers and data-protection answers in the questionnaire are free of contradictions. Where needed, our DPO leads the mandate.

Matching building blocks for your vendor security review

AI compliance is one part of the answer. These topics round out your vendor review:

Ready to make your AI features audit-ready?

We inventory and classify your AI features under the EU AI Act and deliver answers that speed up your vendor security review.