RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The archive · 200 retrospective records ↗

The archive / Compliance & obligations

Compliance & obligations / From the archive · 1 August 2024 event · prepared 16 September 2026

Embedding a foundation model can make a SaaS its own AI provider

The AI Act's own text sets out when integrating a third-party model shifts provider obligations onto the company that embeds it.

eur-lex.europa.euprimary record

Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (AI Act)

Document
13 June 2024
Event
1 August 2024
Retrieved
16 September 2026
No visual was published with this record, so its primary document stands in its place.

The workload

A SaaS product that calls a third-party foundation model through an API is not automatically a 'provider' under the AI Act. Article 3(3) defines a provider as the party that develops an AI system or model, or has one developed, and places it on the market under its own name. Article 3(4) defines a 'deployer' as the party using an AI system under its own authority. Most founders sit as deployers of the underlying model and, separately, as the provider of whatever system they build on top of it; the workload is working out which obligations attach to which role before shipping.

What the documents show

Verified: the regulation's own text, Article 25, states that a deployer or other third party becomes a provider of a high-risk AI system, subject to the Article 16 provider obligations, if it modifies the intended purpose of a system, including a general-purpose AI system, in a way that makes it high-risk under Article 6. Verified: Article 113 sets a phased timetable, not one date: Chapters I and II apply from 2 February 2025; the general-purpose-model provisions from 2 August 2025; most remaining obligations from 2 August 2026; and the high-risk classification rule in Article 6(1) from 2 August 2027. Verified: the European Commission's own AI Act page describes the regulation as setting risk-based rules for developers and deployers. Which tier applies to embedding a model is a case-by-case reading of Article 6, and this area is still settling.

The operating cost

The regulation sets no licence fee; it sets obligations whose labour cost depends on risk tier. A deployer of a general-purpose model that does not change its intended purpose carries lighter, transparency-based duties; a business that repurposes a system into a use Article 6 treats as high-risk takes on the fuller Article 16 obligations, including a conformity assessment. Neither document prices that work in currency terms; it is a classification question with a labour consequence, not a stated fee.

The stop condition

Editorially, since the sources do not name one directly: the point to reassess is any change to what the embedded model is used for, since Article 25 turns on a change of intended purpose, not on the act of integration itself. A product that keeps a third-party model's original purpose intact carries a lighter load than one that repurposes it into a use Annex III or Article 6 treats as high-risk.

  • Has the intended purpose of the embedded model changed from what its own provider documented, in a way Article 6 would treat as high-risk?
  • Which of the Article 113 application dates actually governs the obligation in question, since they are not all the same date?
  • Is the product a deployer of someone else's system, a provider of its own, or both at once, under the Article 3 definitions?

The AI Act does not treat calling an API as a blanket exemption, but it also does not automatically make every integrator a regulated AI provider. The regulation's own risk-classification test, not the fact of embedding a model, decides which obligations attach.

Sources & reading trail

Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (AI Act) ↗

The regulation's own text: Article 3(3)-(4) define provider and deployer; Article 25 sets when an integrator of a third-party model becomes a provider of a high-risk system; Article 113 sets the phased application dates.

Source published: 13 June 2024 · Retrieved: 16 September 2026

AI Act | Shaping Europe's digital future ↗

European Commission's own policy page describing the AI Act as a risk-based framework for AI developers and deployers, as maintained on the retrieval date.

Source published: Not established · Retrieved: 16 September 2026

Vendor documentation, regulator records and founder-published documents establish the entry; the workload reading and the stop condition are Solo Product Office editorial analysis. This retrospective draft does not imply the site published on the event date.