SaaS AI Provider
stable saas-ai-provider · v1.0A vendor that builds a cloud product with AI in it, runs it for many customers and places it on the market under its own name. This is the AICF library as written: every control, evidence record and question was drafted from this seat, so the profile marks every control as required apart from the four conformity and market-obligation controls that bind only a provider whose system falls in a high-risk or general-purpose class. It covers the security programme a SaaS company runs, the privacy duties it owes as a processor and as a controller, the AI governance of the systems it builds and the transparency duties that attach to generative features. The duties of the customer that deploys the product belong to enterprise-ai-deployer; the Chapter V duties of a general-purpose model provider belong to gpai-model-provider.
- Roles
- Provider
- Deployment models
- Cloud, multi-tenant SaaSCloud, single tenant
- Risk classes
- noneminimaltransparencyhigh-risk-annex-iiigpai
- Jurisdictions
- EUUS-federalINT
- Frameworks
- SOC2ISO-27001NIST-800-53CSA-CCMCSA-AICMISO-42001NIST-AI-RMFNIST-AI-600-1OWASP-LLMOWASP-AGENTICEU-AI-ActGDPR
GOV · Governance & Risk
The provider seat is what brings a customer's supervisor to the organisation: the duty arrives through a customer contract rather than through a law binding the organisation directly. A provider whose customers are unregulated still holds the row, because what is tested is that the route exists, that the access is committed and that no contract term obstructs it. The register may legitimately be empty for a period, in which case the route is tested instead.
IAM · Identity & Access Management
DAT · Data Protection
Customer-held keys are a commitment of a hosted service.
Location transparency is a commitment of a hosted service to its tenants.
Export and portability are commitments of a hosted service to its tenants.
Exit is executed by the provider on the customer's behalf, because the customer cannot run the transition on infrastructure it does not control.
Retrieval interfaces and the information needed to stand the service up elsewhere are commitments of a hosted service to its tenants, on the same footing as the export capability in DAT-023.
APP · Application Security
INF · Infrastructure & Cloud Security
Tenant isolation exists because the product is cloud-hosted and shared.
MON · Monitoring & Logging
The service level objective and the status channel are commitments of a hosted service.
VND · Vendor & Third-Party Risk
The shared responsibility matrix exists because the customer's workload runs on the provider's service.
Requests for customer data reach the provider because it hosts the tenant's data.
A hosted service has customers whose data it holds, so the terms on which a customer leaves and the terms a regulation makes compulsory for that data are commitments of the service rather than internal practice.
A customer scoping its own controls over a workload it does not run needs a stated route to inspect the provider. VND-011 publishes the boundary; this states the access across it.
The chain behind a multi-tenant service is invisible to the customer unless it is disclosed, and a change to it lands on the customer's workload without the customer touching anything.
INC · Incident Response
BCM · Business Continuity
AIG · AI Governance
Art.50 disclosure binds every provider of an interacting or generating system, whatever its risk class.
Art.5 binds every provider, whatever the risk class of its other systems.
Instructions for use, the provider identification and the customer agreement are provider duties (Art.13, Art.16.2, ISO 42001 A.8).
The provider is also a user of AI systems, including the models beneath its product. The use register covers both.
The statement on customer data in training and the opt-out are the provider's to give.
Any organisation that trains, fine-tunes or evaluates a production model runs the pipeline this control secures. A provider that only calls a third-party model records that no pipeline exists against the inventory entry.
Required, as the library states every control whose trigger is a feature set rather than a facet (DAT-018, AIG-014, AIG-042, AIG-056): the documented assessment the control opens with is the first artefact. It bites where a system relies on user-supplied or external audio, image or video as evidence of a person's identity, of the provenance of an artefact or of a real-world event, which is a live case for identity verification, onboarding, claims and content-moderation features. An organisation whose assessment finds no such intake point records that finding and the detection limb has nothing to attach to. Restated from recommended on the S13 benchmark (ADR-049 amendment, 2026-09-16).
HRS · Human Resources Security
AIG · AI Governance
Condition: ai_risk_class in high-risk-annex-iii
Art.17 quality management system binds providers of high-risk systems.
Condition: ai_risk_class in high-risk-annex-iii
Conformity assessment, the declaration and the CE marking (Art.43, 47, 48) bind providers of high-risk systems.
Condition: ai_risk_class in high-risk-annex-iii and the organisation is established outside the Union
Art.22 binds providers of high-risk systems established outside the Union. The Art.54 arm for general-purpose model providers belongs to the gpai-model-provider profile.
Condition: ai_risk_class in high-risk-annex-iii
Art.20 and Art.21 bind providers of high-risk systems. The Art.53.5 cooperation duty on general-purpose model providers belongs to the gpai-model-provider profile.
AIG · AI Governance
Worker notification before a system is put into use at a workplace is an employer's duty under Art.26(7). A provider placing the system on the market owes it for its own workforce only where it is also the deployer, which is the enterprise-ai-deployer seat.
Registration by the organisation using the system is a deployer duty under Art.49(3). The provider registration of Art.49(1) and (2) sits on AIG-003 and is required of this profile there.
The fundamental rights impact assessment of Art.27 is owed by the deployer about the use it makes of the system. A provider's duty is to supply the information the assessment draws on, which AIG-034 carries.
Documentation of a general-purpose model as such is the gpai-provider seat (gpai-model-provider, ADR-046). A SaaS provider documents its product under AIG-015 and, where it also trains and offers a general-purpose model, holds the gpai-provider role and that profile alongside this one.
The public training content summary is the gpai-provider seat (ADR-046). A provider that fine-tunes a third-party model for its product records provenance under AIG-013 and is not the models provider.
The copyright policy and crawler conduct of a general-purpose model provider are the gpai-provider seat (ADR-046). A SaaS providers own licensed assets and training data licences are GOV-015 and AIG-013.
Systemic risk at Union level attaches to a designated general-purpose model and its provider (ADR-046). Risk from the systems a SaaS provider builds is AIG-005.
Evaluation under standardised protocols attaches to a designated general-purpose model (ADR-046). A SaaS provider evaluates the systems it operates under AIG-026 and AIG-008.
Protection of a designated models weights to a stated security goal is the gpai-provider seat (ADR-046). A SaaS providers development assets and training pipeline are IAM-014 and AIG-055.
Reporting to the AI Office about a designated model is the gpai-provider seat (ADR-046). A SaaS provider reports a systems serious incident to the competent authority under AIG-021.
The safety and security model report is the gpai-provider seat (ADR-046) and is recommended rather than required even there.
Published 2026-09-14