The AI Act for WordPress SaaS with AI agents
Guide for WordPress SaaS with AI agents: upstream/downstream roles, transparency, permissions, approvals, versions, tests and release evidence.
AI ACT · SAAS AND AGENTS
A product connecting a general-purpose model to WordPress is not merely “a prompt with a UI”. Once it reads data, decides steps and can change a website, it has its own purpose, limits and chain of responsibility that must be documented.
Separate the upstream model from your system
The GPAI model provider documents the model and meets its own duties. The downstream SaaS combines it with prompts, sources, memory, permissions, tools and interface for a specific purpose. API use does not automatically make you the GPAI model provider, but you may be the provider of the system placed on the market under your name. [EU-REG] [EU-GPAI-G] [EU-GPAI-OBL]
The product record should name model and version, intended purpose, users, data, functions, limits, excluded uses and dependencies. Do not copy upstream model limits as though they describe the entire SaaS: orchestration and WordPress access can create failures the model card does not cover. [EU-GPAI-G] [OAI-ACT]
Define autonomy in levels
Level 0 explains; level 1 recommends; level 2 prepares a draft; level 3 executes after confirmation; level 4 executes within pre-authorised limits. Each WordPress tool—reading, editing, publishing, plugins, users and redirects—gets the lowest necessary level and permission. [EU-LIT] [EU-REG]
Publishing, deletion, permission changes and hard-to-reverse modifications require an effect summary and explicit confirmation. The system should distinguish questions from commands and avoid turning ambiguous wording into action. Draft mode is a technical control, not merely an editorial preference. [EU-LIT] [EU-REG]
Transparency starts in the interface
Where the agent interacts directly with a person, Article 50 requires clear disclosure from the start of the first interaction, subject to a narrowly interpreted exception where AI is obvious. Calling it a “copilot” or using an avatar is not enough. The interface identifies AI, purpose and action limits. [EU-A50] [EU-A50-G]
For the site administrator, transparency also means an intelligible trail: user request, sources read, model and version, tool called, proposed change, approver and executed result. Do not retain more data than the trail’s purpose justifies. [EU-LIT] [EU-REG] [EDPB-28]
Each release needs an evidence pack
For each release retain reviewed purpose and classification, models and vendors, changelog, tests, known limits, permission set, transparency copy, security results, approval and rollback plan. A prompt change can be material even without a plugin-version change. [EU-REG] [EU-GPAI-G] [EU-LIT]
Test cases include empty and large sites, insufficient permissions, incompatible plugins, API failure, language changes, contradictory sources, malicious page instructions, ambiguous commands, cancellation and rollback. Test the WordPress effect, not only the model’s prose. [EU-LIT] [EU-REG]
A model change is a product change
A new model may change refusals, cost, context length, languages, tool use and failure profile. Do not automatically promote a vendor alias to production. Run evaluations, compare results and preserve pinning or rollback. Reassess roles if model or system modification is substantial. [EU-GPAI-G] [OAI-ACT]
Keep a degraded mode: analysis without action, draft without publication or conventional functions when the model is unavailable. A safe product does not turn vendor downtime into an invitation to bypass approval. Status and limits should be visible to the administrator. [EU-LIT] [EU-REG]
A prudent operating model for AYSA.AI
As a recommended model, AYSA.AI would inventory each agent by purpose and tools, retain model and prompt versions, limit permissions, explain AI interaction, default to drafts, require action confirmation and link each release to testing and rollback. These are product criteria, not claims about current implementation. [EU-REG] [EU-A50] [EU-LIT]
Final classification requires actual functions, intended purpose, customers, data and consequences. An SEO or productivity tool is not automatically high-risk, and “low risk” is not an official certificate. Use the legal text and Service Desk tools, escalating sensitive cases to specialist assessment. [EU-RISK] [EU-DESK] [EU-REG]
Official sources and verification date
- Regulation (EU) 2024/1689 — Artificial Intelligence Act
- European Commission — AI Act Service Desk and Compliance Checker
- European Commission — AI Literacy Questions & Answers
- European Commission — transparency obligations under Article 50
- European Commission — guidelines on transparency obligations
- European Commission — high-risk AI system classification
- European Commission — guidelines for general-purpose AI model providers
- European Commission — general-purpose AI obligations under the AI Act
- European Data Protection Board — Opinion 28/2024 on AI models
- OpenAI — EU AI Act primer and GPAI Code approach