Regulation explainerPrivate Capital

How the EU AI Act affects private equity portfolios, acquisitions and fund operations

The EU AI Act regulates the companies that build and use AI systems rather than funds as such, which places most of a sponsor's exposure inside the portfolio. This page turns the Act, as amended by the Digital Omnibus on AI, into a sponsor's workflow: classify each company's role and systems, track the dates that now apply, add the right questions to diligence and set governance at board level. It is general information, not legal advice.

Reviewed 8 min read

On this page
  1. Why AI Act exposure becomes a sponsor's problem
  2. The roles that decide a portfolio company's obligations
  3. Instruments a sponsor's AI review should cover
  4. Which AI Act dates matter after the AI Omnibus
  5. Running an AI exposure scan across the portfolio
  6. AI Act questions to add to acquisition diligence
  7. Hypothetical: an HR software company that ranks job applicants
  8. AI the fund uses in its own operations
  9. General information, not legal advice
  10. Questions and answers
  11. Sources

Why AI Act exposure becomes a sponsor's problem

Fines under the Act fall on the operator, typically the portfolio company, and are set as the higher of a fixed amount or a share of worldwide annual turnover, with the top tier reserved for prohibited practices (Article 99)1. A company that must withdraw a product feature, rebuild documentation or add human oversight late carries that cost into its plan, and the sponsor carries it into returns.

Exposure also shows up at exit. Buyers increasingly ask for an inventory of AI systems, their classification and the evidence behind it, and a gap found in diligence becomes a price discussion. LPs who already ask how managers oversee technology risk in portfolio companies can be expected to extend those questions to AI.

The roles that decide a portfolio company's obligations

Provider
Develops an AI system or general-purpose model, or has one developed, and places it on the market or into service under its own name. Providers carry most high-risk obligations1.
Deployer
Uses an AI system under its authority in a professional activity. A company using a bought AI recruiting or credit tool is its deployer, with Article 26 duties if the system is high-risk1.
Importer and distributor
Bring another company's AI system to the EU market or make it available there, and must check the provider's conformity first1.
Provider by modification
Under Article 25, a deployer or distributor that rebrands a high-risk system, substantially modifies it or changes its purpose so it becomes high-risk takes on provider obligations1.
General-purpose AI model provider
Trains or places on the market a model that can perform a wide range of tasks. Portfolio companies calling such a model through an API are not its provider1.

Instruments a sponsor's AI review should cover

EU AI Act (Regulation (EU) 2024/1689)

European Union

Applies whenA company places an AI system on the EU market or puts it into service, uses one in the EU, or is established outside the EU but the system's output is used in the EU (Article 2)1.

  • No prohibited practices under Article 5, such as emotion recognition in workplaces or social scoring1.
  • High-risk systems in Annex I and Annex III need risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness1.
  • Transparency duties under Article 50 for systems that interact with people or generate synthetic content1.
  • Deployers of high-risk systems follow Article 26, and some, including deployers of creditworthiness and life or health insurance pricing systems, carry out a fundamental rights impact assessment under Article 271.

Digital Omnibus on AI (Regulation (EU) 2026/1744)

European Union

Applies whenAmends the AI Act; published in the Official Journal on 24 July 2026 and in force three days later2.

  • Moves Annex III high-risk obligations to 2 December 2027 and Annex I obligations to 2 August 20282.
  • Recasts the Article 4 AI literacy duty as taking measures to support AI literacy, without requiring a set level for individuals2.
  • Adds prohibitions that apply from 2 December 2026 and extends some simplifications to small mid-cap companies2.

GDPR (Regulation (EU) 2016/679)

European Union and EEA

Applies whenAn AI system processes personal data of people in the EU, such as applicants, borrowers, customers or individual investors3.

  • A lawful basis and transparency for each processing purpose3.
  • Article 22 limits on solely automated decisions with legal or similarly significant effects3.
  • A data protection impact assessment under Article 35 for likely high-risk processing3.

ISO/IEC 42001:2023 (voluntary standard)

International

Applies whenA company wants a certifiable AI management system to show governance to customers, buyers or investors4.

  • Voluntary; a management-system structure of policy, risk assessment, controls and audit that can support AI Act work4.

Which AI Act dates matter after the AI Omnibus

ObligationApplies fromWhat a sponsor should do now
Prohibited practices (Article 5)2 February 20251Confirm no portfolio company runs a prohibited practice
AI literacy (Article 4)2 February 2025, recast by the Omnibus as support measures2Keep proportionate training records for each company's AI users
General-purpose AI model obligations2 August 20251Identify any company that trains a general-purpose model rather than only using one
Transparency duties (Article 50)2 August 2026, with marking of content from generative systems already on the market due by 2 December 20262Check chatbots and synthetic media features for disclosure and marking
Prohibitions added by the Omnibus2 December 20262Screen image-generation products against the new prohibited uses
Annex III high-risk systems2 December 20272Inventory and gap-assess employment, credit, education and insurance use cases now
Annex I product-embedded systems2 August 20282Align with existing product conformity work, such as for medical devices

Dates as set out in Regulation (EU) 2026/1744 and the Act it amends. Check the consolidated text in the Official Journal before relying on them.

Running an AI exposure scan across the portfolio

  1. Build an AI inventory per company

    List every AI system each company builds, sells or uses, including features inside bought software and tools staff adopted themselves.

    Output
    AI system register
    Owner
    Portfolio company CTO or COO
  2. Assign a role to each system

    Record whether the company is provider, deployer, importer or distributor for each system. A software company is often provider for its product's AI feature and deployer for its HR tools.

    Output
    Role for every register entry
    Owner
    Company legal lead
  3. Classify the risk tier

    Check each system against the prohibited practices, Annex I and the Annex III areas. Where a company relies on the Article 6(3) exception, require a documented assessment.

    Output
    Classification with reasoning
    Owner
    Company legal lead with counsel
  4. Gap-assess high-risk systems

    For provider systems, compare practice with the requirements on risk management, data governance, documentation, logging, oversight and accuracy. For deployer systems, check Article 26 and whether Article 27 applies.

    Output
    Gap list with effort estimates
    Owner
    Product and compliance leads
  5. Fund remediation in the plan

    Put material gaps into the value-creation plan, or the first hundred days of a new holding, with a budget, an owner and a date ahead of the deadline.

    Output
    Remediation plan
    Owner
    Operating partner and company CEO
  6. Report to the board and sponsor

    Add the register and open gaps to the regular board pack, so AI exposure is reviewed with other operational risks.

    Output
    Board AI risk report
    Owner
    Company board

AI Act questions to add to acquisition diligence

Add these to the wider technology diligence described in the AI due diligence use case; warranties and indemnities belong with transaction counsel.

0 of 7 checked

Hypothetical: an HR software company that ranks job applicants

AI the fund uses in its own operations

Tools a manager uses for sourcing, screening, monitoring and investor communications generally fall outside Annex III. Its credit category concerns the creditworthiness of individuals, so a direct lender assessing companies is usually outside it, while a consumer-lending portfolio company is likely inside1. Chatbots answering LP questions still need Article 50 disclosure.

GDPR applies to the fund's own AI use whenever it processes data about founders, management teams or individual LPs3. Scoring people, for example ranking founders from public profiles, is profiling under GDPR and needs a lawful basis and transparency even when the AI Act does not treat it as high-risk.

Questions and answers

Does the AI Act reach portfolio companies based outside the EU?

Yes, in several situations. It applies to providers placing AI systems on the EU market wherever they are located, and to providers and deployers in third countries where the system's output is used in the EU1. A US or UK software company selling AI features to EU customers is therefore likely in scope for those features.

Is the fund or the portfolio company responsible under the AI Act?

Obligations attach to the operator, such as the provider or deployer of a system, which for portfolio AI is normally the portfolio company rather than the fund. The sponsor's exposure is economic and governance-related: remediation costs, value at exit and board oversight. Where the fund or a group entity provides AI to several companies, confirm the position with counsel.

Do portfolio companies need ISO/IEC 42001 certification?

No law requires it. ISO/IEC 42001 is a voluntary management-system standard that gives an AI programme structure and can reassure customers or buyers4. It does not by itself show compliance with the AI Act, whose technical requirements are supported by separate harmonised standards. Certification makes most sense where customers ask for it.

Did the AI Omnibus remove obligations for high-risk systems?

No. It moved most high-risk obligations to fixed later dates: 2 December 2027 for Annex III systems and 2 August 2028 for systems embedded in products under Annex I2. The requirements remain. Companies that pause preparation risk compressing documentation, testing and contract changes into the final months.

Sources

  1. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) — EUR-Lex · checked 10 October 2026
  2. Regulation (EU) 2026/1744 (Digital Omnibus on AI) amending Regulation (EU) 2024/1689 — EUR-Lex · checked 10 October 2026
  3. Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex · checked 10 October 2026
  4. ISO/IEC 42001:2023 — AI management systems — International Organization for Standardization · checked 10 October 2026

More in Private Capital

Back to Private Capital

Next step

Ask for an AI exposure scan across your portfolio companies

Send the list of portfolio companies, their main products and the markets they sell into. We will suggest how to build the AI inventory, which companies to classify first and where counsel should be involved.

Discuss a portfolio AI scan