Regulation explainerPrivate Capital
How the EU AI Act affects private equity portfolios, acquisitions and fund operations
The EU AI Act regulates the companies that build and use AI systems rather than funds as such, which places most of a sponsor's exposure inside the portfolio. This page turns the Act, as amended by the Digital Omnibus on AI, into a sponsor's workflow: classify each company's role and systems, track the dates that now apply, add the right questions to diligence and set governance at board level. It is general information, not legal advice.
On this page
- Why AI Act exposure becomes a sponsor's problem
- The roles that decide a portfolio company's obligations
- Instruments a sponsor's AI review should cover
- Which AI Act dates matter after the AI Omnibus
- Running an AI exposure scan across the portfolio
- AI Act questions to add to acquisition diligence
- Hypothetical: an HR software company that ranks job applicants
- AI the fund uses in its own operations
- General information, not legal advice
- Questions and answers
- Sources
Why AI Act exposure becomes a sponsor's problem
Fines under the Act fall on the operator, typically the portfolio company, and are set as the higher of a fixed amount or a share of worldwide annual turnover, with the top tier reserved for prohibited practices (Article 99)1. A company that must withdraw a product feature, rebuild documentation or add human oversight late carries that cost into its plan, and the sponsor carries it into returns.
Exposure also shows up at exit. Buyers increasingly ask for an inventory of AI systems, their classification and the evidence behind it, and a gap found in diligence becomes a price discussion. LPs who already ask how managers oversee technology risk in portfolio companies can be expected to extend those questions to AI.
The roles that decide a portfolio company's obligations
- Provider
- Develops an AI system or general-purpose model, or has one developed, and places it on the market or into service under its own name. Providers carry most high-risk obligations1.
- Deployer
- Uses an AI system under its authority in a professional activity. A company using a bought AI recruiting or credit tool is its deployer, with Article 26 duties if the system is high-risk1.
- Importer and distributor
- Bring another company's AI system to the EU market or make it available there, and must check the provider's conformity first1.
- Provider by modification
- Under Article 25, a deployer or distributor that rebrands a high-risk system, substantially modifies it or changes its purpose so it becomes high-risk takes on provider obligations1.
- General-purpose AI model provider
- Trains or places on the market a model that can perform a wide range of tasks. Portfolio companies calling such a model through an API are not its provider1.
Instruments a sponsor's AI review should cover
EU AI Act (Regulation (EU) 2024/1689)
European UnionApplies whenA company places an AI system on the EU market or puts it into service, uses one in the EU, or is established outside the EU but the system's output is used in the EU (Article 2)1.
- No prohibited practices under Article 5, such as emotion recognition in workplaces or social scoring1.
- High-risk systems in Annex I and Annex III need risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness1.
- Transparency duties under Article 50 for systems that interact with people or generate synthetic content1.
- Deployers of high-risk systems follow Article 26, and some, including deployers of creditworthiness and life or health insurance pricing systems, carry out a fundamental rights impact assessment under Article 271.
Digital Omnibus on AI (Regulation (EU) 2026/1744)
European UnionApplies whenAmends the AI Act; published in the Official Journal on 24 July 2026 and in force three days later2.
- Moves Annex III high-risk obligations to 2 December 2027 and Annex I obligations to 2 August 20282.
- Recasts the Article 4 AI literacy duty as taking measures to support AI literacy, without requiring a set level for individuals2.
- Adds prohibitions that apply from 2 December 2026 and extends some simplifications to small mid-cap companies2.
GDPR (Regulation (EU) 2016/679)
European Union and EEAApplies whenAn AI system processes personal data of people in the EU, such as applicants, borrowers, customers or individual investors3.
ISO/IEC 42001:2023 (voluntary standard)
InternationalApplies whenA company wants a certifiable AI management system to show governance to customers, buyers or investors4.
- Voluntary; a management-system structure of policy, risk assessment, controls and audit that can support AI Act work4.
Which AI Act dates matter after the AI Omnibus
| Obligation | Applies from | What a sponsor should do now |
|---|---|---|
| Prohibited practices (Article 5) | 2 February 20251 | Confirm no portfolio company runs a prohibited practice |
| AI literacy (Article 4) | 2 February 2025, recast by the Omnibus as support measures2 | Keep proportionate training records for each company's AI users |
| General-purpose AI model obligations | 2 August 20251 | Identify any company that trains a general-purpose model rather than only using one |
| Transparency duties (Article 50) | 2 August 2026, with marking of content from generative systems already on the market due by 2 December 20262 | Check chatbots and synthetic media features for disclosure and marking |
| Prohibitions added by the Omnibus | 2 December 20262 | Screen image-generation products against the new prohibited uses |
| Annex III high-risk systems | 2 December 20272 | Inventory and gap-assess employment, credit, education and insurance use cases now |
| Annex I product-embedded systems | 2 August 20282 | Align with existing product conformity work, such as for medical devices |
Dates as set out in Regulation (EU) 2026/1744 and the Act it amends. Check the consolidated text in the Official Journal before relying on them.
Running an AI exposure scan across the portfolio
Build an AI inventory per company
List every AI system each company builds, sells or uses, including features inside bought software and tools staff adopted themselves.
Assign a role to each system
Record whether the company is provider, deployer, importer or distributor for each system. A software company is often provider for its product's AI feature and deployer for its HR tools.
Classify the risk tier
Check each system against the prohibited practices, Annex I and the Annex III areas. Where a company relies on the Article 6(3) exception, require a documented assessment.
Gap-assess high-risk systems
For provider systems, compare practice with the requirements on risk management, data governance, documentation, logging, oversight and accuracy. For deployer systems, check Article 26 and whether Article 27 applies.
Fund remediation in the plan
Put material gaps into the value-creation plan, or the first hundred days of a new holding, with a budget, an owner and a date ahead of the deadline.
Report to the board and sponsor
Add the register and open gaps to the regular board pack, so AI exposure is reviewed with other operational risks.
AI Act questions to add to acquisition diligence
Add these to the wider technology diligence described in the AI due diligence use case; warranties and indemnities belong with transaction counsel.
Hypothetical: an HR software company that ranks job applicants
AI the fund uses in its own operations
Tools a manager uses for sourcing, screening, monitoring and investor communications generally fall outside Annex III. Its credit category concerns the creditworthiness of individuals, so a direct lender assessing companies is usually outside it, while a consumer-lending portfolio company is likely inside1. Chatbots answering LP questions still need Article 50 disclosure.
GDPR applies to the fund's own AI use whenever it processes data about founders, management teams or individual LPs3. Scoring people, for example ranking founders from public profiles, is profiling under GDPR and needs a lawful basis and transparency even when the AI Act does not treat it as high-risk.
General information, not legal advice
Questions and answers
Does the AI Act reach portfolio companies based outside the EU?
Yes, in several situations. It applies to providers placing AI systems on the EU market wherever they are located, and to providers and deployers in third countries where the system's output is used in the EU1. A US or UK software company selling AI features to EU customers is therefore likely in scope for those features.
Is the fund or the portfolio company responsible under the AI Act?
Obligations attach to the operator, such as the provider or deployer of a system, which for portfolio AI is normally the portfolio company rather than the fund. The sponsor's exposure is economic and governance-related: remediation costs, value at exit and board oversight. Where the fund or a group entity provides AI to several companies, confirm the position with counsel.
Do portfolio companies need ISO/IEC 42001 certification?
No law requires it. ISO/IEC 42001 is a voluntary management-system standard that gives an AI programme structure and can reassure customers or buyers4. It does not by itself show compliance with the AI Act, whose technical requirements are supported by separate harmonised standards. Certification makes most sense where customers ask for it.
Did the AI Omnibus remove obligations for high-risk systems?
No. It moved most high-risk obligations to fixed later dates: 2 December 2027 for Annex III systems and 2 August 2028 for systems embedded in products under Annex I2. The requirements remain. Companies that pause preparation risk compressing documentation, testing and contract changes into the final months.
Sources
- Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) — EUR-Lex · checked 10 October 2026
- Regulation (EU) 2026/1744 (Digital Omnibus on AI) amending Regulation (EU) 2024/1689 — EUR-Lex · checked 10 October 2026
- Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex · checked 10 October 2026
- ISO/IEC 42001:2023 — AI management systems — International Organization for Standardization · checked 10 October 2026