Skip to main content

Nexus Expert Research

EU’s New AI Act Could Fine PE Firms €35 Million – Here’s What Changes for Due Diligence Starting This Year

Private equity firms have spent the past two years racing to put AI into every part of the deal process, from CIM extraction to due diligence review. Starting August 2, 2026, that same AI has to answer to a regulator. The EU AI Act’s high-risk obligations take effect on that date, and for the first time, PE firms operating in or serving the EU face real financial exposure if the AI systems inside their portfolio companies aren’t compliant.

The headline penalty figure gets attention for a reason: prohibited AI practices carry fines of up to €35 million or 7% of a company’s total worldwide annual turnover, whichever is higher. Non-compliance with high-risk system obligations specifically, which is where most PE exposure actually sits, carries fines up to €15 million or 3% of global turnover. Either way, both figures dwarf anything most compliance teams have dealt with before, including GDPR.

What Actually Changes This Year

The EU AI Act has been rolling out in phases since it entered into force in August 2024. Prohibited AI practices, like certain types of biometric surveillance, were already banned starting February 2025. General-purpose AI model obligations kicked in that August. August 2026 is different because it’s when the bulk of the regulation starts applying to systems businesses actually use every day: transparency requirements, enforcement powers over general-purpose AI, and critically, full compliance obligations for high-risk AI systems across eight sectors, including financial services, employment, and essential services.

For portfolio companies operating in the EU, or serving EU customers, this means any AI system used for things like credit scoring, insurance pricing, or employment screening now needs documented risk management, technical documentation, human oversight processes, and in many cases, registration in an EU database, all completed and demonstrable by the deadline.

A Complication Worth Knowing About

Here’s something most coverage of this deadline skips over. The EU is currently working through a “Digital Omnibus” proposal that could push the heaviest high-risk obligations back to December 2027 or August 2028. The European Parliament adopted its position supporting that delay in March 2026, but as of this writing, that proposal has not been formally adopted into law. Until it is, August 2, 2026 remains the legally binding date. PE firms and portfolio companies planning around an assumed delay are making a bet on a political process, not a confirmed legal outcome. The safer approach, and the one most compliance advisors are recommending, is to treat August 2026 as real until an extension is formally signed into law.

Where This Hits Portfolio Companies Hardest

The categories that matter most for a typical PE portfolio are spelled out directly in the regulation’s Annex III. Credit scoring and creditworthiness assessment tools are explicitly classified as high-risk. So is AI used in insurance pricing and risk assessment, employment screening and hiring decisions, and systems supporting essential services. For a fund with fintech, insurtech, or HR-tech companies in its portfolio, that’s not an edge case. That’s the core product.

This creates a specific due diligence problem that didn’t exist two years ago. A deal team evaluating an acquisition now has to assess not just whether the target’s AI systems work, but whether they’re classified correctly under the Act, whether the required technical documentation exists, and whether the company can demonstrate human oversight over automated decisions. Getting this wrong doesn’t just create post-close compliance work. It can materially change what the company is worth, since a target facing potential eight-figure penalties or forced market withdrawal of a core AI system is not being acquired at the price everyone thought.

What This Means for How Diligence Gets Done

AI compliance review is quickly becoming its own line item in due diligence, alongside financial, legal, and commercial diligence. Firms are documenting AI system inventories inside portfolio companies, running gap analyses against Annex III classifications, and building the same kind of structured checklist for AI risk that they’ve long used for financial red flags.

But classification and documentation only tell part of the story. Knowing whether a target’s AI system is technically compliant is different from knowing whether the business built around it is durable once compliance costs and potential restrictions are factored in. That’s where conversations with people who actually understand the target’s regulatory environment, whether that’s a compliance specialist in the relevant industry or someone who has navigated a similar classification process at another company, add something a document review can’t: a real sense of how enforcement is actually playing out on the ground, not just what the regulation says on paper.

The Bottom Line

The EU AI Act doesn’t just add a compliance checkbox to due diligence. For any fund with AI-driven fintech, insurtech, or HR-tech exposure in its portfolio, it changes what needs to be verified before a deal closes, and how much a target might actually be worth once regulatory risk is priced in. With the Digital Omnibus delay still unconfirmed, treating August 2026 as the real deadline, and building diligence processes around it now, is the only approach that doesn’t depend on guessing how Brussels votes.

Sarah Mitchel

Sarah Mitchell is Head of Research Intelligence at Nexus Expert Research, where she oversees content strategy, research methodology, and institutional buyer education across the firm's expert network and primary research practice.

Write a comment

Your email address will not be published. Required fields are marked *