Insights
The EU AI Act, in Plain English, for Mid-Market Portfolio Companies
July 13, 2026 · AI Governance · PE Value Creation
Sujit Maharana · Managing Director, Technology & AI Advisory
The EU AI Act is the first cross-sector AI law anywhere, and it is already in force. Its obligations phase in on a schedule rather than all at once. Most mid-market portfolio companies therefore still have time to prepare. Few have started. This post covers what applies and why buyers now raise it in diligence as well as in compliance reviews.
Who's in scope
Most US mid-market companies assume the Act applies only to companies based in Europe. The Act applies based on where your AI system's output is used or who it affects, not where your company is incorporated. If you have EU customers, or your systems process data on EU residents, you're in scope, even if you have no employee or office on the continent. A Delaware-incorporated SaaS company selling to European customers is covered. Check this now, before a buyer asks about it in a data room.
The four risk tiers
The Act classifies AI systems into four tiers, and the tier determines what you have to do:
- Unacceptable risk: banned outright. Social scoring, manipulative AI, certain biometric uses.
- High-risk: the tier with the substantive obligations. This covers AI used in hiring and employment decisions, credit and lending, access to essential services, and critical infrastructure. These are common categories in mid-market software and services businesses.
- Limited risk: transparency duties. Users need to know they're interacting with AI (chatbots, generated content).
- Minimal risk: most day-to-day uses. Internal tools, recommendation features, most productivity AI. Light or no additional obligation.
The main task under the Act is to classify each AI system you run, by use case rather than by vendor or model, because the tier sets everything that follows. A company that hasn't inventoried its AI systems can't answer this question, and most mid-market companies haven't.
Obligations for high-risk systems
For systems in the high-risk tier, four obligations matter most:
- Risk classification: documented, not assumed.
- Human oversight (Article 14): a person can meaningfully review and override the system's output, rather than approving it by default.
- Transparency and disclosure (Article 50): users need to know when they're subject to an AI-driven decision.
- Technical documentation: the system's design, data, and testing, recorded in enough detail to pass an audit.
One more obligation applies regardless of tier. AI literacy (Article 4) has been in force since February 2025. It requires staff who work with AI systems to have a baseline understanding of how those systems work and what can go wrong. It is the cheapest obligation to meet. Few companies have implemented it.
The compliance timeline
Prohibited-use rules and obligations on general-purpose AI models arrived first. The heavier high-risk system requirements phase in later, largely across 2026 into 2027. The delay is deliberate. A portfolio company that starts an inventory and classification exercise now can do the work on a normal timeline. A company that waits until the requirements are live will be doing crisis remediation under a deadline it didn't choose.
Penalties
The penalties are fixed in law rather than projected. Prohibited-use violations can draw up to EUR 35 million or 7% of global annual turnover. High-risk non-compliance can draw up to EUR 15 million or 3% of global annual turnover. In both cases the higher figure applies. For a portfolio company selling into the EU, that exposure scales with turnover and exists whether or not anyone has assessed it yet.
Why buyers ask about it in diligence
Buyers are starting to ask portfolio companies about AI governance directly: what systems exist, how they are classified, and whether oversight and documentation exist. The question is showing up earlier in diligence than most sellers expect. An unprepared answer is treated the way an undocumented data breach used to be. It does not disqualify the company by itself, but it leads to a discount, a delay, or a rep-and-warranty issue. AI Act exposure is becoming an exit-multiple question well before regulators begin enforcement. Doing the inventory, the classification and the basic controls early costs materially less than facing the question unprepared in a diligence room.
This is a briefing, not legal advice. EU AI Act obligations depend on your specific systems, data flows, and use cases. Work through classification and compliance with qualified counsel.
The AI Governance Readiness Assessment scores your AI governance across five pillars in about fifteen minutes. EU AI Act exposure is part of the score.
Working through a version of this?
A 30-minute call about your situation. We will not present slides or a sales pitch.