The EU AI Act for US Private Equity: A Portfolio-Company Checklist for 2026
Dr. Leigh Coney
Founder, WorkWise Solutions
July 20, 2026
16 min read
TLDR: The EU AI Act can reach a US private equity firm, and it almost always does so through a portfolio company rather than the fund. The Act follows where an AI system is deployed and sold, so a portfolio company with an EU entity, EU customers, or EU users can be in scope even while the GP sits in New York. It sorts AI into four tiers (prohibited, high-risk, limited-risk, minimal-risk), and the heavy obligations fall on a short list of high-risk uses like hiring, credit, and insurance decisions. The dates are phased: prohibited practices have applied since February 2 2025, governance and general-purpose-AI obligations from August 2 2026, and most high-risk obligations by August 2 2027. Penalties for the worst breaches run to 35 million EUR or 7 percent of global annual turnover. For a US sponsor the work is a portfolio exercise: inventory each company's AI, find its EU nexus, classify the few high-risk systems, and get owners and documentation in place before the 2026 milestone.
Table of Contents
1. Does the EU AI Act Reach a US Fund?
The short answer is that the EU AI Act can reach a US private equity firm, and it usually does so through a portfolio company rather than the fund. The Act applies based on where an AI system is placed on the market and where it is used, so a US-headquartered GP is rarely in scope for its own back-office operations. The exposure runs through the companies it owns.
That framing matters because it changes who does the work. A New York fund with a Munich software company is exposed through that company. A US portfolio company whose hiring tool screens applicants in France is exposed through that use. The passport of the fund is close to irrelevant, and what counts is where the AI gets deployed and sold.
The reason to do this now, rather than in 2027, is lead time. The high-risk obligations that bite hardest, documentation, human oversight, and risk management, take months to build properly inside an operating company, and they cannot be assembled the week before an audit. A sponsor that starts the inventory in 2026 has room to fix what it finds. One that waits is choosing to remediate under pressure.
So for most US sponsors the EU AI Act is a portfolio question, answered company by company. The rest of this guide gives you the tiers, the dates, and a board-level checklist to run across the portfolio before the 2026 milestone. If you also want the US side of the same governance program, our companion guide on state AI laws for investment firms maps Texas and Colorado onto the same posture.
2. How the Act Reaches a US-Headquartered Sponsor
Three doors put a company in scope, and a US portfolio company can walk through any of them.
An EU entity or workforce. A portfolio company with a subsidiary, an office, or employees in the EU is operating inside the Act's territory. If it runs AI that affects those people or that market, the Act applies to that use.
The EU market. A company that places an AI system or an AI-enabled product on the EU market is in scope even when it is headquartered in Austin or Boston. Selling an AI feature to European customers is enough.
EU users or affected people. The Act also reaches situations where the output of an AI system is used in the EU, or where people in the EU are affected by it. A US company screening EU-based job applicants with an automated tool is the textbook example.
It is worth separating the fund's own AI use from the portfolio's, because they usually sit in different tiers. A GP running Claude or Copilot to draft memos and summarize documents is doing minimal-risk work, wherever it is domiciled. The high-risk exposure lives downstream, in the companies that make automated decisions about employees, borrowers, or customers. That is another reason the fund-level answer and the portfolio-level answer come apart, and why a single firmwide yes or no misleads.
None of these require the fund itself to have any EU presence. That is why the analysis belongs at the portfolio-company level, one company at a time, rather than as a single yes or no for the firm.
3. The Four Risk Tiers at a Glance
The Act sorts AI systems into four tiers by the risk they pose, and the obligations scale with the tier. Most of what a portfolio company runs will land in the bottom two tiers with light or no obligations. The work is finding the few systems that sit higher.
| Risk tier | What the Act requires | Typical portfolio-company examples | Board action |
|---|---|---|---|
| Prohibited | Banned outright. A small set of uses the Act treats as unacceptable, such as social scoring, certain manipulative or exploitative systems, and some biometric practices. | Rare in ordinary portfolio companies. Occasionally surfaces in aggressive HR surveillance or scoring tools. | Confirm none are in use. This ban has applied since February 2 2025. |
| High-risk | The heavy tier: risk management, data governance, technical documentation, human oversight, logging, and accuracy and robustness requirements. | AI in hiring and worker management, credit and insurance decisions, eligibility for essential services, certain biometric uses, safety components of regulated products. | Inventory, assign an owner, and start the documentation ahead of the 2027 deadline. |
| Limited-risk | Transparency duties. People must be told when they are dealing with AI, and AI-generated or manipulated content must be labeled. | Customer-facing chatbots, AI-generated marketing content, synthetic media and deepfakes. | Add clear disclosures and content labels. |
| Minimal-risk | No mandatory obligations under the Act. | Most internal productivity: drafting, summarizing, research, coding assistants. | Voluntary good practice and a light usage policy. |
Read the table as a triage tool. Almost everything a company does with AI for internal productivity is minimal-risk. The compliance weight concentrates on high-risk uses, which is a short and specific list.
4. Which Portfolio-Company Systems Land in High-Risk
High-risk is where the real work is, and it is narrower than the panic suggests. The Act reserves the tier for AI used in areas it treats as consequential for people's lives and rights.
For a private equity portfolio, the high-risk uses that come up most often are employment and worker management (screening resumes, ranking candidates, informing promotion or termination), access to credit and financial services (automated lending or pricing decisions), insurance underwriting and pricing, and eligibility for essential public or private services. AI that acts as a safety component of a regulated product, common in industrial or medical portfolio companies, also lands here.
What does not land here is most of what people worry about. An analyst using a chatbot to draft a memo, a finance team summarizing contracts, a marketing team generating copy: those are minimal-risk, or for the chatbot and the generated content, limited-risk with a disclosure duty. The board-level task is to separate the short high-risk list from the long minimal-risk one, because that is what decides where the money and the documentation go.
A worked example makes the sorting concrete. Take a mid-market software company in the portfolio that sells into Germany. Its customer-support chatbot is limited-risk, so it needs a disclosure that users are talking to AI. Its internal tool that drafts release notes is minimal-risk, so no obligation attaches. Its AI-assisted resume screener for its own hiring is high-risk, so it needs documentation, human oversight, and logging. Three systems, three tiers, one company. The board's job is to make sure someone has actually walked each system to its tier rather than assuming the whole company is either fine or doomed.
When a system's classification is genuinely ambiguous, and some are, that is a question for counsel rather than a judgment call for the deal team. Guessing low on a system that turns out to be high-risk is the expensive mistake.
5. The Phased Deadlines That Matter
The Act does not switch on all at once. It phases in, and three dates matter for a portfolio.
February 2 2025. The ban on prohibited practices and the AI-literacy obligations have applied since this date. If a portfolio company is running a prohibited use, it is already late, which is why confirming there are none is step one.
August 2 2026. Obligations for general-purpose AI models and the Act's governance and enforcement framework apply from here. This is the near milestone a US sponsor should plan the portfolio around.
August 2 2027. Most obligations for high-risk systems phase in by this date, with certain high-risk systems embedded in regulated products falling on the later end of the schedule.
Having the high-risk work underway means something specific. It means each high-risk system has a named owner, a started set of technical documentation, a defined human-oversight step, and logging switched on. None of that requires the final implementing guidance to exist, and it is the groundwork that every version of the obligation will demand. Starting it early turns a future scramble into a routine.
Attribute the schedule to the EU AI Act itself, and confirm it with EU counsel before you rely on any single date, because implementation guidance and secondary rules keep arriving. The safe posture is to treat August 2 2026 as the planning milestone and to have the high-risk work underway well before 2027.
6. Are Your Companies Providers or Deployers?
One distinction decides how much of the Act lands on a given company: is it a provider of an AI system or a deployer of one? A provider builds an AI system or a general-purpose model, or substantially modifies one, and puts it on the market under its own name. A deployer uses a system under its own authority.
Most portfolio companies are deployers. They buy a hiring tool, a credit model, or a chatbot and run it. Deployer obligations are lighter than provider obligations, and for high-risk systems they are still real: use the system as intended, keep humans in the oversight loop, monitor it, and retain logs. A company that trains or heavily customizes its own model, or ships an AI feature inside a product sold into the EU, can cross into provider territory, where the obligations are heavier and where the general-purpose-AI model rules that arrive in the August 2 2026 window may apply.
General-purpose AI models sit at the top of this chain. These are the large models that many tools are built on, and their own obligations, including transparency about the model and technical documentation for downstream users, apply from the August 2 2026 window. Most portfolio companies never become general-purpose-AI providers, because they consume a model through a vendor rather than release one. The companies to watch are the ones building AI products of their own, where a feature shipped into the EU can pull them up the chain into heavier obligations.
The practical instruction is simple: for each in-scope system, write down whether the company is the provider or the deployer, because the answer sets the obligation. When a portfolio company genuinely cannot tell which hat it wears, that determination belongs with counsel.
7. The Penalties, in Proportion
The penalties are sized to make the worst breaches a board issue. For prohibited-practice violations, the Act allows fines of up to 35 million EUR or 7 percent of a company's total worldwide annual turnover, whichever is higher. Other categories of breach carry lower ceilings.
The figure that matters for a portfolio is the 7 percent of turnover, because for a mid-sized portfolio company that percentage can exceed 35 million EUR by a wide margin. This is tail risk, rare but large, and tail risk is exactly what boards exist to price.
Fines are not the only cost. A high-risk system that cannot produce its documentation may have to be pulled from use, which is an operational hit during a hold period when the value-creation plan may depend on that system running. The price of getting this wrong shows up in downtime and remediation as much as in penalties.
8. The Board-Level Checklist
Here is the board-level checklist, ordered so the work stays tractable.
1. Inventory the AI. Ask every portfolio company for a list of the AI systems it uses or sells, who owns each one, and what data each touches. Classification is impossible without the list, and most sponsors have never actually assembled it.
2. Find the EU nexus, company by company. Does the company have an EU entity, EU customers, EU users, or EU employees affected by an AI system? A company with no EU nexus has no EU AI Act exposure, though its SEC and state obligations still stand.
3. Classify by tier. For companies with a nexus, sort each system into prohibited, high-risk, limited-risk, or minimal-risk. Most will be minimal. The point of the exercise is to surface the few that are not.
4. Clear the prohibited tier first. That ban has applied since February 2025, so it is the most urgent check even though it rarely turns anything up.
5. Prioritize the high-risk systems. Assign an owner, begin the technical documentation, and build in human oversight. This is the work with the longest lead time, which is why it starts now for a 2027 deadline. It is also where a finding from BCG, quoted below, applies to compliance as much as to strategy: the firms that get ahead concentrate on a smaller number of higher-value efforts rather than spreading thin across everything.
6. Handle limited-risk with disclosure. Chatbots and synthetic media need to say they are AI. This is cheap to fix and easy to forget.
7. Set the reporting line. Decide how each portfolio company reports its AI-risk status up to the GP, and how the GP reports portfolio-level exposure to its own stakeholders. Run this once, then refresh it whenever a company adds a material AI system or enters the EU market.
One more move pays off at the front end: fold this into diligence. When you are underwriting a new platform with EU exposure, the AI inventory and tier classification belong in the diligence checklist rather than the post-close scramble. A target's unmanaged high-risk system is a real, priceable liability, and finding it before signing costs less than finding it after.
9. Where to Start
Start with the inventory, because every later step depends on it, and because most sponsors find they have less high-risk exposure than they feared and less visibility than they assumed. The systems that carry real obligation, a hiring screen here, a credit model there, are a short list once someone actually looks for them.
For the portfolio-company work, our Secure AI Adoption engagement ($7,500 per company) puts sanctioned tools, a usable AI policy, and the documentation trail a European regulator or an SEC examiner would ask for in place at each company. It is the on-the-ground version of the checklist above.
For the firm-level program that ties EU, SEC, and state obligations into one governance posture, our AI Governance work builds the framework and the evidence file once, so the same inventory and documentation answer more than one regulator. The EU AI Act is one more reason to run AI governance as a standing program rather than a fire drill.
"Only a minority of companies are capturing significant value from AI, and the gap between them and everyone else is widening. The ones ahead concentrate on a smaller number of higher-value uses and change how the work gets done around them."
BCG, "Where's the Value in AI?" and "The Widening AI Value Gap" (2025)
- •The EU AI Act reaches US private equity mainly through portfolio companies, not the fund: a portco with an EU entity, EU customers, or EU users can be in scope while the GP sits in the US.
- •The Act sorts AI into four tiers (prohibited, high-risk, limited-risk, minimal-risk); most portfolio-company uses are minimal-risk, and the heavy obligations land on a short set of high-risk systems.
- •High-risk covers uses like hiring and HR screening, credit and insurance decisions, and eligibility for essential services, which is where boards should focus first.
- •The deadlines are phased: prohibited practices since February 2 2025, governance and general-purpose-AI obligations from August 2 2026, and most high-risk obligations by August 2 2027.
- •Penalties for prohibited-practice breaches run up to 35 million EUR or 7 percent of global annual turnover, so the tail risk is real even if it is rare.
- •The practical response is a portfolio inventory: list each company's AI, find its EU nexus, classify the few high-risk systems, and assign an owner and documentation per company.
- •Run this as one governance program alongside SEC and state obligations, so the same evidence answers a European regulator and an SEC examiner.
Frequently Asked Questions
Does the EU AI Act apply to US private equity firms?
Usually yes, but through the portfolio rather than the fund. The Act applies based on where an AI system is deployed or placed on the market, so a US-headquartered GP is rarely in scope for its own operations. Exposure runs through portfolio companies that have an EU entity, sell into the EU, or have EU users or employees affected by an in-scope AI system. A New York fund with a German software portco, or a US portco whose hiring tool screens applicants in France, can be reached even though the fund itself is not established in the EU. The practical takeaway: run the analysis company by company, not at the fund level.
What are the EU AI Act deadlines?
The Act applies in phases. Prohibited practices and AI-literacy obligations have applied since February 2 2025. Obligations for general-purpose AI models and the Act's governance framework apply from August 2 2026. Most obligations for high-risk systems phase in by August 2 2027, with some product-embedded high-risk systems on the later end of that timeline. For a US sponsor, August 2 2026 is the near milestone to plan around: governance structures and any general-purpose-AI exposure should be sorted by then, and the high-risk conformity work for portfolio companies should already be underway. Confirm the current schedule with EU counsel before relying on any single date.
Which AI systems are high-risk under the EU AI Act?
High-risk is a defined category, and it is narrower than most people assume. It covers AI used in areas the Act treats as consequential: employment and worker management (hiring, screening, promotion), access to credit and insurance, eligibility for essential public and private services, education, certain biometric uses, and AI that is a safety component of a regulated product. Most internal productivity uses, drafting, summarizing, coding help, sit in the minimal-risk tier with no mandatory obligations. The board-level job is to find the small number of portfolio-company systems that fall in the high-risk list and give them owners, documentation, and human oversight. When a system's classification is genuinely unclear, that is a question for counsel, not a guess.
Related Guides & Articles
AI Governance and SEC Exam Readiness
The US side of the same program: what examiners ask about AI and how a firm shows a documented governance posture.
State AI Laws for Investment Firms
Texas TRAIGA and Colorado's amended AI law, and the NIST-based posture that travels across state lines and the Atlantic.
AI Governance Audit Checklist
The self-scoring checklist that maps control areas to the documents that prove them, built for an SEC exam and reusable here.
Secure AI Adoption
The portfolio-company build: sanctioned tools, a usable policy, and the documentation trail, at $7,500 per company.
Turn the EU AI Act into a portfolio checklist
Our Secure AI Adoption engagement ($7,500 per company) runs the inventory, the classification, the sanctioned tools, and the documentation trail at each portfolio company, so a European regulator or an SEC examiner meets evidence instead of guesses. For the firm-level program that ties EU, SEC, and state obligations into one posture, our AI Governance work builds the framework once and keeps it current. Confirm the specific dates and any article-level requirements with EU counsel before you rely on them.
Book a Call