Tous les articles

The EU AI Act is now a due diligence line item

If you invest in European software, the EU AI Act has moved from a legal footnote to a due diligence line item. From 2 August 2026 the European Commission holds enforcement powers over general-purpose AI providers, and the Act’s transparency obligations apply. At the same time, most of the heavy high-risk obligations were just postponed to late 2027 and 2028.

Deal teams are drawing two wrong conclusions from this. Some believe everything is delayed and drop the topic. Others believe everything applies and price panic into the deal. Neither is true, and knowing which obligations bite when is worth real money in a negotiation.

Where AI Act enforcement stands in mid-2026

The timeline has moved twice this year, so here is the current state. The implementation timeline at artificialintelligenceact.eu tracks it in detail.

Prohibited practices have been banned since 2 February 2025: social scoring, emotion recognition in workplaces and schools, certain biometric categorization. Fines reach 35 million euros or 7 percent of worldwide turnover. Obligations for general-purpose AI model providers have applied since 2 August 2025.

From 2 August 2026, two things change. Article 50 transparency duties apply: chatbots must disclose that they are AI, synthetic content must be marked, deepfakes must be labeled. And the Commission’s AI Office can actually enforce against general-purpose model providers, with fines up to 15 million euros or 3 percent of global turnover.

The high-risk tier moved the other way. The Digital Omnibus, adopted by the European Parliament on 16 June 2026 with Council approval following, pushes stand-alone high-risk systems (Annex III) to 2 December 2027 and AI embedded in regulated products (Annex I) to 2 August 2028. Gibson Dunn’s summary of the agreement is a good plain reading of what changed and what did not.

So the delay is real, but narrow. It buys time on the heaviest compliance regime. It does not touch prohibitions, transparency, or the model-provider rules.

Which targets are actually exposed

Almost none of the companies we audit are general-purpose model providers, so the obligations that grab headlines rarely apply directly. The exposure sits elsewhere, and it clusters.

The obvious bucket is Annex III territory: HR tech that screens candidates, fintech that scores credit, insurance pricing engines, education products that grade or proctor, anything touching biometric identification. These now have until December 2027, which sounds comfortable until you map what compliance requires: a quality management system, technical documentation, logging, human oversight, conformity assessment. That is quarters of work, and it lands inside a fund’s holding period.

The second bucket is Annex I: AI inside products already covered by EU product law, medical devices above all. Their deadline is August 2028, but their certification cycles are long enough that the work starts now.

The third bucket is quieter and more common: companies whose enterprise customers are already writing AI Act compliance into contracts, ahead of any legal obligation. We have seen procurement teams demand high-risk-grade documentation from vendors that are plainly not high-risk. Whether the target can answer those questionnaires without stalling deals is a commercial question as much as a legal one.

And one bucket that gets missed: a target that fine-tunes a foundation model, rebrands it, or substantially modifies a high-risk system can inherit provider obligations it never planned for. The classification is not always where the founders think it is.

The questions to add to your due diligence

We now run these on every European AI deal:

  • Has the target classified its systems under the Act, and can it show the analysis rather than a one-line assertion
  • Which features fall under Annex III, and what is the plan, owner, and budget to comply by December 2027
  • Is anything in the product within reach of a prohibited practice, including features on the roadmap
  • Are the Article 50 duties live in the product today: does the chatbot disclose, is generated content marked
  • Do customer contracts already promise AI Act compliance, and does the product deliver what the contract says
  • Does any fine-tuning or white-labeling make the target a provider in the Act’s sense, with the heavier duties that follow

The pattern of answers matters as much as the content. A team that has done the classification exercise, even roughly, is a team that reads its regulatory environment. A team that answers "our lawyers are looking at it" two years after the Act entered into force is telling you something about how it handles every other obligation, GDPR included. The findings often overlap with the ones we describe in the GDPR gaps that surface after closing, and with training data provenance, because the same discipline produces or fails to produce all three.

How to price the finding

Most AI Act findings are a budget line, not a deal breaker. A classification exercise, documentation, logging, and process work: for a typical Annex III target this is a defined project with a defined cost, and it belongs in the post-close plan with an owner and a deadline comfortably ahead of December 2027.

A minority of findings are severe. A product whose core mechanic sits in prohibited territory, or close enough that a regulator could read it that way. A roadmap that depends on a high-risk use the team has no capacity to certify. Contracts promising compliance the architecture cannot deliver. Those belong in the same category as the structural problems in the red flags that actually matter: they change price or terms, and occasionally the decision.

When we run a technical and AI audit on a European target, AI Act exposure now has its own line in the risk register, ranked by severity next to security and scalability, with a remediation cost attached. That is what a regulation becoming operational looks like from inside a deal.