You plan to perfom a Tech DD? We are happy to share insighs from our data-driven approach and strong experienced CTOs.
Updated September 2026 to reflect the Digital Omnibus on AI.
The European Union's Artificial Intelligence Act (AI Act) came into force on August 1st, 2024, and was amended in July 2026 by the Digital Omnibus on AI. The regulation promotes the safe and ethical development and use of artificial intelligence while encouraging innovation and safeguarding fundamental rights. The Act categorises AI systems by risk: systems posing unacceptable risk are prohibited since 2 February 2025 (Art. 5). High-risk classification follows Art. 6, via Annex I (safety components) or Annex III (eight listed areas). These systems face extensive compliance requirements from 2 December 2027 (Annex III) and 2 August 2028 (Annex I). Non-compliance incurs substantial penalties, similar to those imposed under GDPR. Already in force for all businesses: risk-classifying their AI systems, supporting AI literacy of staff (Art. 4, since Feb 2025), and transparency duties for chatbots and AI-generated content (Art. 50, since Aug 2026). Although the high-risk obligations have been deferred to 2027/28, it is crucial for companies and investors with EU exposure to familiarise themselves with these regulations to mitigate unplanned cost and delays in their operational timelines.
Amidst ongoing debates about the regulation of AI systems across different global regions, the EU has emerged as one of the first jurisdictions to establish a robust framework for these technologies. Proponents of the regulation laud its focus on promoting ethical development and banning certain types of systems, such as social scoring. However, the regulation has also faced criticism for potentially over-regulating and imposing additional compliance costs. For instance, Vinod Khosla, the former Co-Founder of Sun Microsystems and a notable investor, remarked that “Europeans have regulated themselves out of leading in any technology area.” (see here).
While the long-term social and economic implications for the EU remain speculative, one certainty is that nearly every company within the EU involved in developing, using, or distributing AI will be impacted by the regulation. This article offers ventures and investors a concise summary of the AI Act's key points. It clarifies the scope of affected parties, how the regulation classifies AI systems by risk level, and the resulting obligations for each risk category.
Prior to delving into the different risk classes and their associated obligations, it is crucial to grasp who is affected by the regulation, and how. Contrary to what one might think, the regulation applies not solely to major AI system manufacturers but encompasses all operators within the AI value chain.
- Providers: An organisation that develops an AI system or has an AI system developed with a view to placing it on the market or putting it into service under its own name or trademark, whether for payment or free of charge.
- Deployers: An organisation using an AI system under its authority as part of its professional or commercial activity.
- Importers: An organisation located or established in the EU that places on the EU market an AI system under the name or trademark of a natural person or legal entity established outside the EU.
- Distributors: An organisation in the supply chain, other than the provider or importer, that makes an AI system available in the EU.
Some important notes here are:
- An organisation can either be a natural person or a legal entity utilising AI systems in a professional way
- According to the definition of deployers, organisations that use AI systems in their products are also covered by the regulation
- End-users of products using AI are not affected by the regulation
The AI Act classifies AI according to its risk. The higher the risk, the stricter the rules. All entities listed above will have to classify their AI risk level.
.png)
Most AI systems are most likely to be categorised as minimal risk. These applications, such as games and spam filters, will operate without strict oversight. AI systems that involve interactions with natural persons will be required to meet limited transparency standards to ensure users are aware they are not interacting with human counterparts.
Systems categorised as high risk include those covered by the EU Product Safety Regulation, such as machinery and equipment, electrical and electronic devices, toys, and medical devices, as well as the following use cases outlined in Annex III of the regulation:
- Recognition and classification based on biometric features
- Operation of critical infrastructure
- Education and vocational training
- Labour, personnel management (HRTech), access to self-employment
- Basic provision of public or private services
- Law enforcement
- Migration, asylum, border control
- Administration of justice and democratic processes
Whether a system is high-risk follows Art. 6: it is either a safety component of a product regulated under Annex I or falls into one of eight areas listed in Annex III. These systems will need to adhere to a wide range of regulatory standards and undergo a conformity assessment, in most cases via internal control; for certain systems (e.g. biometrics, Annex I products) a notified body is required.
Most of the regulation addresses providers and deployers of high-risk AI systems. Importers and distributors are primarily responsible for ensuring that the high-risk AI systems they import or distribute are compliant.
High-risk AI providers must register with the EU AI database (Art. 71) by the applicable deadline (2 December 2027 for standalone Annex III systems), conduct a conformity assessment, and retrieve certification evidence to demonstrate compliance with EU regulations. In order to be compliant, providers must fulfil a range of obligations, including the establishment of a risk management system and providing technical documentation.

An adjusted rule set has been defined for high-risk AI deployers, which includes the requirement to control input data and monitor operations. Added obligations for GPAI model providers include monitoring, recording, and disclosing the actual or estimated energy consumption of the model.
The AI Act establishes substantial penalties for businesses that fail to comply, mirroring the GDPR's approach to enforcement.
- Businesses found to be in breach of regulations regarding prohibited AI systems may face penalties of up to EUR 35 million, or 7% of their global annual turnover.
- Failure to comply with regulations for operators of AI systems in any other category may lead to fines of up to EUR 15 million, or 3% of the company's worldwide annual revenue.
- Providing incorrect, incomplete, or misleading information to notified bodies or national competent authorities in response to a request may result in administrative fines of up to EUR 7.5 million or 1% of the total worldwide annual turnover.
The EU Council approved the AI Act in May 2024. The prohibitions on unacceptable-risk AI systems (Art. 5) apply since 2 February 2025. In July 2026 the Digital Omnibus on AI (Regulation (EU) 2026/1744) amended the AI Act: the high-risk obligations were deferred, with standalone Annex III systems now applying from 2 December 2027 and AI embedded in Annex I products from 2 August 2028. The Art. 50 transparency duties for chatbots and AI-generated content were not deferred and apply since 2 August 2026. Systems already placed on the market before the new dates remain largely exempt unless substantially modified.

A 2021 study conducted by the EU estimated that the annual compliance costs for each AI model classified as high-risk will be approximately €52,000. This total comprises €29,000 for internal compliance requirements, such as additional documentation and human oversight, along with €23,000 for external auditing costs pertaining to mandatory conformity assessments. However, the actual costs are likely to be higher, as the assumed hourly rate of €32 is notably low for data engineers and data scientists operating within the EU.
On the other hand, regulated companies can gain a competitive advantage by marketing their ethical AI practices, attracting clients prioritising responsible AI use and data protection. Certification can further instil trust in clients, demonstrating the company's commitment to security and sustainability.
What does the EU AI Act mean for M&A due diligence?
For any acquisition or investment involving an AI component, EU AI Act compliance is now a mandatory diligence item - not an afterthought. Specifically:
- Risk classification of the target's AI systems must be assessed during Tech DD. A system that qualifies as high-risk adds €50k+ in annual compliance costs and requires external auditing.
- Unresolved compliance gaps in a high-risk system can block product launches or trigger fines post-close - material risks that affect valuation.
- GPAI model providers (companies building on top of foundation models like GPT or Claude for commercial use) have additional disclosure and monitoring obligations since August 2025.
TechMiners includes EU AI Act risk classification as a standard component of technology due diligence for any AI-enabled target.
The EU AI Act establishes a regulatory framework that offers long-term predictability for AI-focused investments in the European Union market. It is designed to establish a secure environment for AI development, offering SMEs a clear legal framework for long-term planning and business stability. This is particularly important as similar regulations are being developed in various other regions, but their final implications remain uncertain.
For existing portfolio companies, we recommend two key actions:
- Evaluate current AI usage and determine risk classifications as per the EU AI Act.
- Incorporate anticipated regulatory and compliance costs into business plans.
For upcoming investments:
- Include EU AI Act compliance in legal and tech due diligence, similar to current GDPR practices.
- Evaluate ventures' existing processes and best practices to gauge the complexity of achieving compliance. Focus on MLOps, cybersecurity, and ethical standards to determine if minor adjustments suffice or if major restructuring is necessary.
The provisions prohibiting unacceptable-risk AI systems have applied since 2 February 2025. As an EU regulation, the AI Act applies directly in all member states without national transposition; member states designate competent authorities and set penalty rules.
The transition period until 2027/28 may appear substantial, but AI companies and investors should initiate preparations promptly, particularly given that conformity assessments, technical documentation, and quality management systems typically require 12-24 months to implement. Entities falling under the scope of the regulation should begin optimising their processes, including implementing MLOps best practices, enhancing documentation protocols, and strengthening cybersecurity measures.
Investors are advised to engage proactively with their portfolio companies to forecast and assess future regulatory compliance costs. For prospective investments, selecting a Product and Technology Due Diligence provider capable of evaluating the potential implications of AI regulations is paramount. TechMiners is closely monitoring these developments to ensure comprehensive risk identification in our projects and to provide forward-looking strategic recommendations to our clients.
Talk to a TechMiners expert
Get a no-obligation assessment of your deal.







%20(1).png)



