Insights
The EU AI Act, in Plain English, for Mid-Market Portfolio Companies
July 13, 2026 · AI Governance · PE Value Creation
Sujit Maharana · Operating Partner, Crescent Capital Advisors
The EU AI Act is the first cross-sector AI law anywhere, and it's already in force. Obligations are phasing in on a schedule, not landing all at once, which means most mid-market portfolio companies still have runway to get ahead of it. Few are using that runway. This is what applies, and why it's becoming a deal issue rather than a compliance footnote.
Who's in scope
The mistake most US mid-market companies make is assuming this is a Europe problem. It isn't. The Act applies based on where your AI system's output is used or who it affects, not where your company is incorporated. If you have EU customers, or your systems process data on EU residents, you're in scope, regardless of whether you have a single employee or office on the continent. A Delaware-incorporated SaaS company selling to European customers is squarely covered. That's the line most operators get wrong, and it's worth checking now rather than in a data room.
Four risk tiers, and the tier is everything
The Act classifies AI systems into four tiers, and the tier determines what you have to do:
- Unacceptable risk: banned outright. Social scoring, manipulative AI, certain biometric uses.
- High-risk: the tier that carries real obligations. This covers AI used in hiring and employment decisions, credit and lending, access to essential services, and critical infrastructure, common categories in mid-market software and services businesses.
- Limited risk: transparency duties. Users need to know they're interacting with AI (chatbots, generated content).
- Minimal risk: most day-to-day uses. Internal tools, recommendation features, most productivity AI. Light or no additional obligation.
The work isn't reading the Act cover to cover. It's classifying each AI system you run (by use case rather than by vendor or model) because the tier sets everything that follows. A company that hasn't inventoried its AI systems can't answer this question, and most mid-market companies haven't.
What bites if you're high-risk
For systems that land in the high-risk tier, four obligations do most of the work:
- Risk classification: documented, not assumed.
- Human oversight (Article 14): a person can meaningfully review and override the system's output, not rubber-stamp it.
- Transparency and disclosure (Article 50): users need to know when they're subject to an AI-driven decision.
- Technical documentation: the system's design, data, and testing, recorded well enough to survive an audit.
One more applies regardless of tier, and it's already live: AI literacy (Article 4) has been in force since February 2025, requiring staff who work with AI systems to have a baseline understanding of how they work and what can go wrong. It's the one obligation almost nobody has implemented, and it's also the cheapest to fix.
The timeline is a runway, not a fire drill
Prohibited-use rules and obligations on general-purpose AI models arrived first. The heavier high-risk system requirements phase in later, largely across 2026 into 2027. That gap is deliberate, and it's the opportunity: a portfolio company that starts an inventory and classification exercise now is doing measured work on a normal timeline. A company that waits until the requirements are live is doing crisis remediation under a deadline it didn't choose.
The penalties are real
These are set in law, not projected: up to EUR 35 million or 7% of global annual turnover for prohibited-use violations, and up to EUR 15 million or 3% of global annual turnover for high-risk non-compliance, whichever is higher. For a portfolio company selling into the EU, that's turnover-scaled exposure sitting on the balance sheet whether or not anyone has looked at it yet.
Why this is a deal issue, not just a compliance one
Buyers are starting to ask portfolio companies about AI governance posture directly: what systems exist, how they're classified, whether oversight and documentation exist. That question is showing up earlier in diligence than most sellers expect, and an unprepared answer reads the way an undocumented data breach used to: not disqualifying by itself, but a discount, a delay, or a rep-and-warranty issue. AI Act exposure is becoming an exit-multiple question well before it becomes a regulatory enforcement one. Getting ahead of it (inventory, classification, the basic controls) is materially cheaper than getting caught flat in a diligence room.
This is a briefing, not legal advice. EU AI Act obligations depend on your specific systems, data flows, and use cases. Work through classification and compliance with qualified counsel.
If you want to see where your AI governance posture stands, including EU AI Act exposure as part of the score, the AI Governance Readiness Assessment reads it across five pillars in about fifteen minutes.
Working through a version of this?
A 30-minute working conversation - no deck, no pitch. Bring the situation you're sitting with.