The European Union's AI Act, alongside existing regulations like GDPR and the increasing emphasis on frameworks like SOC 2, is reshaping how investors and acquirers evaluate a target company's technological health. The declared purpose of the regulation is to "improve the functioning of the internal market and promote the uptake of human-centric and trustworthy artificial intelligence (AI), while ensuring a high level of protection of health, safety, fundamental rights enshrined in the Charter, including democracy, the rule of law and environmental protection, against the harmful effects of AI systems in the Union and supporting innovation". The Act is publicly debated, but I'm not going into the dive into the scope, maintainability, criticality and political debates around it.

To be completely honest here I haven't talked to founders or investors about the AI Act yet, but I decided to dig in and evaluate how it will affect the world of Technical Due Diligence based on its letter and spirit. We'll touch on the critical interplay between security, compliance and AI and how companies can demonstrate readiness in this new era.

The EU AI Act: A New Paradigm for Due Diligence

Risk-based approach

The EU AI Act introduces a risk-based approach to AI regulation. This means that the level of scrutiny and compliance requirements for an AI system will depend on the potential harm it can cause. For investor due diligence this translates into a critical first step: classifying the target company's AI systems according to the Act's risk categories:

  • Unacceptable Risk: AI systems that pose a clear threat to fundamental rights (e.g., social scoring by governments) are banned. Any presence of such systems in a target company might be an immediate deal-breaker.
  • High-Risk AI Systems: These systems are subject to stringent requirements, including robust risk management systems, data governance, technical documentation, human oversight and conformity assessments (e.g.: critical infrastructure, employment, law enforcement, credit scoring). For companies developing or deploying high-risk AI, due diligence will involve a deep dive into their compliance frameworks, testing methodologies and data quality processes. Investors will need to verify that the company has established an AI risk management system, it maintains comprehensive technical documentation and has a clear plan for keeping security, compliance and AI-risk controls alive and verifiable in the long run.
  • Limited Risk AI Systems: These systems have specific transparency obligations (e.g.: chatbots must inform users they are interacting with an AI). Due diligence here would focus on verifying these transparency mechanisms are in place.
  • Minimal or No Risk AI Systems: Most AI systems fall into this category and are subject to voluntary codes of conduct. While less regulated, investors may still look for evidence of responsible AI practices.

Key Due Diligence areas under the EU AI Act

  • Risk Management System: Does the company have a documented and implemented risk management system for its AI applications? This includes identifying, analyzing and evaluating risks, as well as implementing appropriate mitigation measures.
  • Data Governance: Given that AI models are only as good as the data they are trained on, due diligence will heavily scrutinize data governance practices. This includes data quality, data collection methods, bias detection and mitigation and data security.
  • Technical Documentation and Record-Keeping: The Act mandates extensive technical documentation for high-risk AI systems. Due diligence will require reviewing these documents to ensure they are complete, accurate and demonstrate compliance.
  • Human Oversight: For high-risk AI, human oversight is crucial. Due diligence will assess the mechanisms in place to ensure human control and intervention capabilities.
  • Conformity Assessment: High-risk AI systems will require a conformity assessment before being placed on the market. Investors will need to verify that these assessments have been conducted and that the systems meet the required standards.
  • Post-Market Monitoring: The Act requires continuous monitoring of high-risk AI systems once they are in use. Due diligence should examine the company's post-market surveillance plans and incident reporting mechanisms.

The EU AI Act fundamentally shifts the burden of proof onto companies developing and deploying AI. For investors this means a more rigorous and specialized due diligence process is required to identify and quantify regulatory risks, ensuring that the target company is not only innovative but also compliant and future-proof in the evolving AI regulatory landscape in the EU.

GDPR and SOC 2 Readiness: Pillars of Compliance

While the EU AI Act introduces new considerations, existing compliance frameworks like GDPR (General Data Protection Regulation) and SOC 2 (Service Organization Control 2) remain critical pillars of due diligence on compliance. Most of what the AI Act demands already lives inside GDPR and SOC 2. GDPR's data-map and Data Privacy Impact Assessment (DPIA) exercises force you to catalogue every dataset, spell out lawful purpose and assess privacy risk complying with the first half of the AI Act's "data governance and risk-management" chapter. SOC 2 then picks up the baton: its security and change-management criteria require immutable logs, access reviews and incident playbooks, which satisfy the AI Act's call for technical documentation, audit trails and secure development. Even the "human-in-the-loop" clause for high-risk AI mirrors safeguards you must document under GDPR Article 22 and rehearse under SOC 2's incident-response control. In short, if you can already show a clean DPIA, a live data-catalog and six months of SOC-style control evidence, you are roughly 70% of the way to an AI Act conformity file.

In times of diligence or audits this approach pays off fast. You are rearranging chapters, not starting with blank pages. Controls are measured in dashboards your teams consult every week, so regulators and investors see living metrics, not promises. Staff have been through GDPR and security training, making an AI-risk module an incremental, not a green-field, task. Vendor contracts already carry data-processing addendum and security questionnaires, so supply-chain scrutiny is not built from scratch either. And because you have run at least one mock SOC 2 or ISO gap assessment, the organization knows how to gather evidence and close tickets on a deadline. The muscle is trained and that will matter when an AI Act assessor or an acquirer comes calling.

Habits worth adopting

  • Be GDPR compliant by design (If you or your customers are in the EU you must be anyways) and SOC 2 ready even if not being audited for it. This will help a lot in times of diligence.
  • Run an annual AI-focused breach drill. A red-team can inject prompt-injection, data-poisoning and model-exfiltration scenarios. Test your resilience and measure response metrics.
  • Risk-tag every ticket. A custom field "AI Act risk: minimal / limited / high" required at ticket creation. Closing a high-risk ticket could trigger an automated checklist: bias test run, explainability score logged, rollback plan merged.
  • Maintain an AI Act heat-map: A single page listing every feature, model and dataset with its risk tier and the control evidence (test, log, document) that supports it.
  • Run periodical self-audits: The "Govern → Map → Measure → Manage" loop surfaces blind spots before investors do.

Mini-Glossary

  • EU AI Act: A proposed European Union regulation that aims to provide a legal framework for artificial intelligence, categorizing AI systems by risk level.
  • GDPR (General Data Protection Regulation): A comprehensive data protection law in the European Union and European Economic Area, governing how personal data is collected, processed and stored.
  • SOC 2 (Service Organization Control 2): An auditing procedure that ensures service providers securely manage data to protect the interests of their clients and the privacy of their customers.
  • DPIA (Data Protection Impact Assessment): A process designed to help organizations identify and minimize the data protection risks of a project or plan.
  • Automated Decision-Making: Decisions made by technological means without human involvement, particularly when they have legal or similarly significant effects on individuals.
  • Trust Services Criteria (TSC): a set of principles and criteria used in SOC 2 audits to evaluate the controls of a service organization related to information security

Your turn

How are you preparing your organization for the evolving AI regulatory landscape? What challenges have you faced in mapping GDPR, EU AI Act and SOC 2 readiness to your due diligence scope? Share your insights and experiences below.

Founders: Need to assess your compliance posture in the AI era or prepare for tech due diligence? Let's talk.

Investors: Looking to navigate the complexities of AI-related security and compliance risks in your investment targets? Let's talk.

Next in the Playbook

In Edition 9 we'll dive into the topic of Vendor Due Diligence & Third-Party Risk. Stay tuned!

Originally published on the Tech Due Diligence Playbook newsletter on LinkedIn.