Reuben AI
    ← Back to Blog

    The Private Capital Fund AI Compliance Checklist: EU AI Act August 2026

    11 min read·Katriona Lee

    Share with your team

    Download the printable, Reuben AI branded checklist PDF.

    A practical guide for fund managers, GPs and family offices preparing for full EU AI Act enforcement on 2 August 2026.

    The EU AI Act is the first comprehensive horizontal regulation of artificial intelligence anywhere in the world. It applies to providers and deployers of AI systems, and most private capital firms with European LPs, portfolio companies or operating teams will be deployers. The high-risk obligations apply in full from 2 August 2026, which is the date most funds need to plan against.

    This checklist breaks the regulation into ten practical steps. It does not replace legal advice. It is designed to give a fund manager, COO or general counsel a clear view of what to do before the August 2026 deadline, and where to focus first.

    Step 1: Establish whether you are in scope

    Have you confirmed any of the following?

    • ☐ The fund places, deploys or uses an AI system inside the EU.
    • ☐ The output of an AI system used by the fund is used inside the EU.
    • ☐ The fund has European LPs, portfolio companies or staff.

    If any of these is true, the EU AI Act applies. Funds headquartered in the United Kingdom, the United States, the UAE, Singapore or Australia are routinely in scope through their European exposures.

    Step 2: Classify every AI system you use

    For each AI system in your stack, assign it to one of four risk tiers.

    • ☐ Prohibited (social scoring, manipulative systems, untargeted scraping for facial recognition).
    • ☐ High-risk (creditworthiness scoring of natural persons, biometric identification, recruiting tools).
    • ☐ Limited-risk (chatbots, content generation, systems requiring transparency to users).
    • ☐ Minimal-risk (spam filters, simple recommendation engines).

    Most fund-side AI tools fall into limited-risk or minimal-risk. Investment scoring, founder scoring and underwriting models that influence access to capital should be reviewed carefully against the high-risk categories in Annex III.

    Step 3: Build an inventory of AI systems and providers

    A defensible inventory is the foundation for every other obligation.

    • ☐ AI system name, version and provider recorded.
    • ☐ Workflow it informs (sourcing, diligence, IC, monitoring, LP reporting).
    • ☐ Data categories processed.
    • ☐ Risk tier assigned.
    • ☐ Named human owner accountable for the system.

    See how Reuben AI captures decision provenance

    Every AI-assisted decision is logged with inputs, model version, output and human reviewer.

    Book a Walkthrough

    Step 4: Confirm provider obligations are met

    Where you rely on a third-party general-purpose AI model, confirm the provider can demonstrate the following.

    • ☐ A published summary of the training data used.
    • ☐ Compliance with EU copyright law.
    • ☐ Technical documentation that lets you meet your deployer obligations.
    • ☐ A clear position on data residency and customer data isolation.

    Step 5: Implement human oversight on high-risk uses

    • ☐ Named humans designated with authority and competence to override AI outputs.
    • ☐ Documented oversight procedure for each high-risk system.
    • ☐ Training records for the people performing oversight.
    • ☐ A defined escalation path when an output is contested.

    Step 6: Capture decision provenance and audit logs

    Article 19 and Article 26 require automatically generated logs for high-risk AI systems, retained for at least six months and reproducible on request.

    • ☐ Inputs, prompts and queries logged.
    • ☐ Model and version recorded with each call.
    • ☐ Output captured and linked to the originating workflow.
    • ☐ Human reviewer and final decision recorded.
    • ☐ Logs immutable, time-stamped and retrievable per system.

    This is the operational backbone of EU AI Act compliance. Funds without a single source of truth for AI inputs and outputs will struggle to meet the logging requirement. Read more on decision provenance.

    Step 7: Run a fundamental rights and bias assessment

    • ☐ Affected persons or groups identified for each high-risk system.
    • ☐ Bias testing on deal screening, founder scoring and credit scoring documented.
    • ☐ Mitigations recorded and reviewed periodically.
    • ☐ Outcomes integrated into IC governance.

    Step 8: Document data governance and residency

    • ☐ Processing locations recorded for each AI system.
    • ☐ Customer data isolated from training data.
    • ☐ Access controls aligned to role and jurisdiction.
    • ☐ Records of processing aligned with GDPR Article 30.

    Step 9: Disclose AI use to LPs, founders and counterparties

    • ☐ LP side letters and DDQ responses updated.
    • ☐ Founder NDAs and engagement letters reflect AI use.
    • ☐ Limited-risk systems disclose to users that they are interacting with AI.
    • ☐ Marketing and pitch materials accurate about AI capabilities.

    Step 10: Establish an AI incident and review process

    • ☐ Incident detection and triage process defined.
    • ☐ Notification path to the relevant national competent authority within Article 73 timeframes.
    • ☐ Board-level AI governance review scheduled at least annually.
    • ☐ Lessons learned fed back into the AI inventory and oversight procedures.

    Key dates

    • 2 February 2025: Prohibitions on unacceptable-risk AI in effect.
    • 2 August 2025: Governance and obligations for general-purpose AI models in effect.
    • 2 August 2026: Full enforcement for high-risk AI systems in financial services.
    • 2 August 2027: Extended transition period ends for AI systems embedded in regulated products.

    How Reuben AI maps to these requirements

    Reuben AI is built around decision provenance, structured audit trails and per-fund data isolation. The platform does not eliminate the regulatory work, but it gives a fund the operational backbone to meet several EU AI Act obligations as a byproduct of normal use.

    • Decision provenance captures inputs, model version, output and reviewer for every AI-assisted decision.
    • Structured audit logs are retained per workspace and exportable on request.
    • Per-fund data isolation keeps customer data segregated from training data.
    • Model versioning is recorded with every call, supporting reproducibility and incident review.
    • Fund governance workflows formalise human oversight on high-risk uses.

    Frequently asked questions

    Are private capital funds in scope of the EU AI Act?

    Yes. Most funds with European LPs, portfolio companies or operating teams act as deployers of AI systems under Article 3 of the EU AI Act. Even funds headquartered outside the EU are in scope where the output of an AI system is used inside the EU.

    Which fund AI use cases are classified as high-risk?

    Annex III lists creditworthiness assessment of natural persons and biometric identification as high-risk. Investment scoring, founder scoring and underwriting models that materially influence access to capital can fall within these categories and should be assessed accordingly.

    What audit trail does the EU AI Act require?

    Deployers of high-risk AI systems must keep automatically generated logs that capture inputs, model version, output and human review for at least six months under Article 19 and Article 26. Logs must be reproducible on request from a national competent authority.

    What happens on 2 August 2026?

    From 2 August 2026 the high-risk obligations of the EU AI Act apply in full. Funds using AI in scoring, underwriting or biometric workflows must have governance, human oversight, logging and transparency controls in place by that date.

    Do I need to comply if I only use third-party AI tools?

    Yes. Using a third-party AI tool makes you a deployer with your own obligations, including human oversight, transparency to affected persons, logging of use and a fundamental rights impact assessment for high-risk systems.

    What is a fundamental rights impact assessment?

    A fundamental rights impact assessment is a documented review required before deploying a high-risk AI system. It identifies the persons or groups affected, the specific risks to their rights, the mitigations in place and the human oversight arrangements.

    Forward this checklist

    Branded PDF for IC packs, LP updates and internal training.

    Not sure where your fund sits against this checklist?

    Reuben AI's decision provenance and audit trail infrastructure maps directly to these requirements. Book a walkthrough and we'll go through it together.

    Book a Walkthrough

    For information only. Not legal or compliance advice. Reuben Ventures Pty Ltd (t/a Reuben AI).

    Related Articles