Reuben AI
    Compliance Checklist

    The Private Capital Fund AI Compliance Checklist: EU AI Act August 2026

    A practical guide for fund managers, GPs and family offices preparing for full EU AI Act enforcement.

    Prepared by Reuben AI
    goreuben.com
    For information only. Not legal or compliance advice.
    Reuben Ventures Pty Ltd (t/a Reuben AI).

    Step 1: Establish whether you are in scope

    Most VC, PE, credit and family office firms with European LPs, portfolio companies or operating teams are deployers under Article 3.

    • ☐ The fund places, deploys or uses an AI system inside the EU.
    • ☐ The output of an AI system used by the fund is used inside the EU.
    • ☐ The fund has European LPs, portfolio companies or staff.

    Step 2: Classify every AI system you use

    Map each AI system to one of four risk tiers under Regulation (EU) 2024/1689.

    • ☐ Prohibited under Article 5(1)(a) to (h): manipulative or exploitative techniques, social scoring by public or private actors, untargeted scraping of facial images to build recognition databases, emotion inference in workplace and education (with narrow exceptions), and real-time remote biometric identification in publicly accessible spaces (with narrow law-enforcement exceptions).
    • ☐ High-risk under Annex III: includes biometrics (Annex III(1)), employment and worker management (Annex III(4)), and creditworthiness or credit scoring of natural persons (Annex III(5)(b), with the fraud-detection carve-out).
    • ☐ Limited-risk: chatbots, content generation and other systems carrying transparency duties under Article 50.
    • ☐ Minimal-risk: spam filters, simple recommendation engines.

    Step 3: Build an inventory of AI systems and providers

    • ☐ AI system name, version and provider recorded.
    • ☐ Workflow it informs (sourcing, diligence, IC, monitoring, LP reporting).
    • ☐ Data categories processed.
    • ☐ Risk tier assigned.
    • ☐ Named human owner accountable for the system.

    Step 4: Confirm provider obligations are met

    • ☐ A published summary of training data used.
    • ☐ Compliance with EU copyright law.
    • ☐ Technical documentation that lets you meet your deployer obligations.
    • ☐ A clear position on data residency and customer data isolation.

    Step 5: Implement human oversight on high-risk uses

    • ☐ Named humans designated with authority and competence to override AI outputs.
    • ☐ Documented oversight procedure for each high-risk system.
    • ☐ Training records for the people performing oversight.
    • ☐ Defined escalation path when an output is contested.

    Step 6: Capture decision provenance and audit logs

    Article 12 requires providers to design automatic logging into high-risk AI systems. Article 26(6) requires deployers to retain those logs for a period appropriate to the intended purpose and at least six months, unless other Union or national law applies.

    • ☐ Inputs, prompts and queries logged.
    • ☐ Model and version recorded with each call.
    • ☐ Output captured and linked to the originating workflow.
    • ☐ Human reviewer and final decision recorded.
    • ☐ Logs immutable, time-stamped and retrievable per system.

    Step 7: Run a fundamental rights and bias assessment

    • ☐ Affected persons or groups identified for each high-risk system.
    • ☐ Bias testing on deal screening, founder scoring and credit scoring documented.
    • ☐ Mitigations recorded and reviewed periodically.
    • ☐ Outcomes integrated into IC governance.

    Step 8: Document data governance and residency

    • ☐ Processing locations recorded for each AI system.
    • ☐ Customer data isolated from training data.
    • ☐ Access controls aligned to role and jurisdiction.
    • ☐ Records of processing aligned with GDPR Article 30.

    Step 9: Disclose AI use to LPs, founders and counterparties

    • ☐ LP side letters and DDQ responses updated.
    • ☐ Founder NDAs and engagement letters reflect AI use.
    • ☐ Limited-risk systems disclose to users that they are interacting with AI.
    • ☐ Marketing and pitch materials accurate about AI capabilities.

    Step 10: Establish an AI incident and review process

    • ☐ Incident detection and triage process defined.
    • ☐ Notification path to the relevant national competent authority within Article 73 timeframes.
    • ☐ Board-level AI governance review scheduled at least annually.
    • ☐ Lessons learned fed back into the AI inventory and oversight procedures.

    Key dates

    • 2 February 2025: Prohibitions on unacceptable-risk AI in effect.
    • 2 August 2025: Governance and obligations for general-purpose AI models in effect.
    • 2 August 2026: Full enforcement for high-risk AI systems in financial services.
    • 2 August 2027: Extended transition period ends for AI systems embedded in regulated products.

    How Reuben AI maps to these requirements

    Reuben AI provides decision provenance, structured audit trails, per-fund data isolation and model versioning. The platform gives a fund the operational backbone to meet several EU AI Act obligations as a byproduct of normal use.

    Book a walkthrough at goreuben.com/demo.

    For information only. Not legal or compliance advice. Reuben Ventures Pty Ltd (t/a Reuben AI). © 2026 all rights reserved. goreuben.com