Article 99 of Regulation (EU) 2024/1689 sets the scale. For a prohibited practice (Article 5), the fine reaches up to 35 million euros or 7% of worldwide turnover, whichever is higher. For a breach of high-risk system obligations: €15M or 3%. For misleading information to authorities: €7.5M or 1%.
A potential fine isn't a debt. It isn't provisioned for until it's notified. So it's absent from the financial statements the buyer reviews in due diligence — even as it sits in the law and attaches to the target's AI system. It's the perfect risk: real, quantifiable, and nowhere in the numbers.
At closing, this exposure changes owners. The acquirer of a non-compliant AI asset inherits the latent fine the way Marriott inherited the Starwood breach. Except here, the scale is known in advance — and it runs into tens of millions.
A sophisticated buyer doesn't leave a quantifiable risk out of the equation. They price it — as a discount, an escrow, a post-closing regulatory indemnity. The question isn't "does this risk exist," but "who has quantified it, and when." The D7™ score establishes the probability of high-risk classification, the level of compliance with Articles 9-15, and the associated Article 99 exposure — before the LOI, so the risk enters the negotiation instead of haunting it afterward.