White paper · MB AI Value Intelligence

The AI Act risk, quantified

Measuring, asserting and maintaining the value of an AI asset under EU regulatory constraint — in M&A, insurance and financing.

MB AI VALUE INTELLIGENCE · 18 JUNE 2026 · EU AI ACT — REGULATION 2024/1689 (consolidated, Digital Omnibus)

An AI Act fine can reach €35M or 7% of global turnover. But the fine isn't the real issue. The real issue: this risk attaches to the asset and survives the transaction — and almost no one can price it today. This white paper explains why, and how to fix it.

01A regulatory liability the market doesn't yet see

Since Regulation (EU) 2024/1689 came into force, an AI system is no longer just a technology asset: it is a regulatory position. Depending on its classification — prohibited practice (Art. 5), high-risk system (Art. 6 and Annex III), or general-purpose model (Art. 51) — it carries distinct obligations and a financial exposure that can be measured.

The key point for anyone buying, insuring or financing: the risk is not resolved at closing. It is attached to the asset itself — to its use, its documentation, its data governance. An acquirer who takes on a non-compliant high-risk system inherits the exposure. An insurer who covers a deal without visibility on that risk underwrites blind.

Let's be precise: the value of an AI asset depends on a thousand factors — its growth, its technology, its team, its market, its IP. The AI Act is only one of them. But it is, today, the only one no one yet scores in a normed, reproducible way — so the only one that gets priced blind. MB AI does not claim to value the asset: it quantifies the regulatory dimension that others can't see, and that adds to all the rest.

The market prices what it can't see: as a discount, as a premium, as a deal that falls through.

02The timeline that changes everything — and the window it opens

The Digital Omnibus (procedure 2025/0359, trilogue agreement in spring 2026) redrew the application timeline. The key dates:

DeadlineWhat applies
Since Feb. 2025Prohibited practices (Art. 5) — unchanged
Since Aug. 2025General-purpose model obligations — GPAI (Art. 51-55)
2 Aug. 2026Transparency & content marking (Art. 50)
2 Dec. 2027High-risk systems (Annex III) — deferred by the Omnibus
2 Aug. 2028High-risk systems embedded in regulated products (Annex I)

The deferral of high-risk systems to 2 December 2027 has been read by many as a reprieve. That is an analytical error. Enforcement of the obligations already in force has begun, and the risk itself exists today: a third party — acquirer, insurer, client, competitor — can raise it at any moment in a transaction. The 2026-2027 window is not a respite: it is the moment when a demonstrable compliance position becomes an advantage, before it becomes a mere obligation.

03Why the risk gets priced — the mechanism

The logic is that of any due diligence: what cannot be demonstrated is treated as a risk, and a risk translates into price. Three concrete channels:

Two risks are often confused and must be distinguished: classification risk (is the asset high-risk, even prohibited? — Art. 5 and 6) and obligations risk (if it is, are the Art. 9-15 requirements met?). The first sets the scope; the second, the cost of remediation.

A point of method. The AI Act does not "cost X%" of value mechanically. It is a recurring factor of discount and friction in transactions involving AI assets — one that materialises all the more when compliance cannot be demonstrated. To quantify it is precisely to take it out of uncertainty.

04The limit of the opinion — why the market needs a rating

Faced with this risk, the reflex is to ask for an opinion: from a lawyer, from a consulting firm. Those opinions are useful, but they hit three limits for transactional use.

They are not normed. Two firms produce two readings, in two formats, with no common scale. An acquirer cannot compare two targets. They are not reproducible. The opinion depends on the analyst; it does not replay identically. They are slow and expensive — an in-depth report takes months and hundreds of thousands of euros.

Yet a transaction needs something else: a quantified, comparable and assertable benchmark. The same logic a rating brings to credit — a normed scale that lets you compare, contract, insure. Not one more opinion: a rating.

A rating, not an opinion: a normed, reproducible, assertable benchmark — one you can compare and write into a contract.

05The risk map — seven dimensions

Assessing the AI Act risk of an asset means covering its whole lifecycle, not just its classification. MB AI's D7™ methodology structures that assessment across seven dimensions, each anchored in public risk-management standards (SR 11-7 on model risk, ISO 31000 on risk, PCAOB AS 2502 and ISA 500 on evidence, Saaty's AHP on weighting) and in the risk grids of leading audit-grade practice, adapted to Regulation 2024/1689.

DimensionWhat it assessesAI Act articles
D1 — Regulatory exposureClassification, probability × impact, exposure to penaltiesArt. 5 · 6 · Annex III · 71
D2 — Technical maturity & model riskValidation, documentation, monitoring, driftArt. 9 · 11 · 15
D3 — Data governance & qualityLineage, GDPR, lawful basis, transfersArt. 10 · GDPR 22/35
D4 — AI governance & controlsHuman oversight, bias management, accountabilityArt. 14 · 9
D5 — Commercial defensibilityBarriers, IP, switching costs, regulatory moat
D6 — Financial value adjustabilityWeighted haircut, escrow, W&I insurability
D7 — Operational & key-person riskDocumentation, dependency, continuityArt. 17

Each dimension receives a score and a verdict (green / amber / red), aggregated into a global score and an opinion — supportable, conditional, or not supportable. The relative weighting of the dimensions and the aggregation formula are proprietary; what matters here is the principle: a multi-criteria, normed and reproducible reading that distinguishes what is proven from what is inferred.

Proven, inferred, absent. A defensible rating distinguishes what rests on documentary proof from what is inferred from sector context. On public data, much is inferred; dataroom access turns inferred into proven — and tightens confidence. Exposed is not non-compliant: a risk visible from the outside may be perfectly covered internally. The point is that a risk that can't be demonstrated doesn't protect you.

06From score to instrument — and why compliance is a state, not a deliverable

A rating only has value if it fits into a transaction. A normed AI Act score feeds the instruments of the deal directly: specific representations & warranties, an escrow calibrated to the identified gaps, a compliance earn-out, and an underwriting file a W&I insurer can use without reprocessing.

But there is a point most players underestimate: AI Act compliance is a state to maintain, not a deliverable acquired once and for all. The law moves — the Digital Omnibus has just shown it. A score set in June does not carry the same weight in December if the framework, the use, or the organisation have changed. The durable value is not in the one-off score: it is in the ability to maintain it over time — re-scan, alert, re-attestation.

Important. A D7™ rating is an assertable expert opinion — the logic of a rating. It is never a regulatory act: the official conformity assessment and CE marking remain the provider's responsibility. MB AI quantifies and documents the risk; your counsel turns it into clauses.

07The right questions to ask about an AI asset

Whether you are an acquirer, an insurer, an investor or a director, seven questions are enough to reveal most of the exposure:

  1. Does the system fall under Annex III (high-risk), and is the company a provider or a deployer?
  2. Has the classification been documented, or merely assumed?
  3. Is there demonstrable technical documentation and a human-oversight framework (Art. 11, 14)?
  4. Does data governance hold up under Art. 10 and the GDPR (lawful basis, DPIA, DPO)?
  5. Is the model validated and monitored, or in production without controls (Art. 15)?
  6. Are these elements provable by documents, or do they rest on the team's word?
  7. Is there a mechanism to maintain compliance over time?

A hesitant answer to any of these is not a verdict — it is an area to quantify. That is precisely the role of a rating: to turn uncertainty into measured, therefore negotiable, risk.

08Conclusion — the window is open

The AI Act risk is real, material, and attached to the asset. It is already being priced, quietly, in transactions involving AI systems. The difference between absorbing that discount and mastering it comes down to one thing: the ability to demonstrate your position — through a rating that is normed, assertable, and maintained over time.

The 2026-2027 window is the moment to take that lead, before demonstrable compliance becomes the standard expected of everyone.

2 Dec. 2027
High-risk deadline (Annex III) — the leadership window
€35M
Maximum fine (or 7% of global turnover)
7
risk dimensions, one score, one verdict

Further readingOn the method and the market

The analyses that detail the D7™ method and the valuation gap. Links prepared — articles in progress, coming soon.

Run your asset through the D7™

This white paper explains the logic. The next step makes it concrete on your case.

Your AI Act compliance — established, then defended over time. Pricing on request.

david.roux@mb-ai.fr · mb-ai.fr
This document is an informational market analysis. It is neither legal advice nor a regulatory act. The official conformity assessment and CE marking remain the responsibility of the system's provider. Fine amounts are those of Regulation (EU) 2024/1689 (Art. 71); the timeline reflects the Digital Omnibus (procedure 2025/0359) as of 18 June 2026.