Measuring, asserting and maintaining the value of an AI asset under EU regulatory constraint — in M&A, insurance and financing.
An AI Act fine can reach €35M or 7% of global turnover. But the fine isn't the real issue. The real issue: this risk attaches to the asset and survives the transaction — and almost no one can price it today. This white paper explains why, and how to fix it.
Since Regulation (EU) 2024/1689 came into force, an AI system is no longer just a technology asset: it is a regulatory position. Depending on its classification — prohibited practice (Art. 5), high-risk system (Art. 6 and Annex III), or general-purpose model (Art. 51) — it carries distinct obligations and a financial exposure that can be measured.
The key point for anyone buying, insuring or financing: the risk is not resolved at closing. It is attached to the asset itself — to its use, its documentation, its data governance. An acquirer who takes on a non-compliant high-risk system inherits the exposure. An insurer who covers a deal without visibility on that risk underwrites blind.
Let's be precise: the value of an AI asset depends on a thousand factors — its growth, its technology, its team, its market, its IP. The AI Act is only one of them. But it is, today, the only one no one yet scores in a normed, reproducible way — so the only one that gets priced blind. MB AI does not claim to value the asset: it quantifies the regulatory dimension that others can't see, and that adds to all the rest.
The Digital Omnibus (procedure 2025/0359, trilogue agreement in spring 2026) redrew the application timeline. The key dates:
| Deadline | What applies |
|---|---|
| Since Feb. 2025 | Prohibited practices (Art. 5) — unchanged |
| Since Aug. 2025 | General-purpose model obligations — GPAI (Art. 51-55) |
| 2 Aug. 2026 | Transparency & content marking (Art. 50) |
| 2 Dec. 2027 | High-risk systems (Annex III) — deferred by the Omnibus |
| 2 Aug. 2028 | High-risk systems embedded in regulated products (Annex I) |
The deferral of high-risk systems to 2 December 2027 has been read by many as a reprieve. That is an analytical error. Enforcement of the obligations already in force has begun, and the risk itself exists today: a third party — acquirer, insurer, client, competitor — can raise it at any moment in a transaction. The 2026-2027 window is not a respite: it is the moment when a demonstrable compliance position becomes an advantage, before it becomes a mere obligation.
The logic is that of any due diligence: what cannot be demonstrated is treated as a risk, and a risk translates into price. Three concrete channels:
Two risks are often confused and must be distinguished: classification risk (is the asset high-risk, even prohibited? — Art. 5 and 6) and obligations risk (if it is, are the Art. 9-15 requirements met?). The first sets the scope; the second, the cost of remediation.
Faced with this risk, the reflex is to ask for an opinion: from a lawyer, from a consulting firm. Those opinions are useful, but they hit three limits for transactional use.
They are not normed. Two firms produce two readings, in two formats, with no common scale. An acquirer cannot compare two targets. They are not reproducible. The opinion depends on the analyst; it does not replay identically. They are slow and expensive — an in-depth report takes months and hundreds of thousands of euros.
Yet a transaction needs something else: a quantified, comparable and assertable benchmark. The same logic a rating brings to credit — a normed scale that lets you compare, contract, insure. Not one more opinion: a rating.
Assessing the AI Act risk of an asset means covering its whole lifecycle, not just its classification. MB AI's D7™ methodology structures that assessment across seven dimensions, each anchored in public risk-management standards (SR 11-7 on model risk, ISO 31000 on risk, PCAOB AS 2502 and ISA 500 on evidence, Saaty's AHP on weighting) and in the risk grids of leading audit-grade practice, adapted to Regulation 2024/1689.
| Dimension | What it assesses | AI Act articles |
|---|---|---|
| D1 — Regulatory exposure | Classification, probability × impact, exposure to penalties | Art. 5 · 6 · Annex III · 71 |
| D2 — Technical maturity & model risk | Validation, documentation, monitoring, drift | Art. 9 · 11 · 15 |
| D3 — Data governance & quality | Lineage, GDPR, lawful basis, transfers | Art. 10 · GDPR 22/35 |
| D4 — AI governance & controls | Human oversight, bias management, accountability | Art. 14 · 9 |
| D5 — Commercial defensibility | Barriers, IP, switching costs, regulatory moat | — |
| D6 — Financial value adjustability | Weighted haircut, escrow, W&I insurability | — |
| D7 — Operational & key-person risk | Documentation, dependency, continuity | Art. 17 |
Each dimension receives a score and a verdict (green / amber / red), aggregated into a global score and an opinion — supportable, conditional, or not supportable. The relative weighting of the dimensions and the aggregation formula are proprietary; what matters here is the principle: a multi-criteria, normed and reproducible reading that distinguishes what is proven from what is inferred.
A rating only has value if it fits into a transaction. A normed AI Act score feeds the instruments of the deal directly: specific representations & warranties, an escrow calibrated to the identified gaps, a compliance earn-out, and an underwriting file a W&I insurer can use without reprocessing.
But there is a point most players underestimate: AI Act compliance is a state to maintain, not a deliverable acquired once and for all. The law moves — the Digital Omnibus has just shown it. A score set in June does not carry the same weight in December if the framework, the use, or the organisation have changed. The durable value is not in the one-off score: it is in the ability to maintain it over time — re-scan, alert, re-attestation.
Whether you are an acquirer, an insurer, an investor or a director, seven questions are enough to reveal most of the exposure:
A hesitant answer to any of these is not a verdict — it is an area to quantify. That is precisely the role of a rating: to turn uncertainty into measured, therefore negotiable, risk.
The AI Act risk is real, material, and attached to the asset. It is already being priced, quietly, in transactions involving AI systems. The difference between absorbing that discount and mastering it comes down to one thing: the ability to demonstrate your position — through a rating that is normed, assertable, and maintained over time.
The 2026-2027 window is the moment to take that lead, before demonstrable compliance becomes the standard expected of everyone.
The analyses that detail the D7™ method and the valuation gap. Links prepared — articles in progress, coming soon.
This white paper explains the logic. The next step makes it concrete on your case.
Your AI Act compliance — established, then defended over time. Pricing on request.
david.roux@mb-ai.fr · mb-ai.fr