Not long ago, AI due diligence followed much the same path as diligence for any other software company: financials, contracts, IP assignment and security. Those areas remain important, but what has changed is where buyers now begin.
When the intelligence layer is a core part of the asset, diligence often opens on the model itself. What the buyer finds there can begin shaping the valuation conversation before the financial diligence is complete.
The distinction is sharper in 2026 than it was even a year ago. AI represents a growing share of transaction activity, EU rules on general-purpose AI are now enforceable, and potential liabilities tied to training-data provenance can transfer with the asset at close rather than remaining with the seller.
This article examines what buyers assess when diligencing AI companies in the $5 million to $100 million ARR range, and how those findings can affect valuation, deal structure, earnouts, and the representations and warranties a founder is asked to provide. It is not a technical audit. It is the commercial read: where value can be lost and how a prepared seller can protect the multiple.
What does AI due diligence mean in an M&A process?
AI due diligence is the review a buyer conducts of a target company’s artificial intelligence assets, including its models, training data, infrastructure and third-party dependencies. The objective is to determine whether those assets are owned, defensible, compliant and transferable to a new owner.
Now, this term is often used to describe two different things, which is where some founders get confused. The first is due diligence on an AI company, where the models, data and intelligence layer form part of the asset being acquired. That is the focus of this article.
The second is the use of AI tools to conduct due diligence on any company, accelerating parts of the financial, legal, technical or commercial review. The two are frequently conflated, both in industry commentary and in AI-generated answers, but they address different questions.
In the type of diligence covered here, the intelligence layer is a central part of the investment case for an AI-native or AI-material company, even when it is not the only source of value. Findings related to the model, data or underlying dependencies can therefore carry significantly more weight in valuation and deal negotiations than they would in a conventional software transaction. They also interact with the financial, legal, security and commercial issues a buyer will continue to examine.
Founders who want the engineering-level view of the stack can read the technical companion to this piece, the M&A technology due diligence checklist.
What buyers actually examine in an AI company
Buyers usually start evaluating an opportunity through a defined set of questions. Each area below maps to a risk that can affect valuation, deal structure or the buyer’s willingness to proceed.
- Training-data provenance and rights: Where did the data come from? Was it licensed, purchased, generated or collected with the necessary consent? Can the company document its right to use that data for training and commercial purposes? An unclear answer can raise questions about whether the model and its outputs can transfer cleanly at close.
- Model ownership and IP: Are the models proprietary, fine-tuned or primarily built by orchestrating third-party systems? Do the model weights, training processes and related IP transfer with the company? Buyers will also check whether employee and contractor assignments cover the AI assets themselves, rather than only the surrounding software code.
- Third-party model dependency: How dependent is the product on external LLMs, APIs or infrastructure providers? The buyer will assess the company’s exposure to changes in pricing, performance, availability, licensing terms or access that sit outside its control.
- AI Defensibility and proprietary data: What does the company own that a competitor cannot reproduce quickly? That may be a proprietary dataset, a differentiated model, embedded workflows, customer feedback loops or domain-specific expertise. Without one of those advantages, the business may be viewed as an AI wrapper rather than a defensible AI company, particularly where much of the underlying intelligence comes from a third-party model.
- Performance, reliability, and governance: How consistently does the system perform in real-world use? Buyers will examine accuracy, hallucination rates, bias controls, monitoring and escalation procedures, as well as whether governance is already documented and operating rather than still on the roadmap.
- Regulatory and compliance exposure: How is the system classified under the EU AI Act where the company or buyer serves the European market? Buyers will also review the privacy treatment of training and inference data, sector-specific requirements and any gap between the company’s marketing claims and what the technology can substantiate.
- Key-person and talent risk: Does the model, product or roadmap depend on a small number of engineers or researchers? If so, the buyer will want to know whether those individuals are staying after close and how much institutional knowledge exists beyond them.
- Switching and cannibalization risk: Could the customer build or vibe-code an adequate alternative instead of continuing to pay for the product? This has become a live question for acquirers and investors. Vertical AI products embedded in complex workflows or legacy industries may be harder to replace than horizontal tools that a capable customer can recreate using widely available models.
The financials, growth, retention and customer base are still examined in full. AI diligence does not replace that work. It sits alongside it and, for an AI-material company, can shape how the buyer interprets the rest of the business.
How does AI due diligence affect valuation and deal structure?
Most legal and technical diligence checklists explain what a buyer will review, but they rarely address how the findings translate into valuation, purchase-price mechanics and negotiation leverage. In an M&A process, each issue can produce a different consequence at the table.
- Gaps in training-data provenance: These widen the seller’s potential exposure. Buyers may respond with broader indemnities, a larger escrow and specific representations and warranties covering data rights. In more serious cases, they may hold back part of the purchase price against the risk.
- Heavy third-party model dependency: This can compress the multiple. When a buyer concludes that it is acquiring orchestration around someone else’s model rather than a defensible AI asset, it may value the company closer to an AI wrapper than to proprietary software.
- Weak defensibility: This can shift value out of upfront cash and into an earnout tied to retention, revenue or product milestones the buyer can verify after close. The headline valuation may remain unchanged while more of the risk moves back to the seller through the structure.
- Concentrated key-person risk: This often pushes consideration into retention packages, rollover equity or earnouts. When much of the model knowledge and product roadmap sits with a small group of people, the buyer will protect itself by tying part of the economics to their remaining with the business. The result may be less cash for the founder at close, even when the overall headline value holds.
- Unresolved AI Act or privacy exposure: This does not always produce a straightforward valuation discount. It may instead extend the diligence process, introduce remediation requirements or conditions to close, and result in a price adjustment for the compliance costs the buyer expects to assume.
- Cannibalization risk: When a buyer believes the end customer could build its own version, or that a strategic acquirer intends to fold the capability into its own agentic roadmap, it either discounts for the shorter runway or perhaps even walks away from the deal. This is one reason vertical products serving industries that will not rebuild the workflow themselves command steadier interest.
At the negotiating table, these are no longer simply technical or legal findings. They become questions of price, timing, cash at close, contingent consideration and post-closing liability. A prepared seller identifies the issues early, addresses what can be fixed and builds the evidence needed to keep the buyer from pricing uncertainty as risk.
What founders can do before buyers begin due diligence
The diligence list can also be seen as a readiness list. The work below is what a seller controls, and addressing them early can be the difference between findings that support the deal and findings that reopen the valuation discussion.
- Build a data-provenance file: document every training and fine-tuning dataset, its source, and the rights under which it was obtained, before a buyer asks for it.
- Map proprietary versus third-party: a one-page view of the AI stack showing what is owned, what is licensed, and exactly where dependency sits.
- Close IP and assignment gaps: confirm the AI itself, not only the code, is assigned to the company across employees and contractors.
- Get ahead of the rules: know your risk classification under the EU AI Act and be able to show a governance posture rather than promise one.
This is part of the work a sell-side advisor should run before a company goes to market. The objective is not to eliminate every issue, but to identify it early, fix what can be fixed and frame the remaining risks before the buyer does. Done well, diligence confirms the investment thesis instead of weakening it.
Turning AI due diligence into leverage
AI due diligence should not be treated simply as a hurdle to clear. It is the point at which a prepared founder can prove that the asset is real, owned, defensible and transferable, while protecting the valuation in the process.
The findings will surface either way. The advantage lies in identifying them early, addressing what can be fixed and framing the remaining risks before the buyer does.
L40° advises SaaS, AI and technology founders through sell-side processes where the defensibility of the intelligence layer, not only the surrounding code, can materially affect how buyers price risk and structure a deal. To prepare an AI company for diligence before going to market, talk to L40°.

.png)
.jpg)

