AI Due Diligence: The Diligence Workstream Nobody Ran Last Cycle

Technology due diligence has a settled shape: architecture, security, technical debt, key-person risk, the state of the codebase. That shape was set before AI moved from a feature to a foundation. In the last cycle, most diligence treated a target’s machine learning as part of “the product” and moved on. That is no longer safe. A target today may have models in its core product, third-party models in its pipeline, and a roadmap that assumes more of both — and each of those carries risk that standard technology diligence was never designed to surface.

AI due diligence is the workstream that closes that gap. It is not a bolt-on to the security review. It is a distinct assessment with its own questions, and on current deal terms it is the one most likely to change a price or a set of warranties.

The four questions standard diligence misses

What models is the target actually running, and does it know? The first finding in most AI diligence is that the target cannot produce a complete inventory of its own models — built, bought, embedded in a SaaS tool a team adopted without telling anyone. You cannot assess what nobody has listed. An acquirer who accepts “we use AI across the platform” without an inventory is buying an unmeasured exposure.

Free · 4 minutes

When two of your systems disagree, do you know which one to believe?

Fourteen questions on ownership, lineage, and quality — the difference between a number on a dashboard and a number you could defend. Banded finding on screen, full sheet by email.

Where did the training data come from, and can the target prove it? Data provenance is where value and liability both concentrate. Models trained on data the target does not clearly have the rights to use are a latent legal problem that transfers with the deal. Models trained on customer data without a lawful basis are a regulatory one. Neither shows up in a code review; both show up after completion, when they are the buyer’s problem.

How exposed is the target under the EU AI Act — and on what timeline? The Act classifies certain uses as high-risk, and the obligations attaching to them are real even though the timeline has shifted. Under the Digital Omnibus agreed in 2026, the high-risk obligations for stand-alone Annex III systems now apply from 2 December 2027 rather than August 2026 — but the transparency duties under Article 50 remain live from August 2026, and the prohibition on certain generative uses lands in December 2026. A target using AI in recruitment, credit, or another Annex III context carries a classification and a compliance cost that a buyer should understand before signing, not discover after.

Is the AI roadmap a real asset or a stated intention? Much of a target’s valuation may rest on what its AI will do next. Diligence should test whether that roadmap is buildable with the team, data and model access the company actually has — or whether it depends on capabilities, licences or data rights the company does not hold.

Why this changes the deal, not just the report

The reason AI diligence matters commercially is that its findings are the kind that move terms. An unlicensed data dependency is a warranty or an indemnity. An unclassified high-risk system is a post-completion remediation cost that belongs in the price. A model whose performance the target cannot explain or reproduce is an integration risk that affects what the asset is worth on day one. These are not “nice to know” observations for an appendix; they are inputs to the negotiation.

They also protect the buyer after the deal. The obligations under the AI Act, and the data-protection questions underneath the models, do not pause because ownership changed. They become the acquirer’s obligations, on the acquirer’s timeline. Surfacing them during diligence is the difference between pricing a known risk and inheriting an unknown one.

Where it sits in the process

AI due diligence runs alongside technology and legal diligence, not after them, because its findings feed both. It needs someone who can read a model card and a data-processing agreement in the same afternoon — assess how a system is built and what regime it falls under — because the risk lives precisely at that intersection. Standard tech diligence tells you whether the engineering is sound. AI diligence tells you whether the intelligence the business is being valued on is something the buyer can actually own, run and defend.

For acquirers, the practical move is to add it to the diligence scope now, as a named workstream with its own deliverable, rather than hoping the security review catches it. For founders preparing to sell, the same assessment run early is the cheapest way to find and fix the findings that would otherwise cost you at the negotiating table.

Who this is for

This reading is for:

  • PE and corporate acquirers building a diligence scope for 2026 deals
  • Deal partners and investment committees pricing AI risk into a valuation
  • Founders preparing an AI-enabled company for sale
  • Boards approving an acquisition where the target’s product leans on models

Sixteen Pillars runs AI due diligence as a named workstream for acquirers and sell-side founders, covering model inventory, data provenance, AI Act classification and roadmap validation. Pricing is published at /pricing/. If this is live for your organisation and you would like an independent reading, the place to start is a conversation.

Sixteen Pillars is a technology governance consultancy based in Cyprus. Engagements run remote across the EU, UK, and Middle East, with on-site time where the engagement requires it.

Free interactive tool

Interactive deadline calculator

Check which regulations apply to you and when

Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.

Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.

Governance is what happens when nobody is watching.

Policies are easy. Consistent decision-making is harder. Understand where governance exists and where it has quietly become assumed.

Full Governance by Sixteen Pillars

Govern your business. Prove your compliance.

A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.

See what's coming