All field guides

AI acquisition diligence

How to verify an AI investment thesis before close.

A transaction-specific AI due diligence framework covering models, data rights, provider concentration, economics, evaluation quality, operations, and governance.

Definition

This guide evaluates AI as an asset, dependency, and operating risk inside an acquisition target. It does not cover using generative AI to automate the diligence process.

01

Translate the AI story into testable claims

AI can matter to revenue, margin, defensibility, customer experience, or operating leverage. Diligence starts by separating those claims and naming the evidence each requires.

Value mechanism

Identify exactly where AI changes the product or economics: an automated workflow, a ranked decision, a generated artifact, or a differentiated data loop. Avoid treating every model-backed feature as one asset.

Benchmark provenance

Inspect what was evaluated, on which data, against which baseline, under which version, and with which acceptance rule. A headline score without representative conditions cannot support the thesis.

Operating evidence

Reconcile offline performance with production usage, human override, failure handling, monitoring, and customer impact. Document where only management assertion is available.

02

Verify models, data, and provider dependence

The asset may sit partly outside the target—in licensed data, hosted models, cloud APIs, and people who know how the system actually behaves.

Model and provider map

Record foundation models, fine-tunes, embeddings, routing, fallback paths, versions, account boundaries, rate limits, contractual dependencies, and the impact of a provider change.

Data rights and lineage

Trace training, retrieval, evaluation, feedback, and customer data to their source, permitted use, retention, and transformation. Separate owned data advantage from access that can be withdrawn.

Inference economics

Rebuild unit economics around real context length, retries, tools, caching, review, failure remediation, and provider price sensitivity—not a single list-price token estimate.

Inspect the sample decision record
03

Diligence the AI system—not only the model

Many operating failures emerge from orchestration, permissions, retrieval, workflow design, and human handoffs rather than model capability in isolation.

Reproducibility and change control

Check whether the team can recreate evaluations, pin model and prompt versions, explain changes, and connect a release to the evidence used to approve it.

Security and abuse paths

Map sensitive tools and data, prompt and retrieval boundaries, identity and authorization, logging, abuse monitoring, and the blast radius of an incorrect or manipulated output.

Human authority

Name who may approve, override, escalate, contain, and roll back consequential behavior. A policy without an operator and exercised path is not an operating control.

04

Carry the result into the transaction

The conclusion should distinguish a damaged thesis from a solvable operating gap and show what must happen next.

Thesis status

State which claims are supported, conditional, unsupported, or unavailable and how each state affects valuation, integration, or the roadmap.

Concentration and portability

Expose reliance on one provider, dataset, employee, integration partner, or undocumented evaluation process before it becomes a post-close surprise.

Post-close evidence plan

Assign the tests, contracts, ownership, monitoring, and specialist reviews that could not be completed in the transaction window.

Sources

Primary references and further reading.