FISTA Solutions does not load Google Analytics until you accept. Rejecting keeps optional analytics off. Read the Cookie Policy.

All field notes

Leadership · 4 minute read

How to Assess AI in M&A Due Diligence

AI diligence should test what is in production rather than what is claimed, quantify dependence on third-party models, find the liabilities that hide in AI estates, and assess whether the target's advantage is proprietary data and workflow depth or a wrapper around a model anyone can license.

By FISTA Solutions· AI-Native Engineering Team·
How to Assess AI in M&A Due Diligence article cover

Targets now describe themselves as AI-enabled or AI-native, and most of those claims have never been tested by anyone with an incentive to test them. For acquirers, AI diligence has become a distinct workstream: verifying what is real, quantifying dependence, finding the liabilities, and assessing whether the capability is durable. This guide covers each.

What should be verified?

Production reality, not roadmaps. The requests that separate substance from claims:

RequestWhat a strong target providesWhat a weak one provides
Inventory of AI systems, including vendor-embeddedA current list with owners and risk tiers"We are compiling that"
Evaluation evidencePass rates, case counts, dates, thresholdsDemos or assurances
Outcome dataBaseline-to-actual on named processesProjected savings
Model dependenceProviders, contracts, alternatives testedOne provider, no alternative
Incident historyRecords with root cause and remediation"No incidents" with no detection capability
PermissionsPer-agent, least privilege, reviewedShared service accounts

Where feasible, run the target's system on your own test cases. The how executives should evaluate an AI demo guide applies directly: a demo is an optimized input, and diligence should not accept one as evidence.

What liabilities hide in AI estates?

Five recur, and none appears in a standard technology diligence checklist:

  1. Data rights. Was training or input data used with the rights to do so? Customer data used to improve a shared product without consent is a common finding.
  2. Undisclosed AI in customer-facing products, or AI claims in marketing the product cannot support, which carries regulatory exposure in several jurisdictions.
  3. Customer contract commitments: service levels, accuracy claims, or exclusivity terms relating to AI features the target cannot reliably meet.
  4. Regulated automated decisions made without documented human oversight, in employment, credit, insurance, or similar contexts.
  5. Licence breaches: model licences with commercial restrictions, or open-source terms not complied with.

Consult counsel on each; this is general guidance, not legal advice. The general counsel's guide to AI and agentic AI covers the contractual landscape.

How is the capability valued?

By asking what a competitor with the same model access would still lack. Durable sources: proprietary data the product accumulates and uses, deep integrations into customer workflows that create switching costs, process knowledge encoded in specifications and evaluation sets, and an operating record that demonstrates reliability.

Non-durable: a prompt and an interface over a publicly available model, however good the demo. That capability can be reproduced quickly and may be absorbed by the next model release. The AI competitive advantage explained piece covers what compounds.

A useful test in management meetings: ask what happens to the product if the leading model ships their core feature natively next quarter. The quality of the answer is informative.

What about dependence?

Quantify it. Which providers, under what contract terms, with what notice on deprecation and pricing; whether an alternative has been validated; whether the architecture allows switching; and what share of cost of goods sold is model inference. A target whose margins depend on current model pricing, with no alternative and no gateway, carries a risk the acquirer inherits. The how to respond to an AI vendor failure guide covers the exposure.

What should be priced into integration?

Bringing the target's AI estate onto the acquirer's platform and standards: inventory creation, permission remediation, gateway migration, evaluation retrofitting, and governance alignment. If the target has no inventory or evaluation, assume this is substantial. Running two ungoverned estates indefinitely is not a viable option, particularly for regulated acquirers.

How does diligence differ by deal type?

For a technology acquisition where the AI is the product, the weight sits on durability of advantage, data rights, and model dependence, because those determine whether what is being bought survives the next model release. For an operating business where AI is an internal efficiency story, the weight sits on whether the claimed savings are real: baselines, production evidence, and whether freed capacity was actually disposed rather than absorbed. For a regulated target, add documented human oversight of automated decisions and the records a regulator would request. The same checklist applies; the emphasis changes, and applying the technology-acquisition emphasis to an operating business is how acquirers end up paying for efficiency that was never realized.

What should acquirers ask management?

  • What is in production today, with named owners and pass rates?
  • What would a competitor with the same model access still lack?
  • Which model providers are load-bearing, and what are the terms?
  • What data was used to train or tune anything, and under what rights?
  • What AI claims are in your customer contracts and marketing?
  • What was your worst AI incident, and how was it detected?

How can FISTA Solutions help acquirers?

FISTA Solutions runs technical AI diligence: testing targets' systems on independent cases, assessing inventories, permissions, evaluation evidence, and model dependence, and pricing integration onto the acquirer's platform, through its AI enablement practice, and delivers the post-close remediation as production AI agents on a governed stack. Since 2017, FISTA has delivered 150+ projects for 50+ companies across 12+ countries.

To run independent AI diligence on a live deal, talk to FISTA on WhatsApp, or read agentic AI for private equity operating partners.

Share-ready article cover

Download the generated social format.

Download cover

Clear answers

Questions raised by this field note.

Straightforward guidance for evaluating scope, fit, and the next step.

01What should AI due diligence cover?

Production reality versus claims; the inventory of AI systems including vendor-embedded ones; model and vendor dependence with contract terms; data rights for training and inputs; evaluation evidence and incident history; security and permissions; the durability of any claimed advantage; and the integration cost into the acquirer's environment.

02How do you test a target's AI claims?

Ask what is in production with named owners, request evaluation results with pass rates and dates, ask for baseline-to-actual outcome data, and where possible run the system on your own test cases. A target that cannot produce evaluation evidence has pilots described as products.

03What AI liabilities hide in acquisitions?

Rights problems in training data and inputs; AI features shipped to customers without disclosure or with unsupportable claims; customer contracts with AI commitments the target cannot meet; regulated automated decisions without documented oversight; unreviewed data flows to model providers; and open-source or model licence breaches.

04How do you value a target's AI capability?

By what a competitor with the same model access would still lack: proprietary data, integrations into customer workflows, encoded process knowledge in specifications and evaluation sets, switching costs, and an operating record. A product that is a prompt and an interface over a public model has little durable value.

05What integration issues follow an AI acquisition?

The target's agents may run on a stack the acquirer cannot govern: different providers, no inventory, permissive permissions, no evaluation. Budget for bringing them onto the acquirer's platform and standards, and price the effort, because running two ungoverned estates is not an option for long.

Start with the hard problem

Need the outcome owned, not merely analyzed?

Tell us where delivery is constrained. We’ll map the fastest credible path from intent to verified production.

Start a project