Leadership · 4 minute read
How to Assess AI in M&A Due Diligence
AI diligence should test what is in production rather than what is claimed, quantify dependence on third-party models, find the liabilities that hide in AI estates, and assess whether the target's advantage is proprietary data and workflow depth or a wrapper around a model anyone can license.
Targets now describe themselves as AI-enabled or AI-native, and most of those claims have never been tested by anyone with an incentive to test them. For acquirers, AI diligence has become a distinct workstream: verifying what is real, quantifying dependence, finding the liabilities, and assessing whether the capability is durable. This guide covers each.
What should be verified?
Production reality, not roadmaps. The requests that separate substance from claims:
| Request | What a strong target provides | What a weak one provides |
|---|---|---|
| Inventory of AI systems, including vendor-embedded | A current list with owners and risk tiers | "We are compiling that" |
| Evaluation evidence | Pass rates, case counts, dates, thresholds | Demos or assurances |
| Outcome data | Baseline-to-actual on named processes | Projected savings |
| Model dependence | Providers, contracts, alternatives tested | One provider, no alternative |
| Incident history | Records with root cause and remediation | "No incidents" with no detection capability |
| Permissions | Per-agent, least privilege, reviewed | Shared service accounts |
Where feasible, run the target's system on your own test cases. The how executives should evaluate an AI demo guide applies directly: a demo is an optimized input, and diligence should not accept one as evidence.
What liabilities hide in AI estates?
Five recur, and none appears in a standard technology diligence checklist:
- Data rights. Was training or input data used with the rights to do so? Customer data used to improve a shared product without consent is a common finding.
- Undisclosed AI in customer-facing products, or AI claims in marketing the product cannot support, which carries regulatory exposure in several jurisdictions.
- Customer contract commitments: service levels, accuracy claims, or exclusivity terms relating to AI features the target cannot reliably meet.
- Regulated automated decisions made without documented human oversight, in employment, credit, insurance, or similar contexts.
- Licence breaches: model licences with commercial restrictions, or open-source terms not complied with.
Consult counsel on each; this is general guidance, not legal advice. The general counsel's guide to AI and agentic AI covers the contractual landscape.
How is the capability valued?
By asking what a competitor with the same model access would still lack. Durable sources: proprietary data the product accumulates and uses, deep integrations into customer workflows that create switching costs, process knowledge encoded in specifications and evaluation sets, and an operating record that demonstrates reliability.
Non-durable: a prompt and an interface over a publicly available model, however good the demo. That capability can be reproduced quickly and may be absorbed by the next model release. The AI competitive advantage explained piece covers what compounds.
A useful test in management meetings: ask what happens to the product if the leading model ships their core feature natively next quarter. The quality of the answer is informative.
What about dependence?
Quantify it. Which providers, under what contract terms, with what notice on deprecation and pricing; whether an alternative has been validated; whether the architecture allows switching; and what share of cost of goods sold is model inference. A target whose margins depend on current model pricing, with no alternative and no gateway, carries a risk the acquirer inherits. The how to respond to an AI vendor failure guide covers the exposure.
What should be priced into integration?
Bringing the target's AI estate onto the acquirer's platform and standards: inventory creation, permission remediation, gateway migration, evaluation retrofitting, and governance alignment. If the target has no inventory or evaluation, assume this is substantial. Running two ungoverned estates indefinitely is not a viable option, particularly for regulated acquirers.
How does diligence differ by deal type?
For a technology acquisition where the AI is the product, the weight sits on durability of advantage, data rights, and model dependence, because those determine whether what is being bought survives the next model release. For an operating business where AI is an internal efficiency story, the weight sits on whether the claimed savings are real: baselines, production evidence, and whether freed capacity was actually disposed rather than absorbed. For a regulated target, add documented human oversight of automated decisions and the records a regulator would request. The same checklist applies; the emphasis changes, and applying the technology-acquisition emphasis to an operating business is how acquirers end up paying for efficiency that was never realized.
What should acquirers ask management?
- What is in production today, with named owners and pass rates?
- What would a competitor with the same model access still lack?
- Which model providers are load-bearing, and what are the terms?
- What data was used to train or tune anything, and under what rights?
- What AI claims are in your customer contracts and marketing?
- What was your worst AI incident, and how was it detected?
How can FISTA Solutions help acquirers?
FISTA Solutions runs technical AI diligence: testing targets' systems on independent cases, assessing inventories, permissions, evaluation evidence, and model dependence, and pricing integration onto the acquirer's platform, through its AI enablement practice, and delivers the post-close remediation as production AI agents on a governed stack. Since 2017, FISTA has delivered 150+ projects for 50+ companies across 12+ countries.
To run independent AI diligence on a live deal, talk to FISTA on WhatsApp, or read agentic AI for private equity operating partners.
Share-ready article cover
Download the generated social format.
Clear answers
Questions raised by this field note.
Straightforward guidance for evaluating scope, fit, and the next step.
01What should AI due diligence cover?
Production reality versus claims; the inventory of AI systems including vendor-embedded ones; model and vendor dependence with contract terms; data rights for training and inputs; evaluation evidence and incident history; security and permissions; the durability of any claimed advantage; and the integration cost into the acquirer's environment.
02How do you test a target's AI claims?
Ask what is in production with named owners, request evaluation results with pass rates and dates, ask for baseline-to-actual outcome data, and where possible run the system on your own test cases. A target that cannot produce evaluation evidence has pilots described as products.
03What AI liabilities hide in acquisitions?
Rights problems in training data and inputs; AI features shipped to customers without disclosure or with unsupportable claims; customer contracts with AI commitments the target cannot meet; regulated automated decisions without documented oversight; unreviewed data flows to model providers; and open-source or model licence breaches.
04How do you value a target's AI capability?
By what a competitor with the same model access would still lack: proprietary data, integrations into customer workflows, encoded process knowledge in specifications and evaluation sets, switching costs, and an operating record. A product that is a prompt and an interface over a public model has little durable value.
05What integration issues follow an AI acquisition?
The target's agents may run on a stack the acquirer cannot govern: different providers, no inventory, permissive permissions, no evaluation. Budget for bringing them onto the acquirer's platform and standards, and price the effort, because running two ungoverned estates is not an option for long.
Continue exploring
Related capabilities
Start with the hard problem
Need the outcome owned, not merely analyzed?
Tell us where delivery is constrained. Weâll map the fastest credible path from intent to verified production.