ChecklistMergers & Acquisitions

Due diligence on AI companies: what to verify before you buy

When a company's value rests on AI, standard technical diligence leaves the expensive questions open: is the model owned or rented, can the data behind it lawfully be used, do the published results hold on data the company has never seen, and what does each customer action cost to serve? This checklist covers those questions in the order buyers need the answers, and shows how findings become price changes and protections.

Reviewed 8 min read

On this page
  1. Classify the target's AI before anything else
  2. Model provider and license checks
  3. Training-data rights and personal data checks
  4. Reproducing performance claims on a buyer-held test set
  5. Inference unit economics: what each customer action costs
  6. Regulatory exposure specific to AI targets
  7. Security, people and intellectual property checks
  8. Red flags that should change the price or the protections
  9. A hypothetical contract-analysis target under test
  10. Questions and answers
  11. Sources

Classify the target's AI before anything else

Most AI companies follow one of three patterns, and each puts value in a different place. Establish which applies from the code, the infrastructure bills and the contracts, not the pitch deck.

QuestionProprietary modelFine-tuned open-weight modelOrchestration over third-party APIs
What the buyer acquiresWeights, training pipeline, data and the team that built themAdapted weights, tuning data and evaluation work on someone else's base modelPrompts, workflows, integrations and customer relationships
Main external dependencyCompute supply and data sourcesThe base model's license termsThe provider's pricing, terms and availability
How hard it is to copyHard if the data and evaluation are uniqueModerate: the base model is public, the tuning data may not beOften easy unless workflow data or distribution are unusual
Where cost exposure sitsTraining and hosting spendHosting, and retraining when the base model changesPer-call fees the target does not control
Evidence to ask forTraining runs, experiment logs, compute invoicesBase model version, license, tuning datasets, evaluationsProvider contracts, usage logs, prompt repositories

Many products mix patterns. Classify each revenue-bearing feature, not the company as a whole.

Model provider and license checks

These items establish whether the business can keep using its models, at a predictable cost, under a new owner.

0 of 7 checked

Training-data rights and personal data checks

Data rights decide whether the model can keep being used and sold. Problems here are costly because the fix can mean retraining.

0 of 6 checked

Reproducing performance claims on a buyer-held test set

Pitch-deck scores are usually measured on data the company chose. A controlled test on data it has never seen tells the buyer far more.

  1. List the claims that carry the valuation

    Record each accuracy, quality or automation claim the business case relies on, with the exact metric and conditions.

    Output
    Claims register
    Owner
    Buyer deal team
  2. Assemble a held-out test set

    Build a sample from the buyer's own data or a fresh source that matches real use, and keep it away from the target until the run.

    Output
    Sealed test set
    Owner
    Buyer data lead
  3. Agree the protocol in writing

    Fix the metric, model version, configuration and pass threshold before anything runs, so the result cannot be argued away.

    Output
    Signed protocol
    Owner
    Both technical leads
  4. Run it under observation

    Execute in a clean room or observed session with logs kept, so nobody tunes the system to the test set mid-run.

    Output
    Run logs and raw outputs
    Owner
    Target engineers, observed by the buyer
  5. Check for contamination

    Look for overlap and near-duplicates between test and training data, and for public benchmarks that leaked into training. Contamination inflates scores.

    Output
    Contamination report
    Owner
    Buyer data lead
  6. Compare against a plain baseline

    Run the same test on a general-purpose model with a sensible prompt. If it comes close, the technical advantage is thinner than claimed.

    Output
    Baseline comparison
    Owner
    Buyer technical lead

Inference unit economics: what each customer action costs

Gross margin in an AI business depends on the cost of one unit of value: a document reviewed, a ticket resolved, a call answered. Ask the target to compute it from production logs: model calls per action, compute or tokens per call, retrieval and storage, and the share of actions retried or escalated to a person.

Then test sensitivity to a provider price rise, to heavy customers growing faster than light ones, and to a forced move to a more capable, more expensive model. A business charging a flat fee per seat while paying per call is exposed to all three. The results belong in the valuation model.

Regulatory exposure specific to AI targets

Sector rules in credit, insurance, health or employment apply on top. Check which obligations apply on the expected closing date.

EU AI Act (Regulation (EU) 2024/1689)

European Union

Applies whenThe target places AI systems or general-purpose models on the EU market, or their outputs are used in the EU1.

  • Establish the target's role for each system: provider, deployer, importer or distributor. A company that substantially modifies a high-risk system or puts its name on one can become its provider.
  • Classify each system as prohibited, high-risk, subject to transparency duties or minimal risk, and check general-purpose model duties if the target trains its own.
  • Ask for the technical documentation and risk-management records that the role and class require.

GDPR (Regulation (EU) 2016/679)

European Union and EEA

Applies whenTraining data, prompts or outputs contain personal data of people in the EU, or the target is established there2.

  • A documented lawful basis for training and for operating the model.
  • Transparency to data subjects and working processes for access, objection and erasure requests.

Security, people and intellectual property checks

0 of 6 checked

Red flags that should change the price or the protections

A proprietary model turns out to be orchestration over a public API

Early signalNo training pipeline in the repositories and no compute spend beyond per-call fees.

MitigationRevalue the business as software and distribution; the AI premium in the price may not hold.

Results were only measured on public benchmarks

Early signalThe target cannot run a test on unseen data before signing.

MitigationRequire a buyer-held test before signing, or tie part of the price to an earn-out with clear quality measures.

Training data of unclear origin

Early signalThe source register has gaps, or datasets arrived with former employees.

MitigationSeek a specific indemnity backed by an escrow or holdback, and a covenant to retrain without the affected data.

Provider terms block a change of control

Early signalThe main model contract allows termination or repricing on a new owner.

MitigationMake provider consent a closing condition, or price in the cost of switching models.

Margin depends on introductory model pricing

Early signalUsage runs on promotional credits that expire soon after closing.

MitigationModel margin at list prices and adjust the valuation, or link deferred consideration to margin.

A hypothetical contract-analysis target under test

Questions and answers

How is diligence on an AI company different from normal technical due diligence?

Technical diligence covers architecture, code quality, scalability, technical debt and engineering talent4. An AI target adds questions those checks miss: whether the model is owned or rented, whether its training data can lawfully be used, whether results hold on unseen data, what each action costs at future model prices, and which AI rules apply.

Can a company built on a third-party model API still be worth buying?

Yes, if you value it for what it owns: workflow design, integrations, usage data, distribution and customer relationships. Then price the dependency by reading the provider contract, testing how much work a switch to another model would take, and modeling margins at list prices rather than introductory ones.

Can AI tools speed up due diligence on an AI company?

They help with reading. ColdAI's use case on AI agents for private equity due diligence describes agents that index a data room and draft a cited red-flag memo. Judgments on this checklist, such as whether a model is defensible or a dataset properly licensed, still need people testing the evidence.

Sources

  1. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) — EUR-Lex · checked 10 October 2026
  2. Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex · checked 10 October 2026
  3. Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models — European Data Protection Board · checked 10 October 2026
  4. Mergers & Acquisitions: technology due diligence and AI and data asset valuation — ColdAI

More in Mergers & Acquisitions

Back to Mergers & Acquisitions

Next step

Send us the AI claims your valuation depends on

Share the target's main performance and technology claims and your timetable. We will reply with the checks that matter most for this target and whether a buyer-held test can fit before signing.

Discuss an AI target