ChecklistMergers & Acquisitions
Due diligence on AI companies: what to verify before you buy
When a company's value rests on AI, standard technical diligence leaves the expensive questions open: is the model owned or rented, can the data behind it lawfully be used, do the published results hold on data the company has never seen, and what does each customer action cost to serve? This checklist covers those questions in the order buyers need the answers, and shows how findings become price changes and protections.
On this page
- Classify the target's AI before anything else
- Model provider and license checks
- Training-data rights and personal data checks
- Reproducing performance claims on a buyer-held test set
- Inference unit economics: what each customer action costs
- Regulatory exposure specific to AI targets
- Security, people and intellectual property checks
- Red flags that should change the price or the protections
- A hypothetical contract-analysis target under test
- Questions and answers
- Sources
Classify the target's AI before anything else
Most AI companies follow one of three patterns, and each puts value in a different place. Establish which applies from the code, the infrastructure bills and the contracts, not the pitch deck.
| Question | Proprietary model | Fine-tuned open-weight model | Orchestration over third-party APIs |
|---|---|---|---|
| What the buyer acquires | Weights, training pipeline, data and the team that built them | Adapted weights, tuning data and evaluation work on someone else's base model | Prompts, workflows, integrations and customer relationships |
| Main external dependency | Compute supply and data sources | The base model's license terms | The provider's pricing, terms and availability |
| How hard it is to copy | Hard if the data and evaluation are unique | Moderate: the base model is public, the tuning data may not be | Often easy unless workflow data or distribution are unusual |
| Where cost exposure sits | Training and hosting spend | Hosting, and retraining when the base model changes | Per-call fees the target does not control |
| Evidence to ask for | Training runs, experiment logs, compute invoices | Base model version, license, tuning datasets, evaluations | Provider contracts, usage logs, prompt repositories |
Many products mix patterns. Classify each revenue-bearing feature, not the company as a whole.
Model provider and license checks
These items establish whether the business can keep using its models, at a predictable cost, under a new owner.
Training-data rights and personal data checks
Data rights decide whether the model can keep being used and sold. Problems here are costly because the fix can mean retraining.
Reproducing performance claims on a buyer-held test set
Pitch-deck scores are usually measured on data the company chose. A controlled test on data it has never seen tells the buyer far more.
List the claims that carry the valuation
Record each accuracy, quality or automation claim the business case relies on, with the exact metric and conditions.
Assemble a held-out test set
Build a sample from the buyer's own data or a fresh source that matches real use, and keep it away from the target until the run.
Agree the protocol in writing
Fix the metric, model version, configuration and pass threshold before anything runs, so the result cannot be argued away.
Run it under observation
Execute in a clean room or observed session with logs kept, so nobody tunes the system to the test set mid-run.
Check for contamination
Look for overlap and near-duplicates between test and training data, and for public benchmarks that leaked into training. Contamination inflates scores.
Compare against a plain baseline
Run the same test on a general-purpose model with a sensible prompt. If it comes close, the technical advantage is thinner than claimed.
Inference unit economics: what each customer action costs
Gross margin in an AI business depends on the cost of one unit of value: a document reviewed, a ticket resolved, a call answered. Ask the target to compute it from production logs: model calls per action, compute or tokens per call, retrieval and storage, and the share of actions retried or escalated to a person.
Then test sensitivity to a provider price rise, to heavy customers growing faster than light ones, and to a forced move to a more capable, more expensive model. A business charging a flat fee per seat while paying per call is exposed to all three. The results belong in the valuation model.
Regulatory exposure specific to AI targets
Sector rules in credit, insurance, health or employment apply on top. Check which obligations apply on the expected closing date.
EU AI Act (Regulation (EU) 2024/1689)
European UnionApplies whenThe target places AI systems or general-purpose models on the EU market, or their outputs are used in the EU1.
- Establish the target's role for each system: provider, deployer, importer or distributor. A company that substantially modifies a high-risk system or puts its name on one can become its provider.
- Classify each system as prohibited, high-risk, subject to transparency duties or minimal risk, and check general-purpose model duties if the target trains its own.
- Ask for the technical documentation and risk-management records that the role and class require.
GDPR (Regulation (EU) 2016/679)
European Union and EEAApplies whenTraining data, prompts or outputs contain personal data of people in the EU, or the target is established there2.
- A documented lawful basis for training and for operating the model.
- Transparency to data subjects and working processes for access, objection and erasure requests.
Security, people and intellectual property checks
Red flags that should change the price or the protections
A proprietary model turns out to be orchestration over a public API
Early signalNo training pipeline in the repositories and no compute spend beyond per-call fees.
MitigationRevalue the business as software and distribution; the AI premium in the price may not hold.
Results were only measured on public benchmarks
Early signalThe target cannot run a test on unseen data before signing.
MitigationRequire a buyer-held test before signing, or tie part of the price to an earn-out with clear quality measures.
Training data of unclear origin
Early signalThe source register has gaps, or datasets arrived with former employees.
MitigationSeek a specific indemnity backed by an escrow or holdback, and a covenant to retrain without the affected data.
Provider terms block a change of control
Early signalThe main model contract allows termination or repricing on a new owner.
MitigationMake provider consent a closing condition, or price in the cost of switching models.
Margin depends on introductory model pricing
Early signalUsage runs on promotional credits that expire soon after closing.
MitigationModel margin at list prices and adjust the valuation, or link deferred consideration to margin.
A hypothetical contract-analysis target under test
Questions and answers
How is diligence on an AI company different from normal technical due diligence?
Technical diligence covers architecture, code quality, scalability, technical debt and engineering talent4. An AI target adds questions those checks miss: whether the model is owned or rented, whether its training data can lawfully be used, whether results hold on unseen data, what each action costs at future model prices, and which AI rules apply.
Can a company built on a third-party model API still be worth buying?
Yes, if you value it for what it owns: workflow design, integrations, usage data, distribution and customer relationships. Then price the dependency by reading the provider contract, testing how much work a switch to another model would take, and modeling margins at list prices rather than introductory ones.
Can AI tools speed up due diligence on an AI company?
They help with reading. ColdAI's use case on AI agents for private equity due diligence describes agents that index a data room and draft a cited red-flag memo. Judgments on this checklist, such as whether a model is defensible or a dataset properly licensed, still need people testing the evidence.
Sources
- Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) — EUR-Lex · checked 10 October 2026
- Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex · checked 10 October 2026
- Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models — European Data Protection Board · checked 10 October 2026
- Mergers & Acquisitions: technology due diligence and AI and data asset valuation — ColdAI