EU AI Act high risk obligations are now enforceable. Check your exposure
Insights About us Careers
Contact us
AI Strategy & Consulting

AI Technical Due Diligence

Independent assessment of a target company's AI claims, covering model reality, data rights, unit economics and defensibility.

2 to 4 weeks
Typical duration
Fixed fee
Commercial model

Describing a company as AI powered costs nothing and is now close to universal. Technical due diligence exists to find out what is behind the claim: whether there is proprietary capability, whether the margins survive at scale, and whether the whole thing depends on three people and one vendor contract.

What we examine

Is the AI real, and is it theirs?

We establish what is actually built versus configured. Wrapping a foundation model in a good interface is a legitimate business, but it is a different asset from proprietary models trained on proprietary data, and it should be valued differently. We look for evidence of genuine technical work: evaluation infrastructure, training or fine tuning pipelines, retrieval architecture, and the engineering around failure handling.

Data rights and provenance

Where did the training data come from, and is there a documented right to use it for this purpose. This is the finding most likely to affect a deal. Models trained on scraped content, on customer data without a clear contractual basis, or on licensed data with restrictive terms carry liability that survives the transaction. We review customer contracts for data use permissions as part of this.

Unit economics at scale

Gross margin on AI products often degrades with usage rather than improving, which is the opposite of the software pattern investors are used to. We model inference cost per customer at current and projected volumes, examine how pricing responds, and identify the point at which margin structure changes. Heavy users of unlimited plans are worth looking at closely.

Dependency and concentration

Which providers is the product built on, what happens if pricing changes or a model is deprecated, how much rework a switch would require, and whether the provider is also a potential competitor. Single provider dependency is common and not automatically disqualifying, but it should be priced.

Defensibility

We assess what would actually be required for a competent team to replicate the product. Proprietary data with a genuine accumulation advantage, workflow integration depth and switching cost tend to be durable. Prompt engineering and model choice are not. This is often the largest gap between the pitch and the finding.

Team and key person risk

How many people genuinely understand the system, how much is documented, and what happens if the two who built it leave within a year of close.

Regulatory exposure

Classification under the EU AI Act and equivalent frameworks in the target's markets, current compliance position, and the cost of closing any gap. For high risk classifications this can be material and is frequently unbudgeted.

What you receive

  • A findings report written for an investment committee, with technical detail in an appendix.
  • A risk register scored by likelihood and impact, separating deal breakers from post-close work items.
  • Flags that bear on valuation or on warranty and indemnity negotiation.
  • An estimate of remediation cost and time for each material gap.
  • A question list for management, with notes on which answers should be verified rather than accepted.
Worth knowing

We report what we find

Our fee does not depend on the deal completing, and we will not soften a material finding to keep a process moving. If the AI claim does not hold up, that appears in the summary rather than in a footnote on page forty.

Who uses this

Private equity and venture investors evaluating a company whose thesis rests on AI capability, corporate acquirers where the target's technology is a primary rationale, and boards assessing a proposed acquisition. It also works in reverse: companies preparing for a raise or a sale sometimes commission the same review on themselves to find and fix problems before a buyer does.

What you leave with

Output

Findings report, risk register, valuation-relevant flags, question list. Delivered in editable formats. Full IP transfers to you on final payment.

Questions

FAQ

How much access do you need from the target?

Code repository read access, architecture documentation, model and data lineage, infrastructure cost data, and two to four hours with the technical leadership. Where access is restricted we can work from a narrower base and will state clearly what could not be verified.

Can this run in a competitive process with a short window?

Yes. A two week version covers model reality, data rights, unit economics and key person risk, which are the findings most likely to move a decision. Defensibility and regulatory analysis need the longer engagement to be done properly.

Do you cover the commercial and financial side?

No. We cover technical, data and AI-specific regulatory matters. We work alongside your commercial and financial advisers and will flag where a technical finding has financial implications they should model.

Will you speak to the investment committee?

Yes. Presentation and questions are included. We prepare for the sceptical questions specifically, since those are the ones that matter in that room.

Is this the right engagement?

Tell us what you are trying to decide. If a different service fits better, or if you do not need us at all, we will say so.