AI Technical Due Diligence
Independent assessment of a target company's AI claims, covering model reality, data rights, unit economics and defensibility.
Describing a company as AI powered costs nothing and is now close to universal. Technical due diligence exists to find out what is behind the claim: whether there is proprietary capability, whether the margins survive at scale, and whether the whole thing depends on three people and one vendor contract.
What we examine
Is the AI real, and is it theirs?
We establish what is actually built versus configured. Wrapping a foundation model in a good interface is a legitimate business, but it is a different asset from proprietary models trained on proprietary data, and it should be valued differently. We look for evidence of genuine technical work: evaluation infrastructure, training or fine tuning pipelines, retrieval architecture, and the engineering around failure handling.
Data rights and provenance
Where did the training data come from, and is there a documented right to use it for this purpose. This is the finding most likely to affect a deal. Models trained on scraped content, on customer data without a clear contractual basis, or on licensed data with restrictive terms carry liability that survives the transaction. We review customer contracts for data use permissions as part of this.
Unit economics at scale
Gross margin on AI products often degrades with usage rather than improving, which is the opposite of the software pattern investors are used to. We model inference cost per customer at current and projected volumes, examine how pricing responds, and identify the point at which margin structure changes. Heavy users of unlimited plans are worth looking at closely.
Dependency and concentration
Which providers is the product built on, what happens if pricing changes or a model is deprecated, how much rework a switch would require, and whether the provider is also a potential competitor. Single provider dependency is common and not automatically disqualifying, but it should be priced.
Defensibility
We assess what would actually be required for a competent team to replicate the product. Proprietary data with a genuine accumulation advantage, workflow integration depth and switching cost tend to be durable. Prompt engineering and model choice are not. This is often the largest gap between the pitch and the finding.
Team and key person risk
How many people genuinely understand the system, how much is documented, and what happens if the two who built it leave within a year of close.
Regulatory exposure
Classification under the EU AI Act and equivalent frameworks in the target's markets, current compliance position, and the cost of closing any gap. For high risk classifications this can be material and is frequently unbudgeted.
What you receive
- A findings report written for an investment committee, with technical detail in an appendix.
- A risk register scored by likelihood and impact, separating deal breakers from post-close work items.
- Flags that bear on valuation or on warranty and indemnity negotiation.
- An estimate of remediation cost and time for each material gap.
- A question list for management, with notes on which answers should be verified rather than accepted.
We report what we find
Our fee does not depend on the deal completing, and we will not soften a material finding to keep a process moving. If the AI claim does not hold up, that appears in the summary rather than in a footnote on page forty.
Who uses this
Private equity and venture investors evaluating a company whose thesis rests on AI capability, corporate acquirers where the target's technology is a primary rationale, and boards assessing a proposed acquisition. It also works in reverse: companies preparing for a raise or a sale sometimes commission the same review on themselves to find and fix problems before a buyer does.
Output
Findings report, risk register, valuation-relevant flags, question list. Delivered in editable formats. Full IP transfers to you on final payment.
FAQ
How much access do you need from the target?
Code repository read access, architecture documentation, model and data lineage, infrastructure cost data, and two to four hours with the technical leadership. Where access is restricted we can work from a narrower base and will state clearly what could not be verified.
Can this run in a competitive process with a short window?
Yes. A two week version covers model reality, data rights, unit economics and key person risk, which are the findings most likely to move a decision. Defensibility and regulatory analysis need the longer engagement to be done properly.
Do you cover the commercial and financial side?
No. We cover technical, data and AI-specific regulatory matters. We work alongside your commercial and financial advisers and will flag where a technical finding has financial implications they should model.
Will you speak to the investment committee?
Yes. Presentation and questions are included. We prepare for the sceptical questions specifically, since those are the ones that matter in that room.
Often paired with
AI Vendor and Model Selection
Structured evaluation of vendors and foundation models, benchmarked against your data rather than public leaderboards.
Read moreAI ROI Analysis and Business Case
A defensible financial model for an AI initiative, built on your numbers, with the assumptions exposed rather than hidden.
Read moreBuild vs Buy Advisory for AI
A structured comparison of building, buying or combining, costed over three years with switching risk priced in.
Read moreIs this the right engagement?
Tell us what you are trying to decide. If a different service fits better, or if you do not need us at all, we will say so.