Skip to main content
Diligence

AI diligence for private equity deals: how to price the claim

A deal team does not need to decide whether a target's AI is impressive. It needs to know which line of the model the AI claim is holding up, what evidence exists behind it, and what happens to that line if the claim turns out to be half true. Those are three different questions, and they are answered with different documents.

An AI claim is a line in the model before it is a technology question

Technology diligence goes wrong when it is scoped as an assessment of quality. Quality is subjective, unbounded, and impossible to close inside an exclusivity window. Pricing is bounded. Every AI claim a target has made is supporting some specific number in the deal model, and the job is to find out which number, then find out whether the claim can carry it. A finding that never reaches a number has not done any work.

There are three places an AI claim lands. The first is revenue quality, which drives the multiple. If the model output is the reason customers signed and the reason they renew, the AI claim is load-bearing on the comparable set. The second is gross margin, because inference and the human review around it sit inside cost of revenue and do not scale the way software historically has. The third is the risk register, which is where weak diligence puts everything and where nothing gets priced.

Sort the claims before examining any of them. AI as the product means the customer is buying the model's output and would not buy without it. AI as a feature means the product sells for other reasons and the model improves it. AI as internal efficiency touches margin and never touches revenue. AI on the roadmap is an option, not an asset. Deal teams routinely pay product prices for feature claims, and the confusion usually starts in the target's own marketing rather than in anyone's bad faith.

Build a claim inventory before anyone opens the repository

Start with a written list of every sentence the target has published asserting that AI does something. Pull it from the website, the sales deck, the data room summary, RFP and RFI responses, master service agreements, statements of work, and press coverage the company amplified. This takes a day and it structures everything after it, because each sentence becomes a testable proposition and, later, a line on the representations schedule.

It is also an enforcement surface. In March 2024 the SEC settled charges against two investment advisers, Delphia (USA) Inc. and Global Predictions Inc., for statements about their use of AI that the orders found to be false or misleading; the firms paid $400,000 in combined civil penalties, $225,000 and $175,000 respectively. The agency's own term for the conduct was AI washing. That September the FTC announced Operation AI Comply, five law enforcement actions against companies it alleged used AI hype to supercharge deceptive conduct, including a settlement under which DoNotPay agreed to pay $193,000 over claims about a service marketed as a robot lawyer that the complaint said the company had not tested against the standard it advertised.

The penalties are small relative to a mid-market transaction, and that is not the point. The point is that a published claim the engineering cannot support is a durable artifact sitting in the target's own archive, discoverable long after close and attributable to a company the buyer will then own. A claim inventory converts that from an unknown into a schedule.

Below is our editorial weighting of how far each class of finding usually travels. A high value means the finding tends to reach the price or the purchase agreement; a lower value means it more often stops at the risk register and gets managed post-close.

How far an AI diligence finding usually travels

Customer data used for training without a contractual right
94%
Published claim contradicted by what the code does
90%
Gross margin exposed to one model provider's pricing
86%
Review labor inside cost of revenue, not in operating expense
82%
Ownership change that ends an eligibility the forecast assumed
78%
Measurement that will not reproduce outside the target's harness
71%

Editorial weighting from practitioner reading. Illustrative of where findings land, not a measured statistic.

Gross margin is where an AI claim usually breaks

Ask for cost per unit of the thing the customer actually pays for: per document processed, per case resolved, per seat per month, at production volume rather than pilot volume. Then ask for the same figure at three times that volume. If nobody at the target can produce the number, the company has not been managing the cost, which means the margin in the model is an assumption someone typed.

Read the model provider agreement as a supply contract, because that is what it is. What notice applies to a price change. What notice applies to a deprecation. What rate limits are in force and what happens when the target exceeds them. Whether the target sits on committed spend and what the commitment period is. Whether the provider's terms permit the target's data uses, including any use the target has promised its own customers.

Then ask the switching question, which decides whether the provider's price is negotiable at all. Does the target hold an evaluation suite that would catch a quality regression if it moved to a different model? If not, the target cannot change providers safely, and its gross margin is set by a counterparty it has no bargaining power over. That is a structural fact about the business, and it belongs in the model rather than the appendix.

Finally, look for the labor. Review queues, annotation contractors, exception handling, and quality passes are the most common place where revenue described as AI-driven turns out to carry services economics. Ask for headcount and contractor spend mapped to producing the AI output, and ask how those hours moved as volume grew. Flat labor against rising volume is a real system. Labor rising in step with volume is a staffing business with a model attached, and it prices differently.

Data rights can shrink the asset, not just the risk register

Four questions decide whether the model the buyer thinks it is acquiring will still exist after close. What was the model trained on, and under what right. Do the customer contracts permit training on customer data, and do they permit keeping a model derived from that data after termination. What licenses govern any third-party corpora and any model weights in the stack, read at the distribution point rather than from a summary blog post. And what rights in the output has the target already granted its customers.

The test that matters for price is a subtraction. If the three largest customers exercised a deletion right or enforced a no-training term tomorrow, what remains? A target whose advantage rests on a proprietary training corpus assembled under permissive contracts is a different asset from one whose corpus sits on rights that terminate with the customer relationship. Both can be good businesses. They are not the same business, and the difference does not show up in the financial statements.

Federally funded IP carries a clock and a standing license

If any part of the technology was developed under a federal funding agreement, ownership is not the whole answer. Under the standard patent rights clause at 37 CFR 401.14, the contractor may retain title to a subject invention, and the federal government holds "a nonexclusive, nontransferable, irrevocable, paid-up license to practice or have practiced for or on behalf of the United States the subject invention throughout the world." That license does not go away because the company was sold. The same clause carries the march-in provisions at paragraph (j).

The provision that surprises sponsors most often is 35 U.S.C. 204, the preference for United States industry. Neither the contractor nor an assignee may grant anyone the exclusive right to use or sell a subject invention in the United States unless that person agrees the products will be manufactured substantially in the United States. A federal agency may waive it case by case, on a showing that reasonable efforts to license domestic manufacturers failed or that domestic manufacture is not commercially feasible. If the thesis involves an exclusive license to an offshore manufacturing partner, that waiver is a condition precedent, not a post-close formality.

Where the funding came through the small business research programs, the data rights are more specific. DFARS 252.227-7018, as amended by a final rule effective January 17, 2025, defines a protection period that begins on the date of the award under which the data were developed and ends 20 years after that date, unless the agency and the contractor negotiate a different period after award. When the protection period expires, the government holds government purpose rights in that data, and those rights do not expire. So the diligence question is not whether the target has data rights; it is which award each protected component traces to, and how much of the clock is left.

One caution on citations. The FAR case that would have implemented the SBA policy directive's data rights terms government-wide was withdrawn on June 12, 2025, with the Councils stating they would re-evaluate implementation after the broader FAR overhaul. Defense contracts carry the DFARS clause; the government-wide picture is unsettled. Read the clause list in each contract rather than assuming one uniform rule across a portfolio of awards.

Asset deal or stock deal decides whether the federal contracts arrive

This is the structural point that separates a private equity read from a generic technology read, and it is decided in the first week rather than at signing. Under FAR 42.1204(a), 41 U.S.C. 6305 prohibits transferring a government contract from the contractor to a third party. The government may recognize a successor in interest, when it is in the government's interest to do so, where all of the contractor's assets or the entire portion of the assets involved in performing the contract transfer. That recognition is discretionary, and it takes the form of a novation the contracting officer executes.

By contrast, FAR 42.1204(b) says a novation is unnecessary where ownership changes through a stock purchase with no legal change in the contracting party, provided that party keeps control of the assets and continues performing. The consequence of getting this wrong is set out plainly at FAR 42.1204(c): where the government does not concur in a transfer, the original contractor remains under contractual obligation and the contract may be terminated for default.

DimensionAsset purchaseStock purchase
Contract continuityRequires a novation; 41 U.S.C. 6305 bars transfer, and recognition is at the government's discretionNo novation needed where the contracting party is legally unchanged and still performs (FAR 42.1204(b))
Who decidesThe responsible contracting officer, after affected offices are given 30 days to comment or object (FAR 42.1203(b)(3))No approval step, though a formal agreement may still be appropriate for change-of-ownership issues
Conflict-of-interest screenThe contracting officer must identify and evaluate significant organizational conflicts under FAR subpart 9.5Not triggered by the transaction itself; existing conflicts continue to apply to performance
Documents requiredPurchase agreement, affected-contract schedule, board resolutions, counsel opinions, audited balance sheets immediately before and after transfer, evidence security clearance requirements are metOrdinary corporate closing documents; clearance and facility questions still get asked separately
Downside if it failsSeller stays obligated and can be terminated for default; buyer holds assets it cannot bill againstContracts continue, so the exposure moves to eligibility, clearances and performance rather than continuity
Timing effectAdds a discretionary government process after close that no party to the deal controlsAdds nothing to the closing critical path from the contract-transfer side

None of this makes an asset deal the wrong structure. It makes the novation a named workstream with an owner, a document list drawn from FAR 42.1204(e) and (f), and a realistic view that the schedule is not the buyer's to set. Sponsors with adjacent holdings should read FAR 42.1204(d) closely: the conflict screen runs against the proposed successor, which puts the rest of the portfolio in scope.

A diligence finding that stops at the risk register did not do its job. The finding has to reach the price, the structure, or the purchase agreement.

A control buyout can end an eligibility the forecast assumed

Where the target's revenue includes federal research awards, the ownership rules are specific enough to change deal structure, and they are in 13 CFR 121.702. An awardee under the small business innovation research program may be more than 50 percent owned by multiple venture capital operating companies, hedge funds, or private equity firms, but only for agencies that have elected to use the authority in 15 U.S.C. 638(dd)(1). Then comes the sentence that matters most to a sponsor: under 13 CFR 121.702(a)(2), no single venture capital operating company, hedge fund, or private equity firm may own more than 50 percent of the concern, unless that firm itself qualifies as a small business concern more than 50 percent directly owned and controlled by United States citizens or permanent residents. A conventional single-fund control position is the case the rule addresses head on.

Two more provisions compound it. The size test at 13 CFR 121.702(c) counts the awardee together with its affiliates against a 500-employee ceiling. The portfolio-company exception at 13 CFR 121.702(c)(9) protects an awardee from being affiliated with the fund's other holdings only where the fund is a minority investor, and it does not apply where the fund owns a majority of a portfolio company or holds a majority of that company's board seats. Control across a portfolio therefore aggregates headcount against the ceiling. Ownership is calculated on a fully diluted basis under 13 CFR 121.702(d), so option pools and convertibles count.

Procedure matters too. Under 13 CFR 121.705(b), a concern majority owned by multiple funds must be registered with SBA as of the date it submits its initial proposal and must say so in the proposal. Under 13 CFR 121.705(c)(1), a concern that becomes majority fund-owned after submission can still receive the award if the agency makes it on or after the date nine months from the end of the submission period. The companion small business technology transfer program, at 13 CFR 121.702(b), has no fund-ownership route at all.

Why this reaches the valuation rather than a compliance memo: under 15 U.S.C. 638(r)(4)(B), agencies may issue follow-on Phase III awards relating to the technology, including sole source awards, without further justification, to the recipient that developed it. That is a directed path to production revenue, and it is one of the more valuable things a research-funded target owns. If the forecast carries that revenue, the ownership structure is part of the forecast, and a minority or structured position may be worth more than a clean majority.

The EU AI Act is live, and its dates moved once already

If the target sells into the European Union, or its product is used there, timing is now a diligence input rather than a future concern. The AI Act entered into force on 1 August 2024 and became applicable on 2 August 2026, with exceptions. The first set of prohibited practices and the AI literacy obligations applied from 2 February 2025. Obligations for general-purpose AI models and the governance rules applied from 2 August 2025. From 2 August 2026 the AI Office and Member State authorities are responsible for implementing, supervising and enforcing the regulation.

The high-risk dates moved. A simplification package known as the AI Omnibus was proposed on 19 November 2025, reached political agreement on 7 May 2026, and entered into force on 27 July 2026. It set high-risk use cases in areas such as biometrics, critical infrastructure, education, employment, migration and border control to apply from 2 December 2027, and rules for AI integrated into regulated products from 2 August 2028. Anyone pricing this obligation from a memo written in 2025 is pricing the wrong calendar.

ObligationApplies fromDeal relevance
Prohibited practices and AI literacy2 February 2025Already in force; a live exposure, not a future one
General-purpose AI models, governance2 August 2025Applies to targets that train or substantially modify a general-purpose model
General applicability, transparency rules, enforcement2 August 2026Disclosure duties bite now; supervisory authorities are operating
High-risk use cases listed in Annex III2 December 2027Extended by the AI Omnibus; verify against the current text before pricing
High-risk AI embedded in regulated products2 August 2028Reaches targets whose model ships inside someone else's certified product

Article 99 sets the ceilings. Non-compliance with the prohibited practices carries administrative fines of up to EUR 35,000,000 or, for an undertaking, up to 7 percent of total worldwide annual turnover for the preceding financial year, whichever is higher. Breaches of provider, deployer, importer, distributor, notified-body and transparency obligations reach EUR 15,000,000 or 3 percent. Supplying incorrect, incomplete or misleading information to authorities reaches EUR 7,500,000 or 1 percent. For small and medium enterprises, including start-ups, each fine is capped at the lower of the amount or the percentage, which matters when modeling exposure for a target that will stop being an SME the moment a large sponsor consolidates it.

Article 25 is the provision a roll-up should read before the rebrand. A distributor, importer, deployer or other third party is treated as the provider of a high-risk AI system, with the full provider obligations of Article 16, in three circumstances: it puts its name or trademark on a system already placed on the market, without prejudice to contractual arrangements allocating the obligations otherwise; it makes a substantial modification to a system already on the market that remains high-risk; or it modifies the intended purpose of a system, including a general-purpose one, so that the system becomes high-risk. Where that happens, the original provider stops being the provider for that system and owes the new provider cooperation, information and reasonable technical access.

In transaction terms: renaming an acquired product under the platform brand can transfer a regulatory role along with the logo. That is a decision for the integration plan and, before it, for the interim operating covenants between signing and close.

State AI law has not settled, and the framework question is the useful one

Colorado's consumer protections for artificial intelligence, SB 24-205, was signed in 2024 with obligations for developers and deployers of high-risk systems keyed to 1 February 2026. A special-session bill, SB 25B-004, approved on 28 August 2025, extended the effective date to 30 June 2026. Dates in this area have moved more than once and remain capable of moving, so confirm the operative date in each state where the target sells rather than relying on a summary written a quarter ago.

The more durable question sits underneath the dates. Colorado's statute provides an affirmative defense tied to compliance with a nationally or internationally recognized AI risk management framework, and that structure recurs in this area of law. The NIST AI Risk Management Framework 1.0 was released on 26 January 2023, and NIST published a Generative AI Profile, NIST AI 600-1, on 26 July 2024; NIST has said AI RMF 1.0 is being revised under the White House AI Action Plan. A target that has implemented a recognized framework, with artifacts a reviewer can inspect, is worth more than one holding a policy nobody has run. Ask for completed impact assessments and the record of a decision the framework changed.

Key-person risk is a documentation question first

The usual question is whether the people who built the system will stay. The better question is whether the system can be rebuilt without them. Ask the target to retrain the production model from the committed pipeline during the diligence window and show the run: the environment, the data snapshot, and the resulting metrics against what is live. A company that can do that on request has an asset. A company where one person's laptop is load-bearing has a retention problem no employment agreement fully solves, and the gap belongs in the price.

The data-room list for the AI claim

Request these early. Most are one file or one query, and the speed of the response is itself information about how the company is run.

  • The claim inventory, assembled by the buyer, then given to the target for correction rather than for authorship.
  • Evaluation artifacts: the datasets, the split dates, the number of runs, the spread across runs, and the baseline that the headline number was measured against.
  • Unit economics: cost per unit of customer-billed output at current volume and at three times current volume, with inference, storage and review labor separated.
  • Model provider agreements, including committed spend, price-change and deprecation notice terms, rate limits, and permitted data uses.
  • Training data register: every corpus, its source, the right relied on, and any field-of-use or scale conditions in the licenses for third-party weights.
  • Customer contract extracts covering training rights, deletion rights, output ownership, and what survives termination.
  • Federal award schedule with clause lists, award dates, protection-period end dates, and any invention disclosures and elections of title.
  • Ownership table on a fully diluted basis, including option pools and convertibles, with any program registrations attached.
  • Framework artifacts: completed impact assessments, model documentation, incident log, and the record of decisions the risk process changed.
  • A reproducible retraining run executed during the diligence window, with the output compared to production.

Turning findings into deal documents

Price. The most valuable output of an AI diligence read is usually a reclassification rather than a defect. Moving a claim from "the product" to "a feature", or moving review labor from operating expense into cost of revenue, changes the comparable set and the margin profile at the same time. That is a bigger number than most individual issues found in the code.

Structure. Where the claim is plausible but not yet demonstrated, tie consideration to a re-run of a measurement after close, on a protocol agreed before signing. Write the protocol into a schedule: the dataset, the split date, the metric, the number of runs, the acceptance threshold, and who executes it. An earnout tied to a metric defined after close is an argument waiting to happen.

Paper. Reps on training data rights and on the accuracy of published AI claims, with a specific indemnity wherever the claim inventory surfaced an exposure. Then interim operating covenants that hold the position between signing and close: no rebranding of an AI product, no change of model provider, no retraining on data whose permission has changed, no new public claims outside the inventory. The rebranding covenant is not housekeeping. Under Article 25 of the AI Act it can decide which company is the provider.

A workstream that fits a deal calendar

The sequence below assumes a mid-market transaction with exclusivity granted. Durations vary with data-room quality and the target's willingness to run things live, but the ordering is stable, and anything that needs the target to do work should be requested on day one rather than discovered in week three.

AI diligence workstream, counted from the start of exclusivity

1
Claim inventory assembled from public and contractual sources
Days 1 to 3
2
Data-room requests issued, including the retraining run and unit economics
Day 1, answered by day 10
3
Evaluation review and an independent measurement on buyer-selected data
Days 5 to 15
4
Rights review: training data, customer contracts, federal awards, licenses
Days 5 to 18
5
Structure review: transfer mechanics, eligibility, regulatory role after rebrand
Days 10 to 20
6
Findings converted into price adjustments, schedules, covenants and indemnities
Days 18 to 25

What a good answer sounds like

Strong targets answer in protocols. "We measured it on this dataset, drawn on this date, held out before training. Five runs, here is the spread. Here is the baseline and who tuned it. Here are the two customer segments where it underperforms and why. Cost per document at production volume is this, and here is the query that produces it." Weak targets answer in adjectives, demonstrations, and references to the sophistication of the approach. The tell is not missing numbers; it is numbers arriving without the conditions that give them meaning. A team that says "we have not measured that yet, and here is what it would take" is in better shape than one that produces a confident figure and cannot say what it was measured against. Honest gaps price. Confident vagueness does not, which is why it gets discounted hardest.

Bottom line

Price the claim, not the technology. Write down every sentence the target has published about its AI, find which line of the model each sentence supports, and get the evidence that would let a reasonable person believe it. Put review labor where it belongs in the margin. Read the model provider agreement as a supply contract. Trace every rights question to a document rather than a policy page. Where federal money built part of the technology, read the clauses, find the protection-period dates, and remember the government's license does not transfer away. Decide the transfer structure early, because it changes what arrives at close. Then make each finding do work in the price, the structure, or the paper. Diligence that ends in a report changes nothing; diligence that ends in a schedule changes the deal.

Frequently asked questions

How long should AI diligence take on a mid-market deal?

Three to four weeks inside a normal exclusivity period, provided the requests that need the target to do work go out on day one. The two items that set the schedule are an independent measurement on buyer-selected data and a live retraining run from the committed pipeline. Everything else is document review that runs in parallel.

Does an acquisition change a company's eligibility for federal research awards?

It can. Under 13 CFR 121.702(a)(2), no single venture capital operating company, hedge fund, or private equity firm may own more than 50 percent of an awardee unless that firm itself qualifies as a small business more than 50 percent owned and controlled by United States citizens or permanent residents. Majority ownership by multiple such funds is permitted only for agencies that elected the authority in 15 U.S.C. 638(dd)(1). Ownership is measured on a fully diluted basis, and a control position also aggregates portfolio headcount against the 500-employee size ceiling.

Do federal contracts transfer automatically when we buy the company?

Not in an asset deal. FAR 42.1204(a) notes that 41 U.S.C. 6305 prohibits transferring a government contract to a third party, and the government recognizes a successor only when it is in the government's interest, through a novation. In a stock purchase where the contracting party is legally unchanged and continues to perform, FAR 42.1204(b) says a novation is unnecessary. If the government declines to concur in an asset transfer, the seller remains obligated and can be terminated for default.

Does rebranding an acquired AI product create new obligations in the EU?

It can. Article 25 of the AI Act treats a distributor, importer, deployer or other third party as the provider of a high-risk AI system, subject to the provider obligations in Article 16, where it puts its name or trademark on a system already on the market, makes a substantial modification, or changes the intended purpose so the system becomes high-risk. The initial provider then stops being the provider for that system. Address the rebrand in the integration plan and in the interim operating covenants.

What is the fastest signal that an AI claim will not survive diligence?

The target cannot state the cost of producing one unit of the output its customers pay for. That single number sits downstream of infrastructure discipline, evaluation discipline, and honest accounting for review labor, so its absence usually means all three are missing. The second-fastest signal is a headline metric with no stated dataset, split date or baseline.

1 business day response

Pricing an AI claim in a live deal?

We build and assess AI, ML, data, and cloud systems, and we run independent technical reads for deal teams: claim inventory, an independent measurement on your data, unit economics, and a rights review written so it can go straight into a schedule.

Send the data room scopeHow we workMore insights →
UEI Y2JVCZXT9HP5CAGE 1AYQ0NAICS 541512SAM.GOV ACTIVE