What is AI due diligence in private equity? A pre close workstream that tests a target's AI exposure, readiness, dependency, and data. Does your deal need one?
Published
Last Modified
Topic
AI Diligence
Author
Jill Davis, Content Writer

TLDR: The short answer to what is AI due diligence in private equity is a pre-close workstream that assesses how much of a target's value is exposed to AI, how ready it is to capture that value, how dependent it already is on AI vendors and models, and whether its data can support any of it. It is distinct from technology diligence, which audits the stack, and from cyber diligence, which audits the perimeter. It is becoming standard because the value creation thesis on most enterprise-scale deals now assumes AI-driven margin, and nobody has been checking the assumption.
Best For: AI operating partners, digital and value-creation partners, and value-creation directors at mid-market PE funds whose portfolio companies are enterprise-scale (1,000 to 15,000 employees), who have been asked whether a live deal needs an AI workstream.
AI due diligence in private equity is a pre-signing assessment that measures a target company's exposure to AI, its readiness to use it, its dependency on outside AI providers, and the condition of the data that any AI program would rely on, so that the investment committee can underwrite or discount the AI assumptions in the value creation plan. It sits alongside commercial, financial, technology, and cyber diligence rather than inside any of them. Where technology diligence asks whether the systems work and cyber diligence asks whether they are defended, AI diligence asks a question neither of them was built for: how much of this company's cost base and revenue will be reshaped by AI over the hold period, and is this company in a position to be the one doing the reshaping. This post defines the workstream, marks its boundaries, explains the four lenses it looks through, and gives a scoping rule for when a deal needs it as a standalone line.
What Is AI Due Diligence in Private Equity, and What Is It Not?
AI due diligence in private equity is the workstream that tests the AI assumptions inside a deal thesis before the fund pays for them. It is not technology diligence, which audits the stack as it exists; not cyber diligence, which audits defenses; and not commercial diligence, which sizes the market. Each of those can borrow from AI diligence, but none of them produces its findings.
The confusion is understandable. The four workstreams share sources. They read the same data room, interview the same CTO, and look at the same vendor contracts. The difference is the question each one is trying to answer, and the table below is the cleanest way to keep them apart.
Workstream | Core question | Time horizon | Typical owner | What it says about AI |
|---|---|---|---|---|
Technology diligence | Do the systems work, scale, and carry acceptable technical debt? | As-is, with a 12 to 24 month remediation view | Tech DD provider or fund CTO | Inventories AI tools as part of the stack; rarely tests value or dependency |
Cyber diligence | Is the company defended, and what would a breach cost? | As-is | Cyber specialist | Flags AI tools as attack surface and data-leak risk |
Commercial diligence | Is the market and the company's position in it what management says? | Hold period | Strategy firm or deal team | Notes AI as a market trend; rarely quantifies exposure at workflow level |
AI diligence | How much value is exposed to AI, can this company capture it, and what does it already depend on? | Hold period, workflow by workflow | Operating partner with a specialist | Produces exposure, readiness, dependency, and data findings the IC can underwrite |
The boundary with technology diligence
Technology diligence will tell you the target runs an ERP from 2011 on a hosted server and has three AI tools in use. Useful, as far as it goes. It will not tell you that 40% of the finance team's hours sit in invoice and reconciliation work an AI agent could absorb, or that the AI tool the sales team loves is a thin layer over a model the vendor does not control. AI diligence starts where the inventory ends: it maps the workflows, estimates the labor and error exposure, and tests whether the tools in the inventory are load-bearing.
The boundary with cyber diligence
Cyber diligence treats AI as a threat surface, and it is right to. Stanford's 2026 AI Index reports that 62% of organizations cite security and risk as the primary blocker to scaling AI agents, and that among organizations reporting incidents, the share with three to five incidents rose from 30% to 50% in a year. AI diligence takes the cyber finding as an input and asks the value question the cyber team does not: if this exposure is closed, what can the company then do that it cannot do today.
A short history of how the workstream emerged
Until about 2023, AI questions in diligence were a paragraph in the tech memo, if that. Two things changed. First, general-purpose AI tools spread through target companies faster than anyone could inventory them; MIT's NANDA initiative found in 2025 that workers at more than 90% of companies used personal AI tools for work while only 40% of companies had bought an official subscription. Second, value creation plans started to assume AI-driven margin expansion without a baseline. Deloitte's 2025 survey of 1,000 senior corporate and PE leaders found 86% already using AI inside their M&A workflows and 35% applying it to diligence itself; using AI to do diligence and doing diligence on AI turned out to be different disciplines, and funds noticed when the second one was missing.
Why AI Due Diligence Is Becoming a Standard Workstream
AI due diligence is becoming a standard workstream because the AI assumptions in deal models have outrun the evidence behind them. Funds are underwriting margin expansion from AI at the same time that most companies cannot show a return from it, and investment committees have started asking who checked. The workstream exists to answer that question before close rather than after.
The evidence problem the IC is reacting to
The numbers explain the discomfort. McKinsey's latest State of AI survey found that nearly nine in ten organizations use AI, but only 37% attribute any earnings impact to it and only 6% qualify as high performers. S&P Global found that 42% of companies abandoned most of their AI initiatives in 2025, up from 17% a year earlier, and that the average organization scrapped 46% of its proofs of concept before production. BCG put it at 74% of companies with no tangible value to show. So when a management deck claims AI-driven efficiency, the base rate says the claim is probably unproven. Not wrong, necessarily. Unproven. Diligence is where that gets tested.
The GP side is not much further ahead
Funds are not immune to the same gap. Bain and StepStone's 2026 GP outlook found that 39% of general partners expect AI to have no material financial impact on their portfolio companies in 2026, and that reported outcomes skew toward cost savings rather than growth. EY's PE research found that 84% of PE firms have appointed a chief AI officer, yet 62% acknowledge difficulty linking productivity gains to AI. A workstream that produces a workflow-level baseline at diligence is the fix for both: it gives the operating team a number on day one, and it gives the IC a claim it can hold management to.
The regulatory surface arrived
The third driver is regulation. The EU AI Act carries penalties of up to 7% of global annual turnover for prohibited practices and up to 3% for non-compliance with high-risk obligations, and its obligations attach to deployers as well as developers, which means a portfolio company using an AI tool in hiring, credit, or insurance decisions carries the exposure. Stanford's AI Index reports that concern about regulatory compliance rose from 63% to 72% of organizations in a year, and that only a third reference the NIST AI Risk Management Framework. None of this was on the cyber checklist three years ago. It is on the AI diligence checklist now.
What Is AI Due Diligence in Private Equity Looking For? The 4 Lenses
AI due diligence in private equity looks through four lenses: exposure (how much of the target's cost and revenue AI will reshape), readiness (whether the company can capture that value), dependency (what it already relies on that it does not control), and data (whether the raw material for any AI program exists in usable form). Each lens produces a finding the IC can act on.
The four lenses are kept separate on purpose. A target can score well on one and badly on another, and the combination is what matters. A company with high exposure and low readiness is an operating opportunity priced as a risk. A company with low exposure and high dependency is carrying a cost it cannot control. The lenses are described here at definition level; the scored version is a separate exercise.
1. Exposure: how much of the business AI will reshape
Exposure is the share of the target's operating cost, and of its revenue, that sits in work AI can substantially change over the hold period. On the cost side that means high-frequency, document-heavy back-office and operational workflows: invoice processing, claims handling, order management, customer correspondence, scheduling. On the revenue side it means the products and services whose value a customer could get from an AI tool instead. PwC's 2025 AI Jobs Barometer found productivity growth in the most AI-exposed industries rose from 7% to 27% between the 2018 to 2022 and 2018 to 2024 periods, while the least exposed industries stayed flat at around 9%. Exposure cuts both ways: it is the upside in the value creation plan and the threat in the disruption assessment, and the same lens produces both.
2. Readiness: whether the company can capture the exposed value
Readiness is the target's ability to turn exposure into results, and it is where most management claims fall apart. Cisco's 2025 AI Readiness Index, drawn from 8,000 senior leaders, found that about 13% of organizations qualify as pacesetters, a share that has not moved in three years, and that 64% struggle to centralize their data. Readiness covers process maturity (are workflows defined, or do they live in people's heads), an owner for AI inside the business, and the management team's actual understanding of what they have bought. A useful proxy for readiness is whether the company can produce a baseline: cycle times, touches per item, and exception rates for its three largest workflows. If the data room cannot produce that in a week, readiness is low whatever the deck says. The maturity scoring approach turns this lens into a number; at definition level, the lens is the question.
3. Dependency: what the company already relies on that it does not control
Dependency is the set of AI vendors, models, and embedded features the target already runs on, and the terms under which it runs on them. This is the lens tech diligence most often misses, because a tool that appears in the inventory as one line item can sit under a customer-facing process. Gartner estimates that only about 130 of the thousands of vendors selling agentic AI have real capability, and predicts over 40% of agentic AI projects will be canceled by the end of 2027. Dependency diligence reads the contracts for data rights and termination, checks whether the vendor owns its model or resells someone else's, and asks what happens to the workflow if the tool is switched off. KPMG's Q2 2026 pulse survey found only 26% of leaders have real-time visibility into what their AI costs to run; a target with agents in production and no cost visibility has a dependency it cannot measure.
4. Data: whether the raw material exists
Data is the lens that determines whether any of the other three can be acted on. It asks where the operating data for the exposed workflows lives, whether it is structured enough to feed an AI program, who owns it under the vendor contracts, and whether it can legally be used for the purpose the value creation plan assumes. Deloitte's M&A survey found data quality and availability cited by 65% of respondents as a primary barrier and data security by 67%. The technology stack assessment covers where the data physically sits; the AI diligence data lens asks whether it is fit for the use the thesis needs.
When a Deal Needs a Standalone AI Diligence Workstream: The Scoping Grid
A deal needs a standalone AI diligence workstream when the value creation plan depends on AI-driven margin or when the target already runs AI in a customer-facing or regulated process. Below those thresholds, AI diligence can run as a module inside technology diligence, and below that again, as a desk review. The grid uses five inputs the deal team already has.
The inputs are the share of the value creation plan attributed to AI, the share of the target's operating cost in high-frequency workflows, the presence of AI in customer-facing or regulated decisions, existing AI spend as a share of the technology budget, and the sector's regulatory surface.
Input | Desk review | Module inside tech DD | Standalone workstream |
|---|---|---|---|
AI share of value creation plan | Under 10% of planned EBITDA improvement | 10% to 25% | Over 25%, or the thesis is AI-led |
Operating cost in high-frequency workflows | Under 15% of opex | 15% to 30% | Over 30% (shared services, claims, distribution, healthcare services) |
AI in customer-facing or regulated decisions | None | Internal only, reviewer in the loop | Any customer-facing, credit, hiring, insurance, or clinical use |
Existing AI spend | Negligible | Under 10% of technology budget | Over 10%, or agents in production |
Regulatory surface | Low | Moderate (data privacy only) | High (EU AI Act high-risk category, healthcare, financial services) |
The rule is blunt: if any single input lands in the standalone column, the workstream is standalone. Two or more in the middle column means a module with a named owner and its own section in the memo. Everything else is a desk review with a written conclusion so that the IC record shows the question was asked.
For a platform acquisition or carve-out where the value creation thesis depends on AI-driven margin expansion and the target already runs AI tools inside a customer-facing or regulated process, a generic technology diligence is not enough; the answer is a dedicated AI diligence workstream that does three things: it baselines the specific workflows the thesis relies on with operating data rather than management estimates, it tests vendor and model dependency in the contracts and in the data rights, and it produces an exposure and readiness finding the investment committee can underwrite and hold the management team to after close.
Who runs it
The workstream is owned by the operating partner or value-creation lead, not the tech DD provider, because the findings feed the value creation plan rather than the remediation budget. It borrows the tech and cyber teams' access and a specialist for the workflow mapping. On a two-week timeline it produces a memo section, not a report; a full AI diligence framework is the longer form for deals that justify it.
What it produces
At definition level, AI diligence produces four findings and one recommendation: an exposure view, a readiness view, a dependency view, a data view, and a statement of which AI assumptions in the value creation plan the IC should keep, discount, or remove. What the fund does with those findings in the first 100 days is a different question, and one that belongs to the operating partner's value creation playbook rather than to diligence.
What Skeptics on the Deal Team Get Wrong
The most common objection is that AI diligence is a slide an AI tool could generate in two seconds, and it is wrong because the matrix is the easy part. The operating data behind it has to be pulled from the target's systems and reconciled against what management claims, and no tool does that from a data room index. Three objections come up on nearly every deal.
"I could ask an AI tool to make that matrix in two seconds"
You could, and it would be empty. The grid above is a scoping rule; the finding is the workflow-level baseline that fills it. That baseline comes from the target's ERP, ticketing system, and claims platform, reconciled with management interviews, and it takes people with access and a method about two weeks to produce. The matrix is the last thing produced, not the first. Ask the tool to produce a cycle time for the target's invoice process and see what comes back.
"This is just RPA with a new name, so tech DD covers it"
Some of it is, and the distinction matters for the exposure lens. Scripted automation covers structured, rule-based steps, and a target that has already deployed it has captured that layer. AI changes the exposure calculation because it reaches the unstructured work: documents, correspondence, exceptions, judgment-assisted steps. A tech DD that inventories the RPA bots will not size the remaining exposure, and it is the remaining exposure that the value creation plan is pricing.
"We already run tech and cyber diligence, and adding a workstream slows the deal"
The scoping grid exists for this objection. On most deals the answer is a module or a desk review, which adds days rather than weeks. On the deals where the answer is standalone, the alternative is underwriting an AI assumption nobody checked; IBM's 2025 CEO study found 64% of CEOs admit they invest in some technologies before understanding the value. An IC that has read that number will ask why the fund did the same.
What Comes Next Once the Workstream Is Defined
Once AI diligence is defined and scoped, the next questions are practical: what the checklist contains, how the four lenses are scored, and what a partner-ready output looks like. Those get their own treatments. The definitional work here comes first for a plain reason: a fund that cannot say what AI diligence is, and is not, cannot decide when to pay for it. It will keep discovering AI dependencies and unbaselined assumptions after close, which is the most expensive moment to find them.
This analysis was developed using methodologies and operating experience from Assembly.
Frequently Asked Questions
What is AI due diligence in private equity?
AI due diligence in private equity is a pre-signing workstream that assesses a target's exposure to AI, its readiness to capture that value, its dependency on outside AI vendors and models, and the condition of its data. It tests the AI assumptions in the value creation plan so the investment committee can underwrite, discount, or remove them before close.
How is AI due diligence different from technology due diligence?
Technology diligence audits the stack as it exists; AI diligence tests what AI will do to the business over the hold period. Tech DD inventories AI tools and technical debt. AI DD maps workflows, sizes labor and error exposure, checks whether existing AI tools are load-bearing, and produces exposure, readiness, dependency, and data findings that feed the value creation plan.
How is AI due diligence different from cyber due diligence?
Cyber diligence treats AI as a threat surface; AI diligence treats it as a value and dependency question. Stanford's 2026 AI Index reports 62% of organizations cite security as the main blocker to scaling AI agents. AI diligence takes that cyber finding as an input and asks what the company could do once the exposure is closed.
What are the four lenses of AI due diligence?
The four lenses are exposure, readiness, dependency, and data. Exposure measures how much cost and revenue AI will reshape. Readiness measures whether the company can capture that value. Dependency identifies the AI vendors and models the company already relies on. Data determines whether usable, legally available operating data exists to support any AI program the thesis assumes.
Why is AI due diligence becoming a standard workstream in private equity?
AI due diligence is becoming standard because deal models now assume AI-driven margin while most companies cannot show a return. S&P Global found 42% of companies abandoned most AI initiatives in 2025, up from 17%. Investment committees have started asking who checked the AI assumption, and the workstream answers that question before close.
When does a deal need a standalone AI diligence workstream?
A deal needs a standalone workstream when AI accounts for over 25% of the planned EBITDA improvement, when the target uses AI in customer-facing or regulated decisions, or when agents are already in production. Deals with moderate exposure get a module inside technology diligence. Everything else gets a desk review with a written conclusion for the IC record.
Who should own AI due diligence on a deal?
The operating partner or value-creation lead should own it, not the technology diligence provider. The findings feed the value creation plan rather than the remediation budget, so the owner must be the person accountable for delivering that plan after close. The workstream borrows the tech and cyber teams' access and adds a specialist for workflow mapping.
What does the exposure lens measure in AI due diligence?
Exposure measures the share of a target's operating cost and revenue that sits in work AI can substantially change during the hold period. PwC's 2025 AI Jobs Barometer found productivity growth in the most AI-exposed industries rose from 7% to 27%, while least-exposed industries stayed near 9%. Exposure is both the upside and the disruption risk.
What does the readiness lens look for?
Readiness looks for defined workflows, a named AI owner inside the business, and management's real understanding of what it has deployed. Cisco's 2025 AI Readiness Index found only about 13% of organizations qualify as pacesetters and 64% struggle to centralize data. A quick proxy is whether the company can produce a workflow baseline within a week.
What does the dependency lens check?
Dependency checks which AI vendors, models, and embedded features the target already runs on, and under what contract terms. It reads data rights and termination clauses, confirms whether each vendor owns its model or resells another, and asks what happens to the workflow if a tool is switched off. Gartner estimates only about 130 agentic AI vendors are real.
What does the data lens assess?
The data lens assesses whether operating data for the exposed workflows exists, is structured enough to use, is owned by the target under its vendor contracts, and can legally be used for the purpose the thesis assumes. Deloitte's M&A survey found data quality and availability cited as a primary barrier by 65% of respondents.
How does regulation affect AI due diligence?
Regulation adds a compliance exposure that older checklists never covered. The EU AI Act carries penalties of up to 7% of global turnover for prohibited practices and up to 3% for high-risk non-compliance, and its obligations reach deployers. A portfolio company using AI in hiring, credit, or insurance decisions carries that exposure directly.
How long does AI due diligence take?
AI due diligence typically fits inside the standard two-week confirmatory window. A desk review takes a day or two, a module inside technology diligence takes several days, and a standalone workstream uses most of the two weeks to pull operating data, map the largest workflows, read the AI vendor contracts, and reconcile management claims against the baseline.
Is AI due diligence just a matrix an AI tool could generate?
No, because the finding is the operating data behind the matrix, not the matrix itself. The scoping grid and the four lenses are the structure. The value comes from workflow-level baselines pulled from the target's ERP, ticketing, and claims systems and reconciled against management interviews, which takes people with access and a method about two weeks.
Does technology diligence already cover AI if the target uses RPA?
No, because scripted automation covers structured, rule-based steps while AI reaches the unstructured work that remains. A tech DD that inventories the RPA bots will confirm what has been captured but will not size the remaining exposure in documents, correspondence, exceptions, and judgment-assisted steps, and that remaining exposure is what the value creation plan is pricing.
What does AI due diligence produce for the investment committee?
AI due diligence produces four findings and one recommendation: an exposure view, a readiness view, a dependency view, a data view, and a statement of which AI assumptions in the value creation plan the IC should keep, discount, or remove. On most deals this is a memo section rather than a standalone report, sized to the scoping grid.
Legal
