This article was written by our 2026 Summer Associate Sam Florence, a University of Cincinnati College of Law student, and was advised by attorney Lisa Caldemeyer Diedrichs.
Artificial intelligence (AI) is rapidly transforming the way businesses operate. What was once viewed primarily as a tool for technology companies is now embedded throughout a wide range of industries, from manufacturing and logistics to healthcare, financial services, and professional services. As AI becomes increasingly integrated into core business functions, it is also becoming an increasingly important consideration in business acquisitions.
Even when AI is not the primary asset driving a transaction, it can significantly affect a target company’s value and risk profile. Consequently, buyers and sellers alike should ensure that AI-related issues receive appropriate attention during the due diligence process.
Identifying AI Within the Target Company
One of the challenges associated with AI due diligence is that many businesses do not view themselves as “AI companies,” despite their growing reliance on AI-enabled tools. AI may be woven into customer relationship management platforms, human resources systems, logistics software, financial reporting applications, or manufacturing processes. In many cases, these technologies are provided through third-party vendors and have become deeply integrated into daily operations.
Buyers should also be aware of “AI washing,” the practice of overstating or misrepresenting a company’s use, sophistication, or proprietary ownership of AI technologies. AI washing can lead buyers to overvalue a target based on perceived technological capabilities that may be little more than standard software tools, third-party products, or undeveloped AI initiatives.
As a result, buyers should understand not only whether AI is being used by the target company, but also how it is being used and the extent to which the business depends upon it.
Regulatory and Compliance Exposure
The legal framework governing AI continues to evolve. While there is no comprehensive federal law regulating AI, businesses may still face risk under existing laws related to consumer protection, employment, privacy, cybersecurity, and industry-specific regulations.
For example, AI-driven hiring or employee evaluation tools may create potential discrimination concerns if they produce biased outcomes. Likewise, AI systems used in customer-facing applications may give rise to regulatory scrutiny if their outputs are inaccurate, misleading, or insufficiently monitored. A thorough due diligence review should assess not only how AI tools function, but also whether appropriate governance and oversight mechanisms are in place.
Data and Intellectual Property Considerations
A key component of AI due diligence involves understanding the data that supports AI systems and the rights associated with that data. AI applications often rely on substantial amounts of customer, employee, operational, or third-party information. Buyers should evaluate whether the target company has the legal right to collect, use, and store that data, and whether any contractual restrictions apply.
Similarly, due diligence should address ownership and intellectual property issues. AI-generated outputs are generally not copyrightable or patentable, and if the prompts and outputs of the target company contain what otherwise might be protectable as trade secrets, their inclusion in the AI data set jeopardizes that trade secret protection. So, it is very important to understand whether and how the target company is using AI in its operations. Moreover, questions frequently arise regarding whether third-party licenses impose limitations on use, and whether the company’s AI-related assets are adequately protected. Unresolved issues in these areas may diminish the value of the acquired business or create unexpected post-closing liabilities.
Vendor and Contractual Risks
For many businesses, AI capabilities are provided through third-party vendors rather than proprietary technology. Accordingly, a review of key vendor agreements is essential.
Among other considerations, buyers should assess assignability, limitations of liability, indemnification provisions, termination rights, service-level commitments, and restrictions relating to data use. In some cases, a target company may be heavily dependent on a single vendor for critical business functions. If that relationship is subject to unfavorable contractual terms or may not survive a change in ownership, material operational risks can arise following closing.
Post-Closing Liability
AI-related issues involving data rights, vendor relationships, regulatory compliance, or system performance may not emerge until months after a transaction has closed. As a result, transaction documents should be carefully tailored to address those risks.
Representations and warranties concerning data practices, intellectual property, regulatory compliance, and technology systems may be particularly important where AI plays a meaningful role in the target company’s operations.
Looking Ahead
As AI adoption continues to accelerate, AI due diligence is becoming an essential part of assessing and managing transactional risk in the M&A process. While AI may not be the primary focus of a transaction, it can significantly impact valuation, risk allocation, and post-closing integration, particularly for companies in healthcare, financial services, and other highly regulated sectors. Buyers who take the time to understand a target company’s use of AI—and sellers who proactively evaluate and address potential concerns before entering the market—will be better positioned to navigate transactions efficiently and reduce the likelihood of costly post-closing disputes.
