AI Due Diligence: When artificial intelligence becomes the object of business due diligence activities

Insights
AI Due Diligence: When artificial intelligence becomes the object of business due diligence activities
Posted on: 17/07/2026

    For decades, investment deals and corporate acquisitions (M&A) have almost always followed a familiar formula. The buyer conducts financial due diligence to assess profitability, tax due diligence to identify potential financial obligations, and legal due diligence to review risks related to contracts, assets, labor and disputes. The results of these three processes are the basis for determining the value of the business as well as deciding whether to continue trading or not.

     

    It's worth noting that the majority of AI risks are beyond the scope of traditional due diligence processes.

     

    M&A transaction due diligence is different today

    For example, an investment fund is considering buying a 35% stake in a startup that provides an AI platform for the healthcare sector. The financial statements show strong revenue growth, complete legal documents, the business has no significant disputes and tax obligations are fulfilled in accordance with regulations. According to traditional due diligence standards, this can be seen as an attractive investment.

    However, it was only after signing the transaction that the investor discovered that the AI model was trained from medical data that had not been fully licensed, that the algorithm regularly produced false results in several patient groups, and that the entire system depended on the AI platform of a foreign provider that the business had no control over. These risks do not appear in financial statements, nor are they reflected in traditional legal documents, but can significantly reduce the value of the business, leading to the risk of sanctions, litigation, or the need to restructure the entire product.

    That is also the reason why AI Due Diligence (appraisal of artificial intelligence applications) is emerging as a new due diligence content in many international investment transactions. If legal due diligence used to become an almost mandatory condition of all M&A deals, AI Due Diligence is gradually being considered a "fourth layer of due diligence", complementing traditional processes to assess risks arising from data, AI models, and artificial intelligence governance mechanisms.

    This change reflects the fact that AI is no longer a mere support software but has become a strategic asset of the business. The value of many technology businesses, financial institutions, hospitals, e-commerce platforms, or logistics companies today lies not only in customers, brands, or patents, but also in training datasets, AI models, predictive algorithms, and the ability to harness data to create a competitive advantage. As these assets increasingly determine the value of a business, they also need to be appraised just like any other material asset.

    It's worth noting that the majority of AI risks are beyond the scope of traditional due diligence processes. A team of lawyers can review hundreds of contracts but still don't know where the AI model's training data is collected from. A financial professional can accurately assess profitability but cannot determine the "hallucination" rate[1] of the language model. A tax professional can fully identify financial obligations, but it is difficult to assess the risk of AI systems being attacked by prompt injection[2] or data poisoning[3]. It is this gap that creates the need for an entirely new method of due diligence.

     

    Unlike legal due diligence, which focuses on the legitimacy of the business, AI Due Diligence directs attention to the entire life cycle of the AI system.

     

    AI Due Diligence – What does it do, specifically?

    Unlike legal due diligence, which focuses on the legitimacy of the business, AI Due Diligence directs attention to the entire life cycle of the AI system. This process begins with evaluating the AI governance mechanism in the enterprise: whether AI is managed according to a clear internal policy, who is responsible for AI-powered decisions, and whether humans have the right to intervene in critical cases. This is followed by a review of the origin of data, a determinant of the quality of all AI models, to determine the right to use the data, the legality of the collection process, the level of representation of the data as well as the ability to comply with regulations on the protection of personal data.

    After the data is the AI model. It is no longer enough to know the model works correctly under ideal conditions; Investors need to know whether the model is biased, how capable it is to interpret the results, what the rate at which misinformation is generated, and whether the system can remain effective when the input data changes. At the same time, cybersecurity factors such as resistance to prompt injection, model extraction,[4] or data poisoning also become part of the evaluation process. For many businesses, these are risks that have a direct impact on the commercial value of AI products.

    Another issue that is getting more and more attention is the dependence on AI providers. Many businesses are now building products based on platform models or third-party cloud computing services. This approach reduces development costs but also creates risks in terms of data ownership, vendor switchability, cost fluctuations, and business continuity. In some trades, it is these risks that can influence investment decisions more than traditional financial indices.

    International practice shows that these are no longer academic assumptions. Amazon once had to cancel its AI system to assist in recruiting after discovering that the model tended to underestimate female candidates due to learning from biased historical data[5]. The lawsuit between Thomson Reuters and Ross Intelligence sets a remarkable precedent when the court determined that the use of copyrighted data to train AI could lead to intellectual property liability[6]. In the medical field, the collaborative project between Royal Free Hospital and Google DeepMind[7] also shows that the improper processing of personal data can become a major risk for the entire AI project. These cases all have one thing in common: the damage does not stem from the AI technology itself, but from the risks associated with AI not being fully identified and controlled in the first place.

    This trend will become even more pronounced as many countries have built their own legal frameworks for AI. From the AI Act of the European Union, the NIST AI Risk Management Framework, the ISO/IEC 42001 standard to the Law on Artificial Intelligence and the Law on Personal Data Protection of Vietnam, the common point is that businesses are required to actively assess and manage AI risks throughout the life cycle of the system. It also means that investment funds, credit institutions, and strategic partners will increasingly consider AI Due Diligence as an inevitable part of the business due diligence process.

    For Vietnamese businesses, this requires a change in management thinking. AI Due Diligence should not only be done when preparing to raise capital or sell a business, but should become a part of the risk management system from the moment AI is designed, developed, and put into operation. Developing internal AI policies, managing the data lifecycle, controlling the origin of models, periodically assessing risks, and establishing human monitoring mechanisms will not only help businesses meet legal requirements but also improve business value in the eyes of investors.

    For many years, the value of a business was measured in terms of revenue, profits, and tangible assets. However, in the AI era, those indicators will no longer fully reflect the strength of a business if we ignore data quality, model reliability, and artificial intelligence management capacity. As AI becomes a strategic asset, AI Due Diligence will no longer be a technical option but will become a new benchmark for investment, M&A and corporate governance. Businesses that prepare for this change early will have more opportunities to attract capital flows, enhance business value, and build a sustainable competitive advantage in the digital economy.

    Lawyer Nguyen Van Phuc

    HM&P Law Firm

     

    Read more: AI Due Diligence: Khi trí tuệ nhân tạo trở thành đối tượng hoạt động thẩm định doanh nghiệp


    [1] AI hallucination is a phenomenon in which artificial intelligence models (especially generative AI) confidently give false, untrue or completely fabricated information, but are presented in an extremely logical, convincing and natural way.

    [2] Prompt injection is a cyber attack technique that targets Artificial Intelligence (AI) and Large Language Model (LLM) systems such as ChatGPT, Claude or Gemini. An attacker will stealthily insert malicious statements into the input text to trick the AI into exposing confidential data, bypassing censorship barriers, or performing unauthorized actions.

    [3] Data poisoning is  the manipulation of the training dataset of an Artificial Intelligence (AI) system. An attacker deliberately injects false or malicious data into the material that the AI learns, causing the AI to learn the wrong pattern, give wrong results, or be biased.

    [4] Model Extraction in the field of Artificial Intelligence (AI) and Machine Learning is the process of an attacker sending a large number of questions (queries) to a working AI model, and then analyzing the answers to copy, steal, or recreate the entire functionality of the original model.

    [5] https://www.reuters.com/article/world/insight-amazon-scraps-secret-ai-recruiting-tool-that-showed-bias-against-women-idUSKCN1MK0AG/, truy cập ngày 04/07/2026.

    [6] https://www.bakerlaw.com/thomson-reuters-v-ross/, accessed on 04/07/2026.

    [7] https://www.theguardian.com/technology/2017/jul/03/google-deepmind-16m-patient-royal-free-deal-data-protection-act, truy cập ngày 04/07/2026.