While reviewing the Due Diligence modules, I started thinking about how quickly AI is changing the way companies operate and whether our DD framework will need to evolve with it.
Today, AI is usually assessed as part of IT, Legal or even IP Due Diligence. But as companies increasingly rely on proprietary models, agentic AI workflows and AI-driven decision-making, I’m not sure those existing categories will be enough. At what point does AI stop being “just another technology” and become a strategic asset that deserves its own assessment?
Beyond understanding the technology itself, there are several questions that could directly impact an acquisition. How should AI capabilities influence valuation? How do we assess the reliability, governance and traceability of AI-driven processes, especially when they operate across multiple countries with different regulations? Should AI governance and compliance remain within Legal DD, or should they be part of a dedicated AI workstream? And are advisory firms already building the multidisciplinary teams needed to assess these risks and opportunities?
Perhaps AI Due Diligence won’t replace IT or Legal DD, but instead become a cross-functional discipline that combines technology, governance, regulation, cybersecurity and business value.
Twenty years ago, Cybersecurity Due Diligence was barely considered in M&A. Could AI Due Diligence become the next specialist workstream? If so, what would you expect it to cover?