AI Governance Due Diligence (2026): The 10-Artifact Evidence Pack + Corrected EU AI Act Timeline
Co-founder and CEO at Peony. I built the data room platform with a background in document security, file systems, and AI. Founded Peony in 2021 in San Francisco.
Last updated: August 2026
I'm Deqian Jia, co-founder of Peony, a virtual data room company. I spend my days on the product side of how deal teams actually run diligence, and over the last eighteen months one workstream went from "nice to have" to a standing line item on the diligence request list: how the target governs its use of AI. Not whether its models are good — that is a different, narrower audit — but whether there is a real program around AI: an inventory, a policy, a role under the EU AI Act, vendor clauses, an incident process, and a board that actually oversees the risk. Buyers started asking for it because AI now touches hiring decisions, credit calls, customer-facing claims, and regulated workflows, and because the regulatory map got both stricter and — as of this summer — genuinely confusing.
AI governance due diligence reviews the program; AI due diligence audits the models. That one sentence is the whole boundary of this post. If you are buying an AI-native company and need to trace training-data provenance, read model cards, and score the model stack, that is the AI due diligence workstream, and its "Governance Layer" classifies the target's own system under EU AI Act tiers. This post is the inverse altitude: the governance program of any company that uses AI — which in 2026 is most targets — and the board-level evidence layer that a buyer inspects to decide whether the program is real, current, and monitored. I run Peony, used by 6,800+ customers, largely as the collection-and-evidence layer for exactly this kind of workstream; I will be honest throughout about where a data room fits and where dedicated governance, risk, and compliance (GRC) or AI-audit tooling wins.
Quick answer: AI governance due diligence is the buyer-side review of how a company that uses AI governs it — the AI inventory, acceptable-use policy, EU AI Act role and timeline mapping, GPAI and vendor-AI exposure, incident process, NIST AI RMF / ISO 42001 alignment, and the board-oversight records that prove the program is real. It is distinct from AI due diligence, which audits an AI-native target's models. The accuracy pivot for 2026: after the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force 27 July 2026), EU AI Act high-risk obligations were deferred — stand-alone (Annex III) to 2 December 2027, embedded (Annex I) to 2 August 2028 — but Article 50 transparency still applies from 2 August 2026, and GPAI obligations have applied since 2 August 2025. The deliverable is a 10-artifact evidence pack; the room is where you collect and evidence it.

What is AI-governance due diligence?
AI-governance due diligence is the buyer-side review of a target's AI governance program — the policies, roles, records, and controls that show how a company that uses AI manages the resulting legal, regulatory, and operational risk — as distinct from a technical audit of the AI models themselves. It answers a question that has become deal-relevant for almost every 2026 target: this company uses AI in ways that touch people, regulators, and revenue — is there a real program governing that, and can the board prove it oversees it?
The cleanest way to hold the distinction is one line: AI governance DD reviews the program; AI due diligence audits the models. The two are complementary workstreams at different altitudes:
- AI due diligence is the technical audit of an AI-native target: training-data provenance and license trail, model ownership and license cliffs, GPU and infrastructure concentration, output and hallucination liability, and — in its Governance Layer — the classification of the target's own AI system under EU AI Act tiers. It is the workstream when the model is the product, and it is where buyer counsel signs off on repricing tied to model risk.
- AI-governance due diligence (this post) is the review of the governance program wrapped around AI, for any company that uses it — most targets in 2026, from a SaaS company that added an AI feature to a lender that scores applicants with a model it did not build. It inspects whether an inventory, policy, role mapping, incident process, and board oversight exist and function. It defers all model-level and training-data depth to the AI due diligence guide.
A worked contrast makes it concrete. Imagine a mid-market insurance-services company that uses a third-party AI model to triage claims and a general-purpose model to draft customer emails. The AI due diligence questions ("what is the model architecture, what was it trained on, what are its eval scores") mostly do not apply — the company did not build the model. The AI-governance questions absolutely do: Is the claims-triage use case high-risk under the EU AI Act, and is the company a deployer of it? Is there a policy governing the general-purpose model's use on customer data? Are AI-generated emails labeled now that Article 50 transparency applies? Does a vendor contract allocate liability for a bad AI decision? Has the board seen any of this? That set — the program, not the model — is the subject of this post.
This post also stays inside clear boundaries with its neighbors. Security controls and incident-response depth belong to cybersecurity due diligence; this post touches AI-specific security (model access, data leakage into third-party models) in a single paragraph and defers. Vendor screening as a discipline belongs to third-party due diligence; this post covers only the "AI vendor clause inventory" slice. General questionnaire mechanics belong to the due diligence questionnaire guide; this post ships the AI-governance-specific question set. And agentic AI access to deal systems belongs to MCP data rooms. The through-line for the whole workstream is the buyer's version of what due diligence is: a structured examination that ends in a repricing, indemnity, or walk decision.
When does a deal need an AI-governance workstream?
A deal needs an AI-governance workstream when AI touches a decision, a regulated function, or a material cost — not merely because the target's pitch deck says "AI-powered." The failure mode in both directions is real: teams either skip the workstream on a target quietly running a hiring-screen model (and inherit undisclosed regulatory exposure), or they burden a target that only uses AI to summarize meeting notes (and waste diligence hours). A short trigger test sorts it.
Ask these five questions. Any yes puts AI-governance DD in scope:
- Does the target deploy AI in a high-risk use case? Hiring and employment decisions, credit and lending, insurance underwriting or pricing, education access, essential public or private services, biometric identification, safety components — these are the EU AI Act Annex III categories and their US-state analogues. AI in these functions carries the heaviest governance weight even though, as covered below, the EU high-risk obligations were just deferred.
- Does AI make or materially influence decisions about people? Approvals, rankings, eligibility, prioritization. Automated decision-making about individuals is where discrimination, transparency, and appeal-rights exposure concentrate — and it is the axis US state laws increasingly regulate.
- Is AI embedded in the product customers pay for, or in a regulated workflow? If the AI feature is load-bearing for revenue or sits inside a compliance-regulated process, its governance is a diligence subject, not a footnote.
- Does the target depend on GPAI or third-party AI vendors for something load-bearing? Reliance on general-purpose models or outside AI APIs imports the vendor's terms, data-handling, and continuity risk into the target — the "vendor AI clause inventory" exists for this.
- Does the target market AI capabilities to customers? Public claims about AI accuracy, autonomy, or substitution ("our AI does X better than a human") are live FTC exposure under Operation AI Comply, independent of whether the model is any good.
If every answer is no — AI is purely an internal productivity aid with no customer, decision, or regulatory surface — then a one-page screening question set folded into the general DDQ is proportionate, and you do not stand up a full workstream. The moment even one answer is yes, you assemble the 10-artifact evidence pack and run the program review. A useful market signal on how normal this has become: in a 2026 Datasite survey of 1,000 dealmakers, 50% said AI is now regularly embedded in their due diligence, 71% ranked accuracy as the top requirement for AI in dealmaking, and 58% said they rely on human review to trust AI outputs — a dealmaking population that both uses AI heavily and expects to govern it, on both sides of the table.
What is the corrected EU AI Act timeline for diligence in 2026?
Here is the correct EU AI Act timeline as of August 2026 — most guidance written before mid-2026 gets it wrong, so start from the table below. The headline: the EU deferred the high-risk obligations, but kept the transparency deadline. Reviewers and sellers who price to "high-risk applies 2 August 2026" are working from an out-of-date calendar.
Here is what happened. Facing a looming 2 August 2026 enforcement date for high-risk systems that much of the ecosystem was not ready for, the EU passed the Digital Omnibus on AI — Regulation (EU) 2026/1744 — which was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, deliberately fast-tracked so the amended deadlines took effect before the original one arrived. It defers the high-risk application dates and leaves the transparency and GPAI obligations essentially on their original schedule.
The corrected timeline, as of August 2026:
| Obligation | Status / application date | Notes |
|---|---|---|
| Prohibited AI practices + AI-literacy duties | Applied 2 February 2025 | Bans on unacceptable-risk uses; staff AI-literacy obligation — both live. |
| General-purpose AI (GPAI) model obligations | Applied 2 August 2025 | Documentation, transparency, copyright-policy, training-data summary for GPAI providers — already in force. |
| Article 50 transparency obligations | Apply 2 August 2026 — NOT deferred | Label AI interactions; mark AI-generated/manipulated content (deepfakes, synthetic media). This deadline held. |
| Stand-alone high-risk (Annex III) obligations | Deferred to 2 December 2027 | Hiring, credit, insurance, education, essential services, biometric ID, etc. Was 2 August 2026. |
| Embedded high-risk (Annex I) obligations | Deferred to 2 August 2028 | AI inside products already regulated by EU sector law (e.g. medical devices, machinery). Was 2 August 2026. |
| Digital Omnibus on AI | In force 27 July 2026 | Regulation (EU) 2026/1744; OJ publication 24 July 2026. The instrument that moved the high-risk dates. |
Any guidance stating 'high-risk applies 2 August 2026' predates the Digital Omnibus and is out of date.
Two practical consequences for a diligence review follow directly.
First, the deferral does not mean "no exposure until 2027." Article 50 transparency is live from August 2026, so a target that generates customer-facing AI content or runs AI chat without disclosure has a current gap. GPAI obligations have applied for a year, so a target that builds or distributes a general-purpose model should already hold the documentation and copyright-policy artifacts. And the deferral buys preparation time on high-risk, not a pass — a target in a high-risk use case with no readiness plan is still a repricing signal, because the obligations are coming and the buyer inherits the runway (or lack of it).
Second, role mapping still drives everything. The AI Act allocates duties by role — chiefly provider (a company that develops an AI system, or has one developed, and puts it on the market under its own name) and deployer (a company that uses an AI system under its own authority). A single target is often both: a provider of the feature it built, and a deployer of the third-party models it uses. For each system in the inventory, the review records the use-case tier (prohibited / high-risk Annex III or I / Article 50 transparency / minimal) and the target's role, because provider duties (conformity assessment, technical documentation, post-market monitoring) are heavier than deployer duties (use as instructed, human oversight, logging). That role-and-tier map, hedged as of August 2026, is the artifact GC-side reviewers care about most. For the model-level tier classification of an AI-native target's own system, defer to the Governance Layer in the AI due diligence guide.
This section is informational, not legal advice; confirm the current text of Regulation (EU) 2026/1744 and its dates with counsel before relying on them.
What is in an AI-governance evidence pack (the 10 artifacts)?
The AI-governance evidence pack is the set of documents a buyer requests to judge whether a target's AI program is real, current, and monitored — and across the deals I see, it converges on ten artifacts. A seller assembling a sell-side room and a buyer building a request list are working from the same list; the only difference is direction. Here it is, in the order a reviewer usually asks for them.
- AI system inventory. A living list of every AI system the target builds, buys, or uses — name, purpose, the business function it touches, whether it makes or influences decisions about people, and the model or vendor behind it. This is artifact one because everything else keys off it: no inventory means the target cannot answer "what AI do you run," which is itself the most common red flag.
- AI policy and acceptable-use rules. The internal policy governing how employees may use AI (including general-purpose tools), what data may go into third-party models, approval gates for new AI systems, and prohibited uses. The reviewer checks that it exists, is current, and is actually enforced — not a one-page aspiration.
- EU AI Act role-and-timeline mapping memo. For each inventoried system, the provider/deployer role, the use-case tier, and the post-Omnibus deadline (transparency from August 2026; stand-alone high-risk from December 2027; embedded high-risk from August 2028; GPAI in force). This is the artifact the corrected-timeline section above produces.
- GPAI usage and third-party model list. Which general-purpose and third-party AI models the target depends on, for what, and under what terms — the dependency map that shows where model risk and vendor lock-in live.
- Vendor AI clause inventory. The AI-specific terms in customer and supplier contracts: data-use and training-rights clauses, IP ownership of AI outputs, indemnities for AI errors, and liability allocation. A live AI deployment with vendor contracts silent on these is an allocation gap. (Vendor screening as a discipline belongs to third-party due diligence; this is only the AI slice.)
- AI incident process and incident log. The documented procedure for handling AI failures — a harmful output, a discriminatory decision, a data leak into a model — plus the actual log of incidents and their resolution. An empty log for a mature deployment reads as "we do not track," not "we have no problems."
- Training-data and IP position. For anything the target built in-house: the provenance and licensing of training data and the IP ownership of resulting models. This is deliberately shallow here — deep training-data provenance is AI due diligence territory — but the governance review still confirms a documented position exists.
- NIST AI RMF / ISO 42001 alignment documentation. Evidence that the program maps to a recognized framework — a NIST AI RMF crosswalk (Govern/Map/Measure/Manage) or, stronger, an ISO/IEC 42001 certificate. Covered in its own section below, including what each does and does not prove.
- Board-oversight minutes and records. The evidence layer: committee charter or board-level owner for AI risk, dated minutes showing AI on the agenda, and management reporting to the board. This is what converts a policy into governance — and what Caremark-line oversight duties press on.
- AI-governance DDQ answers. The target's completed responses to the AI-governance questionnaire, which cross-references the nine artifacts above and surfaces gaps as written answers a reviewer can test in Q&A.
Assembled, these ten let a buyer make the judgment model-level testing cannot: not "is the model good," but "does this company govern AI deliberately, and can it prove the board is watching." A seller who populates this pack early turns a nervous, open-ended request list into a bounded, credible folder — and, as I will cover in the collection section, that folder has a natural home and index in the data room.
What should board minutes and records show about AI oversight?
Board minutes and records should show that the board actually oversees AI as a risk — with a named owner, a reporting cadence, and evidence of engagement — not that it approved a policy once and never returned to it. This is the evidence layer of the whole workstream: the AI-governance review inspects board records precisely because they are the hardest thing to fake. A polished policy can be written in an afternoon; a two-year trail of minutes showing AI on the agenda, management reporting, and follow-ups cannot.
Concretely, a diligence reviewer looks for four things in the board and committee records:
- A named owner for AI risk. A board committee (often audit, risk, or technology) or a specific board-level mandate that owns AI oversight, evidenced by a charter or resolution — not a diffuse "the whole board cares about it."
- AI on the agenda, with dated minutes. Recurring, dated entries showing the board or committee considered AI risk, regulatory exposure, and material incidents — the cadence that proves oversight is a standing function.
- Management reporting up to the board. Evidence that management reports the AI inventory, incident summaries, and regulatory-readiness status to the board, so directors are informed rather than nominal.
- Engagement and follow-through. Signs the board asked questions, requested information, and tracked remediation to closure — the difference between monitoring a system and merely possessing one.
The legal backdrop, hedged carefully: as of August 2026, Delaware's Caremark line of cases sets the oversight-duty standard for directors, and the Delaware Supreme Court's decision in Marchand v. Barnhill (2019) sharpened it — holding that directors must implement and monitor a reasonable board-level system for mission-critical risks, and that a board with no committee or process to oversee such a risk can face a viable bad-faith oversight claim. Marchand concerned food safety at an ice-cream company; the framework is general. Commentators — including work out of Harvard's Safra Center on the Caremark rule and board-level AI risk — increasingly argue that for an AI-dependent business, AI governance is exactly the kind of mission-critical risk the oversight duty reaches. I am stating the direction of commentary, not a settled holding that "boards must oversee AI"; this is informational, not legal advice, and the contours of mission-criticality are genuinely contested.
The distribution mechanics matter too. Board members increasingly consume this material as a live, permissioned artifact rather than a static PDF attachment — see our guide to sharing an interactive board report for how the oversight record itself gets surfaced securely to directors. In diligence, that same set of minutes and management reports becomes an evidence artifact the buyer inspects, which is why keeping it in one gated, watermarked place — rather than scattered across email and slide decks — is what makes the oversight story provable when a reviewer asks.
What US state and federal AI laws matter in 2026 diligence?
Beyond the EU, the US layer matters in 2026 diligence — and its defining feature is that the dates keep moving, so every one must be verified fresh at the time of the deal. Three anchors carry most of the weight, and one of them changed twice in eighteen months.
Colorado AI Act (SB 24-205) — now effective 1 January 2027. Colorado's landmark AI law, aimed at algorithmic discrimination in consequential decisions, has been delayed twice. It was originally set for 1 February 2026, then pushed to 30 June 2026 in a 2025 special session — and then, before that date arrived, SB 189 (signed 14 May 2026) moved the effective date to 1 January 2027 and replaced the original risk-based framework with a narrower disclosure-and-transparency model, eliminating the developer/deployer duty-of-care and impact-assessment obligations of the 2024 statute. For diligence, the practical read as of August 2026 is that a Colorado-touching target faces a lighter and later Colorado obligation than the 2024 statute implied — but confirm the current text, because this is the single most-amended AI law in the US and further change is plausible.
Texas TRAIGA (HB 149) — effective 1 January 2026. The Texas Responsible Artificial Intelligence Governance Act took effect 1 January 2026. It takes an intent-based approach (unlike Colorado's impact-based model), prohibiting AI developed or deployed to intentionally discriminate, manipulate behavior, or produce certain harmful content, alongside disclosure duties for government use of AI and biometric-consent rules. Enforcement is exclusive to the Texas Attorney General, with a 60-day cure period and no private right of action. For a target operating in Texas, the diligence question is whether any AI use could be read as intentionally within a prohibited category, and whether disclosure obligations are met.
FTC enforcement — Operation AI Comply, ongoing. At the federal level, there is no comprehensive US AI statute, but the FTC's Operation AI Comply — launched September 2024 with five enforcement actions, including against a company selling an "AI Lawyer" service (DoNotPay) and one whose tool generated fake reviews (Rytr) — established that existing consumer-protection law reaches deceptive AI claims. As of August 2026, that enforcement posture has continued: the FTC's own follow-ups and outside analysis (e.g. Holland & Knight's "two years later" review) confirm the through-line that "there is no AI exemption from the laws on the books." For diligence, this is the home of the marketing-claims red flag: aggressive public claims about AI capability, with no substantiation, are live exposure regardless of model quality.
The synthesis for a reviewer: the US layer is a patchwork on shifting timelines, so the workstream records, per target, which states it operates in, what AI claims it makes publicly, and whether its consequential-decision use cases intersect Colorado's (later, lighter) regime or Texas's intent-based prohibitions. Every date in this section is stated as of August 2026 and should be re-verified before it is relied on — this area has moved faster than any other in the diligence map.
What do NIST AI RMF and ISO/IEC 42001 each prove in diligence?
The two frameworks a diligence reviewer meets most often are the NIST AI Risk Management Framework and ISO/IEC 42001, and the key insight is what each evidences — and what neither proves. Both are about the governance program, not about any individual model's correctness. Confusing "we align to NIST AI RMF" or "we are ISO 42001 certified" with "our models are safe and compliant" is the most common overread in this part of diligence.
NIST AI RMF (AI Risk Management Framework 1.0, released January 2023, with the Generative AI Profile NIST.AI.600-1 added in July 2024) is a voluntary US framework organized around four functions — Govern, Map, Measure, Manage. It is not certifiable; there is no "NIST AI RMF certificate." What alignment evidences is that the target has structured its AI risk work, and the four functions double as evidence buckets in diligence:
- Govern — is there AI risk ownership, policy, and an accountability structure? (Maps to the policy and board-oversight artifacts.)
- Map — has the target inventoried its AI systems, their context, and their risks? (Maps to the AI inventory and role memo.)
- Measure — does it test and monitor performance, bias, robustness, and safety? (Maps to evals and monitoring records.)
- Manage — does it prioritize, treat, document, and respond to risks and incidents? (Maps to the incident process and log.)
ISO/IEC 42001:2023 is the world's first international AI-management-system (AIMS) standard, and unlike NIST it is certifiable — an accredited third party audits and issues a certificate. Certification proves that an independent auditor validated the organization operates a structured management system for AI: policies, roles, risk assessment, controls, and continual improvement across the AI lifecycle. It is stronger diligence evidence than a self-attested NIST crosswalk because it is externally audited.
Here is the line both frameworks share, and the one a reviewer must not blur: neither proves that any specific model is safe, accurate, unbiased, or legally compliant in a given use case. A NIST-aligned, ISO-42001-certified company can still deploy a flawed model, and — critically — ISO 42001 certification is not an EU AI Act conformity assessment. The frameworks evidence that a governance program exists and (for 42001) is audited; they are necessary signals, not sufficient proof. The reviewer's move is to treat framework alignment as strong evidence of program maturity, then still test the systems that matter to the deal — the security-control depth of which crosses into cybersecurity due diligence, where model access and data-leakage controls get their proper audit. For how the older security-and-controls certifications behave as diligence evidence, the same "certifies the system, not the outcome" logic runs through our guide to SOC 2 and ISO 27001 for data rooms.
What AI-governance red flags reprice or kill deals?
The red flags that reprice or kill deals in this workstream are almost all absence-of-program signals — the target cannot produce an artifact that should exist, or produces one with nothing behind it. Buyer counsel converts each into an indemnity ask, an escrow, a price chip, or, at the extreme, a walk. Here are the recurring ones, roughly in ascending severity.
- No AI inventory. The target cannot list the AI systems it runs. This is the foundational red flag: if the company does not know what AI it uses, it cannot govern it, and every downstream artifact is unreliable. It reprices because it implies undiscovered exposure.
- A policy with no board reporting behind it. An acceptable-use policy exists, but there is no reporting cadence, no minutes, no evidence the board or a committee ever engaged — governance theater. Given the Caremark-line oversight framing, this is a governance-quality discount and, for an AI-dependent business, a potential director-liability surface.
- A high-risk use case with no role analysis or readiness plan. The target runs AI in hiring, credit, insurance, or another Annex III function but has done no provider/deployer analysis and has no plan for the (now-deferred, but coming) high-risk obligations. The deferral to December 2027 softens the timing, not the existence, of this gap.
- AI-generated content with no Article 50 transparency posture. Now that transparency applies from August 2026, undisclosed AI chat or unlabeled synthetic content in an EU-touching business is a current compliance gap, not a future one.
- AI vendor contracts silent on data, IP, and liability. Load-bearing AI vendors with no clauses on training-data rights, output IP ownership, or indemnity for AI errors leave the target — and the buyer — holding unallocated risk.
- No incident process, or an empty log for a live deployment. No documented way to handle an AI failure, or a mature deployment with a suspiciously empty incident log, reads as "we do not track incidents," which is itself the finding.
- Unlicensed training data or unresolved IP provenance. For anything built in-house, a documented-but-shaky (or absent) training-data and IP position — the governance-level flag that hands off to deep AI due diligence for quantification.
- Aggressive AI marketing claims with no substantiation. Public claims about AI autonomy, accuracy, or human substitution, with no evidence file — the live FTC exposure that Operation AI Comply is built to police.
The severity ladder is the useful part. A missing inventory or empty incident log is a program-maturity discount, usually curable with a remediation plan and a modest chip. A prohibited EU AI Act use case in an EU-touching deal, or substantiation-free marketing claims already drawing regulatory attention, sits at the top — the first can be a walk, the second an indemnity with real numbers attached. In every case the mechanism is the same: the absence of an artifact the 10-artifact pack says should exist becomes a written finding, surfaced in Q&A, and priced.
How do you run the AI-governance workstream in the data room?
You run the AI-governance workstream in a data room by collecting the 10 artifacts through per-owner file requests, indexing them under a dedicated "AI Governance" folder, running the Q&A against them, and — where you want speed — using governed AI on the deal itself with permissions and citations enforced. This is the section where I am most direct about where Peony fits and where it does not, because overreaching here is exactly the failure mode I want to avoid.
Collection — file requests to the target. The pack is a document chase across several owners: legal holds the vendor clauses and the role memo, engineering holds the inventory and incident log, the corporate secretary holds the board records. In Peony you issue a file request — a checklist of exactly the artifacts due — to each owner, who uploads into their own space; you see completeness at a glance instead of reconstructing status from an email thread. This is the same per-owner collection pattern the due diligence data room checklist builds around, applied to the AI pack.
Index placement. Give the pack a top-level "AI Governance" folder, sub-foldered to the ten artifacts, so a reviewer lands on the inventory, policy, role memo, vendor clauses, incident log, and board records without hunting. On the Data Room plan ($52/admin/mo, billed annually), auto-indexing keeps that structure clean as documents arrive, and granular per-viewer permissions wall the sensitive material — board minutes, incident logs — so outside counsel sees what they need while the broader deal team does not.
Protection and evidence. Board-oversight minutes and incident logs are the most sensitive documents in the pack. The Data Room plan applies dynamic watermarking (every page stamped with the viewer's identity, so a leak is traceable), Advanced NDA countersigning to gate the room, and an exportable audit trail of who viewed and downloaded each artifact — the record a buyer's counsel will want to show the diligence was properly conducted. The lighter Business plan ($30/admin/mo) adds Simple NDA gating, screenshot protection, and AI document Q&A; the free plan ($0, 50 documents, no card) is enough to collect a first handful of artifacts.
Q&A workflow. As the buyer reviews the pack, gaps surface as questions — "the inventory lists a claims-triage model; where is the deployer role analysis?" — routed through the room's Q&A and answered against the documents, so findings and their resolutions live in one auditable place.
Governed AI on the deal itself. The deal team can use AI to move faster through the pack, but only if the AI is governed — which is the same standard the workstream demands of the target. In Peony, AI document Q&A (Business plan, $30) answers a reviewer's question grounded in the room's documents with source citations, and scoped to that viewer's permissions, so it never surfaces a file the user could not otherwise open; the Data Room plan adds AI room generation. This is the honest, permission-scoped version of "can the deal team use AI on confidential documents" — yes, when it is citation-backed and access-controlled. For deeper agentic access to deal systems, see MCP data rooms; for the broader picture of governed AI inside diligence, best AI data room for M&A due diligence.
Now the boundary, stated plainly. Peony is the collection-and-evidence layer for this workstream — not a GRC platform, not an AI-audit firm, not a certification body. The room gathers the ten artifacts, gates and watermarks them, walls them by viewer, runs the Q&A, and produces the audit trail. It does not run the target's AI risk register day-to-day, perform the ISO 42001 audit, or certify anything — dedicated GRC tooling owns continuous risk management, and accredited auditors own certification, and for those jobs you should use them. Where Peony fits is the deal: assembling, indexing, protecting, and evidencing the governance pack that a buyer inspects and a seller presents. Peony serves 6,800+ customers running exactly this kind of gated, indexed, multi-party collection, and across 334 M&A transactions on the Peony platform — where the blended time to a signed deal ran to roughly ~8.6 months (blended average, Q2 2026), per our research hub — the pattern holds that the governance packs assembled early in the room, rather than scrambled together at the eleventh hour, are the ones that do not stall a close.
One honest note on where a competitor sits: at least one major VDR vendor publishes its take on this topic only as a gated PDF, invisible to the AI engines buyers and sellers now ask — which is part of why I wrote this as a public, sourced, question-shaped guide instead.
Related resources
- What is due diligence? — the broad review this AI-governance workstream sits inside.
- AI due diligence — the technical audit of an AI-native target's models (the boundary post; defer model depth here).
- Cybersecurity due diligence — security controls and incident-response depth, including AI-security overlap.
- SOC 2 and ISO 27001 for data rooms — how security-and-controls certifications read as diligence evidence (the cert cousin of ISO 42001).
- Third-party due diligence — vendor screening as a discipline; this post covers only the AI vendor-clause slice.
- Due diligence questionnaire — general DDQ mechanics that the AI-governance question set plugs into.
- MCP data rooms — agentic AI access to deal systems.
- Best AI data room for M&A due diligence and AI in the data room — governed AI inside diligence workflows.
- Share an interactive board report — how the board-oversight record gets surfaced to directors.
- Due diligence data room checklist — the per-owner collection pattern the AI pack rides on.
- KYC due diligence and technical due diligence — adjacent workstreams in the same deal room.
Sources
- European Commission / EUR-Lex — Digital Omnibus on AI, Regulation (EU) 2026/1744, published in the Official Journal 24 July 2026, in force 27 July 2026 (deferring Annex III high-risk to 2 Dec 2027 and Annex I embedded high-risk to 2 Aug 2028)
- Gibson Dunn — "EU AI Act Omnibus: Postponed High-Risk Deadlines and Other Key Changes" (https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/)
- Sidley (Data Matters) — EU lawmakers' agreement to delay key EU AI Act obligations (Annex III → 2 Dec 2027; Annex I → 2 Aug 2028) (https://datamatters.sidley.com/2026/06/22/eu-lawmakers-reach-provisional-agreement-to-delay-key-eu-ai-act-obligations/)
- White & Case — "EU AI Omnibus enters into force, amending the AI Act" (Article 50 transparency remains 2 Aug 2026; high-risk deferrals) (https://www.whitecase.com/insight-alert/eu-ai-omnibus-enters-force-amending-ai-act)
- Lewis Silkin — "The Digital Omnibus on AI enters into force today" (27 July 2026) (https://www.lewissilkin.com/insights/2026/07/27/the-digital-omnibus-on-ai-enters-into-force-today-102nedo)
- Freshfields — "EU AI Act unpacked #34: The final Digital Omnibus on AI" (https://www.freshfields.com/en/our-thinking/blogs/technology-quotient/eu-ai-act-unpacked-34-the-final-digital-omnibus-on-ai-key-amendments-to-the-a-102nber)
- NIST — AI Risk Management Framework (AI RMF 1.0, released 26 January 2023; Generative AI Profile NIST.AI.600-1, released 26 July 2024; functions Govern/Map/Measure/Manage) (https://www.nist.gov/itl/ai-risk-management-framework)
- ISO/IEC 42001:2023 — Artificial Intelligence Management System (AIMS), the first certifiable AI management-system standard (https://www.iso.org/standard/42001); explainers: DNV (https://www.dnv.com/services/iso-iec-42001-artificial-intelligence-ai--250876/) and KPMG (https://kpmg.com/ch/en/insights/artificial-intelligence/iso-iec-42001.html)
- Marchand v. Barnhill (Del. 2019) — mission-critical oversight duty (Caremark line): Jones Day analysis (https://www.jonesday.com/en/insights/2019/08/delaware-court-reinforces-directors-oversight) and Harvard Safra Center, "The Caremark Rule and Board-Level AI Risk Management" (https://www.ethics.harvard.edu/blog/post-6-caremark-rule-and-board-level-ai-risk-management)
- Colorado AI Act (SB 24-205) — effective date delayed to 1 January 2027 and scaled back by SB 189 (signed 14 May 2026): Hunton (https://www.hunton.com/privacy-and-cybersecurity-law-blog/colorado-ai-act-amended-and-effective-date-delayed) and Akin (https://www.akingump.com/en/insights/ai-law-and-regulation-tracker/colorado-postpones-implementation-of-colorado-ai-act-sb-24-205)
- Texas Responsible Artificial Intelligence Governance Act (TRAIGA, HB 149) — effective 1 January 2026; exclusive AG enforcement, 60-day cure: K&L Gates (https://www.klgates.com/Pared-Back-Version-of-the-Texas-Responsible-Artificial-Intelligence-Governance-Act-Signed-Into-Law-6-24-2025) and Holland & Knight (https://www.hklaw.com/en/insights/publications/2025/06/texas-enacts-comprehensive-ai-governance-laws)
- FTC — "Operation AI Comply" (announced 25 September 2024; five enforcement actions incl. DoNotPay and Rytr) (https://www.ftc.gov/news-events/news/press-releases/2024/09/ftc-announces-crackdown-deceptive-ai-claims-schemes); Holland & Knight, "Operation AI Comply Two Years Later" (Aug 2026) (https://www.hklaw.com/en/insights/publications/2026/08/operation-ai-comply-2-years-later-continued-enforcement)
- Datasite × FT Longitude — "The New Deal Team" (June 2026), survey of 1,000 senior dealmakers (50% embed AI in due diligence; 71% rank accuracy first; 58% rely on human review) (https://www.datasite.com/en/company/news/most-dealmakers-say-human-only-decision-making-is-no-longer-defensible-in-complex-deals)
- Peony first-party — 6,800+ customers; 334 M&A transactions on the Peony platform; ~8.6 months blended time-to-close (State of M&A Data Rooms, Q2 2026); dataset index at (https://www.peony.ink/research)
You might also like
May 11, 2026
AI Due Diligence (2026): 5-Layer Audit + EU AI Act Map + 12 Deals
Aug 21, 2026
ESG Due Diligence (2026): The Post-Omnibus Scope Reset + the Scope 3 Evidence Test
Aug 21, 2026
Insurance Due Diligence in M&A (2026): The Collateral Trap + Loss-Run Playbook

