State of M&A Data Rooms — Q2 2026 Read the report →

AI Due Diligence Checklist

90 buy-side checks for diligencing an AI company, grouped by the five layers of the AI Target Audit — Data, Model, Infrastructure, Output and Governance — plus the three cross-cutting groups the audit feeds: customer Contracts, the research Team, and the inference Economics. Every line names the evidence to request, the reviewer who reads it, its disclosure wave, and whether the finding walks the deal, moves price, or simply confirms posture. Free, no signup, and every line traces to the AI due diligence guide.

Loading the checklist…

Download the checklist

The full 90-line list is available in three formats, all generated from the same source module, all free and signup-free. The CSV opens in a spreadsheet as one row per check with the layer, evidence, wave, reviewers, severity and source columns intact. The Markdown file is the machine-legible version — clean GFM task lists, one section per layer. The PDF is the print surface, laid out to hand to a deal team.

How do you use it in the data room?

Five top-level folders keyed to the five audit layers, one reviewer group per specialist tier, and three disclosure waves. Wave one is the teaser stage — a one-page AI exposure summary carrying the five layer scores and the EU AI Act tier classification summary, before any deep folder is visible. Wave two is the LOI stage — the AI risk register, the model inventory, the compute-spend picture and the tier classification in full. Wave three is confirmatory — every layer folder open, including the training-data manifest, the conformity assessment file and the red-team log. The wave column on each line is what tells the seller which folder to populate when.

The reviewer column drives the visitor groups. The buyer’s AI/ML advisor needs the model and infrastructure folders; IP counsel needs the training-data licenses and fine-tune lineage; data-protection counsel needs the PII inventory and the DPIA; the lender usually needs only the summary and the committed-spend schedules. The failure mode in AI diligence is not under-sharing — it is a lender or an operating-team member landing in the training-data manifest.

I run Peony, a data room company. Per-group permissions of this shape sit on the Data Room plan at $52 per admin per month — granular per-file and per-user permissions with a full audit trail, dynamic watermarking on every model card, and the advanced NDA with a countersigned PDF. Business at $30 per admin per month covers the lighter end: screenshot protection, allow/block visitor lists and a simple acknowledge-only NDA. The free plan at $0 handles up to 50 documents, which is enough for a teaser-stage AI exposure summary and nothing more. Reviewers are free on every plan, so a fifth group costs nothing to add, and 6,800+ customers run rooms on this model.

Where do these checks come from?

Every line is a projection of one written guide — AI Due Diligence (2026) — and nothing appears here that is not in it. Where a line rests on a primary source, the source link renders on the row itself. Where the guide labels a rule of thumb as ours rather than as published market data, that label travels with the line: the 70-percent single-hyperscaler concentration flag and the repricing framing behind the score bands are practitioner judgement from our own deal exposure, not a published dataset.

One thing this tool deliberately does not publish is a dollar range or a week-count for AI diligence itself. There is no published, independent benchmark for either, so the checklist carries the five cost drivers and the phase durations instead — the Data Layer at roughly two to four weeks as the long pole, Governance bimodal between days and months.

AI due diligence checklist FAQ

What is AI due diligence?

AI due diligence is the buy-side review of an AI company you are acquiring — its training data, its models, its compute, its output liability and its governance file — not the use of AI to run a conventional diligence process. Same three letters, opposite job. It runs as the 5-Layer AI Target Audit: Data, Model, Infrastructure, Output and Governance, each scored 1 to 5 and summed into a 5-25 AI Deal Health Score. This checklist is that audit expressed as a request list, so each line names the check, the document or artifact that evidences it, the reviewer who reads it and the disclosure wave it belongs to.

How do you use this AI due diligence checklist?

Filter to the layers, waves, reviewers and severities that match the deal, tick the lines as evidence arrives, and export what is still outstanding as your request list. The severity tag tells you what a finding does: a walk item can stop the deal or force an asset-only restructure, a price item moves price, escrow or the indemnity ask, and a confirm item verifies posture rather than repricing it. Ticks are kept in your own browser only — nothing you check is sent to or stored on our servers — and the CSV, Markdown and PDF exports carry the same lines, so the outstanding-request list can go straight into an email or a deal-team tracker.

Which layer should you start with?

Start with the Data Layer, because it is the long pole at roughly two to four weeks on a serious target: per-dataset traceability cannot be parallelized past the point where the target's own engineers become the bottleneck. Model, Infrastructure and Output run concurrently once the folders open, each gated by document production rather than by review capacity. Governance is bimodal — days if a conformity assessment file and an AI risk register already exist, months if they have to be built — which is exactly why the EU AI Act tier classification belongs in the LOI wave rather than in confirmatory diligence.

How do the disclosure waves work?

In three waves. Wave one is the teaser stage: a one-page AI exposure summary carrying the five layer scores plus the EU AI Act tier classification summary, before any deep folder is visible. Wave two is the LOI stage: the AI risk register, the model inventory, the compute-spend picture and the EU AI Act tier classification in full. Wave three is confirmatory diligence: every layer folder in full, including the training-data manifest, the conformity assessment file and the red-team log. The structure protects the seller's most sensitive artifacts until the buyer has demonstrated seriousness through LOI and exclusivity, and it is why every line on this checklist carries a wave number.

Does this checklist replace legal counsel?

No. It is a scoping and request tool, not advice. The license-cliff tests, the dataset-license and acquisition-receipt review, the EU AI Act tier classification and the Article 99 exposure model all name a specific reviewer for a reason — IP counsel, data-protection counsel, an AI/ML advisor, regulatory counsel, commercial counsel, EU AI Act counsel — because each finding turns on documents and jurisdictions a checklist cannot see. Use it to make sure nothing is missed and to brief the specialists faster; the scoring bands and the repricing framing are practitioner judgement from our own deal exposure, not a published dataset.

How should the data room be structured for AI due diligence?

Five top-level folders keyed to the five audit layers, and one reviewer group per specialist tier so nobody sees more than their scope: the AI/ML advisor needs the model and infrastructure folders, IP counsel needs training-data licenses and fine-tune lineage, data-protection counsel needs the PII inventory, and the lender usually needs only the summary. Peony delivers per-group permissions of this shape on the Data Room plan at $52 per admin per month, the tier carrying granular per-file and per-user permissions with a full audit trail, dynamic watermarking and the advanced NDA. Business at $30 per admin per month covers the lighter end — screenshot protection, allow/block visitor lists and a simple acknowledge-only NDA. The free plan at $0 handles up to 50 documents, enough for a teaser-stage AI exposure summary and nothing more. Reviewers are free on every plan, so a fifth group costs nothing to add, and 6,800+ customers run rooms on this model.