M&A Diligence Is Missing the Unlogged Prompts Behind the Research
Traditional M&A due diligence checks code and contracts, but misses shadow AI agents driving pricing, retention, and customer ops.
A data room is a theory of the company: the contracts that bind it, the systems that run it, the people who know how. Generative tools have opened a second company beside that one. Prices are proposed in chats that are not the CRM. Customer concessions are drafted in personal accounts. Code is explained by an assistant that saw a repository it was not supposed to retain. The quality of earnings may depend on a process that exists only as habit. Diligence that does not ask about that habit is diligence of a prior decade.
This is not a reason to avoid targets that use AI. McKinsey’s 2025 survey suggests you will struggle to find a target that does not: 88 percent of organisations report use in at least one function. It is a reason to stop treating “AI strategy” as a management presentation and start treating it as a set of workflows with owners, logs, and failure modes. The presentation will be optimistic. The workflows will be where the indemnity lives.
What you are actually buying
You are buying three things that do not appear in a software inventory.
Dependence. Which revenue or cost processes stall if a particular model, plugin, or personal subscription disappears? A customer-support flow that “uses AI” may in fact depend on a consumer account a supervisor pays for. Microsoft’s Work Trend Index found that 78 percent of AI users bring their own tools. In a target, that statistic is a transition risk. On day one those personal accounts are not yours. The knowledge inside them is not in the data room. The person who holds the login may not be in the retention plan.
Liability already incurred. A chatbot that has been making customer promises, a hiring tool that has been rejecting applicants, a drafting aid that has been inserting clauses. The Air Canada decision shows a company held to its bot’s words. The EEOC’s iTutorGroup settlement shows a company held to its screening rule. Neither will be labelled “AI litigation” in the target’s disclosure schedule unless someone asks the operational question: where do automated words or automated rejections touch a person?
Claims you may inherit in the market. If the target has told its customers or its investors that a product is AI-powered in a way the product is not, you are buying a statement. The SEC’s March 2024 cases against advisers who described AI they did not run are the template. Read the website as an examiner would. The FTC’s guidance on AI claims is a useful checklist for the buyer’s counsel, not only for the seller’s marketing team.
| What the inventory will not show | What you are actually buying | The question that prices it | If the answer is empty |
|---|---|---|---|
| A consumer subscription a supervisor pays for | Dependence. The process stalls when the login walks | Which revenue or cost process stops if this account disappears on day one? | Transition risk. Budget a sanctioned path before close, not after |
| A bot that has been offering remedies, or a screener that has been rejecting people | Liability already incurred | Where do automated words or automated rejections touch a person? | It will not be on the disclosure schedule. Ask the operator |
| “AI-powered” on the site or in the deck | A statement you inherit | Can someone show the capability the adjective describes? | Strike it before the joint press note, or you chose the exhibit |
Questions for the first request list
Ask for the inventory of systems that generate text, scores, or actions used in the business, including experiments. Ask which of them can send, post, or change a record in a system of record. Ask for an example log: one customer answer, one internal decision, with the human who approved it if any human did. If the target cannot produce a single example, the process is not controlled. Price that.
Ask what data has been pasted into tools outside the enterprise agreement in the last year, and whether anyone investigated. Samsung’s experience, reported widely in 2023, is no longer an exotic anecdote. It is a pattern. IBM’s 2025 figures — shadow AI in one in five studied breaches, 97 percent of AI-related breaches lacking access controls — belong in the risk memo even if the target’s own incident log is empty. An empty log may mean an empty practice of looking.
Ask who owns the model outputs as intellectual property, and whether customer data or employee data was used to improve a vendor model under an old click-through. That clause is often in a team’s “free tier” terms, accepted by someone without authority. It is still a fact about the company’s data.
Ask about jurisdictions. A target serving Europeans, hiring globally, or moving personal data into a vendor region needs the privacy answer and, where relevant, the EU AI Act answer. “We will comply closer to the deadline” is not diligence. It is a timetable you must fund after close.
| Request | A complete answer looks like | How an incomplete answer should move price or the plan |
|---|---|---|
| Inventory of systems that generate text, scores, or actions, including experiments | A list with owners, not a strategy slide | Missing experiments are where the habit lives. Assume more than you were shown |
| Which of them can send, post, or change a system of record | Read versus write, per system | Every write without a named approver is a reserve and a temporary human review |
| One example log: a customer answer and an internal decision, with the human who approved | The output, not a description of the output | No example means the process is not controlled. Price that |
| Data pasted outside the enterprise agreement in the last year, and whether anyone looked | An investigation, or an honest “we did not look” | An empty log plus no investigation is an empty practice. Use the IBM base rates in the risk memo anyway |
| Who owns outputs, and whether customer or employee data trained a vendor model under a click-through | The clause, even if someone without authority accepted it | It is a fact about the company’s data. Counsel reads the free-tier terms |
| Jurisdictions: customers, hiring, and where prompts are processed | A region, a basis, and a timetable you can fund | “Closer to the deadline” is a cost after close, not a status |
The Monday after close
Whatever the model said in the investment memo, Monday is a list. Personal accounts that touch customer data, code, or unpublished numbers stop, and a sanctioned account exists the same day. If the account does not exist, do not issue the ban. You will teach the acquired team to hide the habit you just paid for. People already route around bans when the official tool is worse. Give them a path, then close the other one.
Writes pause until an owner and a log exist. Refunds, entitlements, access, public replies. A temporary human review is a cost of close, like a systems freeze. Budget it in the integration plan so it is not “discovered” as a delay. You are on the hook for promises the target’s channel already made. Read the last month of outbound answers before your executives introduce themselves to the target’s customers.
Public claims get a same-week pass by counsel. Anything on the site or the deck that says the product does something you have not seen is either demonstrated or removed before the joint press note. That demonstration is the whole of the regulatory lesson so far. Buyers who leave the adjectives up because marketing is “not an integration workstream” are choosing the exhibit.
| Monday | Do this | Do not do this |
|---|---|---|
| Personal accounts touching customer data, code, or unpublished numbers | Close them the same day a sanctioned account exists | Issue the ban first and provision the path later. The work goes underground |
| Writes: refunds, entitlements, access, public replies | Pause until an owner and a log exist. Fund the human review as a cost of close | Discover the pause as a “delay” after the integration plan is locked |
| The last month of outbound answers | Read them before executives meet the target’s customers | Assume the website matches the contract |
| Public claims | Demonstrate or remove, the same week, before the joint note | Leave the adjective because marketing is not an integration workstream |
Day thirty, in four lines
Report at day thirty with four lines:
- Jobs now written to a log you can reopen.
- Writes still paused, with the reserve beside them.
- Claims struck from the site and the deck because nobody could show them.
- Shadow paths closed only where a sanctioned path exists.
An empty line is the next month’s work. Do not average the four lines into “integration on track.” You inherited the sentences already in the market and the promises already made to customers. The four lines are how you stop inheriting the next month’s as well. Put an operator’s name on each line. A workstream with no name is a risk memo. Names are what make day thirty a plan rather than a status colour. Status colours do not survive a customer complaint.
| Line | Green only if | If it is empty |
|---|---|---|
| Jobs on a log you can reopen | Someone who was not in the deal team can open one customer answer and one internal decision | Next month’s work. Not “on track” |
| Writes still paused, reserve beside them | Refunds, entitlements, access, and public replies have an owner, or they are still paused on purpose | You are issuing promises you cannot reconstruct |
| Claims struck | Every adjective nobody could demonstrate is off the site and the deck | You kept the exhibit |
| Shadow paths | Closed only where the sanctioned path already exists | A ban without a path is a hidden process you paid for |
A call to corporate-development leaders
Put an operator in the diligence room, not only a lawyer and a banker. The operator should sit with a frontline manager and watch a real job run, including the tabs that are not in the architecture diagram. What you see there is part of the asset and part of the liability.
Buy the company you can reconstruct. If you cannot reconstruct how it decides, you do not yet know what you are paying for.
References
- McKinsey, The State of AI: Global Survey 2025
- Microsoft and LinkedIn, 2024 Work Trend Index
- Moffatt v. Air Canada, 2024 BCCRT 149
- EEOC, iTutorGroup settlement
- U.S. SEC press release 2024-36
- U.S. FTC, Keep your AI claims in check
- CNBC, Samsung restricts generative AI
- IBM newsroom, 30 July 2025
- Regulation (EU) 2024/1689
About Nimbus
Nimbus is a Collaborative AI Operating System built around four core pillars that bring human teams and autonomous AI together into a single, unified workspace.
Communication: Keep context tied to the job. Unify emails, meeting recordings, transcripts, and operational files directly within active projects—ending knowledge silos buried in private inboxes, scattered Slack threads, or unrecorded calls.
Collaboration: Work alongside AI in real time. Bring people and AI agents onto the exact same brief, visual canvas, or initiative. Query company-wide data, invite agents into live calls, and co-create in one shared space—eliminating the split between human group chats and isolated AI sidebars.
Automation: Put routine workflows on autopilot. Connect more than 2,000 enterprise tools and standardize repetitive operations. Background loops run on schedules or data triggers with full execution logs, ensuring operational knowledge is shared across the team rather than trapped in one person’s head.
Governance: Deploy AI with absolute control. Enforce strict role-based access controls across workspaces. AI agents can analyze, summarize, and draft—but no live system changes or external communications occur without explicit, verified human sign-off.
Unlogged prompts are part of the price
What does traditional diligence miss?
The unlogged prompts that now shape prices, claims, and product decisions. Contracts and code do not show that.
Why is that a purchase-price issue?
You may be buying a way of working that cannot be reconstructed, plus the customer and regulatory exposure that comes with it.
What should a buyer ask for?
Where assistants are allowed to act, what they have changed, and whether those changes can be replayed after the people leave.
See what governed AI looks like on your stack.
Connect your tools, run a workstream, and keep every decision on your ledger. Start on Free.