Acquiring an AI Company? The Training-Data Diligence That Determines What You Actually Own

By Laith Sarhan

Business Transactions Data Protection & Cybersecurity

The standard technology diligence playbook was built for a different asset. IP assignment agreements, invention-assignment confirmations, data privacy policy review, cybersecurity posture — that checklist assumes the target's core asset is code, and that code's provenance is settled by employment contracts and clean-room development. When the target is an AI company, none of those assumptions hold. What you're actually buying is some combination of trained models, proprietary datasets, fine-tuning pipelines, and contractual rights to third-party models and data — most of which is undocumented, and some of which may not be the target's to sell.

Deal counsel reading this: this is the diligence layer your technology specialists and IP counsel don't cover, because it sits at the intersection of privacy law, copyright, and contract — and it is where AI deal risk actually lives. The workstreams below are the difference between discovering problems in diligence and discovering them in a post-closing indemnity fight.

1. Training Data Provenance

The threshold question: what data trained the models, and does the target have rights to it that survive the transaction? You're asking for documentation of how each training corpus was obtained — licensed (check field-of-use and sublicensing), scraped (check robots.txt/opt-out compliance and the jurisdiction's text-and-data-mining posture), customer-derived (check consent and DPA terms), or synthetic (check the upstream model's provenance — synthetic data inherits chain-of-title problems one level removed). Major firm guidance now treats training-data rights as fundamental representations in the purchase agreement — the kind that survive longer and carry larger caps — precisely because they can't be verified from the target's own assurances. The litigation backdrop matters: Thomson Reuters v. Ross Intelligence, Bartz v. Anthropic (US$1.5B settlement on the pirated-copies claim), and pending Canadian cases (a BC proposed class action against MosaicML/Databricks, and Canadian news media v. OpenAI in Ontario) mean the acquirer isn't just buying a model — it's buying a position in an unsettled legal landscape. (For the full review framework, see the chain-of-title piece.)

2. The Proprietary-vs-Dependency Map

How much of the "AI" is actually the target's? Acquirers increasingly find the intelligence layer is a thin wrapper over a foundation model API, with the differentiation living in prompts and workflows that are neither owned nor defensible. Map it: proprietary models and weights (owned how, trained on what), fine-tunes of third-party models (does the provider's agreement give the target rights in the fine-tuned artifact, and are those rights assignable?), and pure API dependencies (what happens to unit economics and capability if the provider reprices, deprecates, or cuts off?). A target whose core capability depends on another company's model on non-assignable enterprise terms has a different valuation than its revenue multiple suggests.

The target's customer contracts and privacy policy promised something about how customer data would be used — does that promise survive your ownership? In Canada, PIPEDA's business-transaction exception (s. 7.2) permits transfer without consent for the transaction, but post-closing use is limited to the purposes for which the information was originally collected (see the companion piece on PIPEDA diligence in acquisitions). If your thesis involves using the target's customer data in new ways — training your models, cross-selling into your portfolio, feeding your analytics — that's a new purpose requiring its own consent basis, and the acquisition price should reflect the gap. Quebec-based targets add s. 18.4 of Quebec's Private Sector Act (the commercial-transaction exception) with its own agreement requirements.

4. Contract Portability

Two directions, both commonly missed.

Vendor-side: the target's AI vendor agreements (model APIs, data licenses, cloud) — do they have change-of-control or assignment clauses that let a provider terminate or renegotiate on closing? A data license that terminates on change of control is a deal-critical finding.

Customer-side: the target's customer MSAs and DPAs — same question in reverse, plus whether enterprise customers have consent rights on assignment that could trigger churn or renegotiation leverage at the worst moment.

5. Regulatory and Litigation Exposure

Beyond the copyright landscape: does the target's product fall in scope of the EU AI Act's high-risk categories (obligations for which began applying August 2, 2026 under the current baseline, with a pending Digital Omnibus package that may adjust dates — verify against the Official Journal)? Any regulator correspondence, complaints, or inquiries (OPC, provincial commissioners, the CAI in Quebec, the FTC)? Any pending or threatened claims over outputs, training data, or customer data use? Any open-source license contamination in the model pipeline? And the governance question buyers now ask as a valuation input: does the target have an actual AI governance program — documented accountability, human-review workflows, incident history — or a policy PDF with nothing behind it?

How the Findings Hit the Deal

Diligence findings translate into deal mechanics, not just memos:

For Sellers' Counsel (and Founders Reading This Backwards)

Every finding above is cheaper to fix before the data room opens than during exclusivity. The seller-side version of this piece — what to build into your data room — is The AI M&A Data Room. The short version: a target that can produce a training-data provenance schedule, a dependency map, and a consent-quality audit on day one of diligence closes faster and at a better number than one that assembles them under deadline pressure.

Last updated: August 2026. This article is educational and does not constitute legal advice. Transaction-specific diligence should be scoped with counsel; the litigation and regulatory landscape described here is moving quickly.

FAQ

What should due diligence on an AI company cover that standard tech diligence doesn't?

Five things: training data provenance (does the target have rights that survive the transaction), a proprietary-vs-dependency map (how much of the "AI" is actually owned vs. rented from a model provider), customer data consent travel (whether post-closing uses exceed original collection purposes), contract portability (change-of-control and assignment clauses in AI vendor and customer agreements), and regulatory/litigation exposure (EU AI Act scope, pending copyright claims, regulator correspondence, governance posture).

Can the buyer rely on the seller's representations about training data rights?

Representations allocate risk; they don't verify it. Major firm guidance treats training-data rights as fundamental reps precisely because they can't be confirmed from the target's assurances — the underlying facts (how corpora were obtained, what licenses say, whether opt-outs were honoured) require document-level review. A rep without diligence behind it is a bet on the indemnity, and indemnities are only as good as the seller's ability to pay them.

Does PIPEDA allow customer data to transfer with an acquired business?

Yes, under the s. 7.2 business-transaction exception — with conditions (a written agreement, safeguards, necessity, and post-closing notification to individuals). But post-closing use is limited to the purposes for which the information was originally collected. Using the acquired database for new purposes (training the buyer's models, cross-selling) requires its own consent basis. Quebec adds s. 18.4 of the Private Sector Act with its own conditions.

What happens to a target's AI vendor agreements on acquisition?

Whatever the change-of-control and assignment clauses say — which is why they're a diligence item. Model API agreements, data licenses, and cloud contracts may terminate, require consent, or trigger renegotiation on a change of control. A data license that dies at closing can be a deal-critical finding; discover it in diligence, not integration.