Executive Leadership

AI Due Diligence When the Target Runs on Agents: What the Legal Checklists Miss

The AI due diligence checklists I have read were written by law firms, and it shows. They are careful about who owns the model. None of them ask who owns the job that emails the renewal list to the sales team at 6 a.m., or whose credit card pays for it.

October 8, 20266 min read

A company you are about to buy may have no proprietary model at all. It can still depend on agents for half of what its operations team does every week.

That second company is the normal case now, and it is the one diligence is worst at. I think about this from two seats. As CEO of Visiting Media I would be the person answering these questions in a data room, and as a director at ACT | The App Association I am the kind of person who should be asking them. I also run a fleet of specialized agents across my own operating work, which means I know exactly which parts of it would look terrible to a buyer on a bad day.

What the standard checklists cover

The guides that rank for this topic read like one long memo split across several firms. Orrick’s widely shared list of ten considerations walks through the technology and how it was built and tested, the team and how to retain it, data protection, the target’s governance model, risk allocation in customer and supplier contracts, then cybersecurity and sector regulation. It closes with the transaction documents: regulatory review, AI-specific representations and warranties, and whether warranty and indemnity insurance will cover any of it. Other versions add training-data bias, open-source licenses inside the code, and the gap between how fast companies adopt AI and how slowly the rules arrive.

Your counsel will run all of that. They should.

All of it treats AI as an asset the target owns, like a patent or a codebase. Fine as far as it goes. An agent that reconciles vendor invoices every Thursday night has no IP worth fighting over, and if it stops the week after closing, the finance team is short a person nobody budgeted for.

The agents might leave at closing

Start here, because it is the failure that costs the most and gets found the latest.

In a young company, a lot of automation runs on the founders’ personal accounts. The API key is on someone’s personal card, the workflow tool is logged in under their personal email, and the schedule lives in a service the company has never been billed for. Everyone involved knows this, and none of it appears in a contract schedule, because nobody thinks of it as a contract. When that founder walks away with their earnout a year later, the agents either stop or keep running on an account the buyer cannot see. I wrote about the second outcome in retiring an AI agent, and it is worse than the first.

So the first request I would put on the diligence list is a schedule of every scheduled or autonomous model call, with the account it runs on and who pays for it. Then I would check that schedule against expense reports, which is the same trick I recommend for finding shadow AI agents inside your own company. A small recurring charge from a model vendor filed under software is often the only paper trail an agent leaves.

Ask for the register, then test it

A well-run target will have a fleet register: every agent, its named human owner, what it can read, what it can change, and who consumes its output. Mine has a named owner on every line, and my delegation matrix was still wrong within six weeks of writing it, when an agent picked up a vendor integration nobody thought to log.

Having one is a good sign. It proves very little on its own.

Pick a handful of entries at random and ask to speak with the named owners. Each owner should be able to say what the agent does in two sentences, what it touched last week, and what would happen if it were turned off tomorrow. An owner who has to go look it up is an owner on paper. Then ask the operations leads to name the automations they rely on, and see how many of those are missing from the register. The gap between those two lists tells you more about the target than the register itself.

Ask for the retirement log

A company that has never turned an agent off has never really looked at its agents.

Check the model calendar against the first hundred days

Model providers retire old versions on their own schedule. If the target’s core workflows are pinned to a model version that the provider retires shortly after closing, the integration team inherits an unplanned migration in the same quarter it is trying to merge payroll systems.

Ask which model versions each production agent runs on, when the provider has said those versions go away, and whether the target keeps frozen evaluation sets to tell whether a replacement is as good. A target that runs real change control on model upgrades can answer in an afternoon. One that cannot will learn about quality drift from its customers, after you own it.

Read the incidents, and how they were handled

Every fleet has bad nights. One of my agents published a fabricated claim at 2:14 one morning, and what I learned from it became my AI incident playbook. I would want a buyer to read that postmortem, because it says more about how I run the fleet than any architecture diagram.

Ask for agent incident postmortems going back as far as the target has them. Zero is a red flag. The useful questions are whether customers were told, how long containment took, and whether anything in the system changed afterward or someone just wrote a stern note in a channel.

Turn what you find into deal terms

None of this is useful unless it shows up somewhere in the agreement or the integration plan. I am not a lawyer, and the drafting belongs to people who are. But I would ask counsel for two things that the standard AI representations tend to leave out.

  1. A disclosure schedule of every agent with write access to customer-facing or financial systems, including whose credentials it uses.
  2. A pre-closing covenant to move those agents onto company-owned accounts, with the buyer able to verify the move before money changes hands.

Put agent owners in the retention plan too. The standard checklists already tell you to keep the AI team, but the person who quietly keeps the invoice agent alive is usually in finance, nowhere near that team.

The covenant matters most. Moving credentials sounds like a chore for the week after closing, and in practice it is the step that finds every agent nobody disclosed, because the ones left on personal accounts stop working and someone in operations notices.

For directors approving the deal

The board deck for an acquisition usually has a technology slide, and it is usually about the product. I would ask management for one more page, built from the diligence findings in roughly the shape of the AI page in the board pack: how many production agents the target runs, how many sit on personal credentials, how many will have no owner on the first day after closing, and which model retirements land inside the integration window.

If management cannot produce that page, the company has not done operational AI diligence, whatever the legal memo says. It belongs next to the vendor concentration questions in what boards should ask about AI, and it is exactly the kind of question a technology board advisor can push on without anyone feeling ambushed. Diligence has always tried to find out what actually runs a company and on whose account. Agents make that older question harder to answer, and a lot more expensive to get wrong.

This article is part of the Executive Leadership cluster, focused on board governance and the operating discipline required to run AI systems responsibly at the executive level.

Related Reading