Back to InsightsResearch

Beyond Caremark: AI Oversight in M&A Due Diligence

By James WaddellApril 16, 202610 min

Beyond Caremark: AI Oversight in M&A Due Diligence

BoardSight Research Brief · Reading time: 10 minutes Category: Research · Published: April 16, 2026 · Author: James Waddell, Cognitive Corp


Abstract

Mergers and acquisitions concentrate governance risk at a single point in time: the closing. When the acquired organization's AI posture is weak, the acquirer inherits the Caremark liability, the D&O exposure, the regulatory non-conformance, and the reputational tail — often without having priced any of them. Through 2024 AI diligence in M&A was a line item inside the IT workstream. In 2025 and 2026 it has become a separable workstream with its own scope, its own document list, and its own veto on closing. This brief documents what AI due diligence actually covers in 2026, where valuations are moving as a result, how boards should structure their diligence oversight, and why the target's governance posture has become a first-order valuation variable. The thesis: AI diligence is no longer about verifying a capability claim. It is about pricing an unpriced governance liability.


1. The shift from capability diligence to governance diligence

Until recently, AI-oriented diligence focused on capability: does the target's AI actually work, is the IP clean, are the data rights in order? Those questions remain, but the 2026 shift is toward governance: does the target have a management system, a conformance posture, an incident history, a vendor portfolio, and a disclosure posture that the acquirer can integrate without inheriting a Caremark gap?

The inflection has several drivers.

Inherited liability. A successor corporation inherits the predecessor's fiduciary exposure. A board approving a transaction in which the target has an undisclosed AI governance gap is approving the acquirer's inheritance of that gap — which becomes an acquirer-board Caremark problem on day one post-close.

Disclosure continuity. Item 1C cybersecurity disclosures and AI-related risk factors carry forward. A target with a weaker disclosure posture forces the combined entity to either match the stronger of the two or disclose the delta, which can create its own securities exposure.

Regulatory integration. The EU AI Act, NIST AI RMF profiles, and sector-specific AI guidance require operational continuity. An acquired entity mid-remediation does not reset the clock on regulatory obligations. The acquirer inherits the mid-stream position and the deadline that was already counting down.

Insurance continuity. D&O, cyber, and E&O towers do not automatically reprice on close. The acquirer's existing tower may not cover AI exposure originated at the target, and the target's tower may lapse in the integration window. The governance gap becomes a coverage gap.

Each of these is knowable in diligence. None of them are knowable by reading the target's marketing collateral.

2. What a modern AI diligence workstream actually covers

An AI diligence workstream in a 2026 transaction of any material size covers ten areas:

1. AI policy and governance structure. Is there a written, board-approved AI policy? Who has oversight? When was it last reviewed?

2. Management system posture. Is the target ISO 42001 certified, mapped, or neither? Is there a NIST AI RMF profile? Is there a Statement of Applicability?

3. AI system inventory. A complete catalog of AI systems developed, deployed, and consumed — with risk classification, lifecycle stage, and business-unit ownership.

4. AI impact assessments. Methodology used, systems assessed in the past 24 months, outcomes, and unresolved findings.

5. Incident log. All AI-related incidents in the past 24 months, with classification, resolution status, disclosure history, and regulatory reporting.

6. Vendor AI contracts. The target's material GPAI and AI-service vendor contracts, with specific attention to EU AI Act flow-down clauses, audit rights, termination rights, and data provenance terms.

7. Training data provenance. For any AI the target has trained or fine-tuned, the provenance of training data, consent basis, and exposure to IP claims (including the unresolved generative-AI copyright landscape).

8. Fairness and bias posture. Testing methodology, results, and remediation status for any model affecting consumer-facing or employment-related decisions.

9. Regulatory disclosure history. 10-K, 10-Q, and proxy disclosures related to AI over the past three years, with particular attention to materiality calls and risk factor evolution.

10. Litigation and regulatory inquiry exposure. Active, threatened, and closed matters related to AI use, including subpoenas, CIDs, and regulator inquiries.

A diligence package with fewer than these ten items is not a complete AI diligence. It is a pre-governance diligence that assumes the question doesn't matter.

3. Where valuations are moving

The directional effect on valuation is consistent across transactions we have observed:

Targets with strong governance posture (ISO 42001 certified or equivalent, clean incident log, modern vendor contracts, documented impact assessments) command valuation premiums in the 3-8% range relative to comparable targets without the posture — because acquirer counsel can represent that governance liability has been priced rather than unpriced.

Targets with weak posture trade at discounts or under indemnification structures — holdbacks, escrow arrangements, or specific reps extending the indemnity period for AI-originated claims. We have seen specific AI reps carved out for 18-24 months post-close, with separate indemnification caps, in several transactions.

Deals collapse on AI diligence findings with enough frequency that specialized diligence vendors have emerged. The pattern is consistent: the issue is rarely that the target is doing something wrong, it is that the target cannot produce the documentary record that demonstrates it is doing something right.

Strategic acquirers price more conservatively than financial acquirers on AI governance — because strategic acquirers are integrating into their own conformance posture and cannot absorb a mismatched target without pulling their own posture down.

4. The acquirer board's role

AI diligence is not a management workstream the board delegates entirely. It is a board-oversight workstream because the liability being priced is board liability. The board's specific responsibilities in a material transaction:

Scope the AI diligence workstream at kickoff. The transaction committee should explicitly require an AI diligence workstream with the ten areas above as scope, and name the advisors conducting it.

Receive a governance posture read-out before signing. The board should see, before the signing meeting, a posture summary: target's conformance posture, material gaps, indemnification mitigation, and residual exposure post-close.

Require an integration plan for the governance gap. Before closing, the acquirer's own governance leadership should produce a 100-day and 12-month integration plan for bringing the target's AI operations into the acquirer's management system.

Update the combined-entity disclosure posture. The first 10-K or equivalent after close should reflect the combined entity's AI posture. The board should see the disclosure language before the filing.

Reassess D&O and insurance posture. Prior to close, the acquirer's risk committee should validate that the D&O tower covers the combined entity's AI exposure, and that gaps are addressed through tower adjustments or run-off coverage on the target's tower.

A board that does these five things has turned AI diligence from a source of hidden liability into a priced component of the transaction.

5. The emerging category: "governance-ready" targets

In 2026 a new kind of target is becoming visible in market diligence: organizations that have invested in governance specifically to be attractive acquisition targets. These are typically mid-market organizations that have run a formal AI governance program, achieved ISO 42001 certification or mapping, and produced a complete AI system inventory — investments that cost $200K-$1M depending on scale.

The payoff is visible in valuation. Strategic acquirers will pay multiple times the investment cost for the governance posture, because it eliminates diligence risk and accelerates integration. Financial acquirers will pay because the governance posture makes the eventual flip cleaner.

The market is beginning to reward governance as an asset on the balance sheet. Boards of mid-market organizations should be asking whether a governance investment is a defensive compliance cost or an offensive valuation lever. Increasingly it is both.

6. The "reverse diligence" question

One pattern is worth calling out explicitly: the target's board sometimes conducts reverse diligence on the acquirer's governance posture. This happens in transactions where the target has sensitive AI exposure (healthcare, defense, consumer trust-critical) and the target's board is concerned about the acquirer's ability to maintain governance standards post-close.

The pattern is not universal but it is growing. Target boards in these sectors increasingly ask for the acquirer's AI policy, incident history, and management review cadence before agreeing to proceed. A target board that does not ask these questions in 2026 is leaving its own fiduciary exposure on the table.

7. Implication for BoardSight clients

BoardSight runs AI diligence engagements in two modes. Buyer-side engagements scope the ten-area workstream, produce a target posture summary, and deliver an integration plan that maps to the acquirer's existing management system. Seller-side engagements produce the documentary package a sophisticated buyer will request, often as a precursor to a process launch.

For boards approaching a material transaction in 2026, the question is not whether AI diligence belongs in the deal. It does. The question is whether the board will scope the diligence explicitly enough to price what is being bought — and document that pricing well enough to satisfy Caremark on both sides of the transaction.


Further reading inside the BoardSight library: ISO 42001 for Boards: The Operational Companion to Caremark · The D&O Pricing Shift: How AI Failures Are Being Underwritten in 2026 · The Board AI Competency Gap: A Diagnostic Framework for Director Capability · EU AI Act Article 55 (GPAI): The Obligations Your Board Hasn't Read

Sources referenced: Delaware M&A jurisprudence on successor liability; Marchand v. Barnhill, 212 A.3d 805 (Del. 2019); In re Boeing Co. Derivative Litigation (Del. Ch. 2021); SEC Item 1C Cybersecurity Disclosure Rule; ISO/IEC 42001:2023; EU AI Act (Regulation 2024/1689); NIST AI Risk Management Framework 1.0; ABA M&A Committee guidance on AI due diligence (2025).

B
BoardSight

The AI Oversight Practice from Cognitive Corp.

Standards

NIST AI RMF 1.0ISO/IEC 42001:2023EU AI ActCOSO ERM

BoardSight provides independent, board-ready oversight evidence and advisory support. It does not provide legal opinions, regulatory certification, statutory audit assurance, or a guarantee that an AI system is safe or compliant.

© 2026 Cognitive Corp. All rights reserved.

BoardSight · AI Governance · Three Lines for AI