// wiki · guide · September 2026
Due diligence of an AI asset
Draft article. A check map for a deal with an AI company; the scope and depth of the check are set by the structure of the specific deal.
A draft for discussion. The article describes the buyer's logic of the check; for a founder the same list is a readiness checklist for a round or a sale.
The short answer
The value of an AI company is the model, the data and the team, not only code and contracts. A standard legal check barely sees these assets: rights to model weights, dataset provenance and the retention of the people who created all of it are checked in separate blocks. Missing any one of them turns buying a technology into buying a risk.
Six blocks of checks
1. Rights to the model and the code
The whole chain is checked: who owns the architecture, the trained weights, the code and the prompt libraries. Key points: works made for hire (Article 1370 of the Civil Code) — are assignments and acceptance acts executed; contracts for work (Article 1296) — do the results of freelancers and agencies belong to the company; development before the company existed — did the founder assign the rights; registrations of programs and databases with Rospatent — as evidence in disputes.
2. Datasets
The data provenance log: sources, licences, consents, restrictions. Contested categories: platform extractions without permission or a licence, personal data without grounds, someone else's databases in full. Details — in the article “Training a model on someone else's works”.
3. Third-party licences and open source
SBOM — the list of components with licences. Focus: GPL/AGPL in server code, “source-available” with commercial restrictions, SDKs with unclear terms — see “Open source in a company product”.
4. Regulatory requirements
Ad labelling if generations take part in promotion; compliance with 152-FZ; the trade secret regime (extractions to public AI services are already the subject of court practice, see “AI and trade secrets”); the map of mandatory product requirements — “Map of AI regulation”.
5. The team
A model without the people who know how to fine-tune it is a box without a key. Checked: options and ESOP (executed, vesting, pool), non-competes and NDAs, dependence on one or two key engineers, rights to side developments.
6. Client contracts
Who owns generations and client data under the contracts; liability caps for model errors; quality warranties (uptime, accuracy); the right to assign contracts when the company's owner changes.
Red flags
| Flag | Why it is expensive |
|---|---|
| Dataset without a provenance history | Rightsholders' claims pass to the buyer together with the model |
| Key code from a freelancer without an assignment of rights | The company does not own its own product |
| AGPL in a SaaS runtime | The duty to open the sources or rewrite the component |
| Client generations owned by no one under the contract | A rights dispute with the largest clients right after closing |
| All knowledge about the model in one employee's head | One person's departure devalues the asset |
Warranties and the price of the question
What is found is not always a dealbreaker: usually it is a negotiation. Instruments: representations and warranties with indemnity for losses, separate indemnities for datasets and licences, escrow of part of the price until remediation, carving out problematic assets. But these instruments only work where the risks have been found and named — which is why the check matters more than the wording of the contract.
Checking an AI asset and supporting the deal is the task of deals and investments practice; the team assembles a checklist for the specific deal structure after an enquiry.