Maine Street Partners

[ MSP.DD ] AI due diligence for investors

Model, moat or wrapper?

Find out what an AI company really owns before you pay for it. In five working days we answer what it built versus rents, what its code hides, what it costs to run, and what the EU AI Act will ask of it.

Fixed price from €7,500. Read-only access under NDA. A report a partner can read in fifteen minutes.

[ MSP.DD.01 ] The four questions

Every report answers four questions.

01

Is the AI real?

What the company built versus what it rents from OpenAI, Anthropic or an open model. Could a competent team rebuild it on an off-the-shelf model within a quarter?

03

What does it cost to run?

Model and hosting cost per customer today and at ten times the usage, and what happens if the main provider changes its price or retires a model.

04

What's the regulatory exposure?

Which EU AI Act risk class each product falls in, which obligations already apply, and which dates are coming.

[ MSP.DD.02 ] Why it matters

AI claims are in every deck. The risks are in the code.

45%

of coding tasks where AI models introduced a security flaw, in Veracode's 2025 tests of 100+ models

Source

35%

of private repositories in GitGuardian's research contained plaintext secrets

Source

86%

of 965 commercial codebases contained vulnerable open source, per Black Duck's 2025 analysis

Source

€35M / 7%

maximum EU AI Act fine for prohibited practices, whichever is higher

Source

A standard technical due diligence with a specialist firm costs $35,000–95,000 and takes two to four weeks, so on smaller rounds it often gets skipped. That is where AI risk goes unpriced.

[ MSP.DD.03 ] The offer

Fixed price. Fixed scope. Five working days.

Free AI Code Scan

Anyone with a public GitHub repository

€0

Under a minute

How much recent work carries AI-tool markers, which AI providers the code depends on, and known vulnerabilities in its dependencies.

AI Due Diligence

VC funds, small-cap PE, family offices, angel syndicates

From €7,500

5 working days

The four questions answered with evidence, a red, amber or green verdict per area, the issues to raise in negotiation, and a 60-minute readout.

Founder Readiness Check

Founders before a round

From €3,500

5 working days

The same analysis on your own code, plus a fix list ranked by what an investor would flag first.

Portfolio AI Review

PE and VC funds

From €15,000 for up to 5 companies

2–3 weeks

Each portfolio company scored on AI risk and on where AI can add value, with a plan for the ones worth building in.

[ MSP.DD.04 ] How it runs

Five working days from access to readout.

  1. Day 1

    Access and kickoff

    Read-only repository access under NDA, the technical documents in the data room, and the questions that matter for this deal.

  2. Days 2–3

    Evidence

    Scans of code, dependencies, secrets and licences. The architecture map: what's built, what's rented. The cost model per customer.

  3. Day 4

    Interviews

    The CTO and the product lead. Every answer is checked against the evidence from days 2 and 3.

  4. Day 5

    Report and readout

    A verdict per area, the evidence behind it, and the issues to raise in negotiation. A 60-minute readout with your deal team.

We build AI systems for a living, so we know where they break. We read the code, not a checklist. We don't give legal or financial advice and the report isn't a certification: issues that need a lawyer go to yours.

[ MSP.DD.05 ] Questions investors ask

The questions, answered.

[ MSP.DD.06 ] FAQ

Before you ask.

What is AI due diligence?
A review of an AI company before you invest in it or buy it. It answers four questions: what the company built versus what it rents from model providers, what the code hides, what the product costs to run, and what the EU AI Act will ask of it. It sits next to financial and legal due diligence and covers what they don't.
How long does it take?
Five working days from the day we get access. The report gives a red, amber or green verdict per area, the evidence behind it and the issues to raise in negotiation, followed by a 60-minute readout.
What does it cost?
From €7,500, fixed before we start. Published ranges for a standard technical due diligence with a specialist firm run from $35,000 to $95,000 over two to four weeks.
What access do you need?
Read-only access to the code repositories under NDA, two interviews (usually the CTO and the product lead), and the technical documents in the data room. If the company won't share code, we work from interviews and documents and say so in the report.
What happens to the company's code?
Access is read-only. Code is stored in the EU, deleted 30 days after delivery, and never used to train models.
How is this different from a standard technical due diligence?
A standard review covers architecture, scalability and the team. We cover those too, and add the AI-specific questions: how much is rented from model providers, how much code was AI-written and what that left behind, model cost per customer, and the EU AI Act. And it takes five working days, not two to four weeks.
Do you give legal advice or certify anything?
No. We flag issues for your lawyers, such as licence conflicts or an AI Act classification question. The report is evidence and judgement, not legal advice, financial advice or a certification.
Can founders buy it?
Yes. The Founder Readiness Check runs the same analysis on your own code before a round, from €3,500, with a fix list ranked by what an investor would flag first.
What does the free scan check?
For a public GitHub repository: how many of the last 100 commits carry AI-tool markers, which AI providers the code depends on, known vulnerabilities in its dependencies, committed environment files, and how concentrated the authorship is. It reads public data only.

Start with the free scan.

Paste a public GitHub repository and see how much recent work carries AI-tool markers, which AI providers it depends on, and its known dependency vulnerabilities. For a live deal, email us and we'll scope it the same day.

Sources

  1. Veracode, 2025 GenAI Code Security Report (press release, 30 July 2025)
  2. GitGuardian, The State of Secrets Sprawl 2025
  3. Black Duck, 2025 Open Source Security and Risk Analysis (press release)
  4. EU AI Act, Article 99 (penalties)
  5. Papermark, Technical due diligence