[ MSP.DD ] AI due diligence for investors
Model, moat or wrapper?
Find out what an AI company really owns before you pay for it. In five working days we answer what it built versus rents, what its code hides, what it costs to run, and what the EU AI Act will ask of it.
Fixed price from €7,500. Read-only access under NDA. A report a partner can read in fifteen minutes.
[ MSP.DD.01 ] The four questions
Every report answers four questions.
01
Is the AI real?
What the company built versus what it rents from OpenAI, Anthropic or an open model. Could a competent team rebuild it on an off-the-shelf model within a quarter?
02
Is the code safe?
How much code was AI-written and what it left behind: vulnerabilities, risky dependencies, leaked secrets, licence problems, and who actually understands it.
- How risky is AI-generated code in an acquisition target?
- How do you measure how much of a codebase was written by AI?
- Why check a target's code for leaked secrets?
- What open-source licence risks show up in tech due diligence?
- How do you assess dependency vulnerabilities in a target's codebase?
- How do you check key-person risk in a startup's codebase?
03
What does it cost to run?
Model and hosting cost per customer today and at ten times the usage, and what happens if the main provider changes its price or retires a model.
04
What's the regulatory exposure?
Which EU AI Act risk class each product falls in, which obligations already apply, and which dates are coming.
[ MSP.DD.02 ] Why it matters
AI claims are in every deck. The risks are in the code.
45%
of coding tasks where AI models introduced a security flaw, in Veracode's 2025 tests of 100+ models
Source86%
of 965 commercial codebases contained vulnerable open source, per Black Duck's 2025 analysis
SourceA standard technical due diligence with a specialist firm costs $35,000–95,000 and takes two to four weeks, so on smaller rounds it often gets skipped. That is where AI risk goes unpriced.
[ MSP.DD.03 ] The offer
Fixed price. Fixed scope. Five working days.
Free AI Code Scan
Anyone with a public GitHub repository
€0
Under a minute
How much recent work carries AI-tool markers, which AI providers the code depends on, and known vulnerabilities in its dependencies.
AI Due Diligence
VC funds, small-cap PE, family offices, angel syndicates
From €7,500
5 working days
The four questions answered with evidence, a red, amber or green verdict per area, the issues to raise in negotiation, and a 60-minute readout.
Founder Readiness Check
Founders before a round
From €3,500
5 working days
The same analysis on your own code, plus a fix list ranked by what an investor would flag first.
Portfolio AI Review
PE and VC funds
From €15,000 for up to 5 companies
2–3 weeks
Each portfolio company scored on AI risk and on where AI can add value, with a plan for the ones worth building in.
[ MSP.DD.04 ] How it runs
Five working days from access to readout.
Day 1
Access and kickoff
Read-only repository access under NDA, the technical documents in the data room, and the questions that matter for this deal.
Days 2–3
Evidence
Scans of code, dependencies, secrets and licences. The architecture map: what's built, what's rented. The cost model per customer.
Day 4
Interviews
The CTO and the product lead. Every answer is checked against the evidence from days 2 and 3.
Day 5
Report and readout
A verdict per area, the evidence behind it, and the issues to raise in negotiation. A 60-minute readout with your deal team.
We build AI systems for a living, so we know where they break. We read the code, not a checklist. We don't give legal or financial advice and the report isn't a certification: issues that need a lawyer go to yours.
[ MSP.DD.05 ] Questions investors ask
The questions, answered.
The due diligence itself
Is the AI real?
Is the code safe?
- How risky is AI-generated code in an acquisition target?
- How do you measure how much of a codebase was written by AI?
- Why check a target's code for leaked secrets?
- What open-source licence risks show up in tech due diligence?
- How do you assess dependency vulnerabilities in a target's codebase?
- How do you check key-person risk in a startup's codebase?
What does it cost to run?
[ MSP.DD.06 ] FAQ
Before you ask.
- What is AI due diligence?
- A review of an AI company before you invest in it or buy it. It answers four questions: what the company built versus what it rents from model providers, what the code hides, what the product costs to run, and what the EU AI Act will ask of it. It sits next to financial and legal due diligence and covers what they don't.
- How long does it take?
- Five working days from the day we get access. The report gives a red, amber or green verdict per area, the evidence behind it and the issues to raise in negotiation, followed by a 60-minute readout.
- What does it cost?
- From €7,500, fixed before we start. Published ranges for a standard technical due diligence with a specialist firm run from $35,000 to $95,000 over two to four weeks.
- What access do you need?
- Read-only access to the code repositories under NDA, two interviews (usually the CTO and the product lead), and the technical documents in the data room. If the company won't share code, we work from interviews and documents and say so in the report.
- What happens to the company's code?
- Access is read-only. Code is stored in the EU, deleted 30 days after delivery, and never used to train models.
- How is this different from a standard technical due diligence?
- A standard review covers architecture, scalability and the team. We cover those too, and add the AI-specific questions: how much is rented from model providers, how much code was AI-written and what that left behind, model cost per customer, and the EU AI Act. And it takes five working days, not two to four weeks.
- Do you give legal advice or certify anything?
- No. We flag issues for your lawyers, such as licence conflicts or an AI Act classification question. The report is evidence and judgement, not legal advice, financial advice or a certification.
- Can founders buy it?
- Yes. The Founder Readiness Check runs the same analysis on your own code before a round, from €3,500, with a fix list ranked by what an investor would flag first.
- What does the free scan check?
- For a public GitHub repository: how many of the last 100 commits carry AI-tool markers, which AI providers the code depends on, known vulnerabilities in its dependencies, committed environment files, and how concentrated the authorship is. It reads public data only.
Start with the free scan.
Paste a public GitHub repository and see how much recent work carries AI-tool markers, which AI providers it depends on, and its known dependency vulnerabilities. For a live deal, email us and we'll scope it the same day.
Sources