Maine Street Partners

[ MSP.DD ] For investors · Updated

AI due diligence checklist for investors

Short answer

Four questions cover most of the risk: Is the AI real? Is the code safe? What does it cost to run? What's the regulatory exposure? Each one maps to evidence you can check in the repository, the bills, the contracts and a short interview with the CTO.

Why it matters

AI claims now sit in almost every deck, and most AI projects never reach a measurable P&L impact. A short, evidence-based checklist separates the companies that own something from the ones that rent it.

The checklist

  1. 01Is the AI real: architecture map, the rebuild-in-a-quarter test, proprietary data and the rights to it.
  2. 02Is the code safe: the AI-written share, review practice, dependency vulnerabilities, secrets in the history, licences and key-person risk.
  3. 03What it costs to run: model and hosting cost per customer, margin at 10× usage, and provider dependency.
  4. 04Regulation: EU AI Act risk class and dates, GDPR touchpoints and the required documentation.
  5. 05Team: who understands each core part, and who has shipped production systems before.

Red flags

  • Answers that can't be matched to evidence.
  • Model costs nobody tracks.
  • Security-sensitive code with no tests.

Good signs

  • The company can show evidence for each answer within a day.
  • Costs, risks and dates are already written down.

The numbers

  • MIT NANDA's 2025 report found that 95% of organisations get no measurable P&L return from their generative AI pilots. [1]
  • AI models introduced security flaws in 45% of Veracode's 80 test tasks. [2]
  • 86% of commercial codebases in Black Duck's 2025 analysis contained vulnerable open source. [3]

Sources

  1. MIT NANDA, The GenAI Divide: State of AI in Business 2025
  2. Veracode, 2025 GenAI Code Security Report (press release, 30 July 2025)
  3. Black Duck, 2025 Open Source Security and Risk Analysis (press release)