[ MSP.DD ] For investors · Updated
AI due diligence checklist for investors
Short answer
Four questions cover most of the risk: Is the AI real? Is the code safe? What does it cost to run? What's the regulatory exposure? Each one maps to evidence you can check in the repository, the bills, the contracts and a short interview with the CTO.
Why it matters
AI claims now sit in almost every deck, and most AI projects never reach a measurable P&L impact. A short, evidence-based checklist separates the companies that own something from the ones that rent it.
The checklist
- 01Is the AI real: architecture map, the rebuild-in-a-quarter test, proprietary data and the rights to it.
- 02Is the code safe: the AI-written share, review practice, dependency vulnerabilities, secrets in the history, licences and key-person risk.
- 03What it costs to run: model and hosting cost per customer, margin at 10× usage, and provider dependency.
- 04Regulation: EU AI Act risk class and dates, GDPR touchpoints and the required documentation.
- 05Team: who understands each core part, and who has shipped production systems before.
Red flags
- Answers that can't be matched to evidence.
- Model costs nobody tracks.
- Security-sensitive code with no tests.
Good signs
- The company can show evidence for each answer within a day.
- Costs, risks and dates are already written down.