Skip to main content

Investment Technology Note

AI diligence in 2026: what investors should test before underwriting the upside

A practical investor framework for distinguishing credible AI value creation from roadmap optimism, vendor dependency and disruption risk.

Published 1 October 20268 minInvestment teams, operating partners and portfolio boards

Key takeaways

What this means for investors

  • AI diligence should test the business case, data, architecture, model/tool choices, team capability and governance together.
  • The investor needs to assess AI upside and AI disruption risk at the same time.
  • Third-party model access can accelerate delivery but may also create dependency, margin and defensibility questions.
  • Governance should be proportional to materiality, not bolted on after deployment.

Continue the discussion

Related Novarra capability

This topic maps to AI & Technology Readiness Assessment.

Start with the investment thesis, not the model

A&M's 2026 diligence survey found AI increasingly embedded in both diligence workflows and investment theses. That makes 'AI readiness' a financial and strategic question before it is a technical one.

The first test is whether AI changes a material part of the thesis: revenue growth, gross margin, operating leverage, product differentiation, customer retention, time-to-market or competitive defense. If the expected value is immaterial, the diligence effort should stay proportionate. If the expected value is material, the underlying assumptions need evidence.

Test six layers of the AI case

  • Use case: What user or operating problem is AI expected to solve, and how is value measured?
  • Data: Is the required data available, lawful to use, sufficiently reliable and properly owned?
  • Architecture: Can the product and integration model support AI safely and economically at scale?
  • Models and vendors: What is proprietary, what is third-party, and where are pricing or continuity dependencies?
  • People and operating model: Who owns model quality, evaluation, security, product outcomes and ongoing monitoring?
  • Governance: What controls apply to privacy, security, bias, explainability, human oversight and model change?

Separate adoption from defensibility

Crosslake's current AI diligence framing distinguishes internal AI capability from disruption and defensibility. That distinction matters because rapid adoption of third-party AI can improve productivity without creating durable differentiation.

Investors should ask what advantage survives if competitors gain access to the same underlying models, tooling and infrastructure. The answer may sit in proprietary data, workflow integration, customer trust, distribution, domain-specific evaluation, operating know-how or simply superior execution—but it should be explicit.

Treat governance as an execution enabler

SDAIA's AI Adoption Framework and 2026 National AI Risk Management Framework emphasize responsible adoption, human capability, privacy, security, accountability and risk monitoring. NCA's 2026 AI cybersecurity consultation likewise places governance, defense, resilience and third-party risk around AI systems.

For investors, this supports a practical principle: governance should protect the value-creation programme from avoidable data, security, model and third-party failures. It should be designed into the delivery model, not added only when a board or customer raises a concern.

Translate the findings into underwriting

  • Which AI benefits are already evidenced versus still assumed?
  • What additional capex or operating cost is required to achieve the plan?
  • Which dependencies could change unit economics or delivery timing?
  • Which governance or data gaps are conditions to scale rather than background observations?
  • What belongs in the first 100 days after close?

Sources

Sources below support the factual and market-context statements in this note. Novarra's recommendations and questions are analytical interpretation, not claims made by the source organizations.

  1. European Due Diligence Report 2026 — Alvarez & Marsal, 2026-08-11
  2. Practices — AI & Data / AI diligence — Crosslake
  3. AI Adoption Framework — Saudi Data & AI Authority
  4. SDAIA Publications — National AI Risk Management Framework — Saudi Data & AI Authority, 2026-04-01
  5. AI Cybersecurity Guidelines public consultation — National Cybersecurity Authority, 2026-07-05

Turn the insight into a decision.

If the issue is material to a live transaction or portfolio company, the next step is to define the evidence required and the decision the work needs to support.

← Back to all insights