AI Due Diligence: From Tech DD to a 100-Day EBITDA Plan

For most of private equity's history, value came from two levers: financial engineering and operational improvement. A third has now joined them, and it is moving quickly. AI due diligence in private equity is no longer a niche line in the technology workstream. It is becoming part of the investment thesis itself. The firms doing this well are not only asking whether a target's technology is sound. They are asking whether the business is ready to use AI to grow margin, and they are turning the answer into the first hundred days of ownership. This is a practitioner's guide to what that looks like, written from the deal side.

AI Due Diligence: From Tech DD to a 100-Day EBITDA Plan - Richard Keenlyside, Fractional CIO, CTO and CISO
AI Due Diligence: From Tech DD to a 100-Day EBITDA Plan

What AI due diligence actually means now

There are two halves to it, and they are easy to confuse.

The first half is assessing the target. How exposed is this business to AI disruption? Does it have the data and the technology foundations to adopt AI effectively? And does management have a credible, costed plan, or a slide that says “AI” with nothing behind it? This is where most of the value for an investor sits. The question underneath all of it is simple: is this a company that can use AI to grow, or one about to be undercut by a competitor that can.

The second half is using AI to run the diligence itself: compressing the read of a data room, contracts and expert-call transcripts, with proper traceability back to source. This is genuinely useful and it is becoming standard, but it does not replace judgement. It surfaces better questions faster. It does not answer them for you.

A board or an investment committee should be clear which half a diligence provider is actually doing. Tooling that reads the data room quickly is not the same as an operator who can tell you whether the AI roadmap will hold.

The six things to test before you sign

A modern technology due diligence has to answer six questions about AI specifically, on top of the usual architecture, security and technical-debt review:

  1. Data quality and rights. Is the data a genuine moat, is it clean enough to build on, and is it lawfully usable under UK GDPR and PECR? Unique, compliant datasets command a valuation premium. Data that cannot be used, or was gathered without proper consent, is a liability dressed as an asset.
  2. Use-case-to-EBITDA line of sight. Are the AI initiatives tied to measurable outcomes on a realistic horizon, or is this AI for its own sake? The test I apply is whether each bet has a visible line to EBITDA within roughly six months.
  3. Talent and adoption. Can the organisation actually run what it buys? A capable tool in an organisation that will not adopt it returns nothing.
  4. Technology and data foundations. Without clean data and sound architecture, AI initiatives stall between pilot and production. This is the single most common reason the promised value never lands.
  5. Governance and responsible-AI risk. Bias, transparency, model provenance and the regulatory horizon. By 2026 this is non-negotiable, not a nice-to-have, and a weak position here can affect both valuation and exit timing.
  6. Disruption exposure. Could AI erode this company's own revenue model, pricing power or switching costs? Some targets look strong today and are quietly being commoditised.

From red flags to the 100-day plan

The most important shift is that diligence is no longer only a risk register. Its findings should pre-load the value-creation plan.

Where the diligence shows AI can drive early margin, that becomes a day-one initiative with an owner and a number against it. Where it needs investment or patience, that is priced into the plan rather than discovered in month nine. Done properly, the deal team walks into the first hundred days with a short list of validated use cases, not a backlog of unknowns. That is the difference between diligence as insurance and diligence as a head start.

This is also why the people doing the diligence matter. A report that lists risks is easy to write. A plan that says “these three things will move EBITDA, in this order, with these owners” requires someone who has actually delivered the work.

Why most AI bets miss, and how to pick the ones that do not

The uncomfortable statistic behind every AI value-creation plan is that the large majority of corporate generative-AI pilots fail to deliver measurable value. MIT's research has put the figure as high as 95 per cent. The reasons are consistent: no clear line of sight to value, weak or unusable data, and an organisation that never adopts the tool.

The discipline, then, is restraint. Back only the use cases with a measurable line to EBITDA on a short horizon, grounded in foundations the diligence has actually validated. Not every win needs a custom build. A well-deployed off-the-shelf assistant in finance or service operations can pay back faster than a bespoke model that takes a year to ship. The job in diligence is to separate the bets that will convert from the ones that sound impressive in a management presentation.

Where an independent operator adds what the big firms cannot

The large advisory firms and the new diligence-tooling vendors cover this territory well in the abstract. What a deal team often lacks is someone who has personally run the diligence and then owned the delivery.

I have conducted technology due diligence on 23 acquisition targets, led 15 private-equity carve-outs and TSA exits, and integrated twelve mergers. I have also delivered the kind of AI and automation that a 100-day plan promises, including around 75,000 hours of annual capacity released through robotic process automation and pragmatic AI. The value I bring to a diligence is not the report. It is knowing which findings will actually convert into EBITDA, because I have had to convert them myself, on the other side of the deal.

This complements, rather than replaces, the broader technology due diligence a sponsor runs. It adds the operator's read on whether the AI story is real.

A final word

In a market paying premium multiples for scarce quality assets, deeper diligence is how sponsors justify the price and protect the return. Bringing an operator's eye to the AI question, before the deal and into the first hundred days, is one of the cheapest forms of insurance available, and one of the most reliable sources of early value.

I help private-equity sponsors with pre-deal technology and AI-readiness diligence and with the post-deal value creation that follows. Book a confidential conversation via the contact page.

Frequently asked questions

What is AI due diligence in private equity?

It is the part of technology diligence that assesses how ready a target is to use AI to grow and how exposed it is to AI-driven disruption. Increasingly it also uses AI tools to accelerate the diligence process itself, with traceability back to source.

How do you assess a target's AI readiness before a deal?

By testing data quality and rights, whether AI use cases have a clear line to EBITDA, the organisation's ability to adopt, the strength of its technology and data foundations, its governance and responsible-AI posture, and its exposure to AI disruption.

What should technology due diligence cover in 2026?

The traditional review of architecture, security and technical debt, plus an explicit AI-readiness assessment and a view on whether unmitigated technology risk could erode target value, which can run to 20 to 30 per cent in the worst cases.

How does AI-readiness diligence feed the 100-day value-creation plan?

Findings that show where AI can drive early margin become day-one initiatives with owners and numbers. Items that need investment are priced in. The deal team starts ownership with validated use cases rather than a list of unknowns.

Can AI realistically deliver EBITDA growth within six months?

Yes, but only for use cases with a clear line to value, clean data and genuine adoption. The realistic test is whether each initiative can show measurable impact within about six months. Most failed pilots fail because they never had that line of sight.

What AI risks should a sponsor check before acquiring a company?

Data provenance and compliance, model bias and transparency, over-reliance on tools the organisation cannot run, regulatory exposure, and the risk that the target's own model is being disrupted by AI rather than strengthened by it.