The new line in the CIM
Every second CIM now carries an AI claim. "AI-powered platform." "Proprietary machine learning." "Agentic workflows across the business." Sometimes it is true and material to value. More often it is a thin wrapper, a pilot that never scaled, or a marketing decision.
Deal teams are well equipped to test revenue quality and customer concentration. Testing AI claims is newer territory, and the information asymmetry favours the seller. I spent almost a decade on the buy side before moving into building these systems, and these are the checks I wish deal teams had used.
Red flags in the claims
"AI-powered" with no named process. Real AI deployments attach to specific workflows: claims triage, pricing, document intake. If management cannot name which processes are automated and what they cost before and after, there is no evidence of an operating system.
Capability described in demos, not usage. A demo proves the system can work once, with the founder driving. Ask instead for usage data: how many transactions ran through the system last month, unattended, in production. Throughput shows whether the capability extends beyond the demonstration.
"Proprietary model" from a 40-person company. Training genuinely proprietary models is expensive and rarely rational at mid-market scale. Most defensible AI in this segment is excellent engineering on top of foundation models plus proprietary data. That is fine, and often better. The red flag is the claim itself, because it suggests management doesn't understand its own stack.
AI revenue that is actually services revenue. Look for AI features that are configured, operated or cleaned up by humans on the payroll. If gross margin on the "AI product" looks like an agency's margin, price it like an agency.
Red flags in the diligence room
No baseline metrics. A business that deployed AI seriously will have before-and-after numbers, because measurement is how the deployment got funded. Without a baseline, either the impact was never measured or it was not worth measuring.
Key-person AI. Ask who maintains the systems. If the answer is one engineer, or worse, a founder's side project, you are buying a dependency, and your hold-period plan needs to price in rebuilding it properly.
The data doesn't support the story. AI systems depend on data. If diligence finds fragmented systems, spreadsheet-based operations and no data governance, the existing AI will be fragile. This cuts both ways: it undermines the seller's claims and shows the real cost of your own post-acquisition AI plans.
Vendor lock-in dressed as capability. "Our AI" sometimes means a per-seat subscription to a third-party tool that any competitor can buy tomorrow. Check the contracts. Capability you can't own or differentiate shouldn't earn a multiple.
The upside read
Red flags are only half the exercise. The same diligence lens finds underpriced upside, and this is where AI diligence earns its place in the model rather than just the risk register.
A target with clean data, measured processes and no AI deployment is often more attractive than one with flashy AI claims: the raw material is there and the value creation is yours to capture rather than already priced in. We covered the mechanics of running diligence itself faster with AI in a separate piece; this one is about what you are looking at, not how fast you look.
Three questions that cut through
Ask these questions in the management presentation:
- "Which processes run without a human in the loop today, and at what monthly volume?" The answer separates production systems from pilots.
- "What did this process cost before the AI, and what does it cost now?" A credible impact claim needs this baseline.
- "If your AI engineer resigned tomorrow, what breaks?" The answer reveals key-person risk and whether the capability is institutionalised.
Management teams with real systems can answer in detail. If the discussion shifts back to demos or broad claims, the diligence team has identified the gap it needs to investigate.