Between 2015 and 2016, IBM assembled Watson Health through acquisition: Truven Health Analytics for $2.6 billion, Merge Healthcare for $1.0 billion, Phytel and Explorys for undisclosed amounts — at least $3.6 billion in disclosed deal value, buying data, algorithms, and the promise of AI-driven healthcare. IBM announced the exit in January 2022; by the time its Q2 2022 10-Q recorded the transaction that summer, the healthcare data and analytics assets had gone to Francisco Partners for $1,065 million. Six years, roughly a $2.5 billion haircut on the disclosed purchases alone, and one of the clearest lessons in modern M&A: the AI you buy is not always the AI you think you bought.
That lesson used to apply only to deals where AI was the asset. Not anymore. Every target you look at today contains AI — in its product, in its internal tooling, in its vendor stack — whether the CIM mentions it or not. And since the EU AI Act, some of that AI is classified regulatory risk with obligations that transfer to you at closing. Standard due-diligence question lists ask about none of it.
The AI a seller claims is now a fraud question
Start with the simplest failure mode: the AI doesn't exist.
In March 2024, the SEC brought its first "AI-washing" enforcement actions — Delphia and Global Predictions paid $400,000 in combined penalties for marketing AI capabilities they didn't have. Then-chair Gary Gensler was blunt: they "marketed to their clients and prospective clients that they were using AI in certain ways when, in fact, they were not." In January 2025 came the first AI-washing action against a public company: Presto Automation, whose "AI voice ordering" turned out to need human intervention — off-site workers — on more than 70% of orders. And in April 2025 it turned criminal: the SEC and DOJ charged the founder of Nate Inc., which had raised over $42 million on the claim of AI-automated checkout with ">90% automation." The actual automation rate: essentially zero, per an internal Nate message cited in the SEC's complaint. The orders were completed manually by overseas contractors.
The escalation path — civil penalty, public-company action, criminal charges — tells you where regulators stand. For a buyer it means something more practical: a seller's AI claims now need the same verification discipline as its financial statements. "Our platform uses machine learning" is a representation. Test it in the demo, in the code, and in the reps.
Liability transfers with the keys
The second failure mode is buying AI liabilities you didn't inventory.
The precedent logic is already settled in data security. Marriott bought Starwood in 2016; Starwood's reservation system had been compromised since 2014; the UK ICO fined Marriott — the acquirer — £18.4 million, and stated in its penalty notice that due diligence on acquired data operations is "not time-limited or a 'one-off' requirement." Verizon repriced Yahoo by $350 million before closing over breach disclosures. I covered how this mechanism plays out for plant systems in the OT blind spot in manufacturing M&A; the AI Act now builds the same transfer mechanism for AI systems.
And the price tags are real — and slow to close. Anthropic's settlement with authors over training data — $1.5 billion, roughly $3,000 per claimed work — is the going benchmark for what unclear data provenance can cost, and a lesson in how long that exposure stays open: preliminary approval came in September 2025, but the final fairness hearing on 14 May 2026 ended without sign-off — the judge withheld final approval pending supplemental briefing on late opt-outs and fees — and a group of authors including Dave Eggers opted out entirely to pursue their own suit. Nearly a year after 'preliminary,' the number still isn't final. If the target's models were trained on data it can't show rights to, that exposure doesn't stay with the seller. It's in the box you're buying.
The deadline moved — the liability didn't
Most published deal guidance hasn't caught up here, so let's be precise about what actually changed.
In June 2026, the European Parliament (16 June) and the Council (29 June) gave final legislative approval to the Digital Omnibus on AI; Official Journal publication — the last formality before entry into force — was still pending as this went to press. Once in force, it moves the compliance dates for high-risk AI systems: obligations for stand-alone high-risk systems under Annex III now apply from 2 December 2027 (previously 2 August 2026), and for high-risk AI embedded in regulated products (Annex I) from 2 August 2028. Most AI Act guidance circulating right now — including pieces updated in 2026 — still shows the old dates.
That doesn't mean relief. Three things I'd have every deal team hold onto:
- Already in force: the prohibited-practices rules and AI-literacy duties (since 2 February 2025), and the general-purpose AI rules plus the penalty regime (since 2 August 2025). Article 99 sets the fine ceilings: up to €35 million or 7% of worldwide turnover for prohibited practices; up to €15 million or 3% for most other violations — and a third tier, up to €7.5 million or 1%, for supplying false information to regulators, the one that touches deal reps and disclosure schedules directly.
- Still landing 2 August 2026: the Article 50 transparency duties — chatbot disclosure and synthetic-content marking.
- The moved date lands inside your integration window. A deal signed in 2026 with a 12–18 month integration plan hits 2 December 2027 mid-integration. The compliance work you didn't price at signing becomes integration scope you fund later.
Three AI due diligence questions that surface what you're buying
Standard DD lists ask about ERP versions and IP assignments. These three questions — askable in any process, answerable from the data room plus one management session — surface the AI layer instead. They're the companion to the five OT questions from part one of this series.
1. Where does AI hide in this company? Three places, and the CIM typically mentions only the first: the product (features marketed as AI — now a verification target, see above), the internal tooling (Microsoft's 2024 Work Trend Index found 75% of knowledge workers already use AI at work and 78% of them bring their own tools — the target's employees are running AI the target never sanctioned), and the vendor stack (Gartner expects 40% of enterprise applications to ship with task-specific AI agents by the end of 2026, up from under 5% in 2025). IBM's 2025 Cost of a Data Breach report puts a number on the second category: one in five studied organizations had a breach linked to shadow AI, at an average $670,000 of additional breach cost. Separately, of the 13% that reported a breach of an AI model or application directly, 97% lacked proper AI access controls. An AI inventory across all three places is the artifact to demand. Platforms like Credo AI can maintain that inventory once they're wired into the target's environment — but that's the catch: they inventory what the target already lets them see, post-close, with cooperation. Pre-close, with no access and no mandate, you're back to asking and reading the answers. And if the target can't produce an inventory at all, you've learned it has never enumerated its own AI use — the operating model behind AI governance starts at exactly that intake-and-inventory stage.
2. Does anything in that inventory map to Annex III? This is where ordinary mid-market targets surprise their buyers. Annex III's high-risk categories include AI used for recruitment and candidate filtering (4(a)), promotion and termination decisions (4(b)), creditworthiness evaluation (5(b)), and life and health insurance pricing (5(c)). The screening module inside the target's applicant-tracking system is enough to put it in scope. High-risk classification brings the full compliance program — risk management (Art. 9), logging (Art. 12), human oversight, conformity assessment — on the December 2027 clock you now own.
3. Who is the provider — and does the deal flip the role? The AI Act splits duties between providers (who develop or place systems on the market under their own name, Art. 3(3)) and deployers (who use them, Art. 3(4)). Deployers carry lighter duties. But Article 25(1) contains the trap for acquirers: put your name or trademark on a high-risk system already on the market, substantially modify one, or repurpose a system so it becomes high-risk — and you become the provider, inheriting the full provider obligations. Rebranding the target's AI product under your house brand post-close is exactly that first trigger — Article 25(1)(a). My evidence test for this question is short: ask for the logs. Article 12 requires high-risk systems to log events automatically across their lifetime; Article 26(6) requires deployers to retain those logs at least six months. No logs, no compliance story — and no way to know what the system did before you owned it.
Finding the AI is the cheap part. Converting what you find into deal mechanics — reps that survive, escrow language, a remediation line in the model, an integration plan that doesn't trip Article 25 — is the due-diligence work itself, and it belongs in the same workstream as the plant systems and the ERP.
If there's a deal on your desk with AI anywhere in it — which is to say, if there's a deal on your desk — that's a conversation, not a pitch.
Next in this series: the Dutch Cyberbeveiligingswet enters into force on 15 August — and why a target's NIS2 compliance state transfers to the buyer, with the board personally in scope.
Sources & further reading
- IBM Q2 2022 Form 10-Q (Watson Health assets divestiture, $1,065M) — SEC EDGAR, 2022
- IBM Watson Health to acquire Truven Health Analytics for $2.6B — IBM Newsroom, 2016
- Merge Healthcare acquisition announcement ($1.0B) — SEC EDGAR, 2015
- SEC charges Delphia and Global Predictions for AI-washing ($400k) — U.S. Securities and Exchange Commission, March 2024
- SEC order: Presto Automation — SEC, January 2025
- SEC litigation release: Nate Inc. / Albert Saniger — SEC, April 2025
- Marriott International Penalty Notice (£18.4M) — UK Information Commissioner's Office, October 2020
- Verizon–Yahoo amended agreement ($350M reduction) — SEC EDGAR, February 2017
- Judge grants preliminary approval to Anthropic's $1.5B authors settlement — CNBC, September 2025
- Little drama at Anthropic's settlement hearing (final approval withheld pending briefing) — Publishers Weekly, May 2026
- Council gives final green light to AI omnibus — Council of the EU, June 2026
- EU AI Act regulatory framework (amended application dates) — European Commission, 2026
- Regulation (EU) 2024/1689 (AI Act) — consolidated text — EUR-Lex, 2024
- Article 25: Responsibilities along the AI value chain — EU AI Act Explorer (Regulation (EU) 2024/1689), 2024
- Article 26: Obligations of deployers of high-risk AI systems — EU AI Act Explorer, 2024
- Annex III: High-risk AI systems — EU AI Act Explorer, 2024
- Microsoft & LinkedIn Work Trend Index 2024 (75% use AI at work; 78% BYOAI) — Microsoft, May 2024
- Cost of a Data Breach Report 2025 (shadow AI findings) — IBM, July 2025
- Gartner: 40% of enterprise apps will feature task-specific AI agents by end of 2026 — Gartner, August 2025
- M&A in the AI Era (AI representations and warranties) — Skadden, January 2026