Guide

AI Due Diligence: How It Works and What It Cannot Do

AI due diligence is the use of language models to screen deal documents for risk signals, producing scored, ranked findings that a human team then verifies. It replaces the first read, not the judgement. This guide covers how the workflow changes, what automated screening genuinely cannot do, how to evaluate a tool, and the confidentiality questions to settle before uploading anything.

What AI due diligence actually means

AI due diligence is the use of language models to screen deal documents for risk signals, producing a scored, ranked set of findings that a human team then verifies. It replaces the first read, not the judgement.

The distinction matters because the term is used loosely. Three quite different things get called AI due diligence:

  • Document screening — scoring uploaded documents across defined risk categories and surfacing the passages that triggered each finding. This is the mature use, and the one that removes the most analyst time.
  • Document Q&A — asking questions of a data room and getting cited answers. Useful, but it answers questions you already knew to ask.
  • Diligence of AI — assessing a target's own AI systems: model and vendor dependency, training-data provenance, EU AI Act classification. A different activity that happens to share the name, covered under AI & tech governance.

How the workflow changes

The bottleneck in diligence has never been analysis. It is reading. A mid-market data room holds thousands of pages, and deciding which of them contain something worth escalating consumes analyst time out of all proportion to the difficulty of the task.

StageTraditionalScreened first
First passAnalysts read everything, flagging as they goEvery document scored across risk categories
PrioritisationEmerges from reading, lateAvailable before reading starts
ConsistencyVaries by reviewer, fatigue and time of daySame rubric applied to every document
Human effortSpread evenly across all documentsConcentrated on documents that scored
Audit trailReviewer notes, variableScore, triggering language and timestamp per document

The order of operations inverts: from read everything, then decide what matters to score everything, then read what scored.

What it does not do

Automated screening does not verify anything independently, conduct primary research, interview management, inspect a site, or exercise legal and accounting judgement. Treating a risk score as a diligence conclusion is a category error — the score tells you where to look, not what to think. Any vendor implying otherwise is describing a product that does not exist.

Three specific limits worth holding onto:

  1. It reads what it is given. A risk absent from the data room is absent from the output. Screening does not detect omission, which is why absence of disclosure should itself be treated as a finding rather than a pass.
  2. It is a screening pass, not a verification pass. A finding is a pointer to a document and a passage. Confirming what it means, and what it is worth, remains human work.
  3. Confidence is not accuracy. Fluent output reads as authoritative regardless of whether it is right. This is the reason findings should always be returned with the quoted source language, so a reviewer can check the basis rather than the assertion.

Evaluating an AI due diligence tool

Questions that separate products in practice:

  1. Does it quote its evidence? A finding without the source passage cannot be verified, and an unverifiable finding is a liability rather than an asset.
  2. Is the rubric fixed and inspectable? Consistency across documents is the main advantage over human review. It only holds if the same categories and thresholds are applied every time, and if you can see what they are.
  3. What happens to long documents? Model context limits are real. Ask specifically whether a 300-page filing is processed in full or truncated, and whether truncation is disclosed on the output.
  4. How is absence handled? A category with no findings should be distinguishable from a category that was never covered.
  5. Is client data used for training? For deal documents this is a threshold question, not a preference.
  6. Is there a real audit trail? Who accessed what, when, and what the system concluded — retained in a form that survives the transaction.
  7. Is tenant isolation enforced below the application layer? Application-layer filtering is one bug away from a cross-client leak. Ask what the second layer is.

The confidentiality question

Deal documents are among the most sensitive material a company handles, and the objection to putting them through any external system is legitimate. The things worth establishing before uploading anything:

  • Training. Whether documents are used to train models. Enterprise API terms generally prohibit it; consumer interfaces frequently do not.
  • Encryption at rest, and the key model. Whether every client shares a key or each engagement has its own derived key.
  • Isolation. Whether one client's data can reach another through an application bug, or whether the database enforces separation independently.
  • Identifier handling. Whether personal identifiers are stripped before text reaches a model.
  • Retention and deletion. What is kept, for how long, and whether deletion is real.
  • Access control and audit. Whether roles are enforced per deal room, and whether every access is logged immutably.

Anweshna's own answers to these are set out on the platform overview: per-client keys derived for each engagement, row-level isolation enforced in the database independently of application logic, identifier stripping before text reaches the model, no training on client data, and an append-only audit trail.

Where it fits, and where it does not

Strong fit: large document volumes, repeated screening against a consistent rubric, portfolio or bolt-on programmes where the same categories are assessed deal after deal, and first-pass triage under time pressure in a competitive process.

Weak fit: single-document questions a lawyer answers in ten minutes, matters turning on negotiation history rather than documents, and any situation where the material has not been reduced to writing. Screening cannot read a room.

Frequently asked questions

What is AI due diligence?

AI due diligence is the use of language models to screen deal documents for risk signals, producing scored and ranked findings that a human team then verifies. It automates the first read - deciding which documents contain something worth escalating - rather than the judgement about what those findings mean or what they are worth.

Can AI replace due diligence?

No. Automated screening does not verify anything independently, conduct primary research, interview management, inspect sites, or exercise legal and accounting judgement. It structures and accelerates the initial screening pass so reviewers start with a ranked queue instead of an undifferentiated pile. Treating a risk score as a diligence conclusion is a category error.

Is it safe to upload confidential deal documents to an AI tool?

It depends entirely on the arrangement. Establish whether documents are used to train models, whether data is encrypted at rest and under whose key, whether tenant isolation is enforced below the application layer, whether personal identifiers are stripped before text reaches the model, what the retention and deletion policy is, and whether access is logged immutably. Enterprise API terms generally prohibit training on inputs; consumer interfaces frequently do not.

How accurate is AI document screening?

The useful question is not accuracy in the abstract but whether a finding can be verified. A screening tool should return the quoted source passage that triggered each finding, so a reviewer checks the basis rather than the assertion. Fluent output reads as authoritative whether or not it is correct, which is why evidence-linked findings matter more than any headline accuracy figure.

What is the difference between AI due diligence and AI governance due diligence?

AI due diligence means using AI to screen deal documents. AI governance due diligence means assessing a target's own AI systems - model and vendor dependency, training-data provenance, EU AI Act classification, AI supply-chain security. They share a name and are otherwise unrelated activities.

Anweshna Demo