Solutions

Legal Due Diligence of AI Projects

An AI project is a bundle of entities, models, data, products, workers, suppliers and contracts. Legal due diligence tests whether the target can lawfully own, develop, deploy, sell and transfer that bundle — the way an investor, acquirer or partner should test it before reliance. Across North America, the EU, the UK and Switzerland, offshore centres, the Middle East, Asia-Pacific, China and India.

Diligencing a crypto or token project instead? See our Web3 Legal Due Diligence.

Scope a due diligence review
Part 02

North America

United States · Canada
In essence

North American legal due diligence of an artificial intelligence project asks whether the target can lawfully own, train, deploy, sell, and transfer its systems across the United States and Canada. This memorandum gives a transaction baseline as of July 22, 2026. It assumes no identified target, sector, transaction structure, or data room. It focuses on United States federal law, Delaware, California, New York, Colorado, Texas, Illinois, Canadian federal law, Quebec, Ontario, British Columbia, and Alberta. Every other state, province, municipality, and sector regulator connected to the target must be added before a transaction decision.

Executive summary
North America

Incorporation does not define the review. Product access, users, workers, data subjects, training sources, compute, suppliers, regulated uses, and transaction parties create separate legal connections.

United States

No single federal private-sector AI statute governs the whole target. Federal consumer, civil-rights, employment, credit, privacy, copyright, trade-secret, export, sanctions, competition, and investment laws operate beside state and municipal AI statutes.

United States

Executive Order 14365 directs federal challenges and possible preemption measures against selected state AI laws. It does not itself repeal those laws. The target must comply unless a competent court, statute, or valid federal rule displaces them.

United States, states

Diligence must separate current duties from readiness duties. California and Texas rules already apply. California content-provenance duties start on August 2, 2026. Colorado and New York material duties start on January 1, 2027.

Canada

The operative private-sector baseline remains the Personal Information Protection and Electronic Documents Act and applicable provincial statutes. Bill C-36 and Bill C-34 are pending. The former Artificial Intelligence and Data Act never became law.

Canada

Quebec requires special review for privacy impact assessments, transfers outside Quebec, and decisions based exclusively on automated processing. Ontario now requires certain public job postings to disclose AI use. Alberta and British Columbia apply general private-sector privacy statutes.

North America

The target must prove title or licensed rights for code, model components, weights, datasets, prompts, evaluations, documentation, patents, brands, and trade secrets. Public availability does not establish training or commercialization rights.

North America

Consequential decisions require use-case testing. Employment, credit, housing, insurance, healthcare, education, public benefits, children, and biometric uses can trigger overlapping laws, notices, testing, review rights, recordkeeping, and discrimination exposure.

Transaction

Missing core title, unlawful irreplaceable data, a prohibited deployment, a non-transferable critical license, an undisclosed serious incident, or a blocking sanctions or investment issue can stop closing. Curable defects belong in conditions, quantified legacy exposure belongs in price and specific protection.

Analysis by issue

The review must begin with the target's operating facts. A North American AI project may involve a Delaware parent, Canadian research staff, California users, Quebec data subjects, Texas customers, and foreign compute. Each connection can trigger a different statute.

Counsel should prepare six linked inventories. They should cover legal entities, products, models, use cases, data flows, and third parties. Each record needs a version date and an identified owner. The inventories should distinguish development, testing, production, resale, white-label use, and customer modification.

The model inventory should identify architecture, weights, checkpoints, fine-tunes, retrieval sources, safety layers, evaluation sets, and release history. The use-case inventory should state the intended purpose and actual customer use. Marketing labels do not control legal classification.

The jurisdiction matrix should record incorporation, offices, workers, customers, users, data subjects, training sources, compute, storage, support, public procurement, and regulated activities. It should also identify the buyer, financing sources, and post-closing integration. Those transaction facts can trigger foreign-investment, export, sanctions, and data-transfer rules.

Time must form a separate diligence dimension. A current breach differs from a law that starts before closing or shortly afterward. The closing checklist should track enactment, effective date, operative date, transition period, regulations, and pending litigation.

Corporate authority, capitalization, and asset location

The buyer must identify the entity that owns each material asset and owes each material obligation. A consolidated brand or website does not prove common ownership.

For a Delaware corporation, the board manages the business unless the certificate provides otherwise. Del. Code tit. 8, § 141(a). Counsel should verify the certificate, bylaws, board and stockholder approvals, delegations, and signing authority. The review should reconcile stock, options, warrants, SAFEs, convertible notes, side letters, and promised equity.

Interested and controller transactions require current Delaware analysis. Section 144 changed materially in 2025. Del. Code tit. 8, § 144. The records should identify controller rights, conflicts, approvals, disclosures, and fairness procedures. Reliance on old checklists creates avoidable closing risk.

AI groups often split research, customer contracting, payroll, and intellectual property among affiliates. Counsel should test every intercompany assignment, service agreement, license, cost allocation, and cash transfer. The revenue entity may not own the model. The employing entity may not own employee inventions.

Security interests also matter. United States perfection may depend on the asset, debtor location, filing office, possession, or control. U.C.C. arts. 8 and 9. Canadian review must test federal and provincial personal-property security registrations. A blanket lien can cover code, accounts, patents, trademarks, and contract rights.

The corporate record request should include minute books, cap tables, securities instruments, beneficial ownership, liens, intercompany agreements, insolvency indicators, tax residence, and change-of-control approvals. Any mismatch between asset use and legal title needs a closing remedy.

United States federal baseline and federal-state conflict

United States diligence starts with issue-specific federal law. Section 5 of the Federal Trade Commission Act prohibits unfair or deceptive acts affecting commerce. 15 U.S.C. § 45(a)(1). Claims about accuracy, neutrality, privacy, training rights, safety, security, human review, and output ownership require dated support.

A disclaimer does not cure a conflicting headline, demo, sales script, or product design. Counsel should match each material claim to the tested model version, prompts, sample, exclusions, result, and approval. Unsupported claims can affect consumer exposure, contract warranties, disclosure schedules, and valuation.

Federal civil-rights and sector laws apply without an AI label. Title VII governs employment discrimination. 42 U.S.C. § 2000e-2. The Americans with Disabilities Act governs covered employment practices. 42 U.S.C. § 12112. The Equal Credit Opportunity Act governs credit discrimination. 15 U.S.C. § 1691. The Fair Credit Reporting Act can apply to reports, investigations, and adverse employment or credit actions. 15 U.S.C. §§ 1681a, 1681b, 1681d, 1681m.

Children's products require a separate screen. The Children's Online Privacy Protection Act and its amended rule govern covered collection from children under 13. 15 U.S.C. §§ 6501-6506; 16 C.F.R. pt. 312. The 2025 rule became effective on June 23, 2025, with general compliance due by April 22, 2026. It adds material consent, retention, security, and biometric issues.

Executive Order 14365, dated December 11, 2025, directs federal review and litigation against selected state AI laws. Exec. Order No. 14,365, §§ 3-8, 90 Fed. Reg. 58,499 (Dec. 16, 2025). The order also directs possible federal disclosure standards and legislative recommendations.

The order does not itself invalidate a state statute. Section 9 requires implementation consistent with existing law and creates no private right. The FTC's July 2026 AI accuracy statement remains proposed. A pending federal challenge also does not suspend a state law without judicial relief.

Diligence should therefore treat state duties as operative according to their own terms. Counsel should record any challenge, injunction, appeal, regulation, or federal action at signing and closing. A contractual promise to follow only federal law is not a legal defense.

State model-development, disclosure, and frontier duties

California imposes several distinct duties. Civil Code sections 3110 and 3111 require covered generative-AI developers to publish specified training-data information. The disclosure should match actual datasets, data categories, sources, ownership status, personal-data content, collection periods, and modification history.

California's frontier-model statute applies to defined frontier models and large frontier developers. Cal. Bus. & Prof. Code §§ 22757.10-22757.16. Covered large developers must maintain and publish a frontier AI framework, publish model transparency reports, report critical safety incidents, and protect qualifying whistleblowers.

The California review should verify compute thresholds, affiliate revenue, model versions, risk assessments, incident channels, publication history, and internal approvals. A target below the large-developer threshold may still face other California statutes, contracts, tort claims, and sector duties.

The California AI Transparency Act governs specified generative-AI providers. Cal. Bus. & Prof. Code §§ 22757-22757.6. Its detection and provenance duties become operative on August 2, 2026. A transaction closing after that date needs tested tools, supported metadata, public disclosures, and retained implementation evidence.

New York's RAISE Act covers defined frontier-model developers and large developers. N.Y. Gen. Bus. Law art. 44-B. Its material duties start on January 1, 2027. They include safety documentation, reporting, filings, and incident duties. The March 2026 chapter amendment controls the final thresholds and procedures.

Texas's Responsible Artificial Intelligence Governance Act took effect on January 1, 2026. Tex. Bus. & Com. Code ch. 552. It reaches specified development, deployment, products, services, and conduct connected to Texas. It restricts designated harmful uses, government social scoring, biometric misuse, and intentional unlawful discrimination.

Texas gives the attorney general exclusive enforcement authority and provides a cure process. The statute also contains defenses tied to reasonable care and recognized risk-management standards. Counsel should not treat the absence of a private statutory action as the absence of contract, tort, privacy, or civil-rights exposure.

For every model-development statute, counsel should create an actor and threshold memorandum. It should identify the developer, deployer, distributor, owner, modifier, affiliate revenue, compute, release date, public availability, and covered outputs. Group-level thresholds can defeat entity-by-entity assumptions.

Consequential decisions, employment, and access to opportunity

Automated decisions require a separate review for each decision type. One system may rank applicants, price insurance, recommend medical care, and detect fraud. Each use can produce different duties.

Colorado Senate Bill 26-189 starts on January 1, 2027. Colo. Rev. Stat. §§ 6-1-1701 to 6-1-1707, as enacted by 2026 Colo. Sess. Laws ch. 131. It covers defined automated decision-making technology used in consequential decisions.

Covered developers must provide technical documentation about intended uses, training-data categories, known limits, and human review. Covered deployers must give notices and specified adverse-outcome information. They must support correction, reconsideration, and meaningful human review where the statute requires.

The Colorado attorney general has exclusive enforcement authority. The statute does not create a new private action. A federal constitutional challenge to Colorado's prior AI statute remains a separate procedural matter. Diligence must track the challenged provisions, the 2026 replacement text, and any court order.

New York City already regulates automated employment decision tools. N.Y.C. Admin. Code §§ 20-870 to 20-874; 6 R.C.N.Y. §§ 5-300 to 5-304. A covered employer or employment agency needs a recent independent bias audit, a public summary, and required notices before use.

Illinois treats specified discriminatory employment AI use as a civil-rights violation from January 1, 2026. 775 Ill. Comp. Stat. 5/2-102(L). Illinois also requires notice, explanation, and consent before covered AI analysis of video interviews. 820 Ill. Comp. Stat. 42/5.

California's CCPA regulations create phased duties for automated decisionmaking technology. Cal. Code Regs. tit. 11, §§ 7000-7304. Significant-decision ADMT duties begin on January 1, 2027. Separate risk-assessment and cybersecurity-audit dates apply.

Ontario now requires covered employers to disclose AI use in publicly advertised job postings. Employment Standards Act, 2000, S.O. 2000, c. 41, s. 8.4; O. Reg. 476/24. The duty applies from January 1, 2026, subject to the regulation's employee threshold and definitions.

The diligence file should contain system instructions, feature lists, training and validation data, protected-class testing, accessibility testing, notices, audit reports, adverse-action forms, override logs, and appeal records. Counsel should compare the documented process with actual recruiter, lender, insurer, clinician, or agency conduct.

A vendor contract cannot shift all discrimination risk to the customer. The developer's claims, design choices, known limits, and documentation remain relevant. The customer also needs enough information to use the system lawfully.

Canadian federal law and pending legislation

Canada does not have an operative federal private-sector AI statute equivalent to a general AI act. The former Artificial Intelligence and Data Act appeared in Bill C-27. That bill did not become law before the prior Parliament ended.

The federal private-sector privacy baseline remains the Personal Information Protection and Electronic Documents Act. S.C. 2000, c. 5. PIPEDA applies to personal information handled in commercial activities, subject to its territorial and provincial rules. It also reaches employee information in federal works, undertakings, and businesses.

An organization must comply with Schedule 1 and may collect, use, or disclose personal information only for purposes a reasonable person would consider appropriate. PIPEDA, s. 5. Valid consent, limiting collection, safeguards, access, accuracy, retention, and accountability require fact-specific review.

PIPEDA requires reporting and notice when a breach creates a real risk of significant harm. Id. ss. 10.1-10.2. The organization must keep a record of every safeguards breach. Id. s. 10.3. The target's incident register should therefore include non-reportable events and the legal analysis for each decision.

PIPEDA contains a business-transaction exception. Id. s. 7.2. It requires necessity, agreements, limited use, safeguards, and post-transaction steps. It does not authorize unrestricted data-room disclosure or continued use after an abandoned deal.

Bill C-36 received first reading on June 15, 2026. It proposes the Protecting Privacy and Consumer Data Act and a new institutional structure. Bill C-34 received first reading on June 10, 2026. It proposes duties for regulated social media, chatbot, and other online services.

Neither bill is law as of July 22, 2026. Their proposed duties should not appear as current compliance findings. They may support a readiness request when the target's product falls within their proposed scope and the transaction extends beyond enactment.

The federal Directive on Automated Decision-Making governs specified federal administrative decisions. It does not regulate ordinary private business operations. It can affect vendors that sell AI systems to Canadian federal institutions because procurement terms may allocate assessment, testing, explanation, and monitoring duties.

Provincial privacy and automated processing

Quebec requires a separate workstream. The Act respecting the protection of personal information in the private sector, CQLR c. P-39.1, applies to covered enterprises. Its requirements exceed a generic PIPEDA checklist in several areas.

A covered enterprise must conduct a privacy impact assessment before acquiring, developing, or redesigning an information system or electronic service involving personal information. Id. s. 3.3. Counsel should obtain the assessment, approval record, project changes, residual risks, and measures adopted.

Quebec section 12.1 applies when an enterprise renders a decision based exclusively on automated processing. The enterprise must give required notice. On request, it must provide specified information about the personal information used, principal factors and parameters, and correction rights. The individual must have an opportunity to submit observations to a qualified staff member.

A transfer of personal information outside Quebec requires a privacy impact assessment and written agreement. Id. s. 17. The analysis must address sensitivity, purpose, safeguards, and the destination's legal regime. Cloud architecture and support access can create transfers even when the main database remains in Canada.

Quebec also has a business-transaction exception with agreement and use limits. Id. s. 18.4. Administrative monetary penalties can reach the greater of C$10 million and two percent of worldwide turnover for the preceding fiscal year. Id. s. 90.12. Penal exposure can be higher for specified offences.

British Columbia and Alberta have substantially similar private-sector privacy statutes. Personal Information Protection Act, S.B.C. 2003, c. 63; Personal Information Protection Act, S.A. 2003, c. P-6.5. Their application can displace PIPEDA for intraprovincial activity, while PIPEDA remains relevant to interprovincial, international, and federal matters.

Ontario lacks a general private-sector privacy statute comparable to Quebec, Alberta, or British Columbia. PIPEDA usually supplies the commercial baseline. Sector statutes remain material, including the Personal Health Information Protection Act, 2004, S.O. 2004, c. 3, Sched. A.

The Canadian data map should therefore identify the organization, province, commercial activity, sector, employee status, transfer path, and recipient. A single Canada-wide privacy policy does not answer which statute controls each processing activity.

Training data, privacy, and data rights

Data diligence must prove source, permission, purpose, and traceability. Possession of a dataset proves none of those points.

The dataset register should cover pretraining, fine-tuning, retrieval, evaluation, red-team, prompt, log, feedback, and support data. Each entry should identify source, acquisition date, collector, method, license, contract, personal-data content, sensitive fields, children, geography, retention, deletion, and downstream use.

United States privacy law remains sectoral and state based. The target may face California, Colorado, Texas, and other state privacy statutes beside federal health, financial, education, communications, and children's rules. The diligence scope must follow actual data subjects and processing purposes.

The CCPA regulations that took effect on January 1, 2026 create phased risk-assessment, ADMT, and cybersecurity-audit obligations. The California Delete Request and Opt-out Platform began accepting requests on January 1, 2026. Registered data brokers must process covered DROP requests from August 1, 2026.

The DOJ Data Security Program restricts specified covered data transactions involving countries of concern or covered persons. 28 C.F.R. pt. 202. Counsel should test bulk sensitive personal data, government-related data, vendor access, employment access, data brokerage, cloud support, and contractual restrictions.

Canadian consent does not cure an inappropriate purpose. PIPEDA section 5(3) applies even when consent exists. Quebec also requires lawful collection, necessity, transparency, access, security, and purpose controls under its own provisions.

De-identification and synthetic data require technical proof. A label does not establish irreversibility or low reidentification risk. Counsel should inspect generation methods, source linkage, memorization testing, access controls, and contractual restrictions.

Deletion and unlearning promises require system-level evidence. The target should identify affected files, checkpoints, embeddings, vector stores, caches, logs, backups, and customer copies. A contractual deletion clause is weak when the target cannot locate the data.

Intellectual property, training, and outputs

The target must prove a continuous chain of title for each material AI asset. Technical control does not establish legal ownership.

United States copyright initially vests in the author, subject to work made for hire. 17 U.S.C. § 201(a), (b). A copyright transfer generally requires a signed writing. Id. § 204(a). Payment to a founder or contractor does not itself transfer ownership.

Copyright protects original expression. It does not protect ideas, processes, systems, or methods of operation. Id. § 102(a), (b). Model architecture, weights, prompts, datasets, and outputs therefore require asset-specific analysis. Protection may depend on copyright, patent, trade secret, contract, database restrictions, or access controls.

Fair use requires the four-factor analysis in 17 U.S.C. § 107. It does not create a categorical training privilege. Thomson Reuters Enterprise Centre GmbH v. Ross Intelligence Inc., No. 20-613-SB, memorandum opinion (D. Del. Feb. 11, 2025), rejected fair use on competing legal-research facts.

Other training cases remain fact bound and procedurally active. Counsel should not convert one district-court ruling into a universal answer. The relevant facts include source, access, copying method, purpose, output behavior, market effect, retention, and acquisition lawfulness.

United States patent inventorship requires a natural person. Thaler v. Vidal, 43 F.4th 1207, 1213 (Fed. Cir. 2022). Diligence should identify the human conception record, prompt and experiment history, inventor declarations, assignments, and prior disclosures.

Canadian copyright first-ownership and assignment rules require separate review. Copyright Act, R.S.C. 1985, c. C-42, s. 13. The statute contains employee rules and requires a signed writing for assignments and grants of interests. Canada has not enacted a blanket statutory permission for commercial AI training.

Output diligence should separate statutory protection, infringement risk, and contract allocation. Customer terms can allocate risk between parties. They cannot create copyright where governing law recognizes no protectable human authorship.

Trade-secret protection requires secrecy measures. 18 U.S.C. §§ 1836-1839; Uniform Trade Secrets Act as enacted by the relevant state. Canadian protection relies on contract, confidence, equitable principles, and applicable provincial law. The review should test access, repositories, publication, model releases, logging, confidentiality, and offboarding.

Third-party code, models, data, and compute

Every external dependency can restrict commercialization or transfer. The target needs more than a software bill of materials.

The dependency register should cover code, open-weight models, hosted models, datasets, benchmarks, APIs, libraries, cloud services, accelerators, and security tools. Each entry needs the exact version, supplier, accepted terms, paying entity, use, and replacement plan.

Counsel should review commercial scope, field limits, geography, user restrictions, training, fine-tuning, distillation, output terms, redistribution, attribution, source duties, audit rights, suspension, termination, assignment, and change of control. A public repository does not establish unrestricted use.

Open-source and open-weight reviews must examine the actual license and integration method. Copyleft effects depend on distribution, linking, modifications, network access, and governing law. Model licenses may impose acceptable-use limits that do not appear in ordinary software licenses.

Cloud and API agreements need capacity, location, security, data use, training use, model changes, deprecation, price resets, service credits, portability, disaster recovery, and exit support. The target may own its application while lacking a transferable right to the model or compute needed for operation.

Benchmarks and evaluation data also create exposure. Counsel should verify license terms, confidential test sets, contamination controls, score methodology, model version, prompt set, sample, exclusions, and publication approvals.

A critical dependency with no assignment consent or substitute can become a closing condition. A supplier's informal assurance should not replace an executed consent or amended contract.

Product claims, synthetic media, chatbots, and children

Product diligence should compare public claims with product behavior and retained evidence. Websites, decks, demos, model cards, sales scripts, security materials, customer responses, and procurement submissions all matter.

Claims about accuracy, bias, safety, privacy, security, training rights, certifications, human review, output ownership, and benchmark rank require a defined test. The record should identify the model version, test set, sample, prompts, exclusions, threshold, result, date, and approver.

California's content-provenance duties require a separate implementation record from August 2, 2026. The target should test whether metadata survives ordinary distribution, editing, export, and platform handling. Detection tools need documented accuracy and limits.

California also regulates covered companion chatbots from January 1, 2026. Cal. Bus. & Prof. Code §§ 22601-22606. Duties include AI disclosure and specified self-harm protocols. Products accessible to minors face added notices, reminders, and sexual-content controls.

Colorado enacted separate conversational-AI duties with material provisions starting on January 1, 2027. The target should classify whether a chatbot is a general assistant, companion, therapeutic product, customer-support tool, or regulated professional service. Actual interaction design controls.

Texas imposes disclosure and use restrictions for specified government and healthcare interactions. Its prohibited-use provisions require product and intent analysis. A safety policy alone does not prove that production controls match the policy.

Children's diligence should cover age signals, actual audience, app-store classification, advertising, profiling, parental consent, retention, chat history, escalation, crisis responses, and human review. Teen products also require state-law review beyond COPPA's under-13 threshold.

Cybersecurity, incidents, and critical systems

AI security diligence must cover the model, data, application, infrastructure, and suppliers. A conventional penetration test may omit prompt injection, model extraction, poisoning, unsafe tool use, and retrieval manipulation.

Counsel should obtain threat models, secure-development records, privileged-access lists, secrets controls, model registries, dataset controls, vendor access, vulnerability reports, red-team results, release approvals, monitoring, backups, recovery tests, and incident exercises.

The United States federal sector screen should include HIPAA, the Gramm-Leach-Bliley Act, the FTC Safeguards Rule, state breach laws, New York Department of Financial Services rules, defense requirements, and public-contract terms. Exact duties depend on entity and data status.

Canada's Critical Cyber Systems Protection Act received Royal Assent on June 15, 2026. S.C. 2026, c. 9, pt. 2. It addresses designated operators in listed federally regulated vital services, including telecommunications, banking, transportation, energy, nuclear, and clearing systems.

Part 2 comes into force by order of the Governor in Council. S.C. 2026, c. 9, s. 16. No commencement order was verified for this memorandum. Covered targets should still prepare for cyber programs, third-party risk controls, incident reporting, directions, audits, records, and enforcement.

The target should maintain one incident register across legal, security, product, and safety teams. It should include breaches, unsafe outputs, discriminatory outcomes, prompt or weight leakage, data poisoning, model extraction, outages, complaints, claims, and regulator contacts.

Each incident entry should record discovery, affected systems, users, jurisdictions, containment, legal analysis, notices, customer communications, insurance, root cause, remediation, and recurrence testing. Missing or inconsistent incident records can affect warranties and disclosure schedules.

Contracts, revenue quality, and continuity

Contract diligence must prove assent, scope, performance, and transferability. A standard form does not prove which terms a customer accepted.

Counsel should review executed customer, reseller, marketplace, API, clickwrap, procurement, data, research, cloud, and supplier agreements. The record should identify the accepted version, signer authority, order of precedence, amendments, renewal, and incorporated policies.

AI terms should address permitted use, prohibited use, training on customer data, prompts, logs, outputs, confidentiality, security, incidents, model changes, documentation, human review, compliance cooperation, audits, indemnities, caps, exclusions, assignment, termination, and transition.

The terms should match product reality. A clause stating that customers control every decision is unreliable when the target markets autonomous operation. A clause promising no training on customer data is dangerous when logs feed evaluation or fine-tuning.

Revenue quality needs contract-to-ledger testing. Counsel should separate recurring production revenue from pilots, credits, contingent milestones, free use, related-party sales, minimum commitments, and cancellable arrangements.

Continuity depends on compute, key models, and key staff. The review should test reserved capacity, minimum spend, hardware limits, region, price changes, suspension, deprecation, portability, key-person knowledge, and disaster recovery.

Competition, exports, sanctions, and investment controls

Competition review should cover exclusivity, most-favored terms, tying, data access, interoperability limits, pricing tools, information exchange, talent restrictions, acquisitions, and customer concentration. The analysis must use current federal, state, and Canadian law.

The United States export review should classify software, source code, model weights, technical data, chips, servers, cloud access, users, end uses, and destinations. The Export Administration Regulations appear in 15 C.F.R. pts. 730-774. Remote access can constitute a controlled release.

United States sanctions review must test parties, beneficial owners, banks, customers, vendors, locations, services, and payments. Relevant rules appear in 31 C.F.R. ch. V and program-specific authorities. OFAC's 50 Percent Rule can block an unlisted entity based on ownership.

The DOJ Data Security Program adds a separate data-access screen. 28 C.F.R. pt. 202. Its concepts do not replace export or sanctions analysis. The same supplier or employee can create several independent restrictions.

CFIUS review can arise from foreign investment in a United States business involving critical technology, critical infrastructure, or sensitive personal data. 50 U.S.C. § 4565; 31 C.F.R. pts. 800 and 802. Non-controlling rights can matter.

United States outbound-investment rules can cover prohibited or notifiable transactions involving defined artificial-intelligence activities and countries of concern. 31 C.F.R. pt. 850. The review must identify United States persons, controlled foreign entities, joint ventures, fund interests, knowledge, and covered activities.

Canadian exports and technology transfers require review under the Export and Import Permits Act. R.S.C. 1985, c. E-19, ss. 7, 13. Counsel should classify controlled technology, destination, recipient, end use, brokering, and permit status.

Canadian sanctions arise under the Special Economic Measures Act, United Nations Act, Justice for Victims of Corrupt Foreign Officials Act, and program regulations. The administrative consolidated list is not the law. Counsel must read the operative regulation and refresh screening at closing.

The Investment Canada Act can trigger notification, net-benefit review, or national-security review. R.S.C. 1985, c. 28 (1st Supp.), pt. IV.1. Sensitive data, dual-use technology, government links, investor identity, and control rights need early analysis.

Deal grading and transaction protections

Each finding needs a legal consequence, business effect, evidence standard, and deal response. A color without those elements is not useful.

Stop-level findings include missing title to a core model, unlawful irreplaceable training data, a prohibited use, an absent critical license, an unlicensed regulated activity, or a sanctions, export, or investment issue that blocks the planned transaction.

Closing conditions fit defects that can be cured before closing. Common items include assignments, consents, lien releases, regulatory filings, privacy assessments, notices, access cleanup, incident remediation, documentation, supplier amendments, and product suspension.

Price adjustments, escrow, holdbacks, exclusions, specific indemnities, and post-closing covenants fit quantified legacy exposure. General warranties provide weak protection for a known defect. Continued unlawful conduct cannot be solved only with indemnity.

Representations should cover corporate authority, capitalization, title, data rights, privacy, AI classification, product claims, security, incidents, employment, licenses, contracts, sanctions, exports, foreign investment, and disputes. Disclosures should identify model and dataset versions, not only product names.

The buyer should require signing-to-closing covenants for model releases, material dataset changes, training practices, supplier changes, incidents, regulator contacts, claims, and legal changes. Bring-down review must include the August 2, 2026 and January 1, 2027 duties relevant to the target.

The priority request list should include the six inventories, corporate records, assignments, dependency registers, dataset provenance, privacy assessments, decision-system records, evaluation evidence, incident history, operative contracts, export classifications, sanctions screens, investment analyses, and insurance.

Open items need an owner, due date, evidence standard, closing effect, and escalation path. The final report should separate verified facts, management assertions, unresolved items, and legal inferences.

Part 03

EU / EEA

AI Act, GDPR and member-state overlays
In essence

European Union and EEA legal due diligence tests whether an AI target can lawfully operate and transfer its business. The review covers its models, systems, data, services, entities, workers, customers, and suppliers across connected jurisdictions. This memorandum states the transaction baseline as of July 23, 2026. It gives priority attention to Ireland, the Netherlands, Luxembourg, Germany, France, Norway, Iceland, and Liechtenstein. No target, sector, transaction structure, or data room was supplied. Every Member State and EEA EFTA State connected through entities, workers, users, data, compute, products, customers, or regulated activity needs a local-law review.

For ongoing AI governance work after diligence, see our AI Governance solution.

Executive summary
European Union

Incorporation does not define the diligence perimeter. Product access, intended purpose, operator role, users, workers, data, compute, suppliers, and transaction parties create separate legal connections.

EU AI Act

Each model and use case needs a written classification. Rebranding, substantial modification, or a changed intended purpose can transfer provider duties to a distributor, importer, deployer, or other party.

EU AI Act

The original August 2, 2026 timetable remains the verified operative text. The 2026 amendment was adopted and signed, but Official Journal publication and entry into force were not verified by July 23, 2026.

EU general-purpose AI

Current duties require technical documentation, downstream information, a Union copyright policy, and a public training-content summary. Systemic-risk models need evaluations, adversarial testing, incident records, and cybersecurity evidence.

EU data and intellectual property

GDPR permission, copyright permission, database rights, contract rights, confidentiality, and sector secrecy are separate. Public access does not establish a right to train or commercialize.

EU cyber and products

NIS2, DORA, the Cyber Resilience Act, product-safety law, sector conformity rules, and the revised Product Liability Directive can apply beside the AI Act. Each has its own actor, product, and date tests.

EU workers and consumers

Equality law, worker consultation, employment data rules, consumer claims, accessibility, and synthetic-content disclosures apply independently. A vendor contract cannot remove the target's own duties.

EEA EFTA

EU acts need act-by-act incorporation into the EEA Agreement. The GDPR and DORA are incorporated. The AI Act, Data Act, DSA, NIS2, Cyber Resilience Act, and revised Product Liability Directive remained under scrutiny.

Transaction

Missing core title, unlawful irreplaceable data, prohibited use, absent conformity, a non-transferable critical license, or a blocking sanctions or investment issue can stop closing. Curable gaps belong in conditions. Quantified legacy exposure belongs in price and specific protection.

Analysis by issue

Diligence perimeter, territorial reach, and timing

The review must follow operating facts rather than labels. Counsel should map every entity, model, system, use case, dataset, worker, supplier, customer class, and sales territory. The map should distinguish research, testing, release, hosting, integration, resale, and customer modification.

Regulation (EU) 2024/1689 reaches providers placing AI systems or general-purpose AI models on the Union market. It applies regardless of the provider's location. It also reaches Union deployers and certain third-country providers or deployers when output is used in the Union. Regulation (EU) 2024/1689, art. 2(1).

Each other law uses its own connector. Regulation (EU) 2016/679 uses establishment and targeted-market tests. Product law follows placing, making available, and putting into service. Employment law follows workers and establishments. NIS2 follows covered entities and national transposition. Foreign-investment review follows the target, buyer, assets, and control rights.

Counsel should create a dated obligations calendar. It should separate duties already active from duties arising before signing, closing, or integration. Key dates include August 2, 2026, September 11, 2026, December 2, 2026, December 9, 2026, January 20, 2027, and December 11, 2027.

A law-change covenant should cover the interim period. The target should report new releases, changed datasets, altered intended purposes, incidents, regulator contact, and material supplier changes. The buyer should repeat classification and status checks at closing.

Corporate structure, authority, and asset location

The buyer must identify which entity owns each asset and owes each duty. A common brand does not prove common ownership. The legal group chart should connect entities to personnel, repositories, datasets, customer contracts, cloud accounts, permits, and revenue.

Corporate law remains national. Counsel should verify formation, constitutional documents, registers, beneficial ownership, capital, options, convertibles, shareholder rights, board authority, and signing power. The review should identify insolvency indicators, distributions, intercompany balances, tax residence, and branch registrations.

AI groups often place intellectual property in one entity and employ researchers through another. The customer entity may only hold an informal license. The cloud account may sit with a founder or affiliate. Each mismatch needs a signed transfer, license, consent, or closing exclusion.

Security interests require local analysis. The review should cover pledges over shares, receivables, bank accounts, patents, trademarks, software, databases, and contract rights. Existing financing may restrict transfers, dividends, new debt, licensing, or change of control.

Corporate diligence should also test grants and public funding. Union, national, university, and regional support can impose location, exploitation, reporting, access, repayment, or state-aid conditions. A transaction may trigger consent, repayment, or a change in eligible status.

AI Act actor and use-case classification

Every product and deployment needs a written AI Act memorandum. The memorandum should identify the AI system, general-purpose AI model, intended purpose, actual use, provider, deployer, importer, distributor, authorised representative, and product manufacturer.

The first screen asks whether the item meets the statutory definition of an AI system or general-purpose AI model. The second asks whether an exclusion applies. Research before market placement, personal non-professional use, military use, and specified open-source releases receive distinct treatment. Regulation (EU) 2024/1689, arts. 2 and 3.

The next screen covers prohibited practices under Article 5. It should test manipulation, exploitation of vulnerabilities, social scoring, certain criminal-risk assessments, untargeted facial-image scraping, workplace or education emotion inference, sensitive biometric categorisation, and remote biometric identification. Sector facts and exceptions control the result.

The high-risk screen has two routes. Article 6(1) covers safety components and products listed in Annex I. Article 6(2) and Annex III cover specified uses involving biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and justice.

Annex III classification depends on intended purpose and use. A general chatbot is not high-risk merely because a customer later asks an employment question. A developer may still face liability when its instructions, promotion, design, or known deployments support a covered use.

Operator roles can change after release. A distributor, importer, deployer, or third party can become the provider of a high-risk system. This occurs after rebranding, substantial modification, or a changed intended purpose that creates a high-risk use. Contract allocation does not override Article 25.

Counsel should compare product documentation with sales conduct. Intended purpose includes instructions, promotional materials, and sales statements. Regulation (EU) 2024/1689, art. 3(12). A narrow contract term cannot cure broader marketing or implementation support.

The classification record should include model versions, technical architecture, use restrictions, customer configurations, substantial modifications, and release dates. It should identify the evidence supporting each result and the person who approved it.

AI Act dates and the 2026 amendment

The original AI Act remains in force. Chapters I and II have applied since February 2, 2025. Article 4 requires providers and deployers to take measures for sufficient AI literacy among relevant staff and operators. The provisions on general-purpose AI models, penalties, notified bodies, and Union administration have applied since August 2, 2025. The general application date is August 2, 2026. Regulation (EU) 2024/1689, arts. 4 and 113.

Under the original text, Article 6(1) and corresponding product-linked high-risk duties apply from August 2, 2027. The remaining high-risk provisions therefore enter general application on August 2, 2026. Article 50 transparency duties also enter general application on that date.

PE-CONS 30/26 would alter this calendar and other substantive rules. The Council approved the text on June 29, 2026. The Presidents signed it on July 8, 2026. As of July 23, EUR-Lex still marked procedure 2025/0359/COD as ongoing. No Official Journal act number was verified.

The adopted text would move Annex III high-risk duties to December 2, 2027. It would move Annex I product-linked duties to August 2, 2028. It would give certain pre-August 2 generative systems until December 2, 2026 to meet Article 50(2). PE-CONS 30/26, arts. 1(39)-(40), 4.

The amendment enters force only after Official Journal publication. Its text states that entry occurs on the third day after publication. Until that event, the original Article 113 timetable supplies the verified operative rule.

This timing conflict is a closing issue. A target cannot rely only on a political announcement or Commission webpage. Counsel should check the Official Journal, consolidated AI Act, national authority notices, and any transitional measures on each material date.

A buyer should require readiness for both outcomes. The target should complete the work needed for current August 2026 duties. The buyer can then recalibrate after the amendment enters force. This avoids a gap if publication is delayed or the final consolidation differs.

High-risk system evidence and conformity

A high-risk classification creates a system-level compliance file. The provider should document risk management, data and data governance, technical documentation, recordkeeping, instructions, human oversight, accuracy, resilience, and cybersecurity. Regulation (EU) 2024/1689, arts. 9-15.

The file should also cover the quality management system, retained records, corrective action, conformity assessment, registration, declaration of conformity, CE marking, post-market monitoring, and serious-incident reporting. Regulation (EU) 2024/1689, arts. 16-21, 43, 47-49, 72-73.

Product-linked systems require coordination with the applicable Annex I legislation. The target should identify the product manufacturer, notified body, conformity route, technical file, certificate, and change-control process. A material model update can affect both AI and sector conformity.

Deployers have their own duties. They must follow instructions, assign competent human oversight, monitor operation, and keep logs under their control. They must also assess the relevance of input data when they control those data. Regulation (EU) 2024/1689, art. 26.

An employer must inform worker representatives and affected workers before using a high-risk system at work. Specified public bodies, public-service providers, creditworthiness users, and life or health insurance users must conduct a fundamental-rights impact assessment. Regulation (EU) 2024/1689, arts. 26(7) and 27.

The diligence record should link every requirement to a model version, release, use, owner, approver, and retained exhibit. A policy without the corresponding tests, logs, approvals, and corrective-action record does not prove conformity.

General-purpose AI models and downstream documentation

A provider of a general-purpose AI model must maintain technical documentation. It must give downstream providers enough information to understand capabilities and limits. It must establish a policy for Union copyright compliance. It must publish a sufficiently detailed training-content summary. Regulation (EU) 2024/1689, art. 53.

Third-country GPAI providers usually need a Union authorised representative before market placement. Regulation (EU) 2024/1689, art. 54. Counsel should inspect the mandate, authority, resources, document access, and termination rights.

The diligence file should identify model ownership, release history, compute, training methods, input types, evaluations, intended uses, limits, and integration instructions. It should preserve the exact document supplied with each model version. Generic product pages do not prove compliance.

Providers of GPAI models with systemic risk face added duties. They must evaluate models, conduct and document adversarial testing, assess Union-level systemic risks, track serious incidents, and protect model and infrastructure security. Regulation (EU) 2024/1689, art. 55.

The Code of Practice can support a compliance showing. It remains voluntary and does not replace the Regulation. Counsel should record which commitments the target follows, which evidence supports them, and where the target uses another method.

GPAI duties have applied since August 2, 2025. The Commission may enforce the GPAI provisions, including fines, from August 2, 2026. Models placed on the market before August 2, 2025 receive the Article 111(3) transition until August 2, 2027.

Downstream contracts should require current documentation, version notices, evaluation information, incident cooperation, and termination support. They should allocate modification and intended-purpose duties. They should not promise information that the model provider cannot lawfully disclose.

Personal data, automated decisions, and transfers

GDPR diligence must identify the controller, joint controller, processor, purpose, lawful basis, data categories, recipients, retention, security, and transfer route for each processing activity. Regulation (EU) 2016/679, arts. 3, 5, 6, 9, 13-15, 24-30, 32-35, 44-49.

Training and deployment require separate analyses. A lawful basis for collecting customer prompts does not authorize model training. A training basis does not authorize disclosure, profiling, or a new consequential use. Purpose compatibility and transparency need their own records.

Special-category data require an Article 9 condition. Bias testing does not create a general permission to process sensitive data. The current AI Act contains a narrow route for certain high-risk providers under Article 10(5). PE-CONS 30/26 proposes broader provisions, but they are not yet operative.

A data-protection impact assessment is required when processing is likely to create high risk. Regulation (EU) 2016/679, art. 35. The assessment should match the released system, affected people, deployment, human review, security, and residual risk. A template completed after launch carries limited evidentiary value.

Article 22 can apply to decisions based solely on automated processing that produce legal or comparably material effects. In SCHUFA Holding, C-634/21, EU:C:2023:957, a score could itself constitute the decision where a third party gives it a determining role.

Article 15 requires meaningful information about the logic involved. Dun & Bradstreet Austria, C-203/22, EU:C:2025:117, requires intelligible information that lets the person understand the procedure. Trade-secret claims do not justify a blanket refusal.

The target should produce decision maps, inputs, feature explanations, validation, notices, human-review procedures, correction routes, and override logs. Counsel should interview actual operators. A written human-review policy does not prove meaningful review.

International transfers need Chapter V support. The review should cover cloud regions, remote administration, support, subprocessors, model providers, telemetry, and incident access. Standard contractual clauses require a transfer assessment and supplementary measures where needed.

M&A data rooms do not create a GDPR exception. The seller should minimize personal data, use staged disclosure, control access, redact where practical, and document the lawful basis. Abandoned transactions need deletion and return procedures.

Data diligence must prove source, permission, purpose, and traceability. Public availability proves only access. It does not prove a right to copy, mine, retain, train, disclose, or redistribute.

Directive (EU) 2019/790 separates research text and data mining from the broader Article 4 exception. Commercial mining requires lawful access. Rights holders may reserve Article 4 uses, including through machine-readable means for online content. Directive (EU) 2019/790, arts. 3-4.

Database rights need a separate screen. Directive 96/9/EC can protect substantial investment in obtaining, verifying, or presenting database contents. Repeated extraction of insubstantial parts can also create exposure. Directive 96/9/EC, art. 7.

Copyright permission does not resolve privacy, contract, confidentiality, or sector secrecy. A dataset license may permit research but bar commercial training. A website term may restrict scraping. Customer material may contain third-party secrets or regulated records.

The target should maintain one register for pretraining, fine-tuning, retrieval, evaluation, red-team, prompt, log, and feedback data. Each entry should record source, date, collector, method, terms, rights reservations, personal data, location, retention, deletion, and downstream use.

Model outputs require separate treatment. Contract terms can allocate risk between parties. They cannot create copyright where national law finds insufficient human authorship. Output controls should address memorization, substantial similarity, defamation, privacy, and confidential information.

Employee and contractor ownership remains national. Software-specific employee rules exist in several Member States. Patent inventorship, employee inventions, moral rights, and contractor assignments also vary. The target needs signed, locally valid transfers from every material contributor.

Trade-secret protection requires secrecy measures. Directive (EU) 2016/943, art. 2(1). Counsel should inspect repository access, model release, publication, confidentiality terms, device controls, logging, and offboarding. A public model release can destroy secrecy for the released material.

Third-party models, software, datasets, cloud, and the Data Act

The target needs a dependency register that extends beyond software. It should cover open-source code, open-weight models, hosted models, datasets, benchmarks, APIs, cloud, accelerators, security tools, and data-processing services.

Each record should identify version, supplier, accepted terms, paying entity, use, transfer rights, and replacement plan. Counsel should review training, fine-tuning, distillation, outputs, redistribution, attribution, source duties, audit, suspension, termination, assignment, and change of control.

An open-source label does not resolve the issue. The exact license, integration, modification, distribution, network use, and notice practice control. Model acceptable-use terms can restrict sectors, users, locations, or content even when weights are publicly downloadable.

Cloud contracts should cover capacity, data location, supplier training, subprocessors, security, model changes, deprecation, pricing, suspension, portability, recovery, and exit assistance. A target may own its application while lacking transferable compute or model access.

Regulation (EU) 2023/2854 has applied since September 12, 2025. It can affect connected products, related services, data holders, users, and data-processing services. Product design duties under Article 3(1) apply to relevant products placed after September 12, 2026.

The Data Act also addresses switching between data-processing services and certain contractual terms. Counsel should test exit charges, technical obstacles, export formats, continuity, interoperability, and termination assistance. These duties may affect cloud resale and managed AI services.

Benchmarks need the same discipline. The target should prove license rights, test-set confidentiality, contamination controls, score methodology, model version, prompts, exclusions, and publication approval. Unsupported rankings can create consumer and contract exposure.

Cybersecurity and operational resilience

Security diligence should cover models, data, applications, infrastructure, and suppliers. Ordinary penetration testing may omit prompt injection, retrieval manipulation, model extraction, poisoning, unsafe tool use, and weight leakage.

Counsel should obtain threat models, secure-development records, privileged-access lists, secrets controls, model registries, dataset controls, supplier access, vulnerability reports, red-team results, release approvals, monitoring, backups, and recovery tests.

NIS2 requires a national-law analysis. Directive (EU) 2022/2555 required Member States to apply transposition measures from October 18, 2024. Scope can include cloud computing, data centres, managed services, online marketplaces, search engines, social networks, research, and listed sectors.

Covered entities need management accountability, risk measures, supply-chain controls, incident reporting, continuity, vulnerability handling, cryptography, and access controls. Directive (EU) 2022/2555, arts. 20-23. Counsel must read the operative statute in each connected Member State.

DORA has applied since January 17, 2025 to covered financial entities. Regulation (EU) 2022/2554. AI vendors can face contractual and audit duties as ICT third-party providers. Critical providers can enter direct Union oversight.

The Cyber Resilience Act covers many products with digital elements. Regulation (EU) 2024/2847. Its conformity-body provisions have applied since June 11, 2026. Article 14 reporting begins September 11, 2026. The main product duties begin December 11, 2027.

The target should maintain one incident register. It should cover breaches, unsafe outputs, discriminatory outcomes, vulnerabilities, prompt leakage, weight leakage, poisoning, model extraction, outages, complaints, and regulator contacts.

Each entry should state discovery, affected systems, people, jurisdictions, containment, legal analysis, notices, insurance, cause, remediation, and recurrence testing. An undisclosed incident can alter warranties, disclosure schedules, coverage, valuation, and closing.

Product safety, conformity, and liability

An AI product may need several conformity analyses. The AI Act does not replace medical-device, machinery, vehicle, aviation, radio, toy, or other product legislation. Regulation (EU) 2024/1689, art. 2(9).

The General Product Safety Regulation has applied since December 13, 2024. Regulation (EU) 2023/988. Its safety assessment considers cybersecurity and evolving, learning, or predictive functions where relevant. Counsel should inspect risk assessments, technical files, warnings, recalls, and market-surveillance contact.

Regulation (EU) 2023/1230 applies from January 20, 2027. Its Annex I includes certain safety components and machinery using self-evolving machine-learning behaviour. An AI-enabled machine may need both machinery and AI Act treatment.

Directive (EU) 2024/2853 must be transposed by December 9, 2026. It applies to products placed on the market or put into service after that date. It treats software as a product and addresses updates, cybersecurity, and learning behaviour.

The revised liability directive excludes free and open-source software developed or supplied outside commercial activity. The exclusion does not protect a commercial actor merely because a component began as open source. Commercial integration, paid supply, and manufacturer-controlled updates require separate analysis.

Product diligence should trace the economic operator, importer, authorised representative, technical documentation, conformity route, CE marking, declarations, post-market monitoring, corrective action, and insurance. Missing conformity can block continued sale.

Contract caps do not bind injured third parties or regulators. Counsel should quantify recall, remediation, replacement, customer termination, defense, and insurance effects. The buyer should test whether policy wording covers software, media, product, cyber, and professional claims.

Online services, consumer claims, synthetic content, and accessibility

The Digital Services Act applies when the target supplies an intermediary service. Regulation (EU) 2022/2065. Counsel should classify mere conduit, caching, hosting, online platform, marketplace, and search functions. An AI interface is not automatically an intermediary.

Covered services may need notice-and-action processes, clear terms, transparency reports, recommender disclosures, trader traceability, complaint handling, and systemic-risk measures. The exact duties depend on service type, size, and designation.

Consumer claims remain subject to Directive 2005/29/EC and national law. Claims about accuracy, bias, privacy, security, training rights, human review, output ownership, and benchmark rank need versioned evidence. Qualified fine print does not cure a contradictory headline or demo.

Directive (EU) 2019/770 can apply to consumer digital content and services. Conformity, updates, remedies, and data-as-counter-performance rules may affect AI subscriptions. Consumer terms also face unfair-terms review under Directive 93/13/EEC.

Article 50 of the AI Act creates disclosures for specified interactions, synthetic content, emotion recognition, biometric categorisation, deepfakes, and certain public-interest text. Regulation (EU) 2024/1689, art. 50. The current date of application is August 2, 2026.

The target should test machine-readable marking across export, editing, compression, and platform handling. Detection tools need measured accuracy and stated limits. Deepfake and public-interest disclosures must be clear to the recipient.

The European Accessibility Act applies to listed products and services from June 28, 2025. Directive (EU) 2019/882. AI projects involving consumer communications, e-commerce, banking, transport, e-books, or electronic communications need an accessibility screen.

Children and vulnerable users require added review. Counsel should examine audience, age signals, profiling, advertising, parental permissions, crisis responses, retention, and human escalation. Sector and national duties can exceed the AI Act.

Employment, worker consultation, and discrimination

Employment AI can trigger the AI Act, GDPR, equality directives, labour law, and collective rights. Annex III covers specified recruitment, selection, employment decisions, task allocation, monitoring, and evaluation uses.

Directive 2000/78/EC prohibits specified discrimination in employment. Directive 2006/54/EC addresses sex equality. Directive 2000/43/EC addresses racial or ethnic origin. A neutral model can create indirect discrimination unless objectively justified under the applicable test.

Counsel should obtain feature lists, data sources, validation, subgroup testing, accessibility testing, notices, adverse-decision records, override logs, and appeal outcomes. The review should compare vendor documentation with actual manager conduct.

National worker participation can arise before the AI Act high-risk duties. France requires prior information on recruitment methods and automated personnel management. Worker monitoring needs information and consultation. Code du travail, art. L2312-38.

Germany applies works council rules to selection guidelines prepared with AI. Betriebsverfassungsgesetz, § 95(2a). Other co-determination, personnel questionnaire, monitoring, and information provisions may apply according to system design.

The Platform Work Directive must be transposed by December 2, 2026. Directive (EU) 2024/2831. Covered digital labour platforms face rules on automated monitoring, automated decisions, worker information, human review, and personal data.

Employment data also need national review. Germany's Bundesdatenschutzgesetz § 26 and national statutes elsewhere can supplement GDPR. Local rules may restrict employee consent, monitoring, biometrics, retention, and transfer.

A vendor cannot assign every discrimination duty to the employer. The developer's design, claims, documentation, limits, and known misuse remain relevant. The deployer also needs enough information to make lawful decisions and conduct meaningful review.

Regulated sectors and public procurement

Sector classification can determine the transaction result. Medical, financial, insurance, transport, energy, telecom, defense, education, and public-sector uses need dedicated review.

Medical software may fall under Regulation (EU) 2017/745 or Regulation (EU) 2017/746. Intended purpose, claims, clinical evidence, software function, and risk class control. An AI Act classification does not replace medical-device conformity.

Financial services may trigger DORA, prudential rules, consumer-credit law, payment law, insurance duties, market rules, outsourcing requirements, and supervisory expectations. Creditworthiness and risk assessment can also enter Annex III.

Public authorities face procurement, transparency, records, equality, and administrative-law duties. Public buyers may impose contract terms that flow down AI Act documentation, security, audit, data location, accessibility, and exit duties.

The target should identify every regulated customer and use. It should produce licenses, registrations, conformity records, audit reports, regulator correspondence, procurement submissions, and contractual compliance schedules.

A prohibited or unlicensed use is not cured by indemnity. The target may need to suspend the feature, narrow claims, change intended purpose, obtain approval, or exclude the business from the transaction.

Competition, merger review, foreign subsidies, investment, exports, and sanctions

Competition diligence should cover exclusivity, most-favoured terms, tying, interoperability limits, data access, and pricing tools. It should also cover information exchange, talent restrictions, customer concentration, and acquisitions.

The EU Merger Regulation applies when its turnover thresholds are met. Regulation (EC) No 139/2004. National merger rules can apply below those thresholds. Some states use transaction-value thresholds or call-in powers.

Illumina v Commission, Joined Cases C-611/22 P and C-625/22 P, EU:C:2024:677, limits Article 22 referrals from states lacking national jurisdiction. It does not remove national thresholds, call-ins, abuse rules, or later legislative change.

The Foreign Subsidies Regulation can add a separate pre-closing filing. Regulation (EU) 2022/2560. Concentration notification can arise where the Union turnover and third-country financial contribution thresholds are met. The Commission can also call in a transaction below thresholds.

Each Member State may screen foreign investment. Regulation (EU) 2019/452 coordinates those reviews and identifies artificial intelligence among critical technologies. The buyer's nationality, funding, government links, rights, data, and target activities matter.

Ireland's Screening of Third Country Transactions Act 2023 requires notification for covered transactions at least ten days before completion. Germany, France, the Netherlands, and Luxembourg operate separate screening systems. Thresholds and sensitive sectors differ.

Export diligence should classify software, source code, model weights, technical data, encryption, chips, remote access, recipients, end uses, and destinations. Regulation (EU) 2021/821 covers listed and certain unlisted dual-use items, software, and technology.

Sanctions screening must cover parties, beneficial owners, controllers, banks, customers, suppliers, destinations, services, and payments. Union measures are program-specific and change frequently. National criminal and licensing rules also matter.

The buyer should refresh merger, foreign-subsidy, FDI, export, and sanctions work at signing and closing. A failed screen can delay, condition, prohibit, or unwind the transaction.

Priority Member State overlays

Ireland often appears as a contracting, employment, data, or holding location. Diligence should cover company authority, share title, employee and contractor rights, data-protection records, consumer law, sector regulation, tax residence, and FDI screening.

The Netherlands often appears through holding entities, cloud operations, customers, or workers. Counsel should test corporate authority, works council rights, employee data, IP title, financial regulation, and the Security Screening of Investments, Mergers and Acquisitions Act.

Luxembourg frequently appears in holding, financing, fund, and licensing structures. The review should cover corporate approvals, beneficial ownership, finance regulation, substance, employment, IP, data protection, and the Law of July 14, 2023 on foreign-investment screening.

Germany needs early worker and product review. Works council rights can affect deployment timing. Employee data, software ownership, product conformity, competition, export controls, and foreign-investment rules can also change closing steps.

France needs a similar early labour review. The social and economic committee receives prior information or consultation for specified recruitment, personnel, monitoring, and technology measures. French employee-software and invention rules also need chain-of-title review.

Other Member States must be added when facts connect them. Local differences affect corporate acts, employment, IP ownership, consumer enforcement, NIS2 transposition, product authorities, sanctions, litigation, and remedies.

The diligence report should not present one Member State as a complete Union answer. Union regulations can apply directly, but directives, remedies, procedures, and many transaction rules remain national.

EEA-specific treatment

Norway, Iceland, and Liechtenstein require an act-by-act EEA check. An EU act marked EEA relevant does not automatically become domestic law. Incorporation requires an EEA Joint Committee Decision, entry into force, adaptations, and national measures where needed.

The GDPR was incorporated by EEA Joint Committee Decision No 154/2018 and entered into force in the EEA on July 20, 2018. DORA was incorporated by Decision No 40/2025 and entered into force in the EEA on July 1, 2025.

As of July 23, 2026, EEA-Lex recorded several major acts as under scrutiny. They included the AI Act, Data Act, DSA, NIS2, Cyber Resilience Act, and revised Product Liability Directive.

That status does not remove Union exposure. An EEA-based provider can still fall within AI Act Article 2 when it places a system or model on the Union market. A Norwegian target serving German users therefore needs both Union-market and Norwegian domestic analysis.

Domestic law may already regulate the same conduct. Norway, Iceland, and Liechtenstein have national privacy, employment, consumer, product, security, and sector rules. Some existing EEA acts also apply while newer Union acts await incorporation.

Counsel should maintain two columns for each EEA EFTA State. One should record direct Union-market exposure. The other should record EEA incorporation, national implementation, adaptations, regulator, and commencement.

The transaction agreement should address later incorporation. A signing-to-closing covenant should require prompt notice of a Joint Committee Decision, national bill, commencement order, or regulator instruction that affects the target.

Contracts, revenue quality, and operational continuity

Contract diligence must prove assent, scope, performance, and transferability. A standard form does not prove which terms the customer accepted. Counsel should obtain executed orders, clickwrap records, amendments, and incorporated policies.

AI clauses should address permitted use, prohibited use, model changes, customer data, prompts, logs, training, outputs, confidentiality, security, incidents, documentation, human review, audits, indemnities, caps, assignment, termination, and transition.

The contract should match product reality. A promise not to train on customer data is dangerous when support logs feed evaluation. A claim that customers control every decision is weak when the product markets autonomous action.

Revenue quality requires contract-to-ledger testing. Counsel should separate production revenue from pilots, free use, credits, related-party sales, minimum commitments, contingent milestones, and cancellable arrangements.

Operational continuity depends on compute, key models, data, suppliers, and staff. The review should test reserved capacity, minimum spend, hardware limits, deprecation, price changes, suspension, portability, recovery, and key-person knowledge.

Assignment and change-of-control clauses require product-specific review. A model API, dataset, cloud commitment, distribution right, or public grant may terminate at closing. Informal supplier comfort is not a substitute for written consent.

Findings and transaction protections

Each finding needs a rule, evidence status, business effect, and deal response. A colour alone does not answer whether the target can continue, transfer, or remediate the activity.

Stop-level findings include missing title to a core model, unlawful irreplaceable data, or a prohibited AI practice. They also include missing mandatory conformity, an absent critical license, unlicensed regulated activity, or a blocking sanctions or investment issue.

Closing conditions fit curable defects. Typical items include assignments, consents, lien releases, regulatory filings, AI classifications, data-protection assessments, worker consultation, product suspension, incident remediation, supplier amendments, and technical documentation.

Price adjustments, escrow, holdbacks, specific indemnities, exclusions, and post-closing covenants fit quantified legacy exposure. General warranties offer weak protection for a disclosed defect. Indemnity does not make continued unlawful conduct acceptable.

Representations should cover authority, capitalization, title, data rights, AI Act status, privacy, product conformity, claims, security, incidents, employment, licenses, contracts, sanctions, exports, investment screening, and disputes.

Disclosures should identify model, dataset, and contract versions. Product names alone are inadequate. The seller should state which facts are verified, asserted by management, disputed, or unresolved.

Open items need an owner, due date, evidence standard, closing effect, and escalation route. The final bring-down should repeat status checks for the AI Act amendment, August 2026 duties, CRA reporting, product-liability transposition, EEA incorporation, sanctions, and filings.

Part 04

UK & Switzerland

Two regimes, connected third countries
In essence

United Kingdom and Swiss legal due diligence tests whether an AI target can lawfully own, train, deploy, sell, and transfer its systems across both markets and connected third countries. The question is whether the target's entities, models, data, products, workers, suppliers, and regulated uses satisfy the current United Kingdom and Swiss rules as of July 23, 2026. The review must also determine whether defects can be cured before closing or require price, indemnity, exclusion, or termination protection. No target, sector, transaction structure, or data room was supplied. This memorandum therefore states a transaction baseline. It also identifies enacted, pending, and future measures that may affect signing, closing, or integration.

Executive summary
United Kingdom and Switzerland

Neither jurisdiction has an operative general private-sector AI statute. Existing data, consumer, intellectual-property, employment, product, cyber, competition, and sector laws control the present review. Pending AI measures have no current legal force.

Cross-border

A United Kingdom or Swiss target may still fall within the EU AI Act or EU GDPR. Union market access, EU establishments, targeted users, monitored individuals, and output used in the Union can create separate duties.

United Kingdom

The Data (Use and Access) Act 2025 replaced UK GDPR Article 22 with Articles 22A to 22D. Significant solely automated decisions using non-special-category data have broader legal routes, but controllers must provide information, contest rights, and human intervention.

Switzerland

The Federal Act on Data Protection applies directly to AI. Article 21 requires notice and, subject to exceptions, a chance to state a position and obtain human review of an automated individual decision.

Intellectual property

The United Kingdom has no general commercial text-and-data-mining exception. Swiss law contains a narrow scientific-research provision, while the copyright treatment of AI training remains unsettled. Data provenance and licenses need asset-level proof.

Online services and claims

The United Kingdom Online Safety Act can reach user-to-user, search, and pornography services. United Kingdom and Swiss consumer, unfair-trading, personality, defamation, and contract rules apply to AI claims and synthetic content.

Cybersecurity and products

United Kingdom NIS, connected-product, sector, and product rules can apply beside data law. Switzerland requires specified critical-infrastructure operators to report qualifying cyberattacks within 24 hours and complete the report within 14 days.

Regulated uses

Employment, financial services, healthcare, medical devices, transport, public administration, biometrics, children, and critical infrastructure require separate classification. General-purpose product terms do not displace sector duties.

Transaction

Missing core title, unlawful irreplaceable data, a prohibited deployment, absent mandatory clearance, a non-transferable critical dependency, or a blocking sanctions issue can stop closing. Curable gaps belong in conditions. Quantified legacy exposure belongs in price and specific protection.

Analysis by issue

Diligence perimeter and cross-border reach

The review must follow operating facts. Incorporation answers only part of the question. Counsel should map each entity, product, model, system, use case, worker, dataset, supplier, customer class, and sales territory.

The United Kingdom comprises England and Wales, Scotland, and Northern Ireland. Corporate, contract, tort, employment, health, consumer, criminal, and procedural rules can differ. Northern Ireland can also retain distinct links to Union product rules. A United Kingdom-wide product label does not resolve those differences.

Switzerland combines federal law, cantonal law, and municipal action. Federal private law governs many commercial issues. Cantonal law can control public bodies, education, healthcare, policing, procurement, and administrative decisions. The target's office, user, worker, and public-customer locations therefore matter.

A target in either jurisdiction can face Union law. Regulation (EU) 2024/1689, Article 2, reaches specified third-country providers and deployers. Regulation (EU) 2016/679, Article 3, reaches some establishments, targeted offerings, and monitoring outside the Union. The prior EU and EEA session should be read with this module.

Counsel should build six linked records. They should cover the legal group, products, models, use cases, data flows, and third parties. Each record needs a version date, responsible owner, connected jurisdictions, and supporting evidence.

Timing needs a separate calendar. The calendar should distinguish current duties, enacted delayed duties, bills, consultations, and regulator guidance. Signing, closing, migration, and product-release dates may produce different answers.

Current AI-specific statutory position

Neither jurisdiction has an operative general AI act for ordinary private-sector activity. That absence does not create a legal vacuum. Technology-neutral and sector statutes already regulate the target's conduct.

The Artificial Intelligence (Regulation) Bill [HL] received its first reading in the House of Lords on March 4, 2025. It had not progressed beyond that stage by the as-of date. It is not law and should not appear as a current compliance requirement.

The United Kingdom signed the Council of Europe Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law on September 5, 2024. Signature does not itself insert the Convention's duties into domestic private law. Ratification and implementing measures require separate confirmation.

Switzerland signed the same Convention on March 27, 2025. The Federal Council directed the administration to prepare a consultation draft by the end of 2026. The planned bill will address transparency, data protection, non-discrimination, and supervision. It is not operative law.

The Swiss administration also plans nonbinding measures by the end of 2026. Those measures may include industry commitments and standards. A diligence report should classify them as voluntary unless a contract, license, procurement term, or regulator makes them binding for the target.

The transaction should still request an internal AI responsibility map. It should identify who approves data, training, releases, claims, high-impact uses, incidents, and customer exceptions. An absent general statute does not excuse an unowned legal risk.

Corporate authority, capitalization, and asset location

The buyer must identify the entity that owns each material asset and owes each material obligation. A common website, brand, or management team does not prove common ownership.

United Kingdom diligence should review incorporation records, articles, shareholder agreements, board and shareholder approvals, registers, people with significant control, capitalization, options, convertibles, charges, and insolvency indicators. Companies Act 2006 requirements must be matched to the actual entity type.

Swiss diligence should review articles, commercial-register entries, share registers, beneficial owners, capital, shareholder arrangements, board authority, signatory powers, security interests, and insolvency indicators. The Swiss Code of Obligations and entity form control the approval route.

AI groups often split research, employment, customer contracts, and intellectual property. The employing entity may lack an invention transfer. The customer entity may hold only an oral or revocable license. The cloud account may remain with a founder or affiliate.

Counsel should trace every core asset to a legal owner. The trace should include repositories, model weights, training pipelines, datasets, evaluation records, patents, brands, domains, customer contracts, and compute accounts. Intercompany services and licenses need written terms.

Public grants, university arrangements, and research collaborations can impose exploitation, location, publication, access, repayment, or change-of-control conditions. The target should produce award terms, consortium agreements, reports, and consent records.

Existing security can impair transfer. Counsel should search registered charges and obtain finance documents, payoff statements, releases, and required consents. Swiss security review must address the asset and perfection method under applicable law.

United Kingdom data protection and automated decisions

United Kingdom AI processing remains subject to the UK GDPR, Data Protection Act 2018, and related sector rules. Counsel should identify the controller, processor, purpose, lawful basis, data categories, recipients, retention, security, and transfer route for each activity.

The Data (Use and Access) Act 2025 changed the rules for solely automated significant decisions. Section 80 replaced UK GDPR Article 22 with Articles 22A to 22D. The data-protection provisions of that Act were fully in force by June 19, 2026.

Article 22A treats a decision as solely automated when it lacks meaningful human involvement. It treats a decision as significant when it creates legal or similarly significant effects. Profiling can affect whether claimed human participation is meaningful.

Article 22B retains stricter conditions for decisions based wholly or partly on special-category data. Explicit consent can support a decision. Contract necessity or legal authority can also support one when the required substantial-public-interest condition applies.

Article 22C requires safeguards for significant solely automated decisions. The controller must provide information about the decision. The person must be able to contest or make representations. The person must also be able to require human intervention.

The wider route for non-special-category data does not remove other duties. The controller still needs lawfulness, fairness, transparency, purpose control, minimisation, accuracy, retention, security, and accountability. UK GDPR arts. 5, 6, 13-15, 24-25, 32 and 35.

A data-protection impact assessment is required where processing is likely to create high risk. The assessment should match the released model, actual use, affected people, data, human review, and residual risk. A generic assessment completed after launch offers weak evidence.

The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026, SI 2026/425, took effect on May 12, 2026. They require the Information Commissioner to prepare a code. The code was not yet issued on the as-of date.

The future code will be nonbinding, but the Commissioner must take it into account when assessing compliance. Counsel should track the draft and final code during the transaction. Existing statutory duties apply without waiting for it.

International transfers require a lawful UK route. The review should cover cloud regions, remote support, subprocessors, telemetry, model providers, and incident access. The renewed EU adequacy decision permits covered EU-to-UK transfers until December 27, 2031, subject to its terms and later review.

M&A data rooms do not create a general exemption. The seller should minimise personal data, stage access, use redaction where practical, control downloads, and document the lawful basis. Failed transactions need return or deletion procedures.

Swiss data protection and automated decisions

The Federal Act on Data Protection, SR 235.1, has applied since September 1, 2023. The Federal Data Protection and Information Commissioner states that it applies directly to AI-supported processing.

The review should identify the controller, processor, purpose, data categories, recipients, retention, security, and foreign disclosure route. The FADP follows an effects principle for circumstances producing effects in Switzerland.

Article 21 applies to an automated individual decision. The controller must inform the affected person. Subject to statutory exceptions, the person may state a position and request review by a natural person.

The exceptions include a decision directly connected with a contract where the person's request is granted. Explicit consent can also disapply the notice and review route. Counsel should not assume that general terms provide explicit consent.

Article 25 access rights include information about the logic underlying an automated decision. The target should preserve input descriptions, decision logic, material factors, validation, notices, override records, and review outcomes.

Articles 22 and 23 require a data-protection impact assessment for likely high-risk processing and consultation where residual high risk remains. The assessment should cover the concrete deployment, not an abstract model.

Article 24 requires notice to the Commissioner where a data-security breach is likely to create high risk. The controller must notify affected people when protection requires it or the Commissioner orders it. Other sector notifications can run in parallel.

Foreign controllers can need a Swiss representative under Article 14. The test addresses offering or monitoring involving people in Switzerland, extensive processing, and high risk. Counsel should inspect the representative appointment, mandate, contact details, and records.

Cross-border disclosures require Articles 16 and 17 analysis. The review should test destination adequacy, contractual protection, exceptions, onward transfer, remote access, and processor terms. EU-to-Switzerland transfers continue to benefit from the Union's adequacy determination.

Specified intentional breaches can create criminal exposure for responsible individuals. FADP arts. 60-64. Transaction documents should not treat all privacy exposure as a corporate administrative fine.

Data diligence must prove source, permission, purpose, and traceability. Public availability proves access, not a right to copy, train, retain, publish, or commercialise.

The United Kingdom Copyright, Designs and Patents Act 1988 reserves copying and other acts to the rights owner. CDPA 1988, s. 16. Section 29A permits computational analysis only for non-commercial research by a person with lawful access.

The United Kingdom therefore lacks a general commercial text-and-data-mining exception. The government's March 2026 report did not change the statute. It stated that reforms would not proceed until the government was satisfied that they met its objectives.

Counsel should review each training source for copyright, database rights, contract terms, confidentiality, privacy, and sector secrecy. The Copyright and Rights in Databases Regulations 1997 can protect qualifying database investment independently of copyright in individual items.

United Kingdom copyright generally starts with the author. Employee ownership and computer-generated works receive statutory treatment. CDPA 1988, ss. 9 and 11. Assignments require signed writing. Id. s. 90(3).

Patent diligence should identify human inventors, conception records, disclosure, and assignments. In Thaler v Comptroller-General of Patents, Designs and Trade Marks [2023] UKSC 49, the Supreme Court held that an AI machine was not an inventor under the Patents Act 1977.

Swiss copyright protects works with individual character. Federal Act on Copyright and Related Rights, SR 231.1, arts. 2 and 6. The official Swiss position states that only human-created works receive copyright protection.

Human creative use of an AI tool can produce protected output. Ordinary prompting that leaves the creative act to the system generally does not. An unprotected output can still infringe a protected work or personality rights.

Swiss law contains a scientific-research text-and-data-mining provision. CopA art. 24d. The Swiss Federal Institute of Intellectual Property states that the provision was not introduced for AI training. Courts must decide its application to those facts.

The Swiss treatment of protected works in AI training remains unsettled. The Institute is preparing a preliminary copyright bill for consultation by the end of 2026. The proposed measure has no present legal force.

Swiss copyright transfers can occur without the United Kingdom's universal signed-writing rule. The scope still needs clear proof. Moral rights and contract interpretation can limit the result. Written assignments remain the safer transaction record.

Employee and contractor title needs local analysis. Swiss Code of Obligations art. 332 addresses employee inventions and designs. Article 17 CopA addresses employee computer programs. Contractor work requires express allocation.

Trade-secret value depends on secrecy measures. The United Kingdom applies the Trade Secrets (Enforcement, etc.) Regulations 2018 and common-law confidence. Swiss protection arises through contract, the Unfair Competition Act, the Criminal Code, and related principles.

Counsel should inspect repository permissions, model releases, publication history, device controls, confidentiality terms, logging, and offboarding. A public weight release may destroy secrecy in the released material.

Third-party code, models, data, and compute

The target needs a dependency register beyond a software bill of materials. It should cover code, open-weight models, hosted models, datasets, benchmarks, APIs, cloud services, accelerators, and security tools.

Each entry should identify the exact version, supplier, accepted terms, paying entity, use, transfer rights, and replacement plan. Counsel should preserve the terms in force when the target accepted them.

The review should test commercial scope, field limits, geography, users, training, fine-tuning, distillation, outputs, redistribution, attribution, source duties, audit, suspension, termination, assignment, and change of control.

An open-source or open-weight label does not answer those questions. The exact license and integration method control. Acceptable-use terms can bar sectors, persons, locations, or content even when weights are downloadable.

Cloud agreements require capacity, location, supplier data use, subprocessors, security, model changes, deprecation, price resets, suspension, portability, recovery, and exit support. A target may own its application but lack transferable compute or model access.

Benchmarks need the same review. Counsel should verify rights, test-set confidentiality, contamination controls, score methods, model version, prompts, exclusions, and publication approval. Unsupported ranking claims create consumer and contract risk.

A critical dependency without consent or substitute can become a closing condition. An informal supplier assurance is not a replacement for a binding consent or amended agreement.

Online services, product claims, and synthetic content

The United Kingdom Online Safety Act 2023 applies according to service function. It can cover regulated user-to-user services, search services, and specified pornography services. A standalone chatbot is not automatically in scope.

A chatbot can fall within the Act when its functions permit user-generated content sharing or regulated search activity. Counsel should map posting, sharing, group, retrieval, moderation, recommender, and age-access features.

Illegal-content duties for regulated user-to-user and search services took effect on March 17, 2025. Child-safety duties took effect on July 25, 2025. The target should produce risk assessments, age analysis, moderation records, complaints, reporting tools, and safety tests.

The Digital Markets, Competition and Consumers Act 2024 strengthened United Kingdom consumer enforcement and replaced the prior unfair-commercial-practices regime. Claims about accuracy, bias, privacy, training rights, security, human review, and output ownership need dated support.

The supporting record should identify the model version, test set, prompts, sample, exclusions, threshold, result, date, and approver. A disclaimer does not cure a contradictory headline, demo, procurement response, or sales script.

Swiss AI claims face the Federal Act against Unfair Competition, the Code of Obligations, sector statutes, and cantonal enforcement. Switzerland does not rely on one general consumer code equivalent to the United Kingdom position.

Synthetic content can engage copyright, passing off, trade marks, privacy, personality rights, defamation, fraud, election, and criminal rules. Counsel should test consent, identity use, voice or likeness replication, labelling, removal channels, and customer controls.

The target should preserve output testing for memorisation, substantial similarity, false attribution, personal data, harmful content, and protected secrets. Terms can allocate risk between parties. They cannot legalise an infringing or deceptive use.

Cybersecurity, incidents, and critical systems

AI security diligence should cover models, data, applications, infrastructure, and suppliers. Ordinary penetration testing may omit prompt injection, retrieval manipulation, data poisoning, model extraction, unsafe tool use, and weight leakage.

Counsel should obtain threat models, secure-development records, access lists, secrets controls, model registries, supplier access, vulnerability reports, red-team results, release approvals, monitoring, backups, and recovery tests.

The Network and Information Systems Regulations 2018 apply to specified United Kingdom essential services and relevant digital service providers. Covered cloud, search, marketplace, health, energy, transport, and infrastructure activities need a service-specific screen.

The Cyber Security and Resilience (Network and Information Systems) Bill had passed the Commons and received its Lords second reading by July 14, 2026. It remained a bill. Its proposed expansion to managed services and data centres is a readiness issue, not current law.

The Product Security and Telecommunications Infrastructure Act 2022 and implementing regulations have applied to covered consumer connectable products since April 29, 2024. The regime addresses passwords, vulnerability reporting, security-update information, and statements of compliance.

The United Kingdom AI Cyber Security Code of Practice is guidance. It can support diligence evidence and contracts. It does not replace legislation, sector rules, or an appropriate threat assessment.

Switzerland requires specified critical-infrastructure operators to report qualifying cyberattacks to the National Cyber Security Centre. The initial report is due within 24 hours of discovery. Missing information can be completed within 14 days.

The Swiss reporting duty has applied since April 1, 2025. Sanctions for failure to report have applied since October 1, 2025. The Information Security Act and Cybersecurity Ordinance control scope, exceptions, and report content.

The target should maintain one incident register. It should include data breaches, unsafe outputs, discriminatory outcomes, vulnerabilities, prompt or weight leakage, poisoning, extraction, outages, complaints, and regulator contact.

Each entry should record discovery, systems, people, jurisdictions, containment, legal analysis, notices, insurance, cause, remediation, and recurrence testing. An undisclosed incident can change warranties, disclosures, coverage, valuation, and closing.

Employment, discrimination, and workplace systems

Employment AI can trigger privacy, equality, contract, consultation, and dismissal rules. The review should cover recruitment, screening, ranking, monitoring, scheduling, productivity scoring, promotion, pay, discipline, and termination.

The United Kingdom Equality Act 2010 prohibits direct and indirect discrimination in covered work and services. It also requires reasonable adjustments in defined circumstances. Equality Act 2010, ss. 13, 19, 20, 29 and 39.

A neutral model can produce indirect discrimination. Counsel should obtain feature lists, data sources, subgroup testing, accessibility testing, adverse outcomes, overrides, appeals, and validation limits. Vendor documentation must be compared with actual manager practice.

United Kingdom employee monitoring also requires UK GDPR, DPA 2018, employment-contract, confidence, and workplace analysis. Collective consultation, trade-union terms, and public-sector duties depend on the workforce and deployment.

Swiss Code of Obligations arts. 328 and 328b protect employee personality and limit employee-data processing. Article 328b focuses on suitability for employment or performance of the employment contract.

Swiss Labour Ordinance 3, Article 26, restricts systems used to monitor worker behaviour. Systems needed for other reasons must be designed and arranged with worker health and movement in view. Cantonal practice and collective agreements can add duties.

The Swiss Gender Equality Act prohibits sex discrimination in employment. Disability and other discrimination require issue-specific statutory and constitutional analysis. Switzerland lacks a single private-employment equality statute matching the United Kingdom model.

A vendor cannot place every duty on the employer. The developer's design, claims, known limits, and documentation remain relevant. The employer still needs enough information to use the system lawfully.

Financial services, healthcare, transport, and public uses

Regulated uses can determine transaction viability. The target should identify every customer and deployment in finance, insurance, healthcare, medical devices, transport, public administration, policing, education, defense, and critical infrastructure.

United Kingdom financial firms remain subject to Financial Conduct Authority and Prudential Regulation Authority rules. PRA Supervisory Statement SS1/23 covers model risk management and reaches vendor, machine-learning, and AI models according to the firm's use.

A sandbox, test service, or regulator discussion does not constitute general approval. Counsel should obtain permissions, model inventories, validation, outsourcing records, consumer-duty work, complaints, and regulator correspondence.

Swiss financial institutions remain subject to technology-neutral FINMA supervision. FINMA Guidance 08/2024 identifies model, data, IT, cyber, third-party, legal, and reputation risks. The exact enforceable duty comes from the governing statute, ordinance, license, order, or supervisory requirement.

Medical software can be a device when its intended purpose meets the statutory test. Great Britain applies the Medical Devices Regulations 2002 and current amendments. Northern Ireland needs a distinct Union-linked product analysis.

Swiss medical software requires review under the Medical Devices Ordinance or In Vitro Diagnostic Medical Devices Ordinance. Intended purpose, claims, function, risk class, clinical evidence, conformity, and surveillance control.

The Automated Vehicles Act 2024 creates a United Kingdom authorization and liability regime for self-driving road vehicles. Full commencement and secondary measures require date-specific review. Ordinary driver-assistance claims remain separate.

Public-sector AI can engage procurement, administrative fairness, human rights, records, equality, reasons, and judicial review. Swiss public-law duties may be federal or cantonal. The target should obtain tender submissions, impact records, decision notices, audit rights, and contract schedules.

Product safety and liability

An AI feature can create product duties even without an AI act. Counsel should classify the product, economic operator, importer, distributor, connected hardware, intended use, warnings, updates, and post-market process.

The United Kingdom Consumer Protection Act 1987 can impose strict liability for a defective product. The General Product Safety Regulations 2005 cover specified consumer products. Contract, negligence, professional duty, and sector rules can apply in parallel.

The treatment of standalone software under strict product liability remains fact sensitive. Counsel should avoid assuming either universal inclusion or exclusion. Hardware integration, updates, safety function, and applicable product legislation matter.

The United Kingdom connected-product security regime requires a separate technical file for covered products. The file should link each security requirement to design, testing, update periods, vulnerability reporting, and the statement of compliance.

Swiss Product Safety Act, SR 930.11, applies to commercial or professional placing of products on the market. Sector product law takes priority where it addresses the same risk. The target should identify the responsible producer, importer, and distributor.

The Swiss Product Liability Act, SR 221.112.944, provides strict producer liability for specified personal injury and private-property damage. The status of standalone software is not settled for every fact pattern.

Switzerland opened consultation on a product-safety revision in June 2026. The proposal is not current law. A transaction extending into the proposed period should track the text, enactment, and commencement.

Insurance review should cover technology errors and omissions, cyber, media, intellectual property, product liability, professional indemnity, directors and officers, and crime. Counsel should test insured entities, products, exclusions, retentions, notice, and change of control.

Contracts, revenue quality, and continuity

Contract diligence must prove assent, scope, performance, and transferability. A template does not prove which terms the customer accepted.

Counsel should review executed orders, clickwrap records, amendments, procurement terms, API terms, reseller agreements, research contracts, cloud contracts, and incorporated policies. The record should identify the operative version and order of precedence.

AI clauses should address permitted use, prohibited use, customer data, prompts, logs, training, outputs, confidentiality, security, incidents, model changes, documentation, human review, audits, indemnities, caps, assignment, termination, and transition.

The contract must match actual conduct. A no-training promise is dangerous when support logs feed evaluation. A customer-control clause is weak when the target markets autonomous operation.

Revenue quality requires contract-to-ledger testing. Counsel should separate production revenue from pilots, free use, credits, related-party sales, minimum commitments, contingent milestones, and cancellable arrangements.

Continuity depends on compute, models, data, suppliers, and key people. The review should test capacity, minimum spend, hardware constraints, deprecation, price changes, suspension, portability, recovery, and concentrated know-how.

Assignment and change-of-control clauses require dependency-level review. A model API, dataset, cloud commitment, distribution right, grant, or public contract may terminate at closing.

Competition, merger review, investment screening, exports, and sanctions

Competition diligence should cover exclusivity, most-favoured terms, tying, interoperability, data access, pricing tools, information exchange, talent restrictions, customer concentration, and prior acquisitions.

The United Kingdom Competition and Markets Authority can review a transaction meeting the turnover, share-of-supply, or hybrid test. The current statutory thresholds include a £100 million target-turnover test and the separate share and hybrid tests.

The United Kingdom merger regime is generally voluntary. That does not remove interim enforcement or completion risk. Counsel should assess reference jurisdiction, substantive competition risk, and whether a briefing paper or notification is appropriate.

The National Security and Investment Act 2021 creates mandatory notification for specified acquisitions in sensitive sectors. The artificial-intelligence sector covers defined work used for identification or tracking, advanced robotics, or cyber security.

Other sensitive sectors can capture an AI target. They include computing hardware, communications, defense, data infrastructure, and critical suppliers. A notifiable acquisition completed without approval is void, subject to validation powers.

The buyer's nationality does not end the inquiry. The Act can apply to acquisitions by any person. Voluntary notification can be appropriate outside the mandatory sectors where a national-security risk may arise.

Switzerland has no operative general investment-screening regime on the as-of date. Parliament adopted the Investment Screening Act on December 19, 2025, with entry expected in 2027.

The Swiss Act will focus on acquisitions of companies in especially critical sectors by foreign state-controlled investors. The implementing ordinance remained in consultation until October 5, 2026. It is a readiness item, not a closing condition under current law.

Current Swiss merger review remains governed by the Cartel Act, SR 251, including Article 9 notification thresholds. A partial revision adopted in December 2025 is expected to enter in 2027 with revised ordinances. Current law controls until commencement.

Export review should classify software, source code, weights, technical data, encryption, chips, remote access, users, end uses, and destinations. United Kingdom controls arise under the Export Control Act 2002, Export Control Order 2008, and current lists.

Swiss controls arise under the Goods Control Act, Goods Control Ordinance, and related lists. Remote access, technical assistance, brokering, and sanctions can create separate restrictions.

Sanctions screening must cover parties, beneficial owners, controllers, banks, customers, suppliers, destinations, services, and payments. United Kingdom measures arise under the Sanctions and Anti-Money Laundering Act 2018 and program regulations.

The United Kingdom Sanctions List became the sole United Kingdom designation list on January 28, 2026. Ownership and control can extend restrictions to an unlisted entity. Program rules and licenses still control the legal answer.

Swiss sanctions arise under the Embargo Act and program ordinances. Switzerland often aligns measures with international partners, but the Swiss ordinance controls. Screening must be refreshed at signing and closing.

Findings and transaction protections

Each finding needs a legal rule, evidence status, business effect, and deal response. A colour without those parts does not answer whether the activity can continue or transfer.

Stop-level findings include missing title to a core model, unlawful irreplaceable training data, a prohibited use, absent mandatory clearance, an unavailable regulated license, or a sanctions restriction that blocks the planned business.

Closing conditions fit curable defects. Common items include assignments, consents, lien releases, privacy assessments, notices, human-review procedures, product suspension, incident remediation, supplier amendments, and regulatory filings.

Price adjustments, escrow, holdbacks, exclusions, specific indemnities, and post-closing covenants fit quantified legacy exposure. General warranties offer weak protection for a known defect.

Representations should cover authority, capitalization, title, data rights, privacy, automated decisions, product claims, security, incidents, employment, licenses, contracts, sanctions, exports, investment review, competition, and disputes.

Disclosure schedules should identify model, dataset, contract, and policy versions. Product names alone are inadequate. The seller should distinguish verified facts, management assertions, disputed matters, and unresolved items.

Interim covenants should restrict material model releases, dataset changes, supplier changes, new high-impact uses, unapproved claims, and unusual customer exceptions. They should require prompt notice of incidents, complaints, regulator contact, and law changes.

Open items need an owner, due date, evidence standard, closing effect, and escalation route. The closing bring-down should repeat AI status, data, copyright, cyber, sanctions, merger, investment, and sector checks.

Part 05

Offshore Centres

Holding, IP, token, fund and financing structures
In essence

Offshore-centre legal due diligence of an AI project asks whether its holding, intellectual-property, financing, token, fund, and operating structures are valid, licensed, transparent, and transferable. It must also test the external laws that govern the target's product, data, workers, customers, and regulated uses. This memorandum states the transaction baseline for the Cayman Islands, British Virgin Islands, Bermuda, Jersey, and Guernsey as of July 23, 2026. No target, sector, transaction structure, or data room was supplied. Each connected operating market still requires separate review.

Executive summary
Offshore centres

The review has two layers. Offshore law controls entity validity, title, filings, substance, licences, and transfer mechanics. Operating-market law controls the AI product and its effects.

All five centres

No enacted general private-sector AI statute was identified. Company, data, intellectual-property, employment, consumer, cyber, financial-services, sanctions, and tax laws supply the current tests.

Corporate and beneficial ownership

The buyer must prove existence, authority, capitalization, registers, beneficial owners, charges, registered-agent records, and filing status. A clean certificate alone is inadequate.

Economic substance

An AI royalty or licensing entity may conduct intellectual-property business. Local direction, core income-producing activity, qualified people, premises, expenditure, and records must match the reported position.

Personal data

Cayman, Jersey, and Guernsey give rights concerning significant solely automated decisions. Bermuda's PIPA and BVI's Data Protection Act also require a separate AI data-processing review.

Digital assets

Cayman applies licensing or registration according to the virtual-asset service. BVI requires VASP registration. Bermuda uses DABA licence classes. Jersey uses VASP registration for AML supervision. Guernsey licenses covered virtual-asset activity.

Funds and finance

Tokens, pooled compute, model-revenue interests, custody, lending, exchange, managed strategies, and fractional rights may trigger fund, securities, credit, or payment laws.

Cyber, sanctions, and tax reporting

The buyer should test incident duties, sector cyber rules, sanctions ownership, wallet screening, CRS, CARF, and economic-substance reporting. Each operates independently.

Transaction

Missing title, false ownership records, sham substance, unlicensed regulated activity, sanctions blocks, or a non-transferable critical dependency can stop closing. Other defects need tailored conditions and price protection.

Analysis by issue

Diligence perimeter and the two-layer method

Offshore incorporation does not determine the full legal perimeter. It governs the entity and many internal affairs. It does not displace the laws of the markets where the AI business operates.

The first layer concerns the offshore structure. Counsel should test existence, authority, shares, beneficial ownership, security, substance, tax reporting, licences, service providers, insolvency, and transfer mechanics.

The second layer concerns the operating business. Counsel should map users, workers, data subjects, training sources, compute, suppliers, public releases, customers, and regulated deployments. Those facts can trigger EU, United Kingdom, United States, Asian, Middle Eastern, or other laws.

A Cayman, BVI, or Bermuda company may contract worldwide. A Jersey or Guernsey entity may hold models or receive royalties. None of those facts proves lawful deployment in the customer's market.

Counsel should prepare linked inventories for entities, models, products, use cases, datasets, and third parties. Each record needs an owner, version date, jurisdiction, and supporting exhibit.

The transaction calendar should separate current duties from signing, closing, and integration duties. Changes in beneficial-ownership access, cyber commencement, tax reporting, sanctions, or licences can alter the closing analysis.

Corporate authority, registers, beneficial ownership, and security

The buyer must identify the legal owner of every material asset. A group website, shared director, or common brand does not prove ownership.

For each entity, counsel should obtain the certificate, constitutional documents, registers, good-standing evidence, annual filings, and registered-office records. The review should include continuations, conversions, mergers, restorations, and prior names.

The capitalization review should reconcile issued interests, options, warrants, convertibles, side letters, nominee arrangements, and promised equity. It should also test pre-emption rights, vetoes, transfer limits, and change-of-control approvals.

Beneficial-ownership records deserve independent testing. Counsel should trace natural persons through trusts, partnerships, foundations, nominees, and intermediate companies. The filed record should match customer due-diligence files and transaction documents.

Cayman now uses the Beneficial Ownership Transparency Act (2026 Revision). BVI companies and limited partnerships file beneficial-ownership information through VIRRGIN. Bermuda enacted the Beneficial Ownership Act 2025 to move its central register to the Registrar of Companies. Counsel should confirm the operative commencement and current filing channel. Jersey and Guernsey also maintain statutory ownership records.

BVI opened legitimate-interest request functionality on April 1, 2026. The target should preserve notices, objections, appeals, and disclosures. A pending request may affect confidentiality and transaction timing.

Counsel should search charges and obtain every finance document. A security package may cover shares, receivables, bank accounts, intellectual property, contracts, or distributions.

The corporate-service-provider file can expose defects absent from management records. It should include registers, resolutions, statutory notices, compliance requests, invoices, resignations, and strike-off warnings.

A valid incorporation does not equal regulatory permission. The buyer must compare the entity's activities with every licence, registration, waiver, exemption, and condition.

Economic substance and intellectual-property holding

Economic-substance review is central to an offshore AI structure. A company that receives model, software, patent, brand, data, or know-how income may conduct intellectual-property business.

The exact classification depends on the statute and facts. Counsel should identify each income stream, asset, counterparty, connected person, and commercial function. Royalty labels do not control the result.

Cayman applies the International Tax Co-operation (Economic Substance) Act (2026 Revision). BVI applies the Economic Substance (Companies and Limited Partnerships) Act 2018. Bermuda applies the Economic Substance Act 2018 and regulations.

Jersey applies the Taxation (Companies – Economic Substance) (Jersey) Law 2019. Partnerships receive separate treatment under the 2021 Law. Guernsey applies the Income Tax (Substance Requirements) (Implementation) Regulations 2021.

The target should identify its core income-generating activities. It should then prove where those activities occur, who performs them, who directs them, and which entity bears the cost.

Board minutes alone are weak evidence when commercial decisions occur elsewhere. Counsel should compare minutes with email, repository access, contracts, travel, payroll, invoices, and approval logs.

A substance file should show local meetings at an adequate frequency. It should also show knowledgeable decision-makers, local records, suitable premises, proportionate expenditure, and qualified personnel or permitted outsourcing.

Outsourcing requires proof of control and non-duplication. The provider should identify its people, premises, time, costs, and functions. Generic corporate-administration services may not perform the relevant income-producing work.

High-risk intellectual-property treatment requires early review. A common risk pattern involves acquiring intellectual property from a connected party, then licensing it abroad without local development functions.

Jersey places the burden on a high-risk IP company to rebut non-compliance. Comparable offshore rules also demand stronger evidence for mobile intellectual-property income.

An entity may satisfy company law yet fail its tax-substance position. Consequences can include penalties, information exchange, regulatory concern, banking problems, and a required reorganization.

AI asset title and intellectual property

The target must prove a continuous chain of title or a sufficient licence for every core AI asset. Technical possession is not legal ownership.

The asset schedule should cover source code, object code, architecture, weights, checkpoints, fine-tunes, prompts, evaluation sets, model cards, documentation, patents, brands, domains, and trade secrets.

Counsel should identify the law governing each contribution. Employee ownership, contractor ownership, assignment form, moral rights, patent inventorship, and database protection can arise under non-offshore law.

Founder work before incorporation needs a signed transfer. Affiliate development needs an intercompany assignment or licence. University and grant work needs a review of funding, publication, access, and commercialization terms.

The buyer should compare legal title with repositories and cloud accounts. A model stored in a group account may belong to another company. A founder-controlled account may create continuity and security risk.

Patent files should identify human inventors, conception records, assignments, priority, prosecution, maintenance, grants, and third-party funding. Marketing references to patented technology should match the actual claims and territories.

Trade-secret value depends on secrecy. Counsel should inspect access lists, confidentiality terms, publications, model releases, logging, devices, and offboarding.

Open-source code and open-weight models need exact licence analysis. The review should address modification, distribution, network use, attribution, source duties, acceptable-use limits, and termination.

Offshore ownership does not cure unlawful training. Copyright, database, privacy, contract, and confidentiality questions usually follow the source material and affected market.

Personal data and automated decisions

AI data diligence must identify the controller, processor, purpose, legal basis, data categories, recipients, retention, security, and transfer route. The result may differ by entity and processing stage.

Training, evaluation, retrieval, prompts, support, telemetry, and automated decisions need separate records. Permission for one purpose does not authorize every later use.

Cayman's Data Protection Act (2021 Revision) contains specific rights for significant solely automated decisions. A controller must notify the person and respond to a timely request for reconsideration. Data Protection Act (2021 Revision), s. 12.

Token human involvement does not resolve the Cayman issue. The reviewer must assess the output and possess authority to change the result.

Jersey gives a right not to face a solely automated decision with legal or comparably material effects. Contract, legal-authority, and explicit-consent exceptions require safeguards. Data Protection (Jersey) Law 2018, art. 38.

Guernsey also regulates automated decisions and profiling. The organisation must support human review when the statutory right applies. Data Protection (Bailiwick of Guernsey) Law 2017, s. 24.

Bermuda's Personal Information Protection Act 2016 became fully operative in 2025. It requires a privacy responsibility structure, appropriate use, notices, security, access, correction, and breach handling.

BVI enacted the Data Protection Act 2021. Target-specific work should verify the operative provisions, regulator practice, and any later instruments before assigning a precise remedy.

The diligence file should include privacy notices, impact assessments, processing records, processor contracts, transfer support, rights requests, breach records, and regulator correspondence.

Automated-decision records should identify inputs, material factors, model version, validation, human review, notices, contest routes, overrides, and outcomes.

Special-category, biometric, health, financial, and children's data need heightened review. A bias-testing purpose does not itself authorize sensitive-data processing.

Training data, confidentiality, and international transfers

A dataset register should prove source, acquisition, permission, purpose, and traceability. Public access proves none of those rights.

The register should cover pretraining, fine-tuning, retrieval, evaluation, red-team, prompt, log, feedback, and support data. Each entry needs the exact source and operative terms.

Counsel should separate copyright, database rights, privacy, contract, confidentiality, and sector secrecy. A valid answer in one category does not cure another.

Customer data may contain third-party secrets or regulated information. Support logs may contain credentials, health details, financial records, or unpublished business plans.

Synthetic data needs source analysis. It may reproduce records, preserve identifiers, or reveal memorized content. The target should document generation methods and reidentification testing.

Cross-border transfer review should follow storage, remote access, support, subprocessors, telemetry, model providers, and incident response. The server's primary location does not answer every transfer question.

M&A data rooms require purpose limits and staged access. The seller should redact, aggregate, or withhold personal data where practical. Failed transactions need deletion and return controls.

Deletion and unlearning promises require technical proof. Counsel should identify affected files, checkpoints, embeddings, vector stores, caches, logs, backups, and customer copies.

Third-party models, software, datasets, and compute

The target needs a dependency register beyond a software bill of materials. It should cover models, datasets, benchmarks, APIs, cloud services, accelerators, and security tools.

Each record should state the version, supplier, accepted terms, paying entity, actual use, transfer rights, and replacement plan.

Counsel should review commercial scope, sectors, geography, users, training, fine-tuning, distillation, outputs, redistribution, attribution, source duties, audits, suspension, and termination.

Assignment and change-of-control terms need special attention. An offshore share sale may still trigger consent or termination under a model, cloud, data, or distribution contract.

Cloud review should cover capacity, location, supplier data use, subprocessors, security, deprecation, price changes, portability, recovery, and exit support.

Benchmarks create legal and claims risk. The target should prove usage rights, contamination controls, test conditions, model versions, prompts, exclusions, and publication approval.

A critical dependency without consent or substitute can stop closing. A supplier email expressing comfort does not replace a binding consent.

Virtual assets, token structures, funds, and financial services

AI projects often add tokens, credits, pooled compute, model-revenue rights, or on-chain control. Those features require product-level classification.

Cayman requires a licence for virtual-asset custody and virtual-asset trading platforms. Other covered services require registration unless a statutory waiver applies. Virtual Asset (Service Providers) Act (2024 Revision), ss. 6 and 16.

BVI requires registration for a person carrying on a virtual-asset service in or from the territory. Custody and exchange applicants face added requirements. Virtual Assets Service Providers Act 2022, s. 7.

Bermuda regulates digital-asset business under the Digital Asset Business Act 2018. The Bermuda Monetary Authority uses Class T, Class M, and Class F licences. Unlicensed business can constitute an offence. Digital Asset Business Act 2018, s. 10.

Jersey requires covered VASPs to register for AML supervision before business starts. The activity definition appears in the Proceeds of Crime (Jersey) Law 1999, Schedule 2, Part 4.

Jersey VASP registration does not itself prove authorization for investment, fund, deposit, trust, payment, or other financial business. Counsel must test the complete product.

Guernsey's Lending, Credit and Finance (Bailiwick of Guernsey) Law 2022 licenses covered virtual-asset, consumer-credit, peer-to-peer, and crowdfunding activity from July 1, 2023.

A token can also be a share, debt claim, fund interest, derivative, electronic money substitute, deposit, or contractual right. The technology does not decide the classification.

Pooled capital used to buy compute, train models, or share revenue may form a fund or collective arrangement. Managed portfolios, custody, dealing, advice, and lending can trigger separate laws.

Counsel should inspect white papers, token terms, smart contracts, treasury controls, wallets, listings, market making, redemption, staking, voting and protocol-control rights, and promotional claims.

A sandbox admission, company registration, or AML registration does not equal full approval. The buyer should verify the public register and every licence condition.

AML, sanctions, and tax transparency

The offshore entity must identify customers, beneficial owners, controllers, counterparties, and source of funds where applicable. Regulated activity adds sector-specific duties.

Virtual-asset diligence should cover wallet screening, travel-rule processes, transaction monitoring, chain analytics, mixers, privacy coins, sanctions, and suspicious-activity reporting.

Sanctions analysis must use the local instrument. UK measures may extend to an Overseas Territory or influence a Crown Dependency, but local orders, laws, and licences control.

The review should screen directors, beneficial owners, controllers, banks, customers, suppliers, wallet addresses, destinations, and service types. Ownership and control can restrict an unlisted entity.

A sanctions warranty cannot replace current screening. The buyer should refresh results at signing, material interim dates, and closing.

CRS, FATCA, CARF, country-by-country reporting, and economic-substance filings need separate classification. An AI token or treasury product may create reporting duties absent from the operating product.

Cayman brought CARF and amended CRS rules into effect from January 1, 2026. Jersey's CARF regulations also took effect on January 1, 2026.

Counsel should reconcile tax filings with contracts, accounts, wallet activity, and public claims. Inconsistent records can affect substance, banking, audits, and purchase-price calculations.

Cybersecurity, incidents, and operational continuity

Security diligence should cover models, data, applications, infrastructure, wallets, keys, and suppliers. A conventional penetration test may omit model-specific threats.

The target should produce threat models, access lists, key controls, secure-development records, vulnerability reports, red-team tests, release approvals, monitoring, backups, and recovery tests.

Model-specific testing should address prompt injection, retrieval manipulation, data poisoning, model extraction, unsafe tool use, memorization, and weight leakage.

Bermuda PIPA applies breach duties to personal information. Regulated digital-asset and financial entities also face sector security and incident rules.

Guernsey requires reportable personal-data breaches to reach the Data Protection Authority within 72 hours. Affected persons may also need notice.

Jersey enacted the Cyber Security (Jersey) Law 2026. A commencement order was published on July 17, 2026. The exact provision-by-provision start dates require a closing bring-down.

The Jersey cyber law addresses designated operators of essential services, security measures, incident notices, and regulatory directions. Covered sectors include banking, health, transport, energy, water, digital services, and public administration.

Cayman and BVI regulated firms face sector cyber, operational, AML, and incident expectations. The exact rules depend on licence type and service.

The target should maintain one incident register. It should include breaches, unsafe outputs, discrimination, vulnerabilities, outages, fraud, key loss, wallet events, and regulator contact.

Each record should state discovery, affected systems, users, jurisdictions, containment, notices, insurance, cause, remediation, and recurrence testing.

Personnel, premises, and local operations

Economic substance and business licensing depend on actual people and premises. Counsel should test the legal and practical location of work.

The personnel file should connect each contributor to an employer, entity, asset, and work product. It should include assignments, confidentiality, prior-employer restrictions, visas, and work permits.

Local directors must exercise real judgment. A service provider that signs prepared minutes without understanding the business may not support the claimed management position.

The buyer should interview directors and key staff. Their answers should match minutes, contracts, technical approvals, and tax filings.

Immigration, local-business, population, housing, and employment rules can limit local operations. Cayman, BVI, Bermuda, Jersey, and Guernsey use different permission systems.

A post-closing migration can change substance and tax residence. Moving founders, repositories, approvals, or customer contracts may create a new legal position.

Key-person dependence needs a continuity plan. The target should identify who can train, deploy, recover, sign transactions, access wallets, or explain critical systems.

Contracts, revenue, insolvency, and transferability

Contract diligence must prove assent, performance, and transferability. A template does not prove which terms a customer accepted.

Counsel should obtain executed customer, reseller, API, cloud, data, employment, service-provider, fund, and token agreements. The file should identify each operative version.

AI terms should address data use, training, prompts, logs, outputs, confidentiality, security, incidents, model changes, documentation, human review, audits, indemnities, caps, assignment, and exit.

The terms must match conduct. A no-training promise is dangerous when support data feeds evaluation. An output-ownership promise may exceed the target's legal rights.

Revenue quality needs contract-to-ledger testing. Counsel should separate production revenue from pilots, credits, token sales, related-party receipts, minimum commitments, and contingent milestones.

The buyer should test solvency, distributions, redemptions, related-party payments, statutory demands, strike-off, restoration, and creditor claims.

Registered-agent resignation can become an operational risk. The target should disclose unpaid fees, incomplete KYC, filing defaults, and threatened resignations.

Continuations and mergers need entity-specific approval. A proposed migration may trigger creditor notices, tax consequences, licence consent, and contract termination.

Cayman Islands

Cayman diligence should start with the Companies Act (2026 Revision), constitutional records, beneficial ownership, charges, and registered-office files. The buyer should verify good standing and every material filing.

The Beneficial Ownership Transparency Act (2026 Revision) requires a current ownership record. Counsel should reconcile that record with the cap table, trust documents, and sanctions analysis.

The International Tax Co-operation (Economic Substance) Act (2026 Revision) requires activity-level classification. An AI intellectual-property company should identify all royalty, licence, and connected-party income.

Cayman's Data Protection Act applies according to its territorial provisions. Section 12 creates a direct diligence item for significant automated decisions.

CIMA licensing must match actual digital-asset activity. Custody and trading platforms need licences from April 1, 2025. Other VASPs generally require registration.

The review should also test mutual-fund, private-fund, securities-investment, money-services, banking, trust, and company-management laws where product facts require them.

Local operation may require trade-and-business, local-company-control, immigration, and work-permit analysis. An exempted company status does not answer those questions.

British Virgin Islands

BVI diligence should reconcile the BVI Business Companies Act 2004 records with VIRRGIN filings. The review should cover directors, members, beneficial owners, charges, annual returns, and registered-agent records.

All BVI companies and limited partnerships became subject to the 2024 beneficial-ownership filing regime from January 2, 2025. The target should prove timely and accurate filings.

Legitimate-interest access started on April 1, 2026. Counsel should identify any request, objection, appeal, disclosure, or exemption concerning the target.

The economic-substance statute appears under inconsistent official titles. The enacted instrument is No. 12 of 2018. Counsel should use the original Act, amendments, and current rules rather than an unofficial consolidation alone.

The Virtual Assets Service Providers Act 2022 took effect on February 1, 2023. Registration, authorized representation, audits, client-asset protection, advertising, reporting, and control changes require evidence.

BVI incorporation does not authorize financial or virtual-asset business. The buyer should verify the FSC register and inspect every condition or restriction.

The Data Protection Act 2021 belongs in the diligence perimeter. Precise commencement, regulator practice, and remedies need confirmation from the current official record for the target's facts.

Bermuda

Bermuda diligence should trace authority, ownership, charges, residence, and licences under the Companies Act 1981 and the target's entity statute.

The Beneficial Ownership Act 2025 provides for the central register's transfer to the Registrar of Companies. Counsel should confirm the operative commencement, filings, discrepancies, and any suppression request.

The Economic Substance Act 2018 and regulations require activity-level proof. The 2026 amendment must be included in the current-law review.

PIPA is fully operative. The target should produce its privacy officer record, privacy programme, notices, rights procedures, security measures, transfers, and breach history.

Digital-asset business requires the correct BMA licence. The file should identify Class T, Class M, or Class F status, permitted activities, conditions, expiry, and supervisory correspondence.

Token issuance can require separate analysis under the Digital Asset Issuance Act 2020. Insurance, funds, investment, banking, trust, money-service, and corporate-service laws may also apply.

The buyer should verify the target against the live regulated-entity register. An expired, restricted, or mismatched licence can affect closing.

Jersey

Jersey diligence should start with the Companies (Jersey) Law 1991, constitutional records, beneficial ownership, significant-person filings, security, and solvency.

The Data Protection (Jersey) Law 2018 is current from April 1, 2026. Article 38 requires a use-case record for solely automated decisions with legal or comparable effects.

Jersey economic-substance laws cover companies and partnerships. High-risk IP companies face a presumption against compliance unless they produce sufficient evidence.

The buyer should compare Jersey board records with where product, pricing, licensing, and technical decisions occur. Records should show the actual governing body.

VASP activity requires JFSC registration before business begins. That registration addresses AML supervision. It does not replace any permit needed under other financial-services laws.

The Cyber Security (Jersey) Law 2026 creates a live status issue. Counsel should confirm the commencement order's exact provisions and dates before signing and closing.

Jersey sanctions apply under the Sanctions and Asset-Freezing (Jersey) Law 2019 and connected orders. The target should reconcile sanctions controls with ownership and payment records.

Guernsey

Guernsey diligence must identify the relevant Bailiwick entity and island. Guernsey, Alderney, and Sark can differ on company, business, property, employment, and public-law matters.

The Companies (Guernsey) Law 2008 supplies the principal company record for Guernsey companies. Beneficial ownership requires separate review under the 2017 Law.

Economic-substance review should use the 2021 Regulations and applicable tax guidance. Partnerships need proof of residence, governing body, local decisions, and records.

The Data Protection (Bailiwick of Guernsey) Law 2017 applies to AI processing within its territorial reach. Section 24 and related duties require review of automated decisions, rights, DPIAs, security, and transfers.

Established organisations processing personal data may need registration with the ODPA. The buyer should verify current registration, renewal, and contact details.

The Lending, Credit and Finance Law requires licences for covered virtual-asset, credit, peer-to-peer, and crowdfunding business. The Protection of Investors Law can apply to investment products and services.

GFSC authorisation, AML rules, sanctions, ownership, and control approvals need product-level review. The public register should match the target's representations.

Findings and transaction protections

Each finding needs a legal rule, evidence status, business effect, and deal response. A colour alone does not answer whether the business can continue or transfer.

Stop-level findings include missing title to a core model, false ownership filings, sham substance, unlawful irreplaceable data, or unlicensed regulated activity.

Other stop-level findings include a struck-off entity, absent mandatory consent, sanctions prohibition, frozen assets, or a non-transferable critical model or cloud right.

Closing conditions fit curable defects. Common items include restoration, good standing, lien releases, assignments, ownership updates, licence approvals, consents, and filing corrections.

Substance remediation may require people, premises, revised decision processes, contracts, and tax filings. New minutes cannot retroactively prove work that occurred elsewhere.

Data and cyber conditions may require notices, impact assessments, processor terms, access cleanup, incident remediation, and tested human-review procedures.

Price adjustments, escrow, holdbacks, exclusions, and specific indemnities fit quantified legacy exposure. General warranties offer weak protection for a known defect.

Representations should cover authority, capitalization, ownership, substance, tax reporting, licences, data, intellectual property, security, incidents, sanctions, and contracts.

Disclosure schedules should identify exact entity, model, dataset, licence, and contract versions. Product names alone are inadequate.

Interim covenants should restrict new token activity, model releases, dataset changes, dividends, migrations, supplier changes, and unusual customer terms.

The closing bring-down should repeat good-standing, ownership, licence, sanctions, cyber, substance, and tax-reporting checks. Open items need an owner, evidence standard, and closing consequence.

Part 06

Middle East

Gulf states and special economic zones
In essence

Middle East legal due diligence of an artificial intelligence project asks whether the target can lawfully own, train, deploy, sell, and transfer its systems across connected states and special economic zones. This memorandum states the transaction baseline for the United Arab Emirates, including mainland UAE, the DIFC, and ADGM; Saudi Arabia; Israel; Qatar, including the QFC; and Bahrain as of July 23, 2026. It focuses on corporate authority, data, cloud, cybersecurity, content controls, intellectual property, employment, regulated services, public procurement, foreign investment, exports, sanctions, and transaction protection. No target, sector, buyer, transaction structure, or data room was supplied. Every additional state connected through entities, workers, users, data, compute, customers, or regulated activity requires separate local-law review.

Executive summary
Middle East

No reviewed jurisdiction has an operative general private-sector AI statute comparable to the EU AI Act. Existing company, data, intellectual-property, cybercrime, consumer, employment, financial-services, product, and sector laws supply the current tests.

United Arab Emirates

Federal law, emirate law, and free-zone law can apply to one group. Mainland UAE, the DIFC, ADGM, Dubai VARA, and sector regulators require separate actor, licence, data, and forum analysis.

Saudi Arabia

The Personal Data Protection Law requires express notice for automated decisions. Where consent supplies the legal basis for a solely automated personal-data decision, the consent must be explicit. New technology and automated decisions can trigger a data-protection impact assessment.

Israel

Privacy Amendment 13 has applied since August 2025. AI linked to military, dual-use, cyber, autonomy, or defense know-how needs early classification under the Defense Export Control Law.

Qatar and Bahrain

The QFC and Bahrain grant specific rights concerning solely automated decisions. Qatar mainland law requires privacy-by-design and pre-processing review, but no general mainland automated-decision right was identified.

Data and intellectual property

Public access does not prove a right to train. Copyright, database or compilation rights, privacy, contract, confidentiality, trade secrets, public-sector secrecy, and sector rules need separate proof.

Cloud and cybersecurity

No single regional data-localisation rule controls every project. Saudi cloud controls, financial-sector outsourcing rules, government-data terms, critical-system duties, remote access, and incident reporting require system-level mapping.

Regulated uses

Credit, investment advice, insurance, healthcare, biometrics, identity, employment, education, transport, defense, public administration, and digital assets can require licences, approvals, local hosting, testing, human review, or regulator access.

Transaction

Missing core title, unlawful irreplaceable data, unlicensed regulated activity, prohibited content or use, a blocking export or sanctions issue, or a non-transferable critical dependency can stop closing. Curable defects belong in conditions. Quantified legacy exposure belongs in price and specific protection.

Analysis by issue

The review must follow the target's actual operations. Incorporation establishes one legal connection. Users, workers, data subjects, data sources, compute, suppliers, public releases, and regulated customers create others.

The region contains overlapping legal systems. UAE federal law applies beside emirate rules and distinct financial free-zone laws. Qatar mainland law differs from QFC law. Public-sector, financial, healthcare, telecom, and critical-infrastructure rules can sit beside general commercial law.

Counsel should prepare linked inventories for legal entities, products, models, use cases, data, and third parties. Each item should identify the responsible entity, legal role, version, location, use, customer class, and supporting record.

The model inventory should cover architecture, weights, checkpoints, fine-tunes, retrieval sources, safety layers, evaluations, and releases. The use-case inventory should distinguish intended purpose from actual customer use. Sales claims and implementation support can widen the legal perimeter.

The jurisdiction map should record each place of incorporation, establishment, work, sale, use, data collection, storage, remote access, technical support, and public procurement. It should identify the buyer and post-closing integration plan. Those facts can create investment, export, sanctions, tax, and transfer duties.

A regional entity can also face external law when it places products or models abroad, targets foreign users, processes their data, employs their workers, or uses controlled technology. Regulation (EU) 2024/1689, art. 2; Regulation (EU) 2016/679, art. 3. The North American, EU and EEA, United Kingdom and Swiss, and offshore modules remain relevant to those connections.

Timing needs a separate obligations calendar. The calendar should distinguish current law, delayed provisions, consultations, policies, and regulator initiatives. A law that starts between signing and closing can change conditions, warranties, and interim covenants.

Corporate authority, foreign ownership, and asset location

The buyer must identify which entity owns each material asset and owes each material obligation. A group brand, common director, or shared repository does not prove legal ownership.

For each entity, counsel should obtain constitutional documents, commercial-register extracts, licences, shareholder and beneficial-owner records, capitalization, security interests, board authority, signing powers, and insolvency indicators. The review should include branches, representative offices, free-zone establishments, and nominee arrangements.

AI groups often split research, payroll, customer contracts, and intellectual property. The entity employing developers may lack a valid invention transfer. The entity invoicing customers may hold only an informal model licence. A cloud account may remain in a founder's name.

The asset map should connect each repository, model, dataset, patent, brand, domain, customer contract, and compute account to a legal owner. Every intercompany transfer, licence, services agreement, and cost allocation needs written terms.

Foreign-ownership rules require activity-level analysis. The UAE generally permits full foreign ownership, subject to strategic-impact and regulated activities. Saudi investment requires registration and may need approval for excluded or restricted activities. Qatar permits foreign investment under Law No. 1 of 2019, subject to sector and approval limits. Bahrain and Israel also use activity-specific restrictions and approvals.

Free-zone registration does not authorize mainland business or regulated services. A DIFC, ADGM, QFC, or other free-zone company may need a mainland licence, local distributor, branch, or regulator approval for the planned activity.

Change-of-control review should cover corporate approvals, regulator consent, government contracts, leases, work permits, public grants, security interests, and supplier contracts. An offshore or foreign parent sale can still trigger local consent.

Current AI-specific statutory position

No operative general private-sector AI act was identified in the reviewed jurisdictions. That finding does not create a legal gap. Existing statutes regulate the target's data, claims, content, decisions, products, workers, customers, and regulated services.

The UAE Cabinet approved creation of a federal Artificial Intelligence and Data Authority in June 2026. Its announced mandate includes national policy, proposed legislation, standards, and federal-entity compliance. The announcement did not create a general private-sector AI licence.

Saudi Arabia offers AI Service Provider Accreditation through the National Data Management Office platform. The process requires entity registration, an AI officer, a product questionnaire, and supporting files. Accreditation is an administrative service and evidence item. It should not be described as universal legal permission to offer AI services.

Israel has public AI institutions and defense AI programmes. They do not replace the Protection of Privacy Law, sector law, competition law, procurement rules, or export controls. Treaty commitments also need domestic legal effect before they control a private transaction.

Qatar operates government AI programmes and sandbox initiatives. Bahrain launched a National AI Policy in 2025. The Bahrain policy mainly addresses government use and related public actors. Neither item was treated as a general private-sector statute.

Diligence should still require an internal approval record. The record should name who approves training data, model releases, high-impact uses, public claims, customer exceptions, and incident responses. Unassigned responsibility increases contract and regulator risk.

Data protection and automated decisions

AI data diligence should identify the controller, processor, purpose, lawful basis, data categories, recipients, retention, security, and transfer route for each processing operation. Training, fine-tuning, retrieval, evaluation, prompts, logs, support, and automated decisions require separate entries.

The UAE Personal Data Protection Law applies to specified processing by UAE and foreign controllers. Federal Decree-Law No. 45 of 2021, art. 2. It requires fair and lawful processing, purpose control, minimisation, accuracy, security, and controller accountability. Id. arts. 5 and 7.

UAE data subjects may object to automated decisions, including profiling, that have legal or adverse effects. Contract, law, and prior-consent exceptions apply. The controller must protect the person's rights and include human review upon request. Id. art. 18.

The DIFC uses a separate regime. DIFC Data Protection Law No. 5 of 2020, Article 38, governs solely automated decisions with legal or comparably material effects. The 2025 amendment added a private right of action through Article 64A. DIFC Data Protection Regulations, Regulation 10, addresses autonomous and semi-autonomous systems, including generative AI and machine learning.

ADGM Data Protection Regulations 2021, section 20, creates a right not to face a solely automated decision with legal or comparably material effects, subject to statutory conditions. ADGM entities processing personal data must also address data-controller registration and transfer duties.

Saudi Arabia's Personal Data Protection Law applies to processing in the Kingdom and specified processing of residents' data from abroad. The Implementing Regulations require notice when the controller uses new technology or automated decisions. The notice must state whether decisions are solely automated. Implementing Regulations, art. 4(5).

Where consent supplies the legal basis for a solely automated personal-data decision, Saudi controllers need explicit consent. Implementing Regulations, art. 11(2)(c). A data-protection impact assessment is required for specified high-risk processing, including new technology, automated decisions, linked datasets, and continuous monitoring. Id. art. 25.

Saudi law also requires a data protection officer for specified public, systematic-monitoring, and sensitive-data operations. Id. art. 32. A qualifying breach must reach the authority within 72 hours. The person must receive notice without undue delay where the regulatory test is met.

Israel's Protection of Privacy Law, 5741-1981, as amended by Amendment 13, has applied in its revised form since August 2025. The amendment expanded enforcement and data-protection-officer duties for specified bodies and processing. Privacy Protection Regulations (Data Security), 5777-2017, require security controls and immediate reporting of a severe security incident where the rule applies.

No general Israeli statutory right against automated individual decisions was identified in the reviewed primary record. Counsel should not import the GDPR test by analogy. Privacy, discrimination, consumer, credit, employment, contract, and sector law can still regulate the decision.

Qatar's Law No. 13 of 2016 requires fair and lawful processing, consent or another permitted basis, privacy-by-design, security, and review before specified new processing. The law does not contain the same general automated-decision right found in the QFC.

QFC Data Protection Regulations 2021, Article 22, gives a person the right not to face a solely automated decision with legal or significant effect. Contract, law, and explicit written consent exceptions apply. Contract and consent cases require human intervention, a chance to state a view, and a right to contest.

Bahrain's Personal Data Protection Law, Law No. 30 of 2018, Article 22, addresses decisions based solely on automated processing that evaluate work performance, financial status, creditworthiness, behaviour, or trustworthiness. The person may request another decision method, subject to the contract exception and required safeguards.

The diligence file should contain notices, impact assessments, consent records, transfer support, processing registers, security evidence, rights requests, and regulator contact. Automated-decision records should identify inputs, material factors, model version, validation, human review, overrides, and outcomes.

Training data, intellectual property, confidentiality, and transfers

A dataset register must prove source, permission, purpose, and traceability. Public availability proves access. It does not prove a right to copy, train, retain, disclose, or commercialize.

The register should cover pretraining, fine-tuning, retrieval, evaluation, red-team, prompt, log, feedback, and support data. Each entry should state the source, acquisition date, collector, method, licence, contract, personal-data content, location, retention, deletion, and downstream use.

Copyright, database or compilation rights, privacy, contract, confidentiality, trade secrets, and sector secrecy require separate answers. A customer may have authority to provide data but lack authority to license third-party content within it.

No broad statutory permission for commercial AI training is currently operative across the reviewed jurisdictions. Counsel should not treat research exceptions, temporary-copy rules, or fair-use concepts from another state as controlling.

UAE copyright review should use Federal Decree-Law No. 38 of 2021 and its executive regulation. Saudi review should use the currently operative copyright law until the new law published on February 13, 2026 becomes effective 180 days after publication. The closing review must verify that transition.

The new Saudi law will add a specific exception for copying a lawfully published and lawfully acquired work to develop AI products and algorithms, limited to the stated purpose. Copyright Law, art. 26(4). That provision has no current force before the law's commencement.

Israel's Copyright Law, 5768-2007, requires a fact-specific review of copying, permitted uses, contracts, and market effects. Qatar and Bahrain also require source-level analysis under their copyright statutes and related civil or criminal rules.

Employee and contractor ownership depends on the governing employment and intellectual-property law. The buyer should obtain signed assignments from founders, employees, contractors, affiliates, universities, and grant participants. Moral rights and local formalities need separate treatment.

Trade-secret value depends on secrecy measures. Counsel should inspect repository permissions, confidentiality terms, model releases, publication history, device controls, logging, and offboarding. A public release can destroy secrecy in the released material.

Cross-border transfers require a system map. Storage location alone is insufficient. Remote administration, support, subprocessors, telemetry, model providers, and incident access can constitute transfers or disclosures.

Saudi transfers can use prescribed routes, including standard clauses, binding common rules, certifications, adequacy, or statutory exceptions. UAE, DIFC, ADGM, Qatar, QFC, Bahrain, and Israel use their own transfer tests. The contract must match the actual technical path.

Deletion and unlearning promises require technical evidence. The target should identify affected source files, checkpoints, embeddings, vector stores, caches, logs, backups, and customer copies. A deletion clause has little value when the target cannot locate the data.

Third-party models, software, datasets, and compute

The target needs a dependency register beyond a software bill of materials. It should cover open-source code, open-weight models, hosted models, datasets, benchmarks, APIs, cloud, accelerators, security tools, and content filters.

Each record should identify the exact version, supplier, accepted terms, paying entity, actual use, transfer rights, and replacement plan. Counsel should preserve the terms in force when the target accepted them.

The review should test commercial scope, field limits, geography, users, training, fine-tuning, distillation, outputs, redistribution, attribution, source duties, audit, suspension, termination, assignment, and change of control.

An open-source or open-weight label does not resolve the issue. The exact licence and integration method control. Acceptable-use terms can bar sectors, persons, locations, or content.

Cloud agreements need capacity, data location, supplier training, subprocessors, security, model changes, deprecation, price resets, suspension, portability, disaster recovery, and exit support. A target may own its application but lack transferable model or compute access.

Saudi cloud deployments require review under NCA Cloud Cybersecurity Controls CCC-2:2024 where applicable. Financial, telecom, health, government, and critical-system customers can impose added localisation, approval, audit, and outsourcing duties.

UAE cloud treatment depends on the entity, data, emirate, free zone, and regulated sector. DIFC, ADGM, financial regulators, health authorities, and government contracts can impose distinct requirements.

Benchmarks need the same discipline. The target should prove usage rights, test-set confidentiality, contamination controls, score methods, model versions, prompts, exclusions, and publication approval.

A critical dependency without consent or substitute can stop closing. Informal supplier comfort should not replace a binding consent or amended contract.

Cybersecurity and incident history

AI security diligence should cover models, data, applications, infrastructure, identities, and suppliers. Ordinary penetration testing may omit prompt injection, retrieval manipulation, poisoning, model extraction, unsafe tool use, and weight leakage.

Counsel should obtain threat models, secure-development records, privileged-access lists, key controls, model registries, dataset controls, supplier access, vulnerability reports, red-team results, release approvals, monitoring, backups, and recovery tests.

UAE cyber review should include Federal Decree-Law No. 34 of 2021 on Countering Rumours and Cybercrimes. Unauthorized acquisition, use, alteration, disclosure, or publication of personal and confidential electronic data can create criminal exposure.

Saudi review should include NCA controls, the Cybercrime Law, sector requirements, cloud controls, and incident channels. Applicability depends on the entity, system, customer, and national-security connection.

Israel's Privacy Protection Regulations (Data Security), 5777-2017, classify databases and prescribe controls. Amendment 13 strengthened enforcement. Defense, critical-infrastructure, health, and financial systems can face added rules.

Qatar's National Cyber Security Agency regulates cybersecurity and administers the mainland privacy statute. Government and critical-sector contracts can impose security, hosting, audit, and incident duties beyond Law No. 13 of 2016.

Bahrain financial institutions and their vendors must review the relevant Central Bank of Bahrain Rulebook module. Outsourcing, cloud, cyber resilience, incident notice, audit, and data access vary by licence class.

The target should maintain one incident register across legal, security, product, and operations teams. It should include data breaches, unsafe outputs, discrimination, vulnerabilities, outages, fraud, prompt leakage, weight leakage, poisoning, extraction, and regulator contact.

Each incident entry should record discovery, affected systems, people, jurisdictions, containment, legal analysis, notices, customer communications, insurance, cause, remediation, and recurrence testing. An undisclosed incident can alter warranties, disclosure schedules, coverage, valuation, and closing.

Content controls, product claims, synthetic media, and children

AI outputs can trigger criminal, media, consumer, defamation, privacy, personality, copyright, public-order, and religious-content rules. The product should map user inputs, output categories, moderation, escalation, and geographic controls.

The UAE cybercrime statute penalizes specified unlawful content and dissemination. Saudi, Qatar, Bahrain, and Israel also apply local criminal, media, public-order, and sector rules. A global moderation policy may not capture local prohibitions.

Marketing diligence should compare public claims with retained evidence. Claims about accuracy, bias, safety, privacy, security, training rights, human review, certification, output ownership, and benchmark rank need dated support.

The supporting file should identify the model version, test set, prompts, sample, exclusions, threshold, result, date, and approver. A disclaimer does not cure a contradictory headline, demo, procurement response, or sales script.

Synthetic media can engage consent, identity, voice, likeness, defamation, fraud, copyright, elections, and criminal law. Counsel should inspect labelling, detection, takedown channels, impersonation controls, and customer restrictions.

Children and vulnerable users require added review. The target should identify actual audience, age signals, parental permissions, profiling, advertising, retention, crisis escalation, and human intervention.

Arabic-language consumer, employment, government, and execution requirements need document-level review. UAE, Saudi, Qatar, and Bahrain official Arabic texts control where the official record so states. Israel requires review of the operative Hebrew text.

Employment, localisation, and workplace systems

Employment AI can trigger data, discrimination, contract, consultation, monitoring, and termination rules. The review should cover recruitment, ranking, scheduling, productivity scoring, promotion, pay, discipline, and dismissal.

Counsel should obtain feature lists, training sources, validation, subgroup testing, accessibility testing, notices, adverse outcomes, overrides, appeals, and vendor communications. Written policy should match actual manager conduct.

UAE employment review should address Federal Decree-Law No. 33 of 2021, free-zone employment rules, work permits, Emiratisation, wage systems, and employee-data processing. DIFC and ADGM use distinct employment laws.

Saudi review should address the Labour Law, work permits, Saudisation, wage protection, employee monitoring, and assignment of inventions. Localisation can also affect substance and licence conditions.

Qatar and Bahrain apply local employment, immigration, wage, and nationalisation rules. The QFC uses separate employment regulations. Israel requires review of labour, privacy, equality, collective rights, and work-permit rules.

A vendor cannot assign every discrimination duty to the employer. The developer's design, claims, limits, and known uses remain relevant. The employer still needs enough information to conduct lawful human review.

Regulated sectors and public procurement

Sector classification can determine whether the transaction is viable. The target should identify every use in credit, investment, payments, insurance, healthcare, medical devices, telecom, transport, energy, education, government, policing, defense, and critical infrastructure.

Financial AI can constitute investment advice, portfolio management, credit scoring, underwriting, fraud detection, payment processing, or outsourcing. Each function requires regulator and licence mapping.

Saudi capital-market rules now define a robo-advisory service involving algorithms and modern technical means. A product that manages client investments can require Capital Market Authority authorization and compliance records.

UAE financial services require separate Central Bank, Securities and Commodities Authority, DFSA, FSRA, and emirate-level analysis. A DIFC or ADGM permission does not authorize the same service throughout the UAE.

QFC financial services require QFCRA authorization where the activity is regulated. Bahrain financial services require the correct CBB licence. Israel and Qatar mainland also apply sector-specific authorization and outsourcing rules.

Healthcare AI needs intended-purpose, clinical, data, advertising, professional, device, and liability review. A wellness label does not control where claims or functions indicate diagnosis, treatment, or clinical decision support.

Public procurement can impose data location, Arabic terms, security clearance, local content, audit, source-code escrow, intellectual-property allocation, incident notice, and sovereign-rights clauses. The target should reconcile tender promises with product reality.

A sandbox admission, accreditation, innovation licence, or pilot approval does not prove full legal authorization. Counsel should identify the exact scope, period, conditions, customer class, and exit route.

Digital assets, payments, and token structures

AI projects that issue tokens, credits, compute rights, revenue interests, or on-chain control need product-level financial classification. The technology does not determine the legal category.

Dubai's Virtual Assets Regulatory Authority regulates virtual-asset activities in Dubai outside the DIFC. The target should identify whether it needs a VARA licence and which rulebooks apply.

DIFC digital-asset activity falls within DFSA rules. ADGM uses FSRA rules for virtual assets, fiat-referenced tokens, and related activities. Each regime has distinct custody, market, capital, technology, and conduct duties.

Saudi digital-asset and payment activity requires review under Saudi Central Bank and Capital Market Authority rules. Qatar mainland, the QFC, and Bahrain use their own central-bank or financial-centre regimes.

Bahrain's CBB Rulebook includes a crypto-asset module, and the CBB introduced a stablecoin issuance regime in 2025. The buyer should verify the live licensing directory and every condition.

A token can also constitute a security, fund interest, debt claim, derivative, payment instrument, deposit, or contractual right. Pooled compute or shared model revenue can create collective-investment or managed-account exposure.

The diligence file should include white papers, token terms, smart contracts, treasury controls, wallets, listings, market-making arrangements, redemption, staking, voting, and protocol-control rights.

AML and sanctions review should cover customers, beneficial owners, wallets, counterparties, source of funds, transaction monitoring, suspicious-activity reporting, mixers, and privacy-enhancing services.

Competition, investment, exports, and sanctions

Competition review should cover exclusivity, most-favoured terms, tying, data access, interoperability restrictions, pricing tools, information exchange, talent restrictions, customer concentration, and acquisitions.

UAE Federal Decree-Law No. 36 of 2023 governs competition. Cabinet Resolution No. 3 of 2025 sets a 40 percent dominance threshold and concentration notification tests based on AED 300 million of relevant UAE sales or a 40 percent transaction share. Cabinet Resolution No. 59 of 2026 takes effect on July 30, 2026 and requires a closing-date update.

Saudi, Israeli, Qatari, and Bahraini competition laws can require merger filings or prohibit restrictive conduct. The buyer should obtain local turnover, market-share, transaction-value, and control information before signing.

Foreign-investment review depends on the activity, investor, ownership, government links, sensitive data, defense ties, and control rights. Registration alone does not resolve national-security or sector approval.

Israel requires early export classification when AI involves defense equipment, defense know-how, defense services, military autonomy, surveillance, cyber, or dual-use functions. Defense Export Control Law, 5767-2007. Marketing, brokering, and transfer can each require authorization.

Other regional states also regulate military and dual-use items. United States, Union, United Kingdom, or supplier-country controls can follow chips, source code, encryption, model weights, or technical data through re-export rules.

Sanctions screening must cover parties, beneficial owners, controllers, banks, customers, suppliers, destinations, services, and payments. Local UAE, Saudi, Israeli, Qatari, and Bahraini measures require separate review from the buyer's home-country sanctions.

UAE targeted-financial-sanctions procedures can require immediate asset freezing where a listed person's ownership or control test is met. Screening must continue through closing because designations and ownership can change.

United Arab Emirates, DIFC, and ADGM

UAE diligence must state which legal zone controls each entity, contract, worker, data operation, and regulated service. Mainland UAE, DIFC, ADGM, and emirate-specific regimes are not interchangeable.

Mainland corporate review should use Federal Decree-Law No. 32 of 2021 on Commercial Companies, the relevant emirate licence, and activity approvals. Strategic-impact activities can retain ownership or approval limits.

Federal data law excludes specified government, security, judicial, and separately regulated health data. Those exclusions do not create unrestricted use. The governing sector or government rule must be identified.

Federal automated-decision rights under Article 18 require a documented objection and human-review process. The target should test whether its contract or consent exception is valid and whether review can change the result.

DIFC entities need Article 38 classification and Regulation 10 evidence. The 2025 private right of action increases transaction exposure. A June 2026 DIFC consultation had closed by the as-of date, but no enacted amendment was verified.

ADGM entities need section 20 classification, controller registration, processing records, transfer support, and Office of Data Protection interaction. A financial entity also needs FSRA analysis.

Digital-asset activity requires the correct regulator. Dubai VARA, DFSA, FSRA, the Central Bank, and the Securities and Commodities Authority have different perimeters.

The buyer should confirm Arabic and English document status. Federal official English text states that Arabic prevails. DIFC and ADGM laws use their own official publication and court systems.

Saudi Arabia

Saudi diligence should connect each entity, licence, worker, server, data subject, customer, and government relationship to the operative statute and regulator. Registration and investment approval should match actual activity.

The PDPL file should include notices, explicit consents, impact assessments, DPO analysis, breach procedures, transfer mechanisms, and destruction evidence. Solely automated decisions require express treatment.

The target should distinguish AI accreditation from licensing. Accreditation may support procurement or market claims. It does not replace a financial, telecom, health, cloud, professional, or investment licence.

Cyber review should map NCA controls, data localisation, cloud tenancy, sector outsourcing, government requirements, and incident reporting. Supplier contracts should permit regulator access and evidence production where required.

Copyright diligence needs a transition calendar. The new Saudi Copyright Law was published on February 13, 2026 and starts 180 days after publication. Until then, the operative prior law controls. The buyer should repeat the check at signing and closing.

Employment review should cover Saudisation, work permits, wage protection, employee inventions, confidentiality, and local staffing required by licences or procurement.

Israel

Israeli diligence should start with privacy, intellectual property, cybersecurity, defense exports, sector regulation, corporate authority, and employment. Product facts determine whether national-security agencies or sector regulators enter the review.

Amendment 13 increases the value of accurate database classification, DPO analysis, security records, and incident reporting. A large sensitive database may require notice to the Privacy Protection Authority under the amended law.

The target should preserve processing inventories, transfer agreements, database-security classifications, access records, breach analyses, and regulator correspondence. No general automated-decision exemption should be inferred from the absence of a dedicated right.

Defense export classification should occur before technical diligence exposes controlled material to a foreign bidder or adviser. The data room may need access restrictions, clean teams, nationality screening, and licence conditions.

Copyright and trade-secret review should separate model ownership from training permission. Defense, university, incubator, and government funding can create publication, control, or transfer restrictions.

Qatar and the Qatar Financial Centre

Qatar diligence must separate mainland law from QFC law. Entity formation, data, employment, contracts, finance, insolvency, and courts can differ.

Mainland Law No. 13 of 2016 requires privacy-by-design and advance review for new processing. The target should produce notices, consents, processing reviews, security measures, breach decisions, and NCSA correspondence.

QFC Article 22 requires a specific automated-decision process. The file should show whether a decision is solely automated, which exception applies, and how human intervention and contest rights work.

Foreign-investment approval should match the actual activity and customer base. A QFC registration does not authorize mainland regulated activity.

Government AI programmes and sandboxes should be recorded as procurement or policy facts. They should not be described as a general private-sector approval.

Bahrain

Bahrain diligence should connect the company, licence, data processing, workers, products, and customers to the operative statute and regulator. The National AI Policy is not a substitute for private-sector legal analysis.

Article 22 of Law No. 30 of 2018 creates a concrete automated-decision workstream for employment, financial, credit, behavioural, and trustworthiness evaluations. The target should document requests for another method and the contract exception.

The privacy file should address the 2022 decisions on transfers, security, impact assessment, breaches, notifications, sensitive data, DPOs, and data-subject rights. The Ministry of Justice performs the statutory authority's functions under Decree No. 78 of 2019.

Financial AI and virtual assets require CBB classification. The target should verify the relevant Rulebook volume, licence category, outsourcing terms, cloud controls, and incident duties.

Contracts, revenue quality, and continuity

Contract diligence must prove assent, scope, performance, and transferability. A template does not prove which terms a customer accepted.

Counsel should obtain executed orders, clickwrap records, amendments, procurement terms, API terms, reseller agreements, research contracts, cloud contracts, and incorporated policies. The record should identify the operative version and order of precedence.

AI clauses should address permitted use, prohibited use, customer data, prompts, logs, training, outputs, confidentiality, security, incidents, model changes, documentation, human review, audits, indemnities, caps, assignment, termination, and transition.

The terms should match actual conduct. A no-training promise is dangerous when support logs feed evaluation. A customer-control clause is weak when the target markets autonomous operation.

Revenue quality requires contract-to-ledger testing. Counsel should separate production revenue from pilots, free use, credits, related-party sales, minimum commitments, contingent milestones, and token proceeds.

Continuity depends on compute, models, data, suppliers, licences, and key people. The review should test capacity, minimum spend, deprecation, price changes, suspension, portability, recovery, and concentrated know-how.

Arabic execution, notarisation, legalization, apostille or consular steps, government templates, and local-signatory authority need contract-specific review. English-only documents may not control before every local court or authority.

Findings and transaction protections

Each finding needs a legal rule, evidence status, business effect, and deal response. A colour alone does not answer whether the activity can continue or transfer.

Stop-level findings include missing title to a core model, unlawful irreplaceable training data, prohibited content or use, unlicensed regulated activity, absent mandatory investment or export approval, or a sanctions block.

Other stop-level findings include a non-transferable critical cloud or model right, false licence representations, material hidden incidents, or a government contract that terminates at closing.

Closing conditions fit curable defects. Common items include assignments, consents, licence approvals, investment filings, data assessments, notices, human-review procedures, product suspension, incident remediation, supplier amendments, and access cleanup.

Price adjustments, escrow, holdbacks, exclusions, specific indemnities, and post-closing covenants fit quantified legacy exposure. General warranties offer weak protection for a known defect.

Representations should cover authority, capitalization, title, data rights, automated decisions, product claims, security, incidents, employment, licences, contracts, sanctions, exports, investment review, competition, and disputes.

Disclosure schedules should identify exact entity, model, dataset, licence, policy, and contract versions. Product names alone are inadequate. The seller should distinguish verified facts, management assertions, disputes, and unresolved items.

Interim covenants should restrict material model releases, dataset changes, new high-impact uses, supplier changes, token activity, unapproved claims, and unusual customer exceptions. They should require prompt notice of incidents, complaints, regulator contact, and law changes.

Open items need an owner, due date, evidence standard, closing effect, and escalation route. The closing bring-down should repeat licence, data, cyber, sanctions, export, investment, competition, and law-status checks.

Part 07

Asia-Pacific

Singapore · Japan · South Korea · Australia
In essence

Asia-Pacific hub legal due diligence of an artificial intelligence project asks whether the target can lawfully own, train, deploy, sell, and transfer its models, systems, data, products, and regulated services across Singapore, Hong Kong, Japan, South Korea, and Australia. This memorandum states the transaction baseline as of July 24, 2026. It tests corporate authority, data processing, automated decisions, training rights, cybersecurity, product claims, regulated uses, foreign investment, exports, and transaction protection. No target, sector, buyer, transaction structure, or data room was supplied. Every additional jurisdiction connected through entities, workers, users, data, compute, customers, or controlled technology requires separate review.

Executive summary
Asia-Pacific

South Korea has an operative general AI statute. Japan has an AI promotion statute, a Cabinet plan, and statutory guidance. Singapore, Hong Kong, and Australia still regulate private AI mainly through privacy, intellectual-property, consumer, cyber, employment, product, and sector laws.

South Korea

The AI Basic Act requires specified notices and labels for high-impact and generative AI. It adds risk, documentation, human-oversight, and domestic-representative duties for covered systems and providers. The Personal Information Protection Act grants rights concerning significant fully automated decisions.

Japan

The 2025 AI Act and the second AI Basic Plan promote development and use rather than impose an EU-style pre-market conformity regime. The final statutory AI guideline and the March 2026 AI Business Guidelines remain central diligence evidence. A July 2026 privacy amendment has delayed commencement.

Singapore

The Personal Data Protection Act and the PDPC AI advisory govern personal-data use. The Copyright Act permits computational data analysis, including machine-learning training, when statutory conditions and lawful access are satisfied. The amended Cybersecurity Act has applied since October 31, 2025.

Hong Kong

The Personal Data (Privacy) Ordinance applies beside the PCPD AI model document. No general statutory automated-decision right was identified. The critical-infrastructure computer-system ordinance has applied since January 1, 2026. AI copyright reform remains pending.

Australia

Existing privacy, consumer, discrimination, cyber, product, and sector laws remain the current private-sector baseline. The government guidance for AI adoption is voluntary. New privacy-policy disclosures for significant computer-program decisions and the Children’s Online Privacy Code are due on December 10, 2026.

Training data and IP

The copyright answer is not regional. Singapore has a broad computational-data-analysis exception. Japan uses a purpose-limited non-enjoyment exception. South Korea relies on fair use and other specific exceptions. Hong Kong and Australia have not enacted a broad commercial text-and-data-mining exception.

Regulated uses

Employment, lending, insurance, healthcare, medical devices, biometrics, education, public administration, critical infrastructure, and financial services require separate licences, notices, testing, human review, security, and regulator-access analysis.

Transaction

Missing core title, unlawful irreplaceable data, unlicensed regulated activity, a prohibited use, a blocking investment or export issue, or a non-transferable critical dependency can stop closing. Curable defects belong in conditions. Quantified legacy exposure belongs in price and specific protection.

Analysis by issue

The review must follow the target’s operating facts. Incorporation answers only the internal-affairs question. Users, workers, data subjects, data sources, compute, support teams, and customers create separate connections.

Counsel should prepare six linked inventories. They should cover legal entities, products, models, use cases, data flows, and third parties. Each item needs an owner, version date, location, legal role, and supporting record.

The model inventory should identify architecture, weights, checkpoints, fine-tunes, retrieval sources, safety layers, evaluations, and release history. The use-case inventory should distinguish intended purpose from actual customer use. Sales materials and implementation support may widen the target’s legal exposure.

The jurisdiction matrix should record each place of incorporation, work, sale, use, collection, storage, remote access, and support. It should include government procurement and regulated customers. It should also identify the buyer and post-closing integration plan.

External law may attach to a regional target. An Asia-Pacific company can enter the EU AI Act through Union market placement or output use. It can enter overseas privacy law through targeting, monitoring, establishments, or local data subjects. The prior regional modules remain relevant to those connections. Regulation (EU) 2024/1689, art. 2; Regulation (EU) 2016/679, art. 3.

Timing requires a separate calendar. Counsel should distinguish current duties, enacted delayed duties, policy documents, consultations, and guidance. The closing analysis should track October 31, 2025, January 1, 2026, January 22, 2026, July 17, 2026, December 10, 2026, and later start dates discussed below.

Corporate authority, capitalization, and asset location

The buyer must identify the entity that owns each material asset and owes each material obligation. A common brand, shared director, or consolidated website does not prove ownership.

Counsel should obtain constitutional documents, registers, capitalization records, beneficial-owner information, board approvals, security interests, and insolvency indicators. The review should include options, convertibles, side letters, nominee interests, and promised equity.

AI groups often separate research, payroll, customer contracting, and intellectual property. The entity employing developers may lack a valid invention transfer. The customer entity may have only an informal model licence. A founder may still control a cloud or code account.

The asset map should connect every repository, model, dataset, patent, brand, domain, customer contract, and compute account to a legal owner. Intercompany assignments, licences, services agreements, and cost allocations need written terms.

Change-of-control review should cover corporate approvals, licences, leases, government contracts, grants, security interests, and supplier consents. A share sale can trigger a consent even when the operating entity remains unchanged.

Foreign-investment review must start early. Singapore’s Significant Investments Review Act applies ownership and control rules to designated entities. It also grants powers concerning any entity that acts against national-security interests. Japan uses FEFTA prior-notification and review rules, with a 2026 amendment and draft implementing measures requiring status checks. South Korea uses the Foreign Investment Promotion Act and sector rules. Australia applies the Foreign Acquisitions and Takeovers Act, including national-security business concepts.

Current AI-specific statutory position

The region no longer supports one description of AI law. South Korea’s AI Basic Act has applied since January 22, 2026. Japan’s Act No. 53 of 2025 has applied in full since September 1, 2025. The two statutes have different legal designs.

South Korea imposes direct duties on covered providers. Article 31 addresses advance notice and AI-generated output labels. Articles 32 to 36 address specified safety systems, high-impact AI, human oversight, documentation, and foreign-provider representation. Investigation and corrective powers support the regime.

Japan’s statute directs national planning, research promotion, guidance, information collection, and public measures. It does not create a general pre-market conformity file or a cross-sector private AI licence. The second AI Basic Plan received Cabinet approval on July 14, 2026. The AI Strategy Headquarters adopted the statutory AI guideline on December 19, 2025.

Singapore, Hong Kong, and Australia have not enacted a comparable cross-sector private AI act. Their regulators use existing statutes, sector rules, and nonbinding AI documents. A policy, sandbox, assurance tool, or voluntary standard does not replace an applicable licence or statute.

The target still needs an internal responsibility record. It should identify who approves training data, model releases, high-impact uses, customer exceptions, product claims, and incident responses. The record should match board reporting and actual practice.

Personal data and automated decisions

Data diligence must identify the controller or equivalent business, processor, purpose, legal basis, data categories, recipients, retention, security, and transfer route. Training, fine-tuning, retrieval, evaluation, prompts, logs, and decisions need separate entries.

Singapore applies the Personal Data Protection Act 2012. Core duties address consent or an exception, notice, purpose, access, correction, accuracy, protection, retention, transfer limits, and breach notice. The PDPC AI advisory explains how those duties apply to recommendation and decision systems. It does not create a separate statute.

The reviewed Singapore Act does not contain a general standalone right equivalent to South Korea’s Article 37-2. That absence does not permit opaque or unfair use. Notice, consent, purpose, accuracy, access, correction, and sector rules may still require explanation and human review.

Hong Kong applies the Personal Data (Privacy) Ordinance, Cap. 486. Its data-protection principles address collection, accuracy, retention, use, security, openness, and access. The PCPD’s AI Model Personal Data Protection Framework recommends risk assessment, human oversight, testing, monitoring, incident response, and clear communication. The document is guidance, not legislation.

The reviewed Hong Kong Ordinance does not contain a general statutory right against solely automated decisions. High-impact uses still engage purpose limits, accuracy, security, discrimination, consumer, employment, credit, and sector rules. Contractual human-review promises must match actual operations.

Japan applies the Act on the Protection of Personal Information and sector rules. The current Act governs acquisition, purpose specification, use, sensitive information, third-party provision, security, breach notice, data-subject requests, and overseas transfers. It does not create a general GDPR-style veto over automated decisions.

Japan promulgated a major APPI amendment on July 17, 2026. Most provisions start on a date set by Cabinet Order within two years. The current-law file and the post-commencement readiness file should remain separate.

South Korea’s PIPA Article 37-2 gives a person rights concerning a decision made entirely by an automated system when it materially affects rights or duties. The person may object or seek an explanation. The controller may need to stop applying the decision or reprocess it with human involvement, subject to statutory exceptions. The controller must disclose decision criteria, procedures, and personal-data handling. Personal Information Protection Act, art. 37-2.

The Korea file should identify whether a human meaningfully participates. A rubber-stamp review remains an automated process in substance. Counsel should inspect authority, timing, information supplied, override rates, and appeal outcomes.

Australia applies the Privacy Act 1988 and the Australian Privacy Principles to covered entities. Current duties address collection, notice, use, disclosure, security, access, correction, overseas disclosure, and eligible data breaches. The Act does not yet grant a general right to reject an automated decision.

New APP 1.7 to 1.9 duties start on December 10, 2026. A covered privacy policy must then describe specified computer-program decisions that may materially affect individual rights or interests. It must identify the personal-information and decision types. The duty applies to relevant decisions from that date, even if the arrangement or data predates it.

The privacy file should contain processing records, notices, consent or exception analyses, impact assessments, transfer records, processor terms, rights requests, and breach decisions. Automated-decision files should add inputs, material factors, validation, human review, overrides, and outcomes.

A dataset register must prove source, permission, purpose, and traceability. Public availability proves access. It does not prove a right to copy, retain, train, disclose, or commercialize.

The register should cover pretraining, fine-tuning, retrieval, evaluation, red-team, prompt, log, feedback, and support data. Each entry should identify source, date, collector, method, terms, personal data, location, retention, deletion, and downstream use.

Copyright, privacy, contract, confidentiality, trade secrets, and sector secrecy require separate answers. A copyright exception does not cure an unlawful data collection. A customer contract cannot grant rights the customer does not hold.

Singapore’s Copyright Act 2021 defines computational data analysis broadly. The permitted use includes text and data mining and machine-learning training. Lawful access remains essential. Statutory restrictions also govern retained copies and communications. Copyright Act 2021, ss. 243-244.

Singapore’s exception does not authorize paywall circumvention or unrelated distribution. Counsel should preserve access records, licence terms, source copies, analysis purpose, and every onward disclosure. Contract and database restrictions remain separate.

Japan’s Copyright Act Article 30-4 permits use when the purpose is not enjoyment of the thoughts or sentiments expressed in a work. Information analysis falls within the provision. The use must remain within the necessary extent and must not unreasonably prejudice the rights holder’s interests.

The Japanese exception needs purpose-level evidence. A training use can fall outside the exception when enjoyment of expression forms part of the purpose. Output generation and market substitution need separate infringement analysis.

South Korea has no dedicated broad commercial TDM exception in the reviewed current Act. Article 35-5 supplies a four-factor fair-use test. Other specific exceptions may apply. The target should document purpose, nature, amount, acquisition, output behaviour, and market effect. Copyright Act, art. 35-5.

Hong Kong completed consultation on AI and copyright in 2024. The 2025 policy record states that the government was preparing a code and legislative proposals. No enacted broad commercial TDM exception was identified by the as-of date. Copyright Ordinance, Cap. 528, remains the operative statute.

Australia’s Copyright Act 1968 remains in force in its April 2, 2026 compilation. Existing fair-dealing exceptions are purpose-specific. The Attorney-General’s Department states that the government is not considering a TDM exception. Each training source therefore needs a licence, another statutory basis, or a defensible non-infringement analysis.

Output diligence should separate subsistence, ownership, infringement, and contract allocation. Customer terms can allocate commercial risk. They cannot create statutory rights where governing law finds no protectable human authorship.

The buyer should inspect memorization and similarity testing. It should also inspect filters for confidential information, personal data, trade marks, voice, likeness, and false attribution. Complaints and takedowns need a versioned incident trail.

Employee and contractor ownership remains jurisdiction-specific. The target should produce signed assignments from founders, staff, contractors, affiliates, universities, and grant participants. Patent files should identify human inventors, conception records, assignments, disclosures, and funding restrictions.

Trade-secret value depends on secrecy measures. Counsel should review repository permissions, model releases, publications, device controls, confidentiality terms, logging, and offboarding. A public release can destroy secrecy in the released material.

Third-party models, software, data, and compute

The target needs a dependency register beyond a software bill of materials. It should cover code, open-weight models, hosted models, datasets, benchmarks, APIs, cloud, accelerators, safety tools, and identity services.

Each entry should identify the exact version, supplier, accepted terms, paying entity, actual use, transfer rights, and replacement plan. Counsel should preserve the terms in force when accepted.

The review should test commercial scope, sectors, geography, users, training, fine-tuning, distillation, outputs, redistribution, attribution, source duties, audit, suspension, termination, assignment, and change of control.

An open-source or open-weight label does not answer those questions. The exact licence and integration method control. Acceptable-use terms may prohibit a sector, person, place, or content type.

Cloud agreements need capacity, data location, supplier training, subprocessors, security, model changes, deprecation, price resets, suspension, portability, disaster recovery, and exit support. A target may own its application while lacking transferable model or compute access.

Benchmarks need the same review. Counsel should verify rights, test-set confidentiality, contamination controls, model version, prompts, sample, exclusions, and publication approval. Unsupported rankings create consumer and contract risk.

A critical dependency without consent or a substitute can stop closing. An informal supplier statement does not replace a binding consent or amendment.

Cybersecurity, critical infrastructure, and incidents

AI security diligence should cover models, data, applications, infrastructure, credentials, and suppliers. Ordinary penetration testing may omit prompt injection, retrieval manipulation, poisoning, extraction, unsafe tool use, and weight leakage.

Counsel should obtain threat models, secure-development records, privileged-access lists, secrets controls, model registries, supplier access, vulnerability reports, red-team results, release approvals, monitoring, backups, and recovery tests.

Singapore’s amended Cybersecurity Act provisions began on October 31, 2025. The changes update CII oversight and add new regulated system classes. Covered CII owners must report specified incidents within two hours. The target should classify every essential service, virtual system, and temporary critical system.

Hong Kong’s Protection of Critical Infrastructures (Computer Systems) Ordinance, Cap. 653, began on January 1, 2026. It applies to designated operators and critical computer systems. It imposes organizational, preventive, reporting, and response duties. The buyer should obtain designation notices, plans, audits, incident records, and Commissioner correspondence.

Japan’s current cyber duties arise from the Basic Act on Cybersecurity, sector rules, contracts, and economic-security measures. The current Basic Act record flags additional provisions for October 1, 2026. METI issued an SCS assessment policy in March 2026. The scheme targets a start around the end of fiscal 2026, so it remains a readiness item.

South Korea requires a system-specific review under PIPA, the Act on the Protection of Information and Communications Infrastructure, financial rules, medical rules, telecom rules, and public-sector duties. The AI Basic Act adds safety duties for systems above a statutory compute threshold. Counsel should verify the current decree, threshold, submission form, and system scope.

Australia’s Cyber Security Act 2024 and the Security of Critical Infrastructure Act 2018 create separate workstreams. Covered ransomware payments trigger reports under rules that began on March 3, 2025. Critical-infrastructure entities may face risk-management, incident, information, and government-assistance duties.

The target should maintain one incident register. It should include data breaches, unsafe outputs, discriminatory outcomes, vulnerabilities, outages, prompt leakage, weight leakage, poisoning, model extraction, and regulator contact.

Each entry should record discovery, systems, people, jurisdictions, containment, legal analysis, notices, customer communications, insurance, cause, remediation, and recurrence testing. An undisclosed incident can alter warranties, disclosure schedules, coverage, valuation, and closing.

Product claims, synthetic media, online services, and children

Marketing diligence should compare public claims with retained evidence. Websites, decks, demos, model cards, security pages, tender responses, and sales scripts all matter.

Claims about accuracy, bias, privacy, security, training rights, certifications, human review, output ownership, and benchmark rank need dated support. The file should identify the model version, test set, prompts, sample, exclusions, threshold, result, and approver.

Singapore’s Consumer Protection (Fair Trading) Act addresses unfair practices in consumer transactions. Hong Kong’s Trade Descriptions Ordinance prohibits false descriptions and specified unfair practices for goods and services, including online sales. Australia’s Australian Consumer Law prohibits misleading or deceptive conduct and false representations. Japanese and Korean consumer and advertising statutes apply to AI claims under their own tests.

A disclaimer does not cure a contradictory headline, demo, or salesperson statement. A model score should not appear as a guaranteed outcome. A certification claim should identify the issuing body, scope, version, and expiry.

South Korea’s Article 31 requires advance notice when a product or service uses high-impact or generative AI. It also requires labels for generative output. Realistic synthetic audio, images, and video need clear notice, subject to the artistic-expression rule.

Other jurisdictions may regulate synthetic content through privacy, passing off, trade marks, defamation, fraud, elections, impersonation, online safety, and criminal law. The target should test consent, likeness and voice rights, labels, detection, takedowns, and customer restrictions.

Australia’s Children’s Online Privacy Code remained in draft after consultation closed on June 5, 2026. The final code must be registered by December 10, 2026. Covered online services likely accessed by children should prepare age, profiling, marketing, deletion, notice, and best-interest records.

Children’s products in every jurisdiction need a separate audience analysis. The review should cover actual users, age signals, parental permissions, profiling, targeted advertising, retention, crisis escalation, and human intervention.

Employment and high-impact decisions

Employment AI can affect recruitment, ranking, monitoring, scheduling, productivity, promotion, pay, discipline, and dismissal. Privacy, equality, labour, contract, and consultation duties may all apply.

Counsel should obtain feature lists, training sources, validation, subgroup testing, accessibility testing, notices, adverse outcomes, overrides, appeals, and vendor communications. The review should compare written policy with manager practice.

South Korea treats employment-related decisions within its high-impact AI categories when the statutory test is met. PIPA Article 37-2 may also apply to fully automated decisions. The provider and employer need separate actor analyses.

Singapore, Hong Kong, Japan, and Australia do not require one universal AI employment filing. Their discrimination, disability, privacy, labour, and workplace laws still apply. State and territory law adds to the Australian federal statutes.

A vendor cannot transfer every discrimination duty to the employer. The developer’s design, claims, known limits, and documentation remain relevant. The employer needs enough information to conduct real review and explain a decision where law or contract requires it.

Financial services, healthcare, and public uses

Regulated uses can decide transaction viability. The target should identify every deployment in credit, insurance, investment, payments, healthcare, medical devices, education, transport, government, policing, defense, and critical infrastructure.

Financial AI may constitute advice, dealing, portfolio management, credit assessment, underwriting, payment processing, or regulated outsourcing. Each function needs a licence and customer-status analysis. Sandbox participation does not grant permission outside its terms.

Singapore financial firms and service providers may face MAS licensing, technology-risk, outsourcing, conduct, and consumer duties. Hong Kong requires separate HKMA, SFC, Insurance Authority, and Mandatory Provident Fund analysis. Japan’s FSA and sector statutes control financial uses. Korea’s FSC and FSS rules apply to financial institutions and vendors. Australia requires ASIC, APRA, credit, payments, and financial-service analysis.

Healthcare AI needs intended-purpose, clinical, privacy, professional, advertising, and device review. Singapore requires covered medical devices to be registered with HSA and meet applicable requirements. Its medical-device cyber label remains voluntary.

Japan, South Korea, and Australia regulate software as a medical device according to function and risk. Australia generally requires inclusion in the Australian Register of Therapeutic Goods unless an exclusion or exemption applies. AI evidence should identify the model, training and test data, change controls, clinical performance, and post-market monitoring.

Public procurement can impose data location, security clearance, audit, source-code escrow, accessibility, incident notice, model-change, intellectual-property, and exit duties. The target should reconcile tender claims with product reality.

A public-sector pilot or innovation programme is not general approval. Counsel should identify scope, term, customer, statutory basis, data rights, publication rights, and transition after the pilot.

Competition, investment, exports, and sanctions

Competition diligence should cover exclusivity, most-favoured terms, tying, data access, interoperability limits, pricing tools, information exchange, talent restrictions, customer concentration, and acquisitions.

The merger and investment analysis needs local turnover, assets, market shares, transaction value, buyer identity, government links, sensitive data, and control rights. Minority rights can matter even when legal control does not pass.

Singapore’s Significant Investments Review Act began on March 28, 2024. Japan’s FEFTA screening regime was amended in June 2026, with draft regulations published in July. South Korea applies the Foreign Investment Promotion Act and sector restrictions. Australia’s Foreign Acquisitions and Takeovers Act remains current in its December 5, 2025 compilation.

Export review should classify chips, servers, encryption, source code, weights, technical data, remote access, users, end uses, and destinations. Singapore uses the Strategic Goods (Control) Act and current control orders. Japan uses FEFTA, the Foreign Exchange Order, and the Export Trade Control Order. South Korea uses the Foreign Trade Act and strategic-item controls. Australia uses the Defence Trade Controls Act 2012 and customs controls.

Sanctions screening must cover parties, beneficial owners, controllers, banks, customers, suppliers, destinations, services, and payments. Local measures need separate treatment from the buyer’s home-country rules. Screening should be refreshed at signing and closing.

Singapore

Singapore diligence should combine the Companies Act, PDPA, Copyright Act, Cybersecurity Act, consumer law, sector licences, SIRA, export controls, employment law, and contract law. The exact set depends on the product and customer.

The PDPA file should identify every organization and data intermediary. It should link each purpose to notice, consent or exception, access, correction, retention, security, transfer, and breach records. The AI advisory should appear as evidence of the target’s interpretation and controls, not as an independent legal safe harbour.

The computational-data-analysis exception can support commercial training. The target still needs lawful access and compliance with the statutory use restrictions. Copies obtained through circumvention or breach of access controls create a serious defect.

Cyber classification should identify CII ownership, provider-owned virtual systems, STCC exposure, and licensed cybersecurity services. Incident procedures should meet the applicable two-hour or other statutory timeline.

A Singapore entity providing healthcare, financial, telecom, digital-payment, medical-device, or online services needs regulator-specific review. Corporate registration alone does not authorize the regulated activity.

Hong Kong

Hong Kong diligence should begin with the Companies Ordinance, PDPO, Copyright Ordinance, Trade Descriptions Ordinance, employment discrimination statutes, sector licences, strategic-commodity controls, and Cap. 653 where applicable.

The PCPD AI model document gives a practical evidence list. The target should produce internal approval records, risk assessments, human-oversight decisions, validation, monitoring, incident response, staff training, and customer communications. Those records should map to the PDPO’s binding duties.

Training rights remain a priority defect area. The government has announced a code and legislative proposals, but the current Copyright Ordinance controls. Counsel should not assume that a proposed TDM rule will protect historic copying.

Cap. 653 applies only after designation. The target should produce every designation, critical-system list, code, plan, audit, incident notice, and regulator direction. A non-designated vendor may still inherit security and audit duties through customer contracts.

Product claims should be tested against the Trade Descriptions Ordinance. It reaches goods, services, online traders, false descriptions, misleading omissions, and other listed unfair practices.

Japan

Japan diligence should separate binding law from the AI Act’s plan and guidance system. The 2025 Act supplies government powers and business cooperation expectations. It does not create a general product certification or CE-style mark.

The second AI Basic Plan was approved on July 14, 2026. The statutory AI guideline was adopted on December 19, 2025. The official list records revised AI Business Guidelines and an AI security technical guideline from March 2026. The target should state which documents it follows and preserve supporting tests.

The current APPI governs present processing. The July 2026 amendment belongs in a separate readiness schedule until its provisions commence. Contracts should allocate work needed for new notices, rights, records, or regulator procedures.

Article 30-4 can support training when the purpose and prejudice limits are met. Counsel should inspect the acquisition path, training purpose, dataset composition, access controls, output behaviour, and market effects.

FEFTA review should cover inward investment, exports, technology release, and sanctions. The June 2026 FDI amendment and July draft regulations need a closing-date status check. Technical diligence may need access restrictions before the buyer reviews controlled material.

South Korea

South Korean diligence must classify each entity as an AI business operator and each product as generative, high-impact, or subject to Article 32. The analysis should use the current Act No. 21311 and current Enforcement Decree.

Article 31 requires advance notice for products and services using high-impact or generative AI. It also requires output marking and clear synthetic-media notice. The target should preserve screenshots, interface versions, API documentation, customer terms, and exception analyses.

Article 33 requires a pre-assessment of high-impact status and permits a confirmation request to the Ministry. Article 34 requires covered measures addressing risk, explanation planning, user protection, human oversight, and documentation. Article 35 encourages a fundamental-rights impact assessment and affects public procurement priority.

Article 32 applies additional lifecycle risk, incident, and reporting duties to AI systems above the statutory compute threshold. Article 36 may require a qualifying foreign provider to appoint a domestic representative. Counsel should verify group turnover, users, local establishment, and decree thresholds.

Enforcement is not uniform across every duty. The Act grants investigation, corrective, and stop powers. Administrative fines apply to specified violations, including certain notice and representative failures. The diligence report should match each defect to the exact remedy.

PIPA Article 37-2 creates a separate automated-decision workstream. AI Basic Act compliance does not replace PIPA. The same system may need notice, explanation, objection handling, human reprocessing, public disclosures, and high-impact documentation.

Australia

Australian diligence should begin with current statutes, not the 2024 mandatory-guardrails proposal. The National AI Plan was published on December 2, 2025. The current government approach uses existing laws, regulator action, safety science, and voluntary adoption guidance.

The Guidance for AI Adoption creates no new legal duty. It can still become relevant through contracts, procurement, board decisions, or representations. The target should identify which voluntary controls it claims to follow and retain proof.

The Privacy Act governs current personal-information handling. The December 10, 2026 automated-decision disclosure rules require an implementation plan now. The target should identify affected decisions, data types, privacy-policy changes, ownership, and release timing.

The Children’s Online Privacy Code remained a post-consultation draft. Covered services should prepare for registration by December 10, 2026. The final text and commencement details require a closing check.

Training data needs source-level copyright review. The Copyright Act has no broad TDM exception. The government’s current work focuses on licensing, AI-generated material, and enforcement, rather than a TDM exception.

Consumer claims face Australian Consumer Law section 18 and specific false-representation provisions. Biometric and facial-recognition uses need privacy, consent, necessity, notice, and impact records. The 2026 Administrative Review Tribunal decision in the Bunnings matter illustrates the evidentiary importance of notice and documented assessment.

Cyber review should cover the Cyber Security Act, ransomware reporting, the SOCI Act, privacy breach notice, APRA standards, and sector contracts. Medical AI needs TGA classification, evidence, registration, change control, and post-market monitoring.

Contracts, revenue quality, and continuity

Contract diligence must prove assent, scope, performance, and transferability. A template does not prove which terms the customer accepted.

Counsel should obtain executed orders, clickwrap records, amendments, procurement terms, API terms, reseller agreements, research contracts, cloud contracts, and incorporated policies. The record should identify the operative version and order of precedence.

AI clauses should address permitted use, prohibited use, customer data, prompts, logs, training, outputs, confidentiality, security, incidents, model changes, documentation, human review, audits, indemnities, caps, assignment, termination, and transition.

The terms should match conduct. A no-training promise is dangerous when support logs feed evaluation. A customer-control clause is weak when the target markets autonomous operation.

Revenue quality requires contract-to-ledger testing. Counsel should separate production revenue from pilots, free use, credits, related-party sales, minimum commitments, contingent milestones, and token proceeds.

Continuity depends on compute, models, data, suppliers, licences, and key people. The review should test capacity, minimum spend, deprecation, price changes, suspension, portability, recovery, and concentrated knowledge.

Assignment and change-of-control clauses require dependency-level review. A model API, dataset, cloud commitment, distribution right, public grant, or government contract may terminate at closing.

Findings and transaction protections

Each finding needs a legal rule, evidence status, business effect, and deal response. A colour alone does not answer whether the activity can continue or transfer.

Stop-level findings include missing title to a core model, unlawful irreplaceable training data, unlicensed regulated activity, a prohibited use, absent mandatory approval, or a sanctions or export block.

Other stop-level findings include a non-transferable critical model or cloud right, false certification claims, material hidden incidents, or a government contract that ends at closing.

Closing conditions fit curable defects. Common items include assignments, consents, licence approvals, investment filings, privacy assessments, notices, human-review procedures, product suspension, incident remediation, supplier amendments, and access cleanup.

Price adjustments, escrow, holdbacks, exclusions, specific indemnities, and post-closing covenants fit quantified legacy exposure. General warranties offer weak protection for a known defect.

Representations should cover authority, capitalization, title, data rights, automated decisions, AI classification, product claims, security, incidents, employment, licences, contracts, sanctions, exports, investment review, competition, and disputes.

Disclosure schedules should identify exact entity, model, dataset, licence, policy, and contract versions. Product names alone are inadequate. The seller should distinguish verified facts, management assertions, disputed matters, and unresolved items.

Interim covenants should restrict material model releases, dataset changes, new high-impact uses, supplier changes, unapproved claims, and unusual customer exceptions. They should require prompt notice of incidents, complaints, regulator contact, and legal changes.

Open items need an owner, due date, evidence standard, closing effect, and escalation route. The closing bring-down should repeat licence, data, cyber, copyright, investment, export, sanctions, and commencement checks.

Part 08

China & India

Two regimes controlling data, models and market entry
In essence

Mainland China and India legal due diligence of an artificial intelligence project asks whether the target can lawfully own, train, deploy, sell, and transfer its models, systems, data, products, and regulated services across both markets. This memorandum states the transaction baseline as of July 24, 2026. It tests corporate authority, AI-specific duties, personal-data processing, training rights, cybersecurity, content controls, licences, foreign investment, exports, and transaction protection. Mainland China excludes Hong Kong and Macao for this session. No target, sector, buyer, transaction structure, or data room was supplied. Each connected province, Indian state, regulated activity, and foreign market needs added review.

Executive summary
Mainland China

China regulates AI through layered binding measures rather than one omnibus cross-sector AI act. Product type, public availability, content function, social-mobilisation capacity, and user group determine the applicable duties.

Mainland China

Public-facing generative AI services need lawful training sources, intellectual-property and personal-information compliance, content controls, user terms, complaints, and regulatory cooperation. Security assessment and algorithm filing apply where the statutory test is met.

Mainland China

AI-generated and synthesised content needs explicit and metadata labels from September 1, 2025. Anthropomorphic emotional-interaction services face added child, dependency, safety, data, labelling, filing, and annual-verification duties from July 15, 2026.

Mainland China

The Personal Information Protection Law regulates automated decisions, sensitive information, children under 14, impact assessments, incidents, overseas controllers, and cross-border transfers. Local storage, security assessment, contracts, or certification may apply according to the actor and data volume.

India

India has no operative omnibus private-sector AI statute. Existing laws control current activity. The November 2025 national AI guidelines remain nonbinding, while the February 2026 synthetic-content amendments impose binding duties on covered intermediaries.

India

The Digital Personal Data Protection Act and 2025 Rules use phased commencement. The Data Protection Board and selected institutional provisions are active. Most controller, rights, child-data, security, breach, and transfer duties start on May 13, 2027.

Both jurisdictions

Public access does not establish a training right. Copyright, personal data, contract, confidentiality, trade secrets, content restrictions, and sector secrecy require separate proof for each dataset.

Both jurisdictions

Cloud, telecom, financial, medical, geospatial, vehicle, education, public-sector, biometric, and critical-system products can require licences, filings, local operation, testing, incident reporting, or regulator access.

Transaction

Missing core title, unlawful irreplaceable data, absent filings, unlicensed regulated activity, prohibited content, a blocking investment or export issue, or a non-transferable critical dependency can stop closing. Other defects need tailored conditions and price protection.

Analysis by issue

The review must follow the target's actual operations. Incorporation answers only the internal company question. Users, workers, data subjects, data sources, compute, suppliers, and regulated customers create separate legal connections.

Counsel should prepare linked inventories for entities, products, models, use cases, datasets, and third parties. Each item needs an owner, version date, location, legal role, and supporting record.

The model inventory should identify architecture, weights, checkpoints, fine-tunes, retrieval sources, safety layers, evaluations, and releases. The use-case inventory should separate intended purpose from customer conduct. Sales materials, interface design, and implementation support can widen the target's exposure.

The jurisdiction map should record each place of work, sale, use, collection, storage, remote access, and technical support. China review should identify the relevant province, telecom authority, sector regulator, and public-facing status. India review should add each connected state or union territory where local labour, health, gaming, transport, police, or public-sector rules matter.

External law can attach to either target. A China or India company may enter the EU AI Act through Union market placement or output use. Overseas privacy, export, sanctions, and product laws may also follow foreign users, controlled technology, or buyer identity.

Timing requires a separate obligations calendar. It should distinguish operative duties, delayed provisions, draft measures, annual filings, permit renewals, and laws commencing before closing. The buyer should repeat these checks at signing, closing, and material product releases.

Corporate authority, capitalization, investment, and asset location

The buyer must identify which entity owns each asset and owes each obligation. A common brand, shared director, consolidated website, or group repository does not prove legal title.

Counsel should obtain formation records, constitutional documents, registers, capitalization instruments, beneficial-owner information, board approvals, security interests, and insolvency indicators. The review should include options, convertibles, side letters, nominees, employee equity, and promised interests.

AI groups often divide research, payroll, customer contracts, cloud accounts, and intellectual property among affiliates. The entity employing developers may lack an invention transfer. The customer entity may possess only a revocable licence. A founder may control a material account or signing key.

The asset map should connect every repository, model, dataset, patent, brand, domain, customer contract, and compute account to one legal owner. Intercompany assignments, licences, services agreements, and cost allocations need written terms.

China foreign-investment review starts with the 2024 nationwide negative list and activity-specific rules. The Special Administrative Measures for Foreign Investment Access (Negative List) (2024 Edition), NDRC and MOFCOM Order No. 23, applies from November 1, 2024. Telecommunications, internet content, news, publishing, audiovisual, and other controlled activities need exact classification.

A consumer-facing AI platform may need an internet-content-provider filing or a value-added telecommunications licence. Cloud, data-centre, content-delivery, virtual-private-network, online data-processing, and information-service functions require service-level review. The Foreign-Invested Telecommunications Enterprises Provisions, as amended in 2022, retain ownership limits unless another rule or pilot applies.

Selected pilot areas relax foreign-ownership caps for specified value-added telecom services. The pilots do not remove content-sector exclusions. Entity location, infrastructure, service type, and licence conditions determine whether a pilot helps the target.

China's Measures for Security Review of Foreign Investment, NDRC and MOFCOM Order No. 37, can reach a transaction that affects or may affect national security. Buyer identity, control rights, sensitive technology, data, critical information infrastructure, and sector ties need early review.

India corporate diligence should reconcile Companies Act records, beneficial ownership, charges, board authority, shareholder rights, foreign investment, and sector caps. Press Note 2 (2026) announced revised land-border beneficial-ownership treatment. S.O. 2174(E), dated May 1, 2026, was issued to amend the Non-Debt Instruments Rules. Closing counsel must verify the Gazette text and current rule before relying on the relaxation.

The announced rule permits the automatic route for an investor incorporated outside a land-border country where non-controlling land-border beneficial ownership does not exceed 10 percent. Sector caps, conditions, reporting, and resident control requirements remain relevant. An investor incorporated in a land-border country remains subject to the government route.

Change-of-control review in both jurisdictions should cover corporate approvals, telecom and sector permits, government contracts, public grants, leases, security interests, data arrangements, and supplier consents. A share sale can trigger consent even when the operating entity remains unchanged.

Mainland China AI classification and public-facing services

China uses product-specific and function-specific AI rules. Counsel should classify every service before testing compliance. A research model, private enterprise tool, public generative service, recommendation engine, deep-synthesis service, and anthropomorphic companion may receive different treatment.

The Interim Measures for the Management of Generative AI Services apply when generative technology supplies text, images, audio, video, or similar content to the public in mainland China. Internal research and non-public development fall outside Article 2, subject to other laws.

A provider must use lawfully sourced data and base models. It must respect intellectual property, obtain consent or another lawful basis for personal information, and improve training-data quality. Interim Measures, art. 7.

The provider also bears content-producer and personal-information duties. It needs user terms, a stated service audience and use, controls against minor dependence, protection for prompts and logs, complaints, and a process for unlawful content. Interim Measures, arts. 9-15.

Services with public-opinion attributes or social-mobilisation capacity require a security assessment and algorithm filing. Id. art. 17. The filing and security record should identify the exact model, version, service entity, data sources, function, release, and material changes.

Regulators can request explanations concerning training-data sources, scale, type, labelling rules, and algorithm operation. Id. art. 19. The target should maintain a regulator-ready record rather than reconstruct one after an inquiry.

Algorithm recommendation providers with public-opinion attributes or social-mobilisation capacity must file within the prescribed period. Material changes and termination require change or cancellation filings. A filing does not constitute state approval or endorsement.

Deep-synthesis providers and technical supporters may face separate filing, labelling, identity, data, security, and content duties. Counsel should determine which entity supplies the technical function and which entity publishes or distributes the output.

The target should reconcile service descriptions across filings, app stores, licences, contracts, privacy notices, model cards, and public claims. Inconsistent descriptions can reveal an omitted filing or an inaccurate risk assessment.

China AI-generated content labels and distribution

The Measures for Labelling AI-Generated and Synthesised Content have applied since September 1, 2025. They operate with the deep-synthesis rules, generative AI measures, algorithm rules, and mandatory national standard GB 45438-2025.

Covered providers must add explicit labels to specified text, audio, image, video, virtual-scene, and interaction outputs. They must also add metadata identifying the synthetic attribute, provider, and content record. Measures for Labelling AI-Generated and Synthesised Content, arts. 4-5.

Distribution services must inspect metadata and user declarations. They must label confirmed, declared, or detected synthetic content according to Article 6. They also need user-declaration tools and propagation metadata.

App stores must ask whether an app offers AI generation and must review its labelling materials. Service agreements must explain the label rules. A provider that supplies an unmarked output at a user's request needs an agreement allocating the user's labelling duties and must retain specified logs for at least six months. Id. arts. 7-9.

Users may not maliciously remove, alter, forge, or conceal required labels. Providers may not supply tools or services for that conduct. Id. art. 10.

Diligence should test the output at creation, download, API delivery, compression, editing, reposting, and cross-platform distribution. Metadata that disappears during ordinary export or upload can create a current product defect.

The evidence file should contain interface screenshots, output samples, metadata extracts, app-store submissions, user terms, unmarked-output records, retention settings, and filing materials. Marketing claims about watermarking or detection should match measured performance.

China anthropomorphic AI and science-and-technology ethics review

The Interim Measures for the Management of Anthropomorphic AI Interaction Services have applied since July 15, 2026. They reach continuous emotional interaction services that simulate human personality, thought patterns, and communication style for the mainland public.

The provider must control unlawful or harmful content and prohibited interaction design. It needs staff, safety systems, lifecycle controls, training-data records, user procedures, and measures addressing dependence and emotional risk. Interim Measures for the Management of Anthropomorphic AI Interaction Services, arts. 8-13.

Minors receive added protection. The rules restrict simulated relatives and partners, require parental consent for users under 14, and call for a minor mode. Id. art. 14. The diligence record should show age signals, consent, mode design, content limits, use reminders, and escalation.

Interaction data receives special treatment. Providers must support copy and deletion rights. Separate consent is required for specified use of sensitive interaction information in training. Minor personal-information handling needs a periodic audit. Id. arts. 16-17.

The interface needs AI identity disclosure, dependence reminders, and time-use prompts. The provider must support exit, service cessation, complaints, and emergency handling. Filing and annual verification apply according to Article 26.

The Measures for AI Science and Technology Ethics Review and Services (Trial), MIIT Joint Science [2026] No. 75, create a separate review route for research and technical development that presents ethics risks. The measure took effect on March 20, 2026.

Projects involving close human-machine integration, behavioural or emotional effects, public-opinion influence, or highly autonomous safety and health decisions may require expert review. The committee can approve, require revision, or reject. Tracking review may occur at intervals not exceeding 12 months.

The buyer should obtain committee composition, conflict records, submissions, minutes, decision letters, conditions, tracking reports, and suspension decisions. An internal product committee does not substitute for the statutory review where the measure applies.

China personal information, automated decisions, and cross-border transfers

The Personal Information Protection Law applies to processing in China and specified overseas processing concerning people in China. Overseas processors may need a mainland representative. Personal Information Protection Law, arts. 3 and 53.

Each processing activity needs a lawful basis under Article 13. Separate consent can apply to third-party provision, sensitive personal information, and cross-border transfer. Children under 14 fall within the sensitive-information rules. Id. arts. 23, 28-31 and 39.

Article 24 governs automated decision-making. The process must be transparent, fair, and impartial. It may not impose unreasonable differential treatment in transaction terms. Marketing must provide a non-personalised option or an easy refusal route.

A person may request an explanation when automated decision-making produces a decision with a major effect on rights or interests. The person may refuse a decision made solely through automated processing. The target should preserve factors, rules, validation, notices, human review, overrides, and outcomes.

A personal-information protection impact assessment is required before specified sensitive processing, automated decisions, entrusted processing, third-party provision, public disclosure, export, and other high-impact activity. Id. arts. 55-56. The assessment should match the current system and model version.

Cross-border transfer needs a route under Articles 38 to 40. The Provisions on Promoting and Regulating Cross-Border Data Flows, effective March 22, 2024, create exemptions and volume-based routes.

A critical information infrastructure operator exporting personal information or important data generally needs a security assessment. A non-CIIO needs an assessment for important data, at least one million individuals' ordinary personal information, or at least 10,000 individuals' sensitive personal information during the calculation period.

A non-CIIO exporting between 100,000 and fewer than one million individuals' ordinary personal information, or fewer than 10,000 individuals' sensitive information, generally uses the standard contract or certification route. Lower-volume transfers may qualify for an exemption, subject to the facts.

Data that has not been identified or notified as important data does not require an important-data assessment solely on speculation. The target should still document its classification, sector notices, and changes.

The buyer should map local storage, remote access, support, telemetry, subprocessors, model providers, and foreign incident response. A mainland server does not resolve an export created by overseas administrator access.

Face-recognition deployments need separate treatment under the Face Recognition Technology Application Security Management Measures, effective June 1, 2025. The rules address necessity, separate consent, alternatives, local-device storage, impact assessment, security, and public-place deployment. Training and research fall outside the measure's direct scope, but PIPL and other laws still apply.

China training rights, cybersecurity, licences, and controlled technology

Publicly available material does not become free training data. The target must prove copyright permission, personal-information lawfulness, contract rights, confidentiality, trade-secret protection, and compliance with content and state-secrecy rules.

China's Copyright Law does not contain a broad commercial text-and-data-mining exception for AI training. Counsel should review each source, licence, access route, copying act, model output, and market effect. Internal policy cannot replace a statutory exception or licence.

Employee and contractor title needs signed records. Patent files should identify human inventors, service inventions, assignments, disclosure, grants, and government or university rights. Trade-secret protection depends on secrecy measures under the Anti-Unfair Competition Law and the Commercial Secret Protection Provisions effective June 1, 2026.

The cybersecurity file should classify networks, data, important data, critical information infrastructure, commercial cryptography, and sector systems. The revised Cybersecurity Law has applied since January 1, 2026. The Network Data Security Management Regulations have applied since January 1, 2025.

Regulated systems may need multilevel protection filings, security assessments, domestic storage, cryptography review, vulnerability processes, real-name controls, content records, and incident reports. The exact duty depends on the network, data, operator, and sector.

The target should maintain one incident record covering personal-information breaches, cyber incidents, unsafe outputs, illegal content, model leakage, data poisoning, prompt injection, extraction, outages, and regulator contacts. Each entry should state discovery, scope, containment, notices, cause, correction, and recurrence testing.

China export review should cover source code, model weights, training methods, architecture, technical data, encryption, chips, servers, remote access, research collaboration, and buyer diligence. The Export Control Law, the Dual-Use Items Export Control Regulation, State Council Order No. 792, and the current control lists apply according to item, destination, end user, and end use.

The Catalogue of Technologies Prohibited or Restricted from Export was adjusted from July 15, 2025. A licence or technology-export contract process may apply even when no physical item leaves China. Data-room access can therefore require classification before disclosure.

Sector licences remain separate. Medical-device software, internet maps, autonomous vehicles, finance, education, news, publishing, audiovisual services, healthcare, and public procurement each need a dedicated workstream.

India current AI position and synthetic-content duties

India has no operative cross-sector private AI act. Existing statutes and sector rules govern present conduct. The national AI guidelines issued in November 2025 are nonbinding and favour use of existing law, sector action, targeted changes, voluntary controls, and testing arrangements.

The target should identify every claim that it follows those guidelines. Board papers, risk records, testing, incident processes, and customer materials should support the claim. Voluntary guidance can become contractually relevant through tenders, policies, or warranties.

Binding AI-specific content duties now arise under the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, as amended by G.S.R. 120(E). The amendment took effect on February 20, 2026.

The amendment defines synthetic generated information by reference to algorithmically created or modified audio, visual, or audiovisual content that appears authentic. Routine good-faith editing, accessibility work, and document preparation can fall outside the definition when they do not materially misrepresent content.

An intermediary offering tools that can create synthetic generated information must use appropriate technical measures against specified unlawful content. It must prominently label other synthetic generated information and preserve metadata or provenance data where technically feasible.

The service should not facilitate removal of the required label, metadata, or unique identifier. Significant social-media intermediaries must obtain user declarations, deploy verification measures, and label content confirmed as synthetic under the amended rules.

Diligence should test creation, upload, distribution, re-encoding, download, reposting, and user removal. The file should contain interface records, model versions, label specifications, metadata samples, user declarations, verification tests, complaint handling, and takedown records.

Draft April 2026 amendments remain proposals. They should not appear as current defects. The buyer should track the final text where closing or integration extends into the consultation period.

India data protection and automated decisions

The Digital Personal Data Protection Act 2023 and Digital Personal Data Protection Rules 2025 use phased commencement. The Data Protection Board and selected institutional, definition, exemption, and procedural provisions have applied since November 13, 2025.

Consent-manager registration duties begin on November 13, 2026. Most substantive processing duties begin on May 13, 2027. Those later duties cover notice, consent, legitimate uses, accuracy, security, breach notification, deletion, rights, children, significant data fiduciaries, and cross-border processing.

The current diligence report should separate present compliance from readiness. A July 2026 failure to meet a May 2027 duty is not yet a statutory breach. It can still impair valuation or integration where the system cannot be remediated before commencement.

The DPDP Act does not create a general right to reject an automated decision. Other laws may require reasons, fair procedure, human review, or non-discrimination in credit, employment, insurance, public administration, consumer services, or regulated sectors.

When the government designates a Significant Data Fiduciary, section 10 will require a data-protection officer, impact assessments, independent audits, and due diligence concerning algorithms used to process personal data. The target should model designation risk using data volume, sensitivity, harm, sovereignty, electoral, security, and public-order factors.

The readiness file should identify each data fiduciary and processor, purpose, notice, legal basis, child-data use, retention, security, transfer, and grievance route. It should include consent records, processor contracts, technical deletion, breach playbooks, and product changes needed by May 2027.

India training rights, cybersecurity, telecom, and geospatial data

India's Copyright Act 1957 does not contain a broad commercial text-and-data-mining exception. Section 52 fair dealing applies to listed purposes, including private or personal use comprising research, criticism or review, and current-event reporting. It does not create a general commercial training licence.

Each training source needs a rights analysis. The target should document lawful access, copying, licence scope, confidentiality, personal data, output similarity, and market substitution. The November 2025 AI policy record itself identifies copyright reform as a possible future issue, not an enacted defence.

Copyright ownership and transfer require review under sections 17 to 19. The buyer should obtain founder, employee, contractor, university, affiliate, and grant assignments. Patent files should identify inventors, assignments, government rights, foreign-filing permissions, and prior disclosure.

CERT-In's April 28, 2022 directions apply to listed service providers, intermediaries, data centres, bodies corporate, cloud providers, virtual private server and network providers, virtual-asset service providers, and government bodies. Covered cyber incidents must be reported within six hours after notice or detection.

The initial report may use the information then available, followed by supplements. A customer or vendor contract cannot transfer away the reporting duty. The target should retain incident timing, scope, communications, logs, root-cause work, and closure evidence.

Telecom and internet functions need classification under the Telecommunications Act 2023 and the 2026 principal-service authorisation rules. A pure software service is not automatically a telecom service. Internet access, messaging, IoT, machine-to-machine connectivity, network operation, numbering, or communication functions may require authorisation.

Location and mapping systems need review under the 2021 geospatial guidelines. Those guidelines expressly cover AI-enabled geospatial technology. They distinguish Indian entities and regulate specified high-accuracy or sensitive datasets, acquisition, storage, and dissemination.

Foreign-owned or foreign-controlled structures need particular attention. Product design, data resolution, local storage, API access, street imagery, surveying, drones, and export functions can alter the answer.

Cloud contracts should cover data location, supplier training, subprocessors, security, deprecation, price changes, suspension, portability, incident cooperation, and exit support. Financial, telecom, health, defense, and government customers may impose added localisation and audit duties.

Regulated uses, product claims, employment, and children

Sector classification can decide transaction viability. Counsel should identify every deployment in finance, credit, insurance, healthcare, medical devices, telecom, mapping, transport, education, employment, public administration, policing, defense, and critical infrastructure.

China high-impact uses may trigger sector permits, security reviews, content duties, local storage, or state procurement terms. India sector regulators apply existing law and may use circulars, licence conditions, outsourcing rules, cybersecurity directions, and supervisory examinations.

India securities firms, exchanges, clearing corporations, mutual funds, and research analysts face SEBI rules or reporting duties concerning AI and machine learning. The exact regulated entity, model use, customer effect, outsourcing, and record must be identified.

India medical AI may qualify as software within the Medical Devices Rules 2017 when intended for diagnosis, prevention, monitoring, treatment, or alleviation. The file should contain intended purpose, risk class, licence, clinical evidence, change control, cybersecurity, and post-market records.

Financial and insurance AI needs separate review in both jurisdictions. Credit scoring, underwriting, fraud detection, advice, portfolio management, payments, and collections can trigger licence, explanation, fair-treatment, model-risk, outsourcing, and recordkeeping duties.

Employment AI should cover recruitment, ranking, monitoring, scheduling, productivity, promotion, pay, discipline, and dismissal. The target should provide feature lists, validation, subgroup testing, notices, appeals, override records, and vendor communications.

A vendor cannot allocate every discrimination or employment duty to the customer. Product design, claims, known limits, and supported uses remain relevant. The employer still needs enough information to make a lawful decision.

Children's products need age analysis, parental processes, profiling controls, advertising limits, retention, crisis response, and human escalation. China imposes specific under-14 and minor-mode duties in several measures. India's child-data rules largely begin with the main DPDP commencement, while current child-protection, intermediary, criminal, and consumer laws still apply.

Marketing claims need dated support. Claims about accuracy, bias, privacy, training rights, security, certification, human review, output ownership, and benchmark rank should identify the model, test set, prompts, sample, exclusions, threshold, result, and approver.

A disclaimer does not cure a contradictory headline, demo, tender answer, or salesperson statement. Synthetic-content, AI-filing, licence, and certification claims should identify the exact authority, scope, version, and status.

Competition, investment, exports, and sanctions

China's merger-control thresholds use the State Council Provisions on Thresholds for Notification of Concentrations of Undertakings, Order No. 773. Filing can arise when combined worldwide turnover exceeds RMB 12 billion and at least two parties each exceed RMB 800 million in China. It can also arise when combined China turnover exceeds RMB 4 billion and at least two parties each exceed RMB 800 million in China.

The State Administration for Market Regulation can investigate a below-threshold transaction that may restrict competition. The buyer should obtain turnover, market share, control rights, data concentration, compute access, platform links, and prior acquisitions.

India's Competition Act sections 5 and 6 create a suspensory merger review. A transaction above INR 2,000 crore can trigger the deal-value threshold when the target has substantial business operations in India. Current asset, turnover, exemption, control, and connected-transaction rules require a live calculation.

Foreign-investment review needs buyer ownership, beneficial ownership, government links, sector caps, sensitive technology, data, and control rights. An automatic-route filing does not resolve a sector permit, security concern, or land-border beneficial-owner issue.

Export review in both markets should occur before the buyer receives controlled material. China uses the Export Control Law, dual-use controls, technology catalogues, encryption rules, and sector restrictions. India uses the Foreign Trade (Development and Regulation) Act 1992, Foreign Trade Policy 2023 Chapter 10, and the current SCOMET list.

The review should classify software, source code, weights, architecture, technical data, encryption, chips, drones, autonomous functions, military or dual-use capabilities, remote access, end users, and end uses. Buyer-home and supplier-country rules may impose separate re-export duties.

Sanctions and restricted-party screening should cover parties, beneficial owners, controllers, banks, customers, suppliers, destinations, services, and payments. Local law and the buyer's home-country law need separate tests. Screening should continue through closing.

Third-party dependencies, contracts, incidents, and continuity

The target needs a dependency register beyond a software bill of materials. It should cover code, open-weight models, hosted models, datasets, benchmarks, APIs, cloud, accelerators, content filters, identity services, and security tools.

Each record should identify the version, supplier, accepted terms, paying entity, actual use, transfer rights, and replacement plan. The review should test training, fine-tuning, distillation, outputs, redistribution, attribution, audit, suspension, termination, assignment, and change of control.

An open-source or open-weight label does not answer those questions. The exact licence and integration method control. Acceptable-use terms may bar a sector, person, location, or content category.

Contract diligence must prove assent, scope, performance, and transferability. Counsel should obtain executed orders, clickwrap records, amendments, procurement terms, API terms, reseller agreements, research contracts, cloud contracts, and incorporated policies.

AI clauses should address customer data, prompts, logs, training, outputs, confidentiality, security, incidents, model changes, documentation, human review, audits, indemnities, caps, assignment, termination, and transition.

The terms should match conduct. A no-training promise is dangerous when support logs feed evaluation. A customer-control clause is weak when the target markets autonomous operation.

Revenue quality requires contract-to-ledger testing. Counsel should separate production revenue from pilots, free use, credits, related-party sales, minimum commitments, contingent milestones, and token proceeds.

Continuity depends on compute, models, data, licences, suppliers, and key people. The review should test capacity, minimum spend, deprecation, price changes, suspension, portability, recovery, filing continuity, and concentrated knowledge.

Findings and transaction protections

Each finding needs a legal rule, evidence status, business effect, and deal response. A colour alone does not answer whether the activity can continue or transfer.

Stop-level findings include missing title to a core model, unlawful irreplaceable training data, absent mandatory filing, unlicensed regulated activity, prohibited content or use, a blocked foreign investment, or an export restriction.

Other stop-level findings include a non-transferable critical model or cloud right, false regulatory claims, material hidden incidents, or a government contract that terminates at closing.

Closing conditions fit curable defects. Common items include assignments, consents, licence approvals, investment and merger filings, algorithm filings, security assessments, privacy assessments, labels, human-review procedures, incident correction, supplier amendments, and access cleanup.

Price adjustments, escrow, holdbacks, exclusions, specific indemnities, and post-closing covenants fit quantified legacy exposure. General warranties offer weak protection for a known defect.

Representations should cover authority, capitalization, title, data rights, AI classification, filings, automated decisions, product claims, security, incidents, employment, licences, contracts, sanctions, exports, investment review, competition, and disputes.

Disclosure schedules should identify exact entity, model, dataset, licence, filing, policy, and contract versions. Product names alone are inadequate. The seller should distinguish verified facts, management assertions, disputed matters, and unresolved items.

Interim covenants should restrict material model releases, dataset changes, new public-facing functions, new high-impact uses, supplier changes, unapproved claims, and unusual customer exceptions. They should require prompt notice of incidents, complaints, regulator contact, and legal changes.

Open items need an owner, due date, evidence standard, closing effect, and escalation route. The closing bring-down should repeat licence, data, filing, cyber, copyright, investment, merger, export, sanctions, and commencement checks.

Ready to test a project before you rely on it?

Book a 30-minute consultation. We'll map the review perimeter and tell you exactly what evidence to request, in plain language.

Book a Consultation