The Framework
An AI project is a bundle of entities, models, data, products, workers, suppliers, and contracts. Legal due diligence must test whether the target can lawfully own, develop, deploy, sell, and transfer that bundle. It must also quantify liabilities that survive closing. This memorandum states a cross-border baseline for an investment, acquisition, financing, joint venture, or strategic contract. No target, sector, transaction structure, or data room was supplied. The analysis therefore uses verified European Union and United States rules as representative reference points. Final answers require the target's records and local-law review in every connected jurisdiction.
Corporate domicile is only one connector. Product use, user location, data subjects, workers, compute, suppliers, contracts, and regulated activities can each trigger separate law.
The buyer must prove:
- title or licensed rights for code
- model architecture
- weights
- datasets
- evaluation records
- prompts
- documentation
- patents
- brands
- domains
- trade secrets
The AI Act demands an actor and use-case classification. GDPR, copyright, database, product, consumer, cybersecurity, and sector rules remain separate.
Federal consumer, copyright, trade-secret, export, sanctions, competition, and sector laws operate with state and local AI laws. Marketing claims and consequential decisions need versioned evidence.
Data diligence must trace:
- acquisition
- permissions
- purpose
- personal and sensitive data
- children
- transfers
- retention
- deletion
- security
- downstream reuse
Third-party code, models, datasets, cloud services, and APIs can limit commercial use, training, output use, sublicensing, geography, assignment, or change of control.
Safety and cybersecurity claims require records:
- test plans
- model evaluations
- red-team results
- incidents
- release approvals
- access logs
- monitoring
- human review
Stop-level defects include:
- missing title
- unlawful irreplaceable data
- prohibited AI use
- an absent critical license
- unlicensed regulated activity
- sanctions and export breaches
Curable gaps belong in closing conditions. Quantified legacy exposure belongs in price, escrow, specific indemnities, exclusions, and post-closing covenants.
Later sessions should cover North America; the European Union and EEA; the United Kingdom and Switzerland; offshore centers; the Middle East; Asia-Pacific hubs; Mainland China and India; and trigger markets elsewhere.
Diligence perimeter and connecting factors
Legal diligence starts with operating reality. The incorporation certificate does not define the applicable law. The review must map:
- every entity
- product
- model
- use case
- user class
- data flow
- worker
- supplier
- reseller
- compute location
- sales territory
Each law uses its own connector. Regulation (EU) 2024/1689 reaches
certain third-country providers and deployers when systems or outputs
are used in the Union, subject to Article 2. Article 25 can treat a
rebrander or material modifier of a high-risk system as its provider.
Regulation (EU) 2016/679 uses establishment and targeted-market rules in
Article 3. U.S. federal, state, local, sector, export, sanctions, and
investment rules can attach to conduct, persons, products, data, or
transactions.
Counsel should create one verified operating map. It should link each entity to its assets, workers, contracts, and territories. It should link each AI feature to its intended purpose and actual deployments. Contract labels do not control statutory status. A reseller, integrator, white-label customer, or model modifier may acquire duties beyond the contract.
The minimum record is a dated group chart, product inventory, model inventory, data-flow map, role matrix, and jurisdiction matrix. Unmapped deployments remain unresolved exposure.
Corporate structure, authority, and capitalization
Corporate diligence must establish which entity can sell the business and which entity owns each critical asset. Counsel should verify existence, good standing, constitutional documents, registers, minute books, and authorized signatories. The review should reconcile issued shares, options, warrants, SAFEs, convertible instruments, tokens, and side letters. It should identify:
- liens
- security interests
- pre-emption rights
- vetoes
- drag rights
- tag rights
- liquidation preferences
- change-of-control approvals
A target may separate its holding company, research team, customer entity, data contracts, and compute contracts. That separation creates title and cash-flow risk when documents do not match conduct. The entity receiving revenue may not own the model. The entity employing researchers may not have transferred inventions. A founder, university, affiliate, or former employer may retain a claim.
Counsel should also test beneficial ownership, related-party dealings, intercompany transfers, distributions, local registrations, insolvency indicators, tax residence, and economic-substance duties. These findings determine signing authority, closing mechanics, post-closing integration, and creditor risk.
AI asset title and intellectual property
Value rests on legal control, not technical possession. The target must show a continuous chain of title or a current license for each critical asset.
Under U.S. law, copyright initially vests in the author, subject to
the work-made-for-hire rule. 17 U.S.C. § 201(a), (b). A transfer of
copyright ownership generally requires a signed writing. Id. § 204(a).
Payment to an independent contractor does not by itself transfer
copyright.
Copyright protects original expression. It does not protect ideas,
procedures, processes, systems, or methods of operation. 17 U.S.C. § 102(a), (b). Model architecture, weights, prompts, and outputs therefore
need asset-specific treatment. Protection may arise from copyright,
patent, trade secret, database rights, contract, or technical access
controls. Some components may lack exclusive statutory protection.
Training rights and output rights are distinct. U.S. fair use turns
on four statutory factors. 17 U.S.C. § 107. It is not a blanket
exemption for model training. In the Union, Directive (EU) 2019/790
distinguishes research text and data mining from the broader Article 4
exception. Article 4 requires lawful access and permits rights holders
to reserve online uses in a machine-readable manner.
Output diligence must separate authorship from contract allocation. A customer term can allocate contractual risk. It cannot create statutory copyright in material that governing law leaves unprotected.
Trade-secret value requires secrecy measures. The U.S. definition
requires reasonable measures and independent economic value from
secrecy. 18 U.S.C. § 1839(3). Directive (EU) 2016/943, Article 2(1),
uses comparable elements. Counsel should test access limits,
repositories, confidentiality terms, publication history, model release,
logging, and offboarding. Target-specific Union work must confirm the
relevant member-state implementation and national case law.
The core records are invention and copyright assignments, employment and contractor terms, founder transfers, university and grant terms, inbound licenses, patent files, trademark and domain records, model licenses, dataset licenses, notices, and contribution history. Patent review should cover:
- inventorship
- ownership
- disclosures
- prosecution status
- maintenance
- funding rights
- relevant freedom-to-operate work
Training, evaluation, and user data
Data diligence has four separate questions: possession, permission, purpose, and proof. Public access does not establish permission for copying, training, storage, or redistribution.
For each dataset, the target should record source, acquisition date, collector, collection method, license, contract terms, opt-outs, notices, personal-data fields, special-category data, children's data, geography, retention, deletion, and downstream use. The same record:
- should cover fine-tuning sets
- evaluation sets
- retrieval corpora
- prompts
- logs
- feedback
- support transcripts
Under Regulation (EU) 2016/679, personal-data processing needs a
lawful basis and compliance with purpose limitation, data minimization,
accuracy, storage limits, security, and accountability. Arts. 5, 6, 9.
Transparency and access duties can apply to training and deployment
records. Arts. 13-15. Automated decisions can trigger Article 22.
High-risk processing can require a data-protection impact assessment
under Article 35. Cross-border transfers require Chapter V analysis.
Contract permission, copyright permission, database rights, privacy permission, confidentiality, and sector secrecy are independent. A valid answer in one category does not cure another.
Prompts and logs may contain customer secrets, personal data, regulated records, or third-party content. Synthetic data needs provenance too. It may reproduce source records or inherit source defects.
Deletion or unlearning commitments need technical evidence. Counsel should verify whether the target can identify affected checkpoints, embeddings, caches, logs, and backups. Failure to reconstruct a critical dataset's lineage is a major title and compliance defect. If the data cannot be replaced, the defect may impair sale or continued use of the model.
Third-party code, models, data, and compute
Every external dependency can limit transfer and commercialization. A software bill of materials is not enough. The target also needs:
- a model
- dataset
- API
- benchmark
- compute dependency register
For each dependency, counsel should review version, source, license, commercial scope, field and geography limits, user restrictions, training and distillation rights, output terms, redistribution, sublicensing, hosted access, attribution, notices, source-code duties, audit rights, termination, assignment, and change of control.
Open-source software and open-weight models require separate analysis. A public download does not prove unrestricted use. Copyleft effects depend on the exact license, integration method, distribution mode, modifications, and governing law.
Cloud and API diligence should test capacity, location, pricing, data use, service changes, model deprecation, export restrictions, security duties, termination, portability, disaster recovery, and assignment. A target can own its application yet lack a transferable right to the model or compute needed to run it.
Benchmarks and evaluation datasets can carry license, confidentiality, and contamination risk. Published scores need:
- the exact model version
- prompt set
- sample
- exclusions
- test conditions
AI and sector classification
Each use case needs a written classification memorandum before signing. The label "AI company" is too broad. One model may support prohibited, high-risk, transparent-use, ordinary, and regulated-sector deployments.
Under Regulation (EU) 2024/1689, diligence should classify prohibited
practices, high-risk systems, transparency duties, general-purpose AI
model duties, systemic-risk duties, and value-chain roles. Arts. 5, 6,
16, 25, 26, 50, 53, 55, 99. The regulation applies through staged dates.
Article 113 supplies the original schedule.
As of 22 July 2026, the Council had given final approval to PE-CONS
30/26. That text sets 2 December 2027 for stand-alone high-risk systems
and 2 August 2028 for systems embedded in products. The retrieved
EUR-Lex procedure still marked the file as ongoing. An Official Journal
publication number was not confirmed. Until entry into force, Article
113's original schedule remains operative. Any transaction must recheck
publication, entry into force, and the consolidated text at signing and
closing.
An EU screen should also test Regulation (EU) 2023/2854 for connected
products and data processing services. Directive (EU) 2022/2555 and its
national implementing law can apply to covered entities. Regulation (EU)
2022/2065 can apply to intermediary services. These duties depend on the
product and entity, not the label AI.
In the United States, diligence must combine federal statutes, state
statutes, local rules, and sector law. Section 5 of the Federal Trade
Commission Act prohibits unfair or deceptive acts or practices. 15 U.S.C. § 45(a)(1). Texas H.B. 149, 89th Leg., R.S. (2025), took effect
on 1 January 2026. Colorado S.B. 26-189, ch. 131 (2026), places material
automated-decision duties on developers and deployers from 1 January
2027. These statutes do not replace credit, employment, housing, health,
insurance, children, privacy, civil-rights, or professional-licensing
rules.
Sector screening should cover medical devices and care, credit and financial services, insurance, employment, housing, education, children, telecoms, transport, defense, critical infrastructure, and public procurement. Intended purpose, claims, customer configuration, and actual use control the review.
Downstream integration can change classification. Contracts should require:
- current documentation
- change notices
- testing evidence
- incident cooperation
- version control
- exit rights
Product claims, consumer protection, and output liability
Marketing diligence should test every material claim against dated evidence. The review should compare websites, decks, demos, model cards, proposals, security materials, terms, sales scripts, and customer responses.
Claims about accuracy, hallucination rates, bias, human review, privacy, security, training rights, certifications, compliance, output ownership, and benchmark rank require a defined test. The record:
- should identify model version
- test set
- sample
- prompts
- exclusions
- threshold
- result
- date
- approver
An unsupported or qualified claim can create deception risk under 15
U.S.C. § 45 and comparable state or national law. A disclaimer does not
cure a contradictory headline or sales practice.
Output risk depends on use. Counsel should map defamation, privacy, copyright, discrimination, physical injury, economic loss, regulated advice, and professional duty. Controls should match the harm:
- input limits
- source grounding
- review
- refusal rules
- logging
- escalation
- correction
- suspension
Customer contracts should allocate responsibilities without contradicting actual product design. Broad customer indemnities do not cure a misleading claim or unlawful feature.
Safety, cybersecurity, and incident history
Policies do not prove operational control. Diligence needs versioned records from design, testing, release, and production.
Counsel should review threat models, secure development, privileged access, model and dataset controls, secrets management, supplier access, vulnerability handling, penetration tests, red-team exercises, prompt-injection tests, data-poisoning tests, model-extraction tests, logging, backups, recovery, release gates, and post-release monitoring.
Regulation (EU) 2024/1689, Article 55, imposes evaluation,
adversarial-testing, systemic-risk, incident, and cybersecurity duties
on providers of general-purpose AI models with systemic risk. GDPR
Article 32 governs security of personal-data processing. Sector rules
can impose shorter notice and testing duties.
The target should maintain one incident register. It should include:
- data breaches
- unsafe outputs
- discriminatory outcomes
- prompt or weight leakage
- copyright complaints
- security reports
- service outages
- regulator contacts
- customer notices
- claims
- remediation
- recurrence tests
An undisclosed incident is not merely a process gap. It may affect warranties, disclosure schedules, insurance notice, customer termination, regulator reporting, valuation, and closing.
Personnel, contractors, confidentiality, and trade secrets
Personnel records must connect each contributor to the work performed and the owning entity. Standard forms alone are not enough.
Counsel should review employment and contractor status, invention terms, copyright assignments, confidentiality, prior-employer restrictions, university duties, founder work before incorporation, side projects, open-source contributions, local consultation duties, and immigration status.
The review should test whether applicable law permits the chosen assignment language and post-termination restrictions. Local law can limit future-invention clauses, non-competes, and waivers of moral rights.
Access should end when a person leaves or changes role. Repositories, model registries, cloud consoles, signing keys, datasets, and customer systems need current access lists.
Key-person dependence is a transaction risk. The target should identify who alone can train, deploy, recover, or explain a critical system. Documented handover and continuity plans are needed when that knowledge is not institutionalized.
Contracts, revenue quality, and operational continuity
Contract diligence must establish assent, scope, performance, liability, and transferability. Template terms do not prove that a customer accepted the operative version.
Counsel should review executed customer, partner, reseller, marketplace, API, clickwrap, procurement, cloud, data, and research agreements. The review should confirm version, signer authority, order of precedence, renewal, amendment, and incorporated terms.
AI clauses should address:
- permitted use
- prohibited use
- training on customer data
- prompts and logs
- output rights
- confidentiality
- security
- incident notice
- model changes
- documentation
- human review
- compliance cooperation
- audit
- indemnity
- caps
- exclusions
- assignment
- change of control
- termination
- transition
Revenue quality requires contract-to-ledger testing. Counsel should separate recurring production revenue from pilots, credits, contingent milestones, free use, related-party sales, and cancellable commitments.
Operational continuity depends on compute and key suppliers. Counsel should review reserved capacity, minimum spend, region, hardware constraints, price resets, suspension, deprecation, portability, exit support, and disaster recovery.
Competition, export controls, sanctions, and foreign investment
AI diligence must test market conduct and cross-border controls before signing. These issues can block closing or restrict post-closing integration.
Competition review should cover:
- exclusivity
- most-favored terms
- tying
- data access
- interoperability limits
- non-competes
- information exchange
- pricing tools
- talent agreements
- merger-control thresholds
Export analysis should classify software, models, chips, technical
data, cloud access, users, end uses, destinations, and remote access.
U.S. controls appear in 15 C.F.R. pts. 730-774. Regulation (EU) 2021/821
controls listed and certain unlisted dual-use items, including software
and technology.
Sanctions screening must cover parties, beneficial owners, banks,
customers, vendors, destinations, and prohibited services. Relevant U.S.
rules appear in 31 C.F.R. ch. V and program-specific regulations.
Screening must continue through closing because lists and ownership can
change.
Foreign-investment review should test buyer identity, target
activities, sensitive data, critical technology, government links, and
control rights. U.S. review can arise under 50 U.S.C. § 4565. Certain
outbound U.S. investments involving artificial intelligence can fall
within 31 C.F.R. pt. 850.
Representations cannot replace classification and screening records. A failed analysis can produce a filing delay, blocked integration, license conditions, penalties, or an unlawful closing.
Disputes, insurance, and financial exposure
Dispute diligence must capture threatened and informal matters, not only filed cases. Counsel should review demand letters, takedowns, security reports, customer escalations, employment complaints, audits, subpoenas, regulator contacts, settlements, releases, holds, and insurance notices.
AI claims may concern training data, outputs, discrimination, privacy, professional use, product injury, contract promises, security, or unfair competition. Each matter needs:
- a chronology
- claimant
- legal basis
- affected model
- alleged loss
- defense
- reserve
- insurance position
- operational response
Counsel should review technology errors and omissions, cyber, media, intellectual-property, product-liability, directors and officers, and crime policies. The review should test:
- insured entities
- covered products
- exclusions
- retroactive dates
- sublimits
- retentions
- notice
- consent
- prior knowledge
- change-of-control provisions
Quantification should state inputs and operations. A range should identify:
- claim count
- exposure period
- contract cap
- defense cost
- insurance recovery
- probability assumption
- tax effect
North America
North American legal due diligence of an artificial intelligence project asks whether the target can lawfully own, train, deploy, sell, and transfer its systems across the United States and Canada. This memorandum gives a transaction baseline as of July 22, 2026. It assumes no identified target, sector, transaction structure, or data room. It focuses on United States federal law, Delaware, California, New York, Colorado, Texas, Illinois, Canadian federal law, Quebec, Ontario, British Columbia, and Alberta. Every other state, province, municipality, and sector regulator connected to the target must be added before a transaction decision.
Incorporation does not define the review. Product access, users, workers, data subjects, training sources, compute, suppliers, regulated uses, and transaction parties create separate legal connections.
No single federal private-sector AI statute governs the whole target. Federal consumer, civil-rights, employment, credit, privacy, copyright, trade-secret, export, sanctions, competition, and investment laws operate beside state and municipal AI statutes.
Executive Order 14365 directs federal challenges and possible preemption measures against selected state AI laws. It does not itself repeal those laws. The target must comply unless a competent court, statute, or valid federal rule displaces them.
Diligence must separate current duties from readiness duties. California and Texas rules already apply. California content-provenance duties start on August 2, 2026. Colorado and New York material duties start on January 1, 2027.
The operative private-sector baseline remains the
Personal Information Protection and Electronic Documents Act and
applicable provincial statutes. Bill C-36 and Bill C-34 are pending. The
former Artificial Intelligence and Data Act never became law.
Quebec requires special review for privacy impact assessments, transfers outside Quebec, and decisions based exclusively on automated processing. Ontario now requires certain public job postings to disclose AI use. Alberta and British Columbia apply general private-sector privacy statutes.
The target must prove title or licensed rights for code, model components, weights, datasets, prompts, evaluations, documentation, patents, brands, and trade secrets. Public availability does not establish training or commercialization rights.
Consequential decisions require use-case testing. Employment, credit, housing, insurance, healthcare, education, public benefits, children, and biometric uses can trigger overlapping laws, notices, testing, review rights, recordkeeping, and discrimination exposure.
Missing core title, unlawful irreplaceable data, a prohibited deployment, a non-transferable critical license, an undisclosed serious incident, or a blocking sanctions or investment issue can stop closing. Curable defects belong in conditions, quantified legacy exposure belongs in price and specific protection.
Diligence perimeter and legal connections
The review must begin with the target's operating facts. A North American AI project may involve a Delaware parent, Canadian research staff, California users, Quebec data subjects, Texas customers, and foreign compute. Each connection can trigger a different statute.
Counsel should prepare six linked inventories. They should cover legal entities, products, models, use cases, data flows, and third parties. Each record needs a version date and an identified owner. The inventories should distinguish development, testing, production, resale, white-label use, and customer modification.
The model inventory should identify architecture, weights, checkpoints, fine-tunes, retrieval sources, safety layers, evaluation sets, and release history. The use-case inventory should state the intended purpose and actual customer use. Marketing labels do not control legal classification.
The jurisdiction matrix should record incorporation, offices, workers, customers, users, data subjects, training sources, compute, storage, support, public procurement, and regulated activities. It should also identify the buyer, financing sources, and post-closing integration. Those transaction facts can trigger foreign-investment, export, sanctions, and data-transfer rules.
Time must form a separate diligence dimension. A current breach differs from a law that starts before closing or shortly afterward. The closing checklist should track enactment, effective date, operative date, transition period, regulations, and pending litigation.
Corporate authority, capitalization, and asset location
The buyer must identify the entity that owns each material asset and owes each material obligation. A consolidated brand or website does not prove common ownership.
For a Delaware corporation, the board manages the business unless the
certificate provides otherwise. Del. Code tit. 8, § 141(a). Counsel
should verify the certificate, bylaws, board and stockholder approvals,
delegations, and signing authority. The review should reconcile stock,
options, warrants, SAFEs, convertible notes, side letters, and promised
equity.
Interested and controller transactions require current Delaware
analysis. Section 144 changed materially in 2025. Del. Code tit. 8, §
144. The records should identify controller rights, conflicts,
approvals, disclosures, and fairness procedures. Reliance on old
checklists creates avoidable closing risk.
AI groups often split research, customer contracting, payroll, and intellectual property among affiliates. Counsel should test every intercompany assignment, service agreement, license, cost allocation, and cash transfer. The revenue entity may not own the model. The employing entity may not own employee inventions.
Security interests also matter. United States perfection may depend on the asset, debtor location, filing office, possession, or control. U.C.C. arts. 8 and 9. Canadian review must test federal and provincial personal-property security registrations. A blanket lien can cover:
- code
- accounts
- patents
- trademarks
- contract rights
The corporate record request should include minute books, cap tables, securities instruments, beneficial ownership, liens, intercompany agreements, insolvency indicators, tax residence, and change-of-control approvals. Any mismatch between asset use and legal title needs a closing remedy.
United States federal baseline and federal-state conflict
United States diligence starts with issue-specific federal law.
Section 5 of the Federal Trade Commission Act prohibits unfair or
deceptive acts affecting commerce. 15 U.S.C. § 45(a)(1). Claims about
accuracy, neutrality, privacy, training rights, safety, security, human
review, and output ownership require dated support.
A disclaimer does not cure a conflicting headline, demo, sales script, or product design. Counsel should match each material claim to the tested model version, prompts, sample, exclusions, result, and approval. Unsupported claims can affect consumer exposure, contract warranties, disclosure schedules, and valuation.
Federal civil-rights and sector laws apply without an AI label. Title
VII governs employment discrimination. 42 U.S.C. § 2000e-2. The
Americans with Disabilities Act governs covered employment practices. 42
U.S.C. § 12112. The Equal Credit Opportunity Act governs credit
discrimination. 15 U.S.C. § 1691. The Fair Credit Reporting Act can
apply to reports, investigations, and adverse employment or credit
actions. 15 U.S.C. §§ 1681a, 1681b, 1681d, 1681m.
Children's products require a separate screen. The Children's Online
Privacy Protection Act and its amended rule govern covered collection
from children under 13. 15 U.S.C. §§ 6501-6506; 16 C.F.R. pt. 312. The
2025 rule became effective on June 23, 2025, with general compliance due
by April 22, 2026. It adds material consent, retention, security, and
biometric issues.
Executive Order 14365, dated December 11, 2025, directs federal
review and litigation against selected state AI laws. Exec. Order No.
14,365, §§ 3-8, 90 Fed. Reg. 58,499 (Dec. 16, 2025). The order also
directs possible federal disclosure standards and legislative
recommendations.
The order does not itself invalidate a state statute. Section 9
requires implementation consistent with existing law and creates no
private right. The FTC's July 2026 AI accuracy statement remains
proposed. A pending federal challenge also does not suspend a state law
without judicial relief.
Diligence should therefore treat state duties as operative according to their own terms. Counsel should record any challenge, injunction, appeal, regulation, or federal action at signing and closing. A contractual promise to follow only federal law is not a legal defense.
State model-development, disclosure, and frontier duties
California imposes several distinct duties. Civil Code sections 3110
and 3111 require covered generative-AI developers to publish specified
training-data information. The disclosure should match actual datasets,
data categories, sources, ownership status, personal-data content,
collection periods, and modification history.
California's frontier-model statute applies to defined frontier
models and large frontier developers. Cal. Bus. & Prof. Code §§
22757.10-22757.16. Covered large developers must maintain and publish a
frontier AI framework, publish model transparency reports, report
critical safety incidents, and protect qualifying whistleblowers.
The California review should verify compute thresholds, affiliate revenue, model versions, risk assessments, incident channels, publication history, and internal approvals. A target below the large-developer threshold may still face other California statutes, contracts, tort claims, and sector duties.
The California AI Transparency Act governs specified generative-AI
providers. Cal. Bus. & Prof. Code §§ 22757-22757.6. Its detection
and provenance duties become operative on August 2, 2026. A transaction
closing after that date needs tested tools, supported metadata, public
disclosures, and retained implementation evidence.
New York's RAISE Act covers defined frontier-model developers and
large developers. N.Y. Gen. Bus. Law art. 44-B. Its material duties
start on January 1, 2027. They include safety documentation, reporting,
filings, and incident duties. The March 2026 chapter amendment controls
the final thresholds and procedures.
Texas's Responsible Artificial Intelligence Governance Act took
effect on January 1, 2026. Tex. Bus. & Com. Code ch. 552. It reaches
specified development, deployment, products, services, and conduct
connected to Texas. It restricts designated harmful uses, government
social scoring, biometric misuse, and intentional unlawful
discrimination.
Texas gives the attorney general exclusive enforcement authority and provides a cure process. The statute also contains defenses tied to reasonable care and recognized risk-management standards. Counsel should not treat the absence of a private statutory action as the absence of contract, tort, privacy, or civil-rights exposure.
For every model-development statute, counsel should create an actor and threshold memorandum. It should identify the developer, deployer, distributor, owner, modifier, affiliate revenue, compute, release date, public availability, and covered outputs. Group-level thresholds can defeat entity-by-entity assumptions.
Consequential decisions, employment, and access to opportunity
Automated decisions require a separate review for each decision type. One system may rank applicants, price insurance, recommend medical care, and detect fraud. Each use can produce different duties.
Colorado Senate Bill 26-189 starts on January 1, 2027. Colo. Rev.
Stat. §§ 6-1-1701 to 6-1-1707, as enacted by 2026 Colo. Sess. Laws ch.
131. It covers defined automated decision-making technology used in
consequential decisions.
Covered developers must provide technical documentation about intended uses, training-data categories, known limits, and human review. Covered deployers must give notices and specified adverse-outcome information. They must support correction, reconsideration, and meaningful human review where the statute requires.
The Colorado attorney general has exclusive enforcement authority. The statute does not create a new private action. A federal constitutional challenge to Colorado's prior AI statute remains a separate procedural matter. Diligence must track the challenged provisions, the 2026 replacement text, and any court order.
New York City already regulates automated employment decision tools.
N.Y.C. Admin. Code §§ 20-870 to 20-874; 6 R.C.N.Y. §§ 5-300 to 5-304. A
covered employer or employment agency needs a recent independent bias
audit, a public summary, and required notices before use.
Illinois treats specified discriminatory employment AI use as a
civil-rights violation from January 1, 2026. 775 Ill. Comp. Stat.
5/2-102(L). Illinois also requires notice, explanation, and consent
before covered AI analysis of video interviews. 820 Ill. Comp. Stat.
42/5.
California's CCPA regulations create phased duties for automated
decisionmaking technology. Cal. Code Regs. tit. 11, §§ 7000-7304.
Significant-decision ADMT duties begin on January 1, 2027. Separate
risk-assessment and cybersecurity-audit dates apply.
Ontario now requires covered employers to disclose AI use in publicly
advertised job postings. Employment Standards Act, 2000, S.O. 2000, c.
41, s. 8.4; O. Reg. 476/24. The duty applies from January 1, 2026,
subject to the regulation's employee threshold and definitions.
The diligence file should contain system instructions, feature lists, training and validation data, protected-class testing, accessibility testing, notices, audit reports, adverse-action forms, override logs, and appeal records. Counsel should compare the documented process with actual recruiter, lender, insurer, clinician, or agency conduct.
A vendor contract cannot shift all discrimination risk to the customer. The developer's claims, design choices, known limits, and documentation remain relevant. The customer also needs enough information to use the system lawfully.
Canadian federal law and pending legislation
Canada does not have an operative federal private-sector AI statute
equivalent to a general AI act. The former Artificial Intelligence and
Data Act appeared in Bill C-27. That bill did not become law before the
prior Parliament ended.
The federal private-sector privacy baseline remains the Personal
Information Protection and Electronic Documents Act. S.C. 2000, c. 5.
PIPEDA applies to personal information handled in commercial activities,
subject to its territorial and provincial rules. It also reaches
employee information in federal works, undertakings, and businesses.
An organization must comply with Schedule 1 and may collect, use, or
disclose personal information only for purposes a reasonable person
would consider appropriate. PIPEDA, s. 5. Valid consent, limiting
collection, safeguards, access, accuracy, retention, and accountability
require fact-specific review.
PIPEDA requires reporting and notice when a breach creates a real
risk of significant harm. Id. ss. 10.1-10.2. The organization must keep
a record of every safeguards breach. Id. s. 10.3. The target's incident
register should therefore include non-reportable events and the legal
analysis for each decision.
PIPEDA contains a business-transaction exception. Id. s. 7.2. It
requires necessity, agreements, limited use, safeguards, and
post-transaction steps. It does not authorize unrestricted data-room
disclosure or continued use after an abandoned deal.
Bill C-36 received first reading on June 15, 2026. It proposes the
Protecting Privacy and Consumer Data Act and a new institutional
structure. Bill C-34 received first reading on June 10, 2026. It
proposes duties for regulated social media, chatbot, and other online
services.
Neither bill is law as of July 22, 2026. Their proposed duties should not appear as current compliance findings. They may support a readiness request when the target's product falls within their proposed scope and the transaction extends beyond enactment.
The federal Directive on Automated Decision-Making governs specified
federal administrative decisions. It does not regulate ordinary private
business operations. It can affect vendors that sell AI systems to
Canadian federal institutions because procurement terms may allocate
assessment, testing, explanation, and monitoring duties.
Provincial privacy and automated processing
Quebec requires a separate workstream. The Act respecting the
protection of personal information in the private sector, CQLR c.
P-39.1, applies to covered enterprises. Its requirements exceed a
generic PIPEDA checklist in several areas.
A covered enterprise must conduct a privacy impact assessment before
acquiring, developing, or redesigning an information system or
electronic service involving personal information. Id. s. 3.3. Counsel
should obtain the assessment, approval record, project changes, residual
risks, and measures adopted.
Quebec section 12.1 applies when an enterprise renders a decision
based exclusively on automated processing. The enterprise must give
required notice. On request, it must provide specified information about
the personal information used, principal factors and parameters, and
correction rights. The individual must have an opportunity to submit
observations to a qualified staff member.
A transfer of personal information outside Quebec requires a privacy
impact assessment and written agreement. Id. s. 17. The analysis must
address sensitivity, purpose, safeguards, and the destination's legal
regime. Cloud architecture and support access can create transfers even
when the main database remains in Canada.
Quebec also has a business-transaction exception with agreement and
use limits. Id. s. 18.4. Administrative monetary penalties can reach the
greater of C$10 million and two percent of worldwide turnover for the
preceding fiscal year. Id. s. 90.12. Penal exposure can be higher for
specified offences.
British Columbia and Alberta have substantially similar
private-sector privacy statutes. Personal Information Protection Act,
S.B.C. 2003, c. 63; Personal Information Protection Act, S.A. 2003, c.
P-6.5. Their application can displace PIPEDA for intraprovincial
activity, while PIPEDA remains relevant to interprovincial,
international, and federal matters.
Ontario lacks a general private-sector privacy statute comparable to
Quebec, Alberta, or British Columbia. PIPEDA usually supplies the
commercial baseline. Sector statutes remain material, including the
Personal Health Information Protection Act, 2004, S.O. 2004, c. 3,
Sched. A.
The Canadian data map should therefore identify the organization, province, commercial activity, sector, employee status, transfer path, and recipient. A single Canada-wide privacy policy does not answer which statute controls each processing activity.
Training data, privacy, and data rights
Data diligence must prove source, permission, purpose, and traceability. Possession of a dataset proves none of those points.
The dataset register should cover pretraining, fine-tuning, retrieval, evaluation, red-team, prompt, log, feedback, and support data. Each entry should identify:
- source
- acquisition date
- collector
- method
- license
- contract
- personal-data content
- sensitive fields
- children
- geography
- retention
- deletion
- downstream use
United States privacy law remains sectoral and state based. The target may face California, Colorado, Texas, and other state privacy statutes beside federal health, financial, education, communications, and children's rules. The diligence scope must follow actual data subjects and processing purposes.
The CCPA regulations that took effect on January 1, 2026 create phased risk-assessment, ADMT, and cybersecurity-audit obligations. The California Delete Request and Opt-out Platform began accepting requests on January 1, 2026. Registered data brokers must process covered DROP requests from August 1, 2026.
The DOJ Data Security Program restricts specified covered data transactions involving countries of concern or covered persons. 28 C.F.R. pt. 202. Counsel should test:
- bulk sensitive personal data
- government-related data
- vendor access
- employment access
- data brokerage
- cloud support
- contractual restrictions
Canadian consent does not cure an inappropriate purpose. PIPEDA section 5(3) applies even when consent exists. Quebec also requires:
- lawful collection
- necessity
- transparency
- access
- security
- purpose controls under its own provisions
De-identification and synthetic data require technical proof. A label does not establish irreversibility or low reidentification risk. Counsel should inspect generation methods, source linkage, memorization testing, access controls, and contractual restrictions.
Deletion and unlearning promises require system-level evidence. The target should identify affected files, checkpoints, embeddings, vector stores, caches, logs, backups, and customer copies. A contractual deletion clause is weak when the target cannot locate the data.
Intellectual property, training, and outputs
The target must prove a continuous chain of title for each material AI asset. Technical control does not establish legal ownership.
United States copyright initially vests in the author, subject to
work made for hire. 17 U.S.C. § 201(a), (b). A copyright transfer
generally requires a signed writing. Id. § 204(a). Payment to a founder
or contractor does not itself transfer ownership.
Copyright protects original expression. It does not protect ideas,
processes, systems, or methods of operation. Id. § 102(a), (b). Model
architecture, weights, prompts, datasets, and outputs therefore require
asset-specific analysis. Protection may depend on copyright, patent,
trade secret, contract, database restrictions, or access controls.
Fair use requires the four-factor analysis in 17 U.S.C. § 107. It
does not create a categorical training privilege. Thomson Reuters
Enterprise Centre GmbH v. Ross Intelligence Inc., No. 20-613-SB,
memorandum opinion (D. Del. Feb. 11, 2025), rejected fair use on
competing legal-research facts.
Other training cases remain fact bound and procedurally active. Counsel should not convert one district-court ruling into a universal answer. The relevant facts include:
- source
- access
- copying method
- purpose
- output behavior
- market effect
- retention
- acquisition lawfulness
United States patent inventorship requires a natural person. Thaler v. Vidal, 43 F.4th 1207, 1213 (Fed. Cir. 2022). Diligence should identify:
- the human conception record
- prompt and experiment history
- inventor declarations
- assignments
- prior disclosures
Canadian copyright first-ownership and assignment rules require
separate review. Copyright Act, R.S.C. 1985, c. C-42, s. 13. The statute
contains employee rules and requires a signed writing for assignments
and grants of interests. Canada has not enacted a blanket statutory
permission for commercial AI training.
Output diligence should separate statutory protection, infringement risk, and contract allocation. Customer terms can allocate risk between parties. They cannot create copyright where governing law recognizes no protectable human authorship.
Trade-secret protection requires secrecy measures. 18 U.S.C. §§ 1836-1839; Uniform Trade Secrets Act as enacted by the relevant state. Canadian protection relies on contract, confidence, equitable principles, and applicable provincial law. The review should test:
- access
- repositories
- publication
- model releases
- logging
- confidentiality
- offboarding
Third-party code, models, data, and compute
Every external dependency can restrict commercialization or transfer. The target needs more than a software bill of materials.
The dependency register should cover code, open-weight models, hosted models, datasets, benchmarks, APIs, libraries, cloud services, accelerators, and security tools. Each entry needs:
- the exact version
- supplier
- accepted terms
- paying entity
- use
- replacement plan
Counsel should review commercial scope, field limits, geography, user restrictions, training, fine-tuning, distillation, output terms, redistribution, attribution, source duties, audit rights, suspension, termination, assignment, and change of control. A public repository does not establish unrestricted use.
Open-source and open-weight reviews must examine the actual license and integration method. Copyleft effects depend on distribution, linking, modifications, network access, and governing law. Model licenses may impose acceptable-use limits that do not appear in ordinary software licenses.
Cloud and API agreements need capacity, location, security, data use, training use, model changes, deprecation, price resets, service credits, portability, disaster recovery, and exit support. The target may own its application while lacking a transferable right to the model or compute needed for operation.
Benchmarks and evaluation data also create exposure. Counsel should verify:
- license terms
- confidential test sets
- contamination controls
- score methodology
- model version
- prompt set
- sample
- exclusions
- publication approvals
A critical dependency with no assignment consent or substitute can become a closing condition. A supplier's informal assurance should not replace an executed consent or amended contract.
Product claims, synthetic media, chatbots, and children
Product diligence should compare public claims with product behavior and retained evidence. Websites, decks, demos, model cards, sales scripts, security materials, customer responses, and procurement submissions all matter.
Claims about accuracy, bias, safety, privacy, security, training rights, certifications, human review, output ownership, and benchmark rank require a defined test. The record:
- should identify the model version
- test set
- sample
- prompts
- exclusions
- threshold
- result
- date
- approver
California's content-provenance duties require a separate implementation record from August 2, 2026. The target should test whether metadata survives ordinary distribution, editing, export, and platform handling. Detection tools need documented accuracy and limits.
California also regulates covered companion chatbots from January 1,
2026. Cal. Bus. & Prof. Code §§ 22601-22606. Duties include AI
disclosure and specified self-harm protocols. Products accessible to
minors face added notices, reminders, and sexual-content controls.
Colorado enacted separate conversational-AI duties with material provisions starting on January 1, 2027. The target should classify whether a chatbot is a general assistant, companion, therapeutic product, customer-support tool, or regulated professional service. Actual interaction design controls.
Texas imposes disclosure and use restrictions for specified government and healthcare interactions. Its prohibited-use provisions require product and intent analysis. A safety policy alone does not prove that production controls match the policy.
Children's diligence should cover age signals, actual audience, app-store classification, advertising, profiling, parental consent, retention, chat history, escalation, crisis responses, and human review. Teen products also require state-law review beyond COPPA's under-13 threshold.
Cybersecurity, incidents, and critical systems
AI security diligence must cover the model, data, application, infrastructure, and suppliers. A conventional penetration test:
- may omit prompt injection
- model extraction
- poisoning
- unsafe tool use
- retrieval manipulation
Counsel should obtain threat models, secure-development records, privileged-access lists, secrets controls, model registries, dataset controls, vendor access, vulnerability reports, red-team results, release approvals, monitoring, backups, recovery tests, and incident exercises.
The United States federal sector screen should include HIPAA, the
Gramm-Leach-Bliley Act, the FTC Safeguards Rule, state breach laws, New
York Department of Financial Services rules, defense requirements, and
public-contract terms. Exact duties depend on entity and data
status.
Canada's Critical Cyber Systems Protection Act received Royal Assent on June 15, 2026. S.C. 2026, c. 9, pt. 2. It addresses:
- designated operators in listed federally regulated vital services
- including telecommunications
- banking
- transportation
- energy
- nuclear
- clearing systems
Part 2 comes into force by order of the Governor in Council. S.C. 2026, c. 9, s. 16. No commencement order was verified for this memorandum. Covered targets should still prepare:
- for cyber programs
- third-party risk controls
- incident reporting
- directions
- audits
- records
- enforcement
The target should maintain one incident register across legal, security, product, and safety teams. It should include:
- breaches
- unsafe outputs
- discriminatory outcomes
- prompt or weight leakage
- data poisoning
- model extraction
- outages
- complaints
- claims
- regulator contacts
Each incident entry should record discovery, affected systems, users, jurisdictions, containment, legal analysis, notices, customer communications, insurance, root cause, remediation, and recurrence testing. Missing or inconsistent incident records can affect warranties and disclosure schedules.
Contracts, revenue quality, and continuity
Contract diligence must prove assent, scope, performance, and transferability. A standard form does not prove which terms a customer accepted.
Counsel should review executed customer, reseller, marketplace, API, clickwrap, procurement, data, research, cloud, and supplier agreements. The record:
- should identify the accepted version
- signer authority
- order of precedence
- amendments
- renewal
- incorporated policies
AI terms should address:
- permitted use
- prohibited use
- training on customer data
- prompts
- logs
- outputs
- confidentiality
- security
- incidents
- model changes
- documentation
- human review
- compliance cooperation
- audits
- indemnities
- caps
- exclusions
- assignment
- termination
- transition
The terms should match product reality. A clause stating that customers control every decision is unreliable when the target markets autonomous operation. A clause promising no training on customer data is dangerous when logs feed evaluation or fine-tuning.
Revenue quality needs contract-to-ledger testing. Counsel should separate recurring production revenue from pilots, credits, contingent milestones, free use, related-party sales, minimum commitments, and cancellable arrangements.
Continuity depends on compute, key models, and key staff. The review should test:
- reserved capacity
- minimum spend
- hardware limits
- region
- price changes
- suspension
- deprecation
- portability
- key-person knowledge
- disaster recovery
Competition, exports, sanctions, and investment controls
Competition review should cover exclusivity, most-favored terms, tying, data access, interoperability limits, pricing tools, information exchange, talent restrictions, acquisitions, and customer concentration. The analysis must use current federal, state, and Canadian law.
The United States export review should classify software, source
code, model weights, technical data, chips, servers, cloud access,
users, end uses, and destinations. The Export Administration Regulations
appear in 15 C.F.R. pts. 730-774. Remote access can constitute a
controlled release.
United States sanctions review must test parties, beneficial owners,
banks, customers, vendors, locations, services, and payments. Relevant
rules appear in 31 C.F.R. ch. V and program-specific authorities. OFAC's
50 Percent Rule can block an unlisted entity based on ownership.
The DOJ Data Security Program adds a separate data-access screen. 28
C.F.R. pt. 202. Its concepts do not replace export or sanctions
analysis. The same supplier or employee can create several independent
restrictions.
CFIUS review can arise from foreign investment in a United States
business involving critical technology, critical infrastructure, or
sensitive personal data. 50 U.S.C. § 4565; 31 C.F.R. pts. 800 and 802.
Non-controlling rights can matter.
United States outbound-investment rules can cover prohibited or notifiable transactions involving defined artificial-intelligence activities and countries of concern. 31 C.F.R. pt. 850. The review must identify:
- United States persons
- controlled foreign entities
- joint ventures
- fund interests
- knowledge
- covered activities
Canadian exports and technology transfers require review under the
Export and Import Permits Act. R.S.C. 1985, c. E-19, ss. 7, 13. Counsel
should classify controlled technology, destination, recipient, end use,
brokering, and permit status.
Canadian sanctions arise under the Special Economic Measures Act,
United Nations Act, Justice for Victims of Corrupt Foreign Officials
Act, and program regulations. The administrative consolidated list is
not the law. Counsel must read the operative regulation and refresh
screening at closing.
The Investment Canada Act can trigger notification, net-benefit
review, or national-security review. R.S.C. 1985, c. 28 (1st Supp.), pt. IV.1. Sensitive data, dual-use technology, government links, investor
identity, and control rights need early analysis.
Deal grading and transaction protections
Each finding needs a legal consequence, business effect, evidence standard, and deal response. A color without those elements is not useful.
Stop-level findings include:
- missing title to a core model
- unlawful irreplaceable training data
- a prohibited use
- an absent critical license
- an unlicensed regulated activity
- or a sanctions
- export
- investment issue that blocks the planned transaction
Closing conditions fit defects that can be cured before closing. Common items include:
- assignments
- consents
- lien releases
- regulatory filings
- privacy assessments
- notices
- access cleanup
- incident remediation
- documentation
- supplier amendments
- product suspension
Price adjustments, escrow, holdbacks, exclusions, specific indemnities, and post-closing covenants fit quantified legacy exposure. General warranties provide weak protection for a known defect. Continued unlawful conduct cannot be solved only with indemnity.
Representations should cover corporate authority, capitalization, title, data rights, privacy, AI classification, product claims, security, incidents, employment, licenses, contracts, sanctions, exports, foreign investment, and disputes. Disclosures should identify model and dataset versions, not only product names.
The buyer should require signing-to-closing covenants for model releases, material dataset changes, training practices, supplier changes, incidents, regulator contacts, claims, and legal changes. Bring-down review must include the August 2, 2026 and January 1, 2027 duties relevant to the target.
The priority request list:
- should include the six inventories
- corporate records
- assignments
- dependency registers
- dataset provenance
- privacy assessments
- decision-system records
- evaluation evidence
- incident history
- operative contracts
- export classifications
- sanctions screens
- investment analyses
- insurance
Open items need an owner, due date, evidence standard, closing effect, and escalation path. The final report should separate verified facts, management assertions, unresolved items, and legal inferences.
EU / EEA
European Union and EEA legal due diligence tests whether an AI target can lawfully operate and transfer its business. The review covers its models, systems, data, services, entities, workers, customers, and suppliers across connected jurisdictions. This memorandum states the transaction baseline as of July 23, 2026. It gives priority attention to Ireland, the Netherlands, Luxembourg, Germany, France, Norway, Iceland, and Liechtenstein. No target, sector, transaction structure, or data room was supplied. Every Member State and EEA EFTA State connected through entities, workers, users, data, compute, products, customers, or regulated activity needs a local-law review.
For ongoing AI governance work after diligence, see our AI Governance solution.
Incorporation does not define the diligence perimeter. Product access, intended purpose, operator role, users, workers, data, compute, suppliers, and transaction parties create separate legal connections.
Each model and use case needs a written classification. Rebranding, substantial modification, or a changed intended purpose can transfer provider duties to a distributor, importer, deployer, or other party.
The original August 2, 2026 timetable remains the verified operative text. The 2026 amendment was adopted and signed, but Official Journal publication and entry into force were not verified by July 23, 2026.
Current duties require technical documentation, downstream information, a Union copyright policy, and a public training-content summary. Systemic-risk models need evaluations, adversarial testing, incident records, and cybersecurity evidence.
GDPR permission, copyright permission, database rights, contract rights, confidentiality, and sector secrecy are separate. Public access does not establish a right to train or commercialize.
NIS2, DORA, the Cyber Resilience Act,
product-safety law, sector conformity rules, and the revised Product
Liability Directive can apply beside the AI Act. Each has its own actor,
product, and date tests.
Equality law, worker consultation, employment data rules, consumer claims, accessibility, and synthetic-content disclosures apply independently. A vendor contract cannot remove the target's own duties.
EU acts need act-by-act incorporation into the EEA
Agreement. The GDPR and DORA are incorporated. The AI Act, Data Act,
DSA, NIS2, Cyber Resilience Act, and revised Product Liability Directive
remained under scrutiny.
Missing core title, unlawful irreplaceable data, prohibited use, absent conformity, a non-transferable critical license, or a blocking sanctions or investment issue can stop closing. Curable gaps belong in conditions. Quantified legacy exposure belongs in price and specific protection.
Diligence perimeter, territorial reach, and timing
The review must follow operating facts rather than labels. Counsel should map every entity, model, system, use case, dataset, worker, supplier, customer class, and sales territory. The map:
- should distinguish research
- testing
- release
- hosting
- integration
- resale
- customer modification
Regulation (EU) 2024/1689 reaches providers placing AI systems or
general-purpose AI models on the Union market. It applies regardless of
the provider's location. It also reaches Union deployers and certain
third-country providers or deployers when output is used in the Union.
Regulation (EU) 2024/1689, art. 2(1).
Each other law uses its own connector. Regulation (EU) 2016/679 uses
establishment and targeted-market tests. Product law follows placing,
making available, and putting into service. Employment law follows
workers and establishments. NIS2 follows covered entities and national
transposition. Foreign-investment review follows the target, buyer,
assets, and control rights.
Counsel should create a dated obligations calendar. It should separate duties already active from duties arising before signing, closing, or integration. Key dates include August 2, 2026, September 11, 2026, December 2, 2026, December 9, 2026, January 20, 2027, and December 11, 2027.
A law-change covenant should cover the interim period. The target should report new releases, changed datasets, altered intended purposes, incidents, regulator contact, and material supplier changes. The buyer should repeat classification and status checks at closing.
Corporate structure, authority, and asset location
The buyer must identify which entity owns each asset and owes each duty. A common brand does not prove common ownership. The legal group chart should connect entities to personnel, repositories, datasets, customer contracts, cloud accounts, permits, and revenue.
Corporate law remains national. Counsel should verify formation, constitutional documents, registers, beneficial ownership, capital, options, convertibles, shareholder rights, board authority, and signing power. The review should identify:
- insolvency indicators
- distributions
- intercompany balances
- tax residence
- branch registrations
AI groups often place intellectual property in one entity and employ researchers through another. The customer entity may only hold an informal license. The cloud account may sit with a founder or affiliate. Each mismatch needs a signed transfer, license, consent, or closing exclusion.
Security interests require local analysis. The review should cover pledges over shares, receivables, bank accounts, patents, trademarks, software, databases, and contract rights. Existing financing may restrict transfers, dividends, new debt, licensing, or change of control.
Corporate diligence should also test grants and public funding. Union, national, university, and regional support can impose location, exploitation, reporting, access, repayment, or state-aid conditions. A transaction may trigger consent, repayment, or a change in eligible status.
AI Act actor and use-case classification
Every product and deployment needs a written AI Act memorandum. The memorandum should identify:
- the AI system
- general-purpose AI model
- intended purpose
- actual use
- provider
- deployer
- importer
- distributor
- authorised representative
- product manufacturer
The first screen asks whether the item meets the statutory definition
of an AI system or general-purpose AI model. The second asks whether an
exclusion applies. Research before market placement, personal
non-professional use, military use, and specified open-source releases
receive distinct treatment. Regulation (EU) 2024/1689, arts. 2 and
3.
The next screen covers prohibited practices under Article 5. It
should test manipulation, exploitation of vulnerabilities, social
scoring, certain criminal-risk assessments, untargeted facial-image
scraping, workplace or education emotion inference, sensitive biometric
categorisation, and remote biometric identification. Sector facts and
exceptions control the result.
The high-risk screen has two routes. Article 6(1) covers safety components and products listed in Annex I. Article 6(2) and Annex III cover:
- specified uses involving biometrics
- critical infrastructure
- education
- employment
- essential services
- law enforcement
- migration
- justice
Annex III classification depends on intended purpose and use. A
general chatbot is not high-risk merely because a customer later asks an
employment question. A developer may still face liability when its
instructions, promotion, design, or known deployments support a covered
use.
Operator roles can change after release. A distributor, importer,
deployer, or third party can become the provider of a high-risk system.
This occurs after rebranding, substantial modification, or a changed
intended purpose that creates a high-risk use. Contract allocation does
not override Article 25.
Counsel should compare product documentation with sales conduct.
Intended purpose includes instructions, promotional materials, and sales
statements. Regulation (EU) 2024/1689, art. 3(12). A narrow contract
term cannot cure broader marketing or implementation support.
The classification record should include model versions, technical architecture, use restrictions, customer configurations, substantial modifications, and release dates. It should identify the evidence supporting each result and the person who approved it.
AI Act dates and the 2026 amendment
The original AI Act remains in force. Chapters I and II have applied
since February 2, 2025. Article 4 requires providers and deployers to
take measures for sufficient AI literacy among relevant staff and
operators. The provisions on general-purpose AI models, penalties,
notified bodies, and Union administration have applied since August 2,
2025. The general application date is August 2, 2026. Regulation (EU)
2024/1689, arts. 4 and 113.
Under the original text, Article 6(1) and corresponding
product-linked high-risk duties apply from August 2, 2027. The remaining
high-risk provisions therefore enter general application on August 2,
2026. Article 50 transparency duties also enter general application on
that date.
PE-CONS 30/26 would alter this calendar and other substantive rules.
The Council approved the text on June 29, 2026. The Presidents signed it
on July 8, 2026. As of July 23, EUR-Lex still marked procedure
2025/0359/COD as ongoing. No Official Journal act number was
verified.
The adopted text would move Annex III high-risk duties to December 2,
2027. It would move Annex I product-linked duties to August 2, 2028. It
would give certain pre-August 2 generative systems until December 2,
2026 to meet Article 50(2). PE-CONS 30/26, arts. 1(39)-(40), 4.
The amendment enters force only after Official Journal publication.
Its text states that entry occurs on the third day after publication.
Until that event, the original Article 113 timetable supplies the
verified operative rule.
This timing conflict is a closing issue. A target cannot rely only on a political announcement or Commission webpage. Counsel should check the Official Journal, consolidated AI Act, national authority notices, and any transitional measures on each material date.
A buyer should require readiness for both outcomes. The target should complete the work needed for current August 2026 duties. The buyer can then recalibrate after the amendment enters force. This avoids a gap if publication is delayed or the final consolidation differs.
High-risk system evidence and conformity
A high-risk classification creates a system-level compliance file.
The provider should document risk management, data and data governance,
technical documentation, recordkeeping, instructions, human oversight,
accuracy, resilience, and cybersecurity. Regulation (EU) 2024/1689,
arts. 9-15.
The file should also cover the quality management system, retained
records, corrective action, conformity assessment, registration,
declaration of conformity, CE marking, post-market monitoring, and
serious-incident reporting. Regulation (EU) 2024/1689, arts. 16-21, 43, 47-49, 72-73.
Product-linked systems require coordination with the applicable Annex
I legislation. The target should identify the product manufacturer,
notified body, conformity route, technical file, certificate, and
change-control process. A material model update can affect both AI and
sector conformity.
Deployers have their own duties. They must follow instructions,
assign competent human oversight, monitor operation, and keep logs under
their control. They must also assess the relevance of input data when
they control those data. Regulation (EU) 2024/1689, art. 26.
An employer must inform worker representatives and affected workers
before using a high-risk system at work. Specified public bodies,
public-service providers, creditworthiness users, and life or health
insurance users must conduct a fundamental-rights impact assessment.
Regulation (EU) 2024/1689, arts. 26(7) and 27.
The diligence record should link every requirement to a model version, release, use, owner, approver, and retained exhibit. A policy without the corresponding tests, logs, approvals, and corrective-action record does not prove conformity.
General-purpose AI models and downstream documentation
A provider of a general-purpose AI model must maintain technical
documentation. It must give downstream providers enough information to
understand capabilities and limits. It must establish a policy for Union
copyright compliance. It must publish a sufficiently detailed
training-content summary. Regulation (EU) 2024/1689, art. 53.
Third-country GPAI providers usually need a Union authorised
representative before market placement. Regulation (EU) 2024/1689, art.
54. Counsel should inspect the mandate, authority, resources, document
access, and termination rights.
The diligence file should identify model ownership, release history, compute, training methods, input types, evaluations, intended uses, limits, and integration instructions. It should preserve the exact document supplied with each model version. Generic product pages do not prove compliance.
Providers of GPAI models with systemic risk face added duties. They
must evaluate models, conduct and document adversarial testing, assess
Union-level systemic risks, track serious incidents, and protect model
and infrastructure security. Regulation (EU) 2024/1689, art. 55.
The Code of Practice can support a compliance showing. It remains voluntary and does not replace the Regulation. Counsel should record which commitments the target follows, which evidence supports them, and where the target uses another method.
GPAI duties have applied since August 2, 2025. The Commission may
enforce the GPAI provisions, including fines, from August 2, 2026.
Models placed on the market before August 2, 2025 receive the Article
111(3) transition until August 2, 2027.
Downstream contracts should require current documentation, version notices, evaluation information, incident cooperation, and termination support. They should allocate modification and intended-purpose duties. They should not promise information that the model provider cannot lawfully disclose.
Personal data, automated decisions, and transfers
GDPR diligence must identify the controller, joint controller,
processor, purpose, lawful basis, data categories, recipients,
retention, security, and transfer route for each processing activity.
Regulation (EU) 2016/679, arts. 3, 5, 6, 9, 13-15, 24-30, 32-35,
44-49.
Training and deployment require separate analyses. A lawful basis for collecting customer prompts does not authorize model training. A training basis does not authorize disclosure, profiling, or a new consequential use. Purpose compatibility and transparency need their own records.
Special-category data require an Article 9 condition. Bias testing
does not create a general permission to process sensitive data. The
current AI Act contains a narrow route for certain high-risk providers
under Article 10(5). PE-CONS 30/26 proposes broader provisions, but they
are not yet operative.
A data-protection impact assessment is required when processing is
likely to create high risk. Regulation (EU) 2016/679, art. 35. The
assessment should match the released system, affected people,
deployment, human review, security, and residual risk. A template
completed after launch carries limited evidentiary value.
Article 22 can apply to decisions based solely on automated
processing that produce legal or comparably material effects. In SCHUFA
Holding, C-634/21, EU:C:2023:957, a score could itself constitute the
decision where a third party gives it a determining role.
Article 15 requires meaningful information about the logic involved.
Dun & Bradstreet Austria, C-203/22, EU:C:2025:117, requires
intelligible information that lets the person understand the procedure.
Trade-secret claims do not justify a blanket refusal.
The target should produce decision maps, inputs, feature explanations, validation, notices, human-review procedures, correction routes, and override logs. Counsel should interview actual operators. A written human-review policy does not prove meaningful review.
International transfers need Chapter V support. The review should
cover cloud regions, remote administration, support, subprocessors,
model providers, telemetry, and incident access. Standard contractual
clauses require a transfer assessment and supplementary measures where
needed.
M&A data rooms do not create a GDPR exception. The seller should minimize personal data, use staged disclosure, control access, redact where practical, and document the lawful basis. Abandoned transactions need deletion and return procedures.
Training data, copyright, database rights, and trade secrets
Data diligence must prove source, permission, purpose, and traceability. Public availability proves only access. It does not prove:
- a right to copy
- mine
- retain
- train
- disclose
- redistribute
Directive (EU) 2019/790 separates research text and data mining from
the broader Article 4 exception. Commercial mining requires lawful
access. Rights holders may reserve Article 4 uses, including through
machine-readable means for online content. Directive (EU) 2019/790,
arts. 3-4.
Database rights need a separate screen. Directive 96/9/EC can protect
substantial investment in obtaining, verifying, or presenting database
contents. Repeated extraction of insubstantial parts can also create
exposure. Directive 96/9/EC, art. 7.
Copyright permission does not resolve privacy, contract, confidentiality, or sector secrecy. A dataset license may permit research but bar commercial training. A website term may restrict scraping. Customer material may contain third-party secrets or regulated records.
The target should maintain one register for pretraining, fine-tuning, retrieval, evaluation, red-team, prompt, log, and feedback data. Each entry should record:
- source
- date
- collector
- method
- terms
- rights reservations
- personal data
- location
- retention
- deletion
- downstream use
Model outputs require separate treatment. Contract terms can allocate risk between parties. They cannot create copyright where national law finds insufficient human authorship. Output controls should address:
- memorization
- substantial similarity
- defamation
- privacy
- confidential information
Employee and contractor ownership remains national. Software-specific employee rules exist in several Member States. Patent inventorship, employee inventions, moral rights, and contractor assignments also vary. The target needs signed, locally valid transfers from every material contributor.
Trade-secret protection requires secrecy measures. Directive (EU)
2016/943, art. 2(1). Counsel should inspect repository access, model
release, publication, confidentiality terms, device controls, logging,
and offboarding. A public model release can destroy secrecy for the
released material.
Third-party models, software, datasets, cloud, and the Data Act
The target needs a dependency register that extends beyond software. It should cover:
- open-source code
- open-weight models
- hosted models
- datasets
- benchmarks
- APIs
- cloud
- accelerators
- security tools
- data-processing services
Each record should identify version, supplier, accepted terms, paying entity, use, transfer rights, and replacement plan. Counsel should review training, fine-tuning, distillation, outputs, redistribution, attribution, source duties, audit, suspension, termination, assignment, and change of control.
An open-source label does not resolve the issue. The exact license, integration, modification, distribution, network use, and notice practice control. Model acceptable-use terms can restrict sectors, users, locations, or content even when weights are publicly downloadable.
Cloud contracts should cover capacity, data location, supplier training, subprocessors, security, model changes, deprecation, pricing, suspension, portability, recovery, and exit assistance. A target may own its application while lacking transferable compute or model access.
Regulation (EU) 2023/2854 has applied since September 12, 2025. It
can affect connected products, related services, data holders, users,
and data-processing services. Product design duties under Article 3(1)
apply to relevant products placed after September 12, 2026.
The Data Act also addresses switching between data-processing services and certain contractual terms. Counsel should test exit charges, technical obstacles, export formats, continuity, interoperability, and termination assistance. These duties may affect cloud resale and managed AI services.
Benchmarks need the same discipline. The target should prove license rights, test-set confidentiality, contamination controls, score methodology, model version, prompts, exclusions, and publication approval. Unsupported rankings can create consumer and contract exposure.
Cybersecurity and operational resilience
Security diligence should cover models, data, applications, infrastructure, and suppliers. Ordinary penetration testing may omit prompt injection, retrieval manipulation, model extraction, poisoning, unsafe tool use, and weight leakage.
Counsel should obtain threat models, secure-development records, privileged-access lists, secrets controls, model registries, dataset controls, supplier access, vulnerability reports, red-team results, release approvals, monitoring, backups, and recovery tests.
NIS2 requires a national-law analysis. Directive (EU) 2022/2555 required Member States to apply transposition measures from October 18, 2024. Scope can include:
- cloud computing
- data centres
- managed services
- online marketplaces
- search engines
- social networks
- research
- listed sectors
Covered entities need management accountability, risk measures,
supply-chain controls, incident reporting, continuity, vulnerability
handling, cryptography, and access controls. Directive (EU) 2022/2555,
arts. 20-23. Counsel must read the operative statute in each connected
Member State.
DORA has applied since January 17, 2025 to covered financial
entities. Regulation (EU) 2022/2554. AI vendors can face contractual and
audit duties as ICT third-party providers. Critical providers can enter
direct Union oversight.
The Cyber Resilience Act covers many products with digital elements.
Regulation (EU) 2024/2847. Its conformity-body provisions have applied
since June 11, 2026. Article 14 reporting begins September 11, 2026. The
main product duties begin December 11, 2027.
The target should maintain one incident register. It should cover:
- breaches
- unsafe outputs
- discriminatory outcomes
- vulnerabilities
- prompt leakage
- weight leakage
- poisoning
- model extraction
- outages
- complaints
- regulator contacts
Each entry should state discovery, affected systems, people, jurisdictions, containment, legal analysis, notices, insurance, cause, remediation, and recurrence testing. An undisclosed incident can alter warranties, disclosure schedules, coverage, valuation, and closing.
Product safety, conformity, and liability
An AI product may need several conformity analyses. The AI Act does
not replace medical-device, machinery, vehicle, aviation, radio, toy, or
other product legislation. Regulation (EU) 2024/1689, art. 2(9).
The General Product Safety Regulation has applied since December 13,
2024. Regulation (EU) 2023/988. Its safety assessment considers
cybersecurity and evolving, learning, or predictive functions where
relevant. Counsel should inspect risk assessments, technical files,
warnings, recalls, and market-surveillance contact.
Regulation (EU) 2023/1230 applies from January 20, 2027. Its Annex I
includes certain safety components and machinery using self-evolving
machine-learning behaviour. An AI-enabled machine may need both
machinery and AI Act treatment.
Directive (EU) 2024/2853 must be transposed by December 9, 2026. It
applies to products placed on the market or put into service after that
date. It treats software as a product and addresses updates,
cybersecurity, and learning behaviour.
The revised liability directive excludes free and open-source software developed or supplied outside commercial activity. The exclusion does not protect a commercial actor merely because a component began as open source. Commercial integration, paid supply, and manufacturer-controlled updates require separate analysis.
Product diligence should trace the economic operator, importer, authorised representative, technical documentation, conformity route, CE marking, declarations, post-market monitoring, corrective action, and insurance. Missing conformity can block continued sale.
Contract caps do not bind injured third parties or regulators. Counsel should quantify recall, remediation, replacement, customer termination, defense, and insurance effects. The buyer should test:
- whether policy wording covers software
- media
- product
- cyber
- professional claims
Online services, consumer claims, synthetic content, and accessibility
The Digital Services Act applies when the target supplies an
intermediary service. Regulation (EU) 2022/2065. Counsel should classify
mere conduit, caching, hosting, online platform, marketplace, and search
functions. An AI interface is not automatically an intermediary.
Covered services may need notice-and-action processes, clear terms, transparency reports, recommender disclosures, trader traceability, complaint handling, and systemic-risk measures. The exact duties depend on service type, size, and designation.
Consumer claims remain subject to Directive 2005/29/EC and national
law. Claims about accuracy, bias, privacy, security, training rights,
human review, output ownership, and benchmark rank need versioned
evidence. Qualified fine print does not cure a contradictory headline or
demo.
Directive (EU) 2019/770 can apply to consumer digital content and
services. Conformity, updates, remedies, and data-as-counter-performance
rules may affect AI subscriptions. Consumer terms also face unfair-terms
review under Directive 93/13/EEC.
Article 50 of the AI Act creates disclosures for specified
interactions, synthetic content, emotion recognition, biometric
categorisation, deepfakes, and certain public-interest text. Regulation
(EU) 2024/1689, art. 50. The current date of application is August 2,
2026.
The target should test machine-readable marking across export, editing, compression, and platform handling. Detection tools need measured accuracy and stated limits. Deepfake and public-interest disclosures must be clear to the recipient.
The European Accessibility Act applies to listed products and
services from June 28, 2025. Directive (EU) 2019/882. AI projects
involving consumer communications, e-commerce, banking, transport,
e-books, or electronic communications need an accessibility screen.
Children and vulnerable users require added review. Counsel should examine audience, age signals, profiling, advertising, parental permissions, crisis responses, retention, and human escalation. Sector and national duties can exceed the AI Act.
Employment, worker consultation, and discrimination
Employment AI can trigger the AI Act, GDPR, equality directives,
labour law, and collective rights. Annex III covers specified
recruitment, selection, employment decisions, task allocation,
monitoring, and evaluation uses.
Directive 2000/78/EC prohibits specified discrimination in
employment. Directive 2006/54/EC addresses sex equality. Directive
2000/43/EC addresses racial or ethnic origin. A neutral model can create
indirect discrimination unless objectively justified under the
applicable test.
Counsel should obtain feature lists, data sources, validation, subgroup testing, accessibility testing, notices, adverse-decision records, override logs, and appeal outcomes. The review should compare vendor documentation with actual manager conduct.
National worker participation can arise before the AI Act high-risk
duties. France requires prior information on recruitment methods and
automated personnel management. Worker monitoring needs information and
consultation. Code du travail, art. L2312-38.
Germany applies works council rules to selection guidelines prepared
with AI. Betriebsverfassungsgesetz, § 95(2a). Other co-determination,
personnel questionnaire, monitoring, and information provisions may
apply according to system design.
The Platform Work Directive must be transposed by December 2, 2026.
Directive (EU) 2024/2831. Covered digital labour platforms face rules on
automated monitoring, automated decisions, worker information, human
review, and personal data.
Employment data also need national review. Germany's
Bundesdatenschutzgesetz § 26 and national statutes elsewhere can
supplement GDPR. Local rules may restrict employee consent, monitoring,
biometrics, retention, and transfer.
A vendor cannot assign every discrimination duty to the employer. The developer's design, claims, documentation, limits, and known misuse remain relevant. The deployer also needs enough information to make lawful decisions and conduct meaningful review.
Regulated sectors and public procurement
Sector classification can determine the transaction result. Medical, financial, insurance, transport, energy, telecom, defense, education, and public-sector uses need dedicated review.
Medical software may fall under Regulation (EU) 2017/745 or
Regulation (EU) 2017/746. Intended purpose, claims, clinical evidence,
software function, and risk class control. An AI Act classification does
not replace medical-device conformity.
Financial services may trigger DORA, prudential rules,
consumer-credit law, payment law, insurance duties, market rules,
outsourcing requirements, and supervisory expectations. Creditworthiness
and risk assessment can also enter Annex III.
Public authorities face procurement, transparency, records, equality, and administrative-law duties. Public buyers may impose contract terms that flow down AI Act documentation, security, audit, data location, accessibility, and exit duties.
The target should identify every regulated customer and use. It should produce licenses, registrations, conformity records, audit reports, regulator correspondence, procurement submissions, and contractual compliance schedules.
A prohibited or unlicensed use is not cured by indemnity. The target may need:
- to suspend the feature
- narrow claims
- change intended purpose
- obtain approval
- exclude the business from the transaction
Competition, merger review, foreign subsidies, investment, exports, and sanctions
Competition diligence should cover exclusivity, most-favoured terms, tying, interoperability limits, data access, and pricing tools. It should also cover information exchange, talent restrictions, customer concentration, and acquisitions.
The EU Merger Regulation applies when its turnover thresholds are
met. Regulation (EC) No 139/2004. National merger rules can apply below
those thresholds. Some states use transaction-value thresholds or
call-in powers.
Illumina v Commission, Joined Cases C-611/22 P and C-625/22 P,
EU:C:2024:677, limits Article 22 referrals from states lacking national
jurisdiction. It does not remove national thresholds, call-ins, abuse
rules, or later legislative change.
The Foreign Subsidies Regulation can add a separate pre-closing
filing. Regulation (EU) 2022/2560. Concentration notification can arise
where the Union turnover and third-country financial contribution
thresholds are met. The Commission can also call in a transaction below
thresholds.
Each Member State may screen foreign investment. Regulation (EU)
2019/452 coordinates those reviews and identifies artificial
intelligence among critical technologies. The buyer's nationality,
funding, government links, rights, data, and target activities
matter.
Ireland's Screening of Third Country Transactions Act 2023 requires
notification for covered transactions at least ten days before
completion. Germany, France, the Netherlands, and Luxembourg operate
separate screening systems. Thresholds and sensitive sectors differ.
Export diligence should classify software, source code, model
weights, technical data, encryption, chips, remote access, recipients,
end uses, and destinations. Regulation (EU) 2021/821 covers listed and
certain unlisted dual-use items, software, and technology.
Sanctions screening must cover parties, beneficial owners, controllers, banks, customers, suppliers, destinations, services, and payments. Union measures are program-specific and change frequently. National criminal and licensing rules also matter.
The buyer should refresh merger, foreign-subsidy, FDI, export, and sanctions work at signing and closing. A failed screen can delay, condition, prohibit, or unwind the transaction.
Priority Member State overlays
Ireland often appears as a contracting, employment, data, or holding location. Diligence should cover:
- company authority
- share title
- employee and contractor rights
- data-protection records
- consumer law
- sector regulation
- tax residence
- FDI screening
The Netherlands often appears through holding entities, cloud operations, customers, or workers. Counsel should test:
- corporate authority
- works council rights
- employee data
- IP title
- financial regulation
- and the
Security Screening of Investments Mergers and Acquisitions Act
Luxembourg frequently appears in holding, financing, fund, and
licensing structures. The review should cover corporate approvals,
beneficial ownership, finance regulation, substance, employment, IP,
data protection, and the Law of July 14, 2023 on foreign-investment
screening.
Germany needs early worker and product review. Works council rights can affect deployment timing. Employee data, software ownership, product conformity, competition, export controls, and foreign-investment rules can also change closing steps.
France needs a similar early labour review. The social and economic committee receives prior information or consultation for specified recruitment, personnel, monitoring, and technology measures. French employee-software and invention rules also need chain-of-title review.
Other Member States must be added when facts connect them. Local differences affect corporate acts, employment, IP ownership, consumer enforcement, NIS2 transposition, product authorities, sanctions, litigation, and remedies.
The diligence report should not present one Member State as a complete Union answer. Union regulations can apply directly, but directives, remedies, procedures, and many transaction rules remain national.
EEA-specific treatment
Norway, Iceland, and Liechtenstein require an act-by-act EEA check. An EU act marked EEA relevant does not automatically become domestic law. Incorporation requires an EEA Joint Committee Decision, entry into force, adaptations, and national measures where needed.
The GDPR was incorporated by EEA Joint Committee Decision No 154/2018
and entered into force in the EEA on July 20, 2018. DORA was
incorporated by Decision No 40/2025 and entered into force in the EEA on
July 1, 2025.
As of July 23, 2026, EEA-Lex recorded several major acts as under
scrutiny. They included the AI Act, Data Act, DSA, NIS2, Cyber
Resilience Act, and revised Product Liability Directive.
That status does not remove Union exposure. An EEA-based provider can
still fall within AI Act Article 2 when it places a system or model on
the Union market. A Norwegian target serving German users therefore
needs both Union-market and Norwegian domestic analysis.
Domestic law may already regulate the same conduct. Norway, Iceland, and Liechtenstein have national privacy, employment, consumer, product, security, and sector rules. Some existing EEA acts also apply while newer Union acts await incorporation.
Counsel should maintain two columns for each EEA EFTA State. One should record direct Union-market exposure. The other should record:
- EEA incorporation
- national implementation
- adaptations
- regulator
- commencement
The transaction agreement should address later incorporation. A signing-to-closing covenant should require prompt notice of a Joint Committee Decision, national bill, commencement order, or regulator instruction that affects the target.
Contracts, revenue quality, and operational continuity
Contract diligence must prove assent, scope, performance, and transferability. A standard form does not prove which terms the customer accepted. Counsel should obtain executed orders, clickwrap records, amendments, and incorporated policies.
AI clauses should address:
- permitted use
- prohibited use
- model changes
- customer data
- prompts
- logs
- training
- outputs
- confidentiality
- security
- incidents
- documentation
- human review
- audits
- indemnities
- caps
- assignment
- termination
- transition
The contract should match product reality. A promise not to train on customer data is dangerous when support logs feed evaluation. A claim that customers control every decision is weak when the product markets autonomous action.
Revenue quality requires contract-to-ledger testing. Counsel should separate production revenue from pilots, free use, credits, related-party sales, minimum commitments, contingent milestones, and cancellable arrangements.
Operational continuity depends on compute, key models, data, suppliers, and staff. The review should test:
- reserved capacity
- minimum spend
- hardware limits
- deprecation
- price changes
- suspension
- portability
- recovery
- key-person knowledge
Assignment and change-of-control clauses require product-specific review. A model API, dataset, cloud commitment, distribution right, or public grant may terminate at closing. Informal supplier comfort is not a substitute for written consent.
Findings and transaction protections
Each finding needs a rule, evidence status, business effect, and deal response. A colour alone does not answer whether the target can continue, transfer, or remediate the activity.
Stop-level findings include missing title to a core model, unlawful irreplaceable data, or a prohibited AI practice. They also include:
- missing mandatory conformity
- an absent critical license
- unlicensed regulated activity
- a blocking sanctions or investment issue
Closing conditions fit curable defects. Typical items include:
- assignments
- consents
- lien releases
- regulatory filings
- AI classifications
- data-protection assessments
- worker consultation
- product suspension
- incident remediation
- supplier amendments
- technical documentation
Price adjustments, escrow, holdbacks, specific indemnities, exclusions, and post-closing covenants fit quantified legacy exposure. General warranties offer weak protection for a disclosed defect. Indemnity does not make continued unlawful conduct acceptable.
Representations should cover:
- authority
- capitalization
- title
- data rights
- AI Act status
- privacy
- product conformity
- claims
- security
- incidents
- employment
- licenses
- contracts
- sanctions
- exports
- investment screening
- disputes
Disclosures should identify model, dataset, and contract versions. Product names alone are inadequate. The seller should state which facts are verified, asserted by management, disputed, or unresolved.
Open items need an owner, due date, evidence standard, closing effect, and escalation route. The final bring-down should repeat status checks:
- for the AI Act amendment
- August 2026 duties
- CRA reporting
- product-liability transposition
- EEA incorporation
- sanctions
- filings
UK & Switzerland
United Kingdom and Swiss legal due diligence tests whether an AI target can lawfully own, train, deploy, sell, and transfer its systems across both markets and connected third countries. The question is whether the target's entities, models, data, products, workers, suppliers, and regulated uses satisfy the current United Kingdom and Swiss rules as of July 23, 2026. The review must also determine whether defects can be cured before closing or require price, indemnity, exclusion, or termination protection. No target, sector, transaction structure, or data room was supplied. This memorandum therefore states a transaction baseline. It also identifies enacted, pending, and future measures that may affect signing, closing, or integration.
Neither jurisdiction has an operative general private-sector AI statute. Existing data, consumer, intellectual-property, employment, product, cyber, competition, and sector laws control the present review. Pending AI measures have no current legal force.
A United Kingdom or Swiss target may still fall within the EU AI Act or EU GDPR. Union market access, EU establishments, targeted users, monitored individuals, and output used in the Union can create separate duties.
The Data (Use and Access) Act 2025 replaced UK
GDPR Article 22 with Articles 22A to 22D. Significant solely automated
decisions using non-special-category data have broader legal routes, but
controllers must provide information, contest rights, and human
intervention.
The Federal Act on Data Protection applies directly
to AI. Article 21 requires notice and, subject to exceptions, a chance
to state a position and obtain human review of an automated individual
decision.
The United Kingdom has no general commercial text-and-data-mining exception. Swiss law contains a narrow scientific-research provision, while the copyright treatment of AI training remains unsettled. Data provenance and licenses need asset-level proof.
The United Kingdom Online Safety Act
can reach user-to-user, search, and pornography services. United Kingdom
and Swiss consumer, unfair-trading, personality, defamation, and
contract rules apply to AI claims and synthetic content.
United Kingdom NIS, connected-product, sector, and product rules can apply beside data law. Switzerland requires specified critical-infrastructure operators to report qualifying cyberattacks within 24 hours and complete the report within 14 days.
Employment, financial services, healthcare, medical devices, transport, public administration, biometrics, children, and critical infrastructure require separate classification. General-purpose product terms do not displace sector duties.
Missing core title, unlawful irreplaceable data, a prohibited deployment, absent mandatory clearance, a non-transferable critical dependency, or a blocking sanctions issue can stop closing. Curable gaps belong in conditions. Quantified legacy exposure belongs in price and specific protection.
Diligence perimeter and cross-border reach
The review must follow operating facts. Incorporation answers only part of the question. Counsel should map:
- each entity
- product
- model
- system
- use case
- worker
- dataset
- supplier
- customer class
- sales territory
The United Kingdom comprises England and Wales, Scotland, and Northern Ireland. Corporate, contract, tort, employment, health, consumer, criminal, and procedural rules can differ. Northern Ireland can also retain distinct links to Union product rules. A United Kingdom-wide product label does not resolve those differences.
Switzerland combines federal law, cantonal law, and municipal action. Federal private law governs many commercial issues. Cantonal law can control public bodies, education, healthcare, policing, procurement, and administrative decisions. The target's office, user, worker, and public-customer locations therefore matter.
A target in either jurisdiction can face Union law. Regulation (EU)
2024/1689, Article 2, reaches specified third-country providers and
deployers. Regulation (EU) 2016/679, Article 3, reaches some
establishments, targeted offerings, and monitoring outside the Union.
The prior EU and EEA session should be read with this module.
Counsel should build six linked records. They should cover the legal group, products, models, use cases, data flows, and third parties. Each record needs a version date, responsible owner, connected jurisdictions, and supporting evidence.
Timing needs a separate calendar. The calendar should distinguish current duties, enacted delayed duties, bills, consultations, and regulator guidance. Signing, closing, migration, and product-release dates may produce different answers.
Current AI-specific statutory position
Neither jurisdiction has an operative general AI act for ordinary private-sector activity. That absence does not create a legal vacuum. Technology-neutral and sector statutes already regulate the target's conduct.
The Artificial Intelligence (Regulation) Bill [HL] received its first
reading in the House of Lords on March 4, 2025. It had not progressed
beyond that stage by the as-of date. It is not law and should not appear
as a current compliance requirement.
The United Kingdom signed the Council of Europe Convention on
Artificial Intelligence and Human Rights, Democracy and the Rule of Law
on September 5, 2024. Signature does not itself insert the Convention's
duties into domestic private law. Ratification and implementing measures
require separate confirmation.
Switzerland signed the same Convention on March 27, 2025. The Federal Council directed the administration to prepare a consultation draft by the end of 2026. The planned bill will address transparency, data protection, non-discrimination, and supervision. It is not operative law.
The Swiss administration also plans nonbinding measures by the end of 2026. Those measures may include industry commitments and standards. A diligence report should classify them as voluntary unless a contract, license, procurement term, or regulator makes them binding for the target.
The transaction should still request an internal AI responsibility map. It should identify who approves data, training, releases, claims, high-impact uses, incidents, and customer exceptions. An absent general statute does not excuse an unowned legal risk.
Corporate authority, capitalization, and asset location
The buyer must identify the entity that owns each material asset and owes each material obligation. A common website, brand, or management team does not prove common ownership.
United Kingdom diligence should review incorporation records,
articles, shareholder agreements, board and shareholder approvals,
registers, people with significant control, capitalization, options,
convertibles, charges, and insolvency indicators. Companies Act 2006
requirements must be matched to the actual entity type.
Swiss diligence should review articles, commercial-register entries,
share registers, beneficial owners, capital, shareholder arrangements,
board authority, signatory powers, security interests, and insolvency
indicators. The Swiss Code of Obligations and entity form control the
approval route.
AI groups often split research, employment, customer contracts, and intellectual property. The employing entity may lack an invention transfer. The customer entity may hold only an oral or revocable license. The cloud account may remain with a founder or affiliate.
Counsel should trace every core asset to a legal owner. The trace should include repositories, model weights, training pipelines, datasets, evaluation records, patents, brands, domains, customer contracts, and compute accounts. Intercompany services and licenses need written terms.
Public grants, university arrangements, and research collaborations can impose exploitation, location, publication, access, repayment, or change-of-control conditions. The target should produce award terms, consortium agreements, reports, and consent records.
Existing security can impair transfer. Counsel should search registered charges and obtain finance documents, payoff statements, releases, and required consents. Swiss security review must address the asset and perfection method under applicable law.
United Kingdom data protection and automated decisions
United Kingdom AI processing remains subject to the UK GDPR, Data Protection Act 2018, and related sector rules. Counsel should identify:
- the controller
- processor
- purpose
- lawful basis
- data categories
- recipients
- retention
- security
- transfer route for each activity
The Data (Use and Access) Act 2025 changed the rules for solely
automated significant decisions. Section 80 replaced UK GDPR Article 22
with Articles 22A to 22D. The data-protection provisions of that Act
were fully in force by June 19, 2026.
Article 22A treats a decision as solely automated when it lacks
meaningful human involvement. It treats a decision as significant when
it creates legal or similarly significant effects. Profiling can affect
whether claimed human participation is meaningful.
Article 22B retains stricter conditions for decisions based wholly or
partly on special-category data. Explicit consent can support a
decision. Contract necessity or legal authority can also support one
when the required substantial-public-interest condition applies.
Article 22C requires safeguards for significant solely automated
decisions. The controller must provide information about the decision.
The person must be able to contest or make representations. The person
must also be able to require human intervention.
The wider route for non-special-category data does not remove other
duties. The controller still needs lawfulness, fairness, transparency,
purpose control, minimisation, accuracy, retention, security, and
accountability. UK GDPR arts. 5, 6, 13-15, 24-25, 32 and 35.
A data-protection impact assessment is required where processing is likely to create high risk. The assessment should match the released model, actual use, affected people, data, human review, and residual risk. A generic assessment completed after launch offers weak evidence.
The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026, SI
2026/425, took effect on May 12, 2026. They require the Information
Commissioner to prepare a code. The code was not yet issued on the as-of
date.
The future code will be nonbinding, but the Commissioner must take it into account when assessing compliance. Counsel should track the draft and final code during the transaction. Existing statutory duties apply without waiting for it.
International transfers require a lawful UK route. The review should cover cloud regions, remote support, subprocessors, telemetry, model providers, and incident access. The renewed EU adequacy decision permits covered EU-to-UK transfers until December 27, 2031, subject to its terms and later review.
M&A data rooms do not create a general exemption. The seller should minimise personal data, stage access, use redaction where practical, control downloads, and document the lawful basis. Failed transactions need return or deletion procedures.
Swiss data protection and automated decisions
The Federal Act on Data Protection, SR 235.1, has applied since
September 1, 2023. The Federal Data Protection and Information
Commissioner states that it applies directly to AI-supported
processing.
The review should identify the controller, processor, purpose, data categories, recipients, retention, security, and foreign disclosure route. The FADP follows an effects principle for circumstances producing effects in Switzerland.
Article 21 applies to an automated individual decision. The
controller must inform the affected person. Subject to statutory
exceptions, the person may state a position and request review by a
natural person.
The exceptions include a decision directly connected with a contract where the person's request is granted. Explicit consent can also disapply the notice and review route. Counsel should not assume that general terms provide explicit consent.
Article 25 access rights include information about the logic
underlying an automated decision. The target should preserve input
descriptions, decision logic, material factors, validation, notices,
override records, and review outcomes.
Articles 22 and 23 require a data-protection impact assessment for
likely high-risk processing and consultation where residual high risk
remains. The assessment should cover the concrete deployment, not an
abstract model.
Article 24 requires notice to the Commissioner where a data-security
breach is likely to create high risk. The controller must notify
affected people when protection requires it or the Commissioner orders
it. Other sector notifications can run in parallel.
Foreign controllers can need a Swiss representative under Article 14.
The test addresses offering or monitoring involving people in
Switzerland, extensive processing, and high risk. Counsel should inspect
the representative appointment, mandate, contact details, and
records.
Cross-border disclosures require Articles 16 and 17 analysis. The
review should test destination adequacy, contractual protection,
exceptions, onward transfer, remote access, and processor terms.
EU-to-Switzerland transfers continue to benefit from the Union's
adequacy determination.
Specified intentional breaches can create criminal exposure for
responsible individuals. FADP arts. 60-64. Transaction documents should
not treat all privacy exposure as a corporate administrative fine.
Training data, copyright, patents, and trade secrets
Data diligence must prove source, permission, purpose, and traceability. Public availability proves:
- access
- not a right to copy
- train
- retain
- publish
- commercialise
The United Kingdom Copyright, Designs and Patents Act 1988 reserves
copying and other acts to the rights owner. CDPA 1988, s. 16. Section
29A permits computational analysis only for non-commercial research by a
person with lawful access.
The United Kingdom therefore lacks a general commercial text-and-data-mining exception. The government's March 2026 report did not change the statute. It stated that reforms would not proceed until the government was satisfied that they met its objectives.
Counsel should review each training source for copyright, database
rights, contract terms, confidentiality, privacy, and sector secrecy.
The Copyright and Rights in Databases Regulations 1997 can protect
qualifying database investment independently of copyright in individual
items.
United Kingdom copyright generally starts with the author. Employee
ownership and computer-generated works receive statutory treatment. CDPA
1988, ss. 9 and 11. Assignments require signed writing. Id. s.
90(3).
Patent diligence should identify human inventors, conception records,
disclosure, and assignments. In Thaler v Comptroller-General of Patents,
Designs and Trade Marks [2023] UKSC 49, the Supreme Court held that an
AI machine was not an inventor under the Patents Act 1977.
Swiss copyright protects works with individual character. Federal Act
on Copyright and Related Rights, SR 231.1, arts. 2 and 6. The official
Swiss position states that only human-created works receive copyright
protection.
Human creative use of an AI tool can produce protected output. Ordinary prompting that leaves the creative act to the system generally does not. An unprotected output can still infringe a protected work or personality rights.
Swiss law contains a scientific-research text-and-data-mining
provision. CopA art. 24d. The Swiss Federal Institute of Intellectual
Property states that the provision was not introduced for AI training.
Courts must decide its application to those facts.
The Swiss treatment of protected works in AI training remains unsettled. The Institute is preparing a preliminary copyright bill for consultation by the end of 2026. The proposed measure has no present legal force.
Swiss copyright transfers can occur without the United Kingdom's universal signed-writing rule. The scope still needs clear proof. Moral rights and contract interpretation can limit the result. Written assignments remain the safer transaction record.
Employee and contractor title needs local analysis. Swiss Code of
Obligations art. 332 addresses employee inventions and designs. Article
17 CopA addresses employee computer programs. Contractor work requires
express allocation.
Trade-secret value depends on secrecy measures. The United Kingdom
applies the Trade Secrets (Enforcement, etc.) Regulations 2018 and
common-law confidence. Swiss protection arises through contract, the
Unfair Competition Act, the Criminal Code, and related principles.
Counsel should inspect repository permissions, model releases, publication history, device controls, confidentiality terms, logging, and offboarding. A public weight release may destroy secrecy in the released material.
Third-party code, models, data, and compute
The target needs a dependency register beyond a software bill of materials. It should cover:
- code
- open-weight models
- hosted models
- datasets
- benchmarks
- APIs
- cloud services
- accelerators
- security tools
Each entry should identify the exact version, supplier, accepted terms, paying entity, use, transfer rights, and replacement plan. Counsel should preserve the terms in force when the target accepted them.
The review should test:
- commercial scope
- field limits
- geography
- users
- training
- fine-tuning
- distillation
- outputs
- redistribution
- attribution
- source duties
- audit
- suspension
- termination
- assignment
- change of control
An open-source or open-weight label does not answer those questions. The exact license and integration method control. Acceptable-use terms can bar sectors, persons, locations, or content even when weights are downloadable.
Cloud agreements require capacity, location, supplier data use, subprocessors, security, model changes, deprecation, price resets, suspension, portability, recovery, and exit support. A target may own its application but lack transferable compute or model access.
Benchmarks need the same review. Counsel should verify rights, test-set confidentiality, contamination controls, score methods, model version, prompts, exclusions, and publication approval. Unsupported ranking claims create consumer and contract risk.
A critical dependency without consent or substitute can become a closing condition. An informal supplier assurance is not a replacement for a binding consent or amended agreement.
Online services, product claims, and synthetic content
The United Kingdom Online Safety Act 2023 applies according to
service function. It can cover regulated user-to-user services, search
services, and specified pornography services. A standalone chatbot is
not automatically in scope.
A chatbot can fall within the Act when its functions permit user-generated content sharing or regulated search activity. Counsel should map:
- posting
- sharing
- group
- retrieval
- moderation
- recommender
- age-access features
Illegal-content duties for regulated user-to-user and search services took effect on March 17, 2025. Child-safety duties took effect on July 25, 2025. The target should produce risk assessments, age analysis, moderation records, complaints, reporting tools, and safety tests.
The Digital Markets, Competition and Consumers Act 2024 strengthened
United Kingdom consumer enforcement and replaced the prior
unfair-commercial-practices regime. Claims about accuracy, bias,
privacy, training rights, security, human review, and output ownership
need dated support.
The supporting record should identify the model version, test set, prompts, sample, exclusions, threshold, result, date, and approver. A disclaimer does not cure a contradictory headline, demo, procurement response, or sales script.
Swiss AI claims face the Federal Act against Unfair Competition, the
Code of Obligations, sector statutes, and cantonal enforcement.
Switzerland does not rely on one general consumer code equivalent to the
United Kingdom position.
Synthetic content can engage copyright, passing off, trade marks, privacy, personality rights, defamation, fraud, election, and criminal rules. Counsel should test:
- consent
- identity use
- voice or likeness replication
- labelling
- removal channels
- customer controls
The target should preserve output testing for memorisation, substantial similarity, false attribution, personal data, harmful content, and protected secrets. Terms can allocate risk between parties. They cannot legalise an infringing or deceptive use.
Cybersecurity, incidents, and critical systems
AI security diligence should cover models, data, applications, infrastructure, and suppliers. Ordinary penetration testing may omit prompt injection, retrieval manipulation, data poisoning, model extraction, unsafe tool use, and weight leakage.
Counsel should obtain threat models, secure-development records, access lists, secrets controls, model registries, supplier access, vulnerability reports, red-team results, release approvals, monitoring, backups, and recovery tests.
The Network and Information Systems Regulations 2018 apply to
specified United Kingdom essential services and relevant digital service
providers. Covered cloud, search, marketplace, health, energy,
transport, and infrastructure activities need a service-specific
screen.
The Cyber Security and Resilience (Network and Information Systems)
Bill had passed the Commons and received its Lords second reading by
July 14, 2026. It remained a bill. Its proposed expansion to managed
services and data centres is a readiness issue, not current law.
The Product Security and Telecommunications Infrastructure Act 2022
and implementing regulations have applied to covered consumer
connectable products since April 29, 2024. The regime addresses
passwords, vulnerability reporting, security-update information, and
statements of compliance.
The United Kingdom AI Cyber Security Code of Practice is guidance. It
can support diligence evidence and contracts. It does not replace
legislation, sector rules, or an appropriate threat assessment.
Switzerland requires specified critical-infrastructure operators to report qualifying cyberattacks to the National Cyber Security Centre. The initial report is due within 24 hours of discovery. Missing information can be completed within 14 days.
The Swiss reporting duty has applied since April 1, 2025. Sanctions
for failure to report have applied since October 1, 2025. The
Information Security Act and Cybersecurity Ordinance control scope,
exceptions, and report content.
The target should maintain one incident register. It should include:
- data breaches
- unsafe outputs
- discriminatory outcomes
- vulnerabilities
- prompt or weight leakage
- poisoning
- extraction
- outages
- complaints
- regulator contact
Each entry should record discovery, systems, people, jurisdictions, containment, legal analysis, notices, insurance, cause, remediation, and recurrence testing. An undisclosed incident can change warranties, disclosures, coverage, valuation, and closing.
Employment, discrimination, and workplace systems
Employment AI can trigger privacy, equality, contract, consultation, and dismissal rules. The review should cover:
- recruitment
- screening
- ranking
- monitoring
- scheduling
- productivity scoring
- promotion
- pay
- discipline
- termination
The United Kingdom Equality Act 2010 prohibits direct and indirect
discrimination in covered work and services. It also requires reasonable
adjustments in defined circumstances. Equality Act 2010, ss. 13, 19, 20, 29 and 39.
A neutral model can produce indirect discrimination. Counsel should obtain feature lists, data sources, subgroup testing, accessibility testing, adverse outcomes, overrides, appeals, and validation limits. Vendor documentation must be compared with actual manager practice.
United Kingdom employee monitoring also requires UK GDPR, DPA 2018, employment-contract, confidence, and workplace analysis. Collective consultation, trade-union terms, and public-sector duties depend on the workforce and deployment.
Swiss Code of Obligations arts. 328 and 328b protect employee
personality and limit employee-data processing. Article 328b focuses on
suitability for employment or performance of the employment
contract.
Swiss Labour Ordinance 3, Article 26, restricts systems used to
monitor worker behaviour. Systems needed for other reasons must be
designed and arranged with worker health and movement in view. Cantonal
practice and collective agreements can add duties.
The Swiss Gender Equality Act prohibits sex discrimination in
employment. Disability and other discrimination require issue-specific
statutory and constitutional analysis. Switzerland lacks a single
private-employment equality statute matching the United Kingdom
model.
A vendor cannot place every duty on the employer. The developer's design, claims, known limits, and documentation remain relevant. The employer still needs enough information to use the system lawfully.
Financial services, healthcare, transport, and public uses
Regulated uses can determine transaction viability. The target should identify:
- every customer and deployment in finance
- insurance
- healthcare
- medical devices
- transport
- public administration
- policing
- education
- defense
- critical infrastructure
United Kingdom financial firms remain subject to Financial Conduct
Authority and Prudential Regulation Authority rules. PRA Supervisory
Statement SS1/23 covers model risk management and reaches vendor,
machine-learning, and AI models according to the firm's use.
A sandbox, test service, or regulator discussion does not constitute general approval. Counsel should obtain permissions, model inventories, validation, outsourcing records, consumer-duty work, complaints, and regulator correspondence.
Swiss financial institutions remain subject to technology-neutral FINMA supervision. FINMA Guidance 08/2024 identifies model, data, IT, cyber, third-party, legal, and reputation risks. The exact enforceable duty comes from the governing statute, ordinance, license, order, or supervisory requirement.
Medical software can be a device when its intended purpose meets the
statutory test. Great Britain applies the Medical Devices Regulations
2002 and current amendments. Northern Ireland needs a distinct
Union-linked product analysis.
Swiss medical software requires review under the Medical Devices
Ordinance or In Vitro Diagnostic Medical Devices Ordinance. Intended
purpose, claims, function, risk class, clinical evidence, conformity,
and surveillance control.
The Automated Vehicles Act 2024 creates a United Kingdom
authorization and liability regime for self-driving road vehicles. Full
commencement and secondary measures require date-specific review.
Ordinary driver-assistance claims remain separate.
Public-sector AI can engage procurement, administrative fairness, human rights, records, equality, reasons, and judicial review. Swiss public-law duties may be federal or cantonal. The target should obtain tender submissions, impact records, decision notices, audit rights, and contract schedules.
Product safety and liability
An AI feature can create product duties even without an AI act. Counsel should classify the product, economic operator, importer, distributor, connected hardware, intended use, warnings, updates, and post-market process.
The United Kingdom Consumer Protection Act 1987 can impose strict
liability for a defective product. The General Product Safety
Regulations 2005 cover specified consumer products. Contract,
negligence, professional duty, and sector rules can apply in
parallel.
The treatment of standalone software under strict product liability remains fact sensitive. Counsel should avoid assuming either universal inclusion or exclusion. Hardware integration, updates, safety function, and applicable product legislation matter.
The United Kingdom connected-product security regime requires a separate technical file for covered products. The file should link each security requirement to design, testing, update periods, vulnerability reporting, and the statement of compliance.
Swiss Product Safety Act, SR 930.11, applies to commercial or
professional placing of products on the market. Sector product law takes
priority where it addresses the same risk. The target should identify
the responsible producer, importer, and distributor.
The Swiss Product Liability Act, SR 221.112.944, provides strict
producer liability for specified personal injury and private-property
damage. The status of standalone software is not settled for every fact
pattern.
Switzerland opened consultation on a product-safety revision in June 2026. The proposal is not current law. A transaction extending into the proposed period should track the text, enactment, and commencement.
Insurance review should cover technology errors and omissions, cyber, media, intellectual property, product liability, professional indemnity, directors and officers, and crime. Counsel should test:
- insured entities
- products
- exclusions
- retentions
- notice
- change of control
Contracts, revenue quality, and continuity
Contract diligence must prove assent, scope, performance, and transferability. A template does not prove which terms the customer accepted.
Counsel should review executed orders, clickwrap records, amendments, procurement terms, API terms, reseller agreements, research contracts, cloud contracts, and incorporated policies. The record should identify the operative version and order of precedence.
AI clauses should address:
- permitted use
- prohibited use
- customer data
- prompts
- logs
- training
- outputs
- confidentiality
- security
- incidents
- model changes
- documentation
- human review
- audits
- indemnities
- caps
- assignment
- termination
- transition
The contract must match actual conduct. A no-training promise is dangerous when support logs feed evaluation. A customer-control clause is weak when the target markets autonomous operation.
Revenue quality requires contract-to-ledger testing. Counsel should separate production revenue from pilots, free use, credits, related-party sales, minimum commitments, contingent milestones, and cancellable arrangements.
Continuity depends on compute, models, data, suppliers, and key people. The review should test:
- capacity
- minimum spend
- hardware constraints
- deprecation
- price changes
- suspension
- portability
- recovery
- concentrated know-how
Assignment and change-of-control clauses require dependency-level review. A model API, dataset, cloud commitment, distribution right, grant, or public contract may terminate at closing.
Competition, merger review, investment screening, exports, and sanctions
Competition diligence should cover:
- exclusivity
- most-favoured terms
- tying
- interoperability
- data access
- pricing tools
- information exchange
- talent restrictions
- customer concentration
- prior acquisitions
The United Kingdom Competition and Markets Authority can review a transaction meeting the turnover, share-of-supply, or hybrid test. The current statutory thresholds include a £100 million target-turnover test and the separate share and hybrid tests.
The United Kingdom merger regime is generally voluntary. That does not remove interim enforcement or completion risk. Counsel should assess reference jurisdiction, substantive competition risk, and whether a briefing paper or notification is appropriate.
The National Security and Investment Act 2021 creates mandatory
notification for specified acquisitions in sensitive sectors. The
artificial-intelligence sector covers defined work used for
identification or tracking, advanced robotics, or cyber security.
Other sensitive sectors can capture an AI target. They include computing hardware, communications, defense, data infrastructure, and critical suppliers. A notifiable acquisition completed without approval is void, subject to validation powers.
The buyer's nationality does not end the inquiry. The Act can apply to acquisitions by any person. Voluntary notification can be appropriate outside the mandatory sectors where a national-security risk may arise.
Switzerland has no operative general investment-screening regime on
the as-of date. Parliament adopted the Investment Screening Act on
December 19, 2025, with entry expected in 2027.
The Swiss Act will focus on acquisitions of companies in especially critical sectors by foreign state-controlled investors. The implementing ordinance remained in consultation until October 5, 2026. It is a readiness item, not a closing condition under current law.
Current Swiss merger review remains governed by the Cartel Act, SR
251, including Article 9 notification thresholds. A partial revision
adopted in December 2025 is expected to enter in 2027 with revised
ordinances. Current law controls until commencement.
Export review should classify software, source code, weights,
technical data, encryption, chips, remote access, users, end uses, and
destinations. United Kingdom controls arise under the Export Control Act
2002, Export Control Order 2008, and current lists.
Swiss controls arise under the Goods Control Act, Goods Control
Ordinance, and related lists. Remote access, technical assistance,
brokering, and sanctions can create separate restrictions.
Sanctions screening must cover parties, beneficial owners,
controllers, banks, customers, suppliers, destinations, services, and
payments. United Kingdom measures arise under the Sanctions and Anti-Money Laundering Act 2018 and program regulations.
The United Kingdom Sanctions List became the sole United Kingdom designation list on January 28, 2026. Ownership and control can extend restrictions to an unlisted entity. Program rules and licenses still control the legal answer.
Swiss sanctions arise under the Embargo Act and program ordinances.
Switzerland often aligns measures with international partners, but the
Swiss ordinance controls. Screening must be refreshed at signing and
closing.
Findings and transaction protections
Each finding needs a legal rule, evidence status, business effect, and deal response. A colour without those parts does not answer whether the activity can continue or transfer.
Stop-level findings include:
- missing title to a core model
- unlawful irreplaceable training data
- a prohibited use
- absent mandatory clearance
- an unavailable regulated license
- a sanctions restriction that blocks the planned business
Closing conditions fit curable defects. Common items include:
- assignments
- consents
- lien releases
- privacy assessments
- notices
- human-review procedures
- product suspension
- incident remediation
- supplier amendments
- regulatory filings
Price adjustments, escrow, holdbacks, exclusions, specific indemnities, and post-closing covenants fit quantified legacy exposure. General warranties offer weak protection for a known defect.
Representations should cover:
- authority
- capitalization
- title
- data rights
- privacy
- automated decisions
- product claims
- security
- incidents
- employment
- licenses
- contracts
- sanctions
- exports
- investment review
- competition
- disputes
Disclosure schedules should identify model, dataset, contract, and policy versions. Product names alone are inadequate. The seller should distinguish verified facts, management assertions, disputed matters, and unresolved items.
Interim covenants should restrict material model releases, dataset changes, supplier changes, new high-impact uses, unapproved claims, and unusual customer exceptions. They should require prompt notice of incidents, complaints, regulator contact, and law changes.
Open items need an owner, due date, evidence standard, closing effect, and escalation route. The closing bring-down should repeat AI status, data, copyright, cyber, sanctions, merger, investment, and sector checks.
Offshore Centres
Offshore-centre legal due diligence of an AI project asks whether its holding, intellectual-property, financing, token, fund, and operating structures are valid, licensed, transparent, and transferable. It must also test the external laws that govern the target's product, data, workers, customers, and regulated uses. This memorandum states the transaction baseline for the Cayman Islands, British Virgin Islands, Bermuda, Jersey, and Guernsey as of July 23, 2026. No target, sector, transaction structure, or data room was supplied. Each connected operating market still requires separate review.
The review has two layers. Offshore law controls entity validity, title, filings, substance, licences, and transfer mechanics. Operating-market law controls the AI product and its effects.
No enacted general private-sector AI statute was identified. Company, data, intellectual-property, employment, consumer, cyber, financial-services, sanctions, and tax laws supply the current tests.
The buyer must prove existence, authority, capitalization, registers, beneficial owners, charges, registered-agent records, and filing status. A clean certificate alone is inadequate.
An AI royalty or licensing entity may conduct intellectual-property business. Local direction, core income-producing activity, qualified people, premises, expenditure, and records must match the reported position.
Cayman, Jersey, and Guernsey give rights
concerning significant solely automated decisions. Bermuda's PIPA and
BVI's Data Protection Act also require a separate AI data-processing
review.
Cayman applies licensing or registration according to the virtual-asset service. BVI requires VASP registration. Bermuda uses DABA licence classes. Jersey uses VASP registration for AML supervision. Guernsey licenses covered virtual-asset activity.
Tokens, pooled compute, model-revenue interests, custody, lending, exchange, managed strategies, and fractional rights may trigger fund, securities, credit, or payment laws.
The buyer should test incident duties, sector cyber rules, sanctions ownership, wallet screening, CRS, CARF, and economic-substance reporting. Each operates independently.
Missing title, false ownership records, sham substance, unlicensed regulated activity, sanctions blocks, or a non-transferable critical dependency can stop closing. Other defects need tailored conditions and price protection.
Diligence perimeter and the two-layer method
Offshore incorporation does not determine the full legal perimeter. It governs the entity and many internal affairs. It does not displace the laws of the markets where the AI business operates.
The first layer concerns the offshore structure. Counsel should test:
- existence
- authority
- shares
- beneficial ownership
- security
- substance
- tax reporting
- licences
- service providers
- insolvency
- transfer mechanics
The second layer concerns the operating business. Counsel should map users, workers, data subjects, training sources, compute, suppliers, public releases, customers, and regulated deployments. Those facts can trigger EU, United Kingdom, United States, Asian, Middle Eastern, or other laws.
A Cayman, BVI, or Bermuda company may contract worldwide. A Jersey or Guernsey entity may hold models or receive royalties. None of those facts proves lawful deployment in the customer's market.
Counsel should prepare linked inventories for entities, models, products, use cases, datasets, and third parties. Each record needs an owner, version date, jurisdiction, and supporting exhibit.
The transaction calendar should separate current duties from signing, closing, and integration duties. Changes in beneficial-ownership access, cyber commencement, tax reporting, sanctions, or licences can alter the closing analysis.
Corporate authority, registers, beneficial ownership, and security
The buyer must identify the legal owner of every material asset. A group website, shared director, or common brand does not prove ownership.
For each entity, counsel should obtain the certificate, constitutional documents, registers, good-standing evidence, annual filings, and registered-office records. The review should include:
- continuations
- conversions
- mergers
- restorations
- prior names
The capitalization review should reconcile issued interests, options, warrants, convertibles, side letters, nominee arrangements, and promised equity. It should also test pre-emption rights, vetoes, transfer limits, and change-of-control approvals.
Beneficial-ownership records deserve independent testing. Counsel should trace natural persons through trusts, partnerships, foundations, nominees, and intermediate companies. The filed record should match customer due-diligence files and transaction documents.
Cayman now uses the Beneficial Ownership Transparency Act (2026
Revision). BVI companies and limited partnerships file
beneficial-ownership information through VIRRGIN. Bermuda enacted the
Beneficial Ownership Act 2025 to move its central register to the
Registrar of Companies. Counsel should confirm the operative
commencement and current filing channel. Jersey and Guernsey also
maintain statutory ownership records.
BVI opened legitimate-interest request functionality on April 1, 2026. The target should preserve notices, objections, appeals, and disclosures. A pending request may affect confidentiality and transaction timing.
Counsel should search charges and obtain every finance document. A security package may cover:
- shares
- receivables
- bank accounts
- intellectual property
- contracts
- distributions
The corporate-service-provider file can expose defects absent from management records. It should include:
- registers
- resolutions
- statutory notices
- compliance requests
- invoices
- resignations
- strike-off warnings
A valid incorporation does not equal regulatory permission. The buyer must compare the entity's activities with every licence, registration, waiver, exemption, and condition.
Economic substance and intellectual-property holding
Economic-substance review is central to an offshore AI structure. A company that receives model, software, patent, brand, data, or know-how income may conduct intellectual-property business.
The exact classification depends on the statute and facts. Counsel should identify each income stream, asset, counterparty, connected person, and commercial function. Royalty labels do not control the result.
Cayman applies the International Tax Co-operation (Economic Substance) Act (2026 Revision). BVI applies the Economic Substance
(Companies and Limited Partnerships) Act 2018. Bermuda applies the
Economic Substance Act 2018 and regulations.
Jersey applies the Taxation (Companies – Economic Substance) (Jersey)
Law 2019. Partnerships receive separate treatment under the 2021 Law.
Guernsey applies the Income Tax (Substance Requirements) (Implementation) Regulations 2021.
The target should identify its core income-generating activities. It should then prove where those activities occur, who performs them, who directs them, and which entity bears the cost.
Board minutes alone are weak evidence when commercial decisions occur elsewhere. Counsel should compare minutes with email, repository access, contracts, travel, payroll, invoices, and approval logs.
A substance file should show local meetings at an adequate frequency. It should also show:
- knowledgeable decision-makers
- local records
- suitable premises
- proportionate expenditure
- qualified personnel or permitted outsourcing
Outsourcing requires proof of control and non-duplication. The provider should identify its people, premises, time, costs, and functions. Generic corporate-administration services may not perform the relevant income-producing work.
High-risk intellectual-property treatment requires early review. A common risk pattern involves acquiring intellectual property from a connected party, then licensing it abroad without local development functions.
Jersey places the burden on a high-risk IP company to rebut non-compliance. Comparable offshore rules also demand stronger evidence for mobile intellectual-property income.
An entity may satisfy company law yet fail its tax-substance position. Consequences can include:
- penalties
- information exchange
- regulatory concern
- banking problems
- a required reorganization
AI asset title and intellectual property
The target must prove a continuous chain of title or a sufficient licence for every core AI asset. Technical possession is not legal ownership.
The asset schedule should cover:
- source code
- object code
- architecture
- weights
- checkpoints
- fine-tunes
- prompts
- evaluation sets
- model cards
- documentation
- patents
- brands
- domains
- trade secrets
Counsel should identify the law governing each contribution. Employee ownership, contractor ownership, assignment form, moral rights, patent inventorship, and database protection can arise under non-offshore law.
Founder work before incorporation needs a signed transfer. Affiliate development needs an intercompany assignment or licence. University and grant work needs a review of funding, publication, access, and commercialization terms.
The buyer should compare legal title with repositories and cloud accounts. A model stored in a group account may belong to another company. A founder-controlled account may create continuity and security risk.
Patent files should identify human inventors, conception records, assignments, priority, prosecution, maintenance, grants, and third-party funding. Marketing references to patented technology should match the actual claims and territories.
Trade-secret value depends on secrecy. Counsel should inspect access lists, confidentiality terms, publications, model releases, logging, devices, and offboarding.
Open-source code and open-weight models need exact licence analysis. The review should address:
- modification
- distribution
- network use
- attribution
- source duties
- acceptable-use limits
- termination
Offshore ownership does not cure unlawful training. Copyright, database, privacy, contract, and confidentiality questions usually follow the source material and affected market.
Personal data and automated decisions
AI data diligence must identify the controller, processor, purpose, legal basis, data categories, recipients, retention, security, and transfer route. The result may differ by entity and processing stage.
Training, evaluation, retrieval, prompts, support, telemetry, and automated decisions need separate records. Permission for one purpose does not authorize every later use.
Cayman's Data Protection Act (2021 Revision) contains specific rights
for significant solely automated decisions. A controller must notify the
person and respond to a timely request for reconsideration. Data
Protection Act (2021 Revision), s. 12.
Token human involvement does not resolve the Cayman issue. The reviewer must assess the output and possess authority to change the result.
Jersey gives a right not to face a solely automated decision with
legal or comparably material effects. Contract, legal-authority, and
explicit-consent exceptions require safeguards. Data Protection (Jersey)
Law 2018, art. 38.
Guernsey also regulates automated decisions and profiling. The
organisation must support human review when the statutory right applies.
Data Protection (Bailiwick of Guernsey) Law 2017, s. 24.
Bermuda's Personal Information Protection Act 2016 became fully operative in 2025. It requires:
- a privacy responsibility structure
- appropriate use
- notices
- security
- access
- correction
- breach handling
BVI enacted the Data Protection Act 2021. Target-specific work should
verify the operative provisions, regulator practice, and any later
instruments before assigning a precise remedy.
The diligence file should include:
- privacy notices
- impact assessments
- processing records
- processor contracts
- transfer support
- rights requests
- breach records
- regulator correspondence
Automated-decision records:
- should identify inputs
- material factors
- model version
- validation
- human review
- notices
- contest routes
- overrides
- outcomes
Special-category, biometric, health, financial, and children's data need heightened review. A bias-testing purpose does not itself authorize sensitive-data processing.
Training data, confidentiality, and international transfers
A dataset register should prove source, acquisition, permission, purpose, and traceability. Public access proves none of those rights.
The register should cover pretraining, fine-tuning, retrieval, evaluation, red-team, prompt, log, feedback, and support data. Each entry needs the exact source and operative terms.
Counsel should separate copyright, database rights, privacy, contract, confidentiality, and sector secrecy. A valid answer in one category does not cure another.
Customer data may contain third-party secrets or regulated information. Support logs may contain credentials, health details, financial records, or unpublished business plans.
Synthetic data needs source analysis. It may reproduce records, preserve identifiers, or reveal memorized content. The target should document generation methods and reidentification testing.
Cross-border transfer review should follow storage, remote access, support, subprocessors, telemetry, model providers, and incident response. The server's primary location does not answer every transfer question.
M&A data rooms require purpose limits and staged access. The seller should redact, aggregate, or withhold personal data where practical. Failed transactions need deletion and return controls.
Deletion and unlearning promises require technical proof. Counsel should identify:
- affected files
- checkpoints
- embeddings
- vector stores
- caches
- logs
- backups
- customer copies
Third-party models, software, datasets, and compute
The target needs a dependency register beyond a software bill of materials. It should cover:
- models
- datasets
- benchmarks
- APIs
- cloud services
- accelerators
- security tools
Each record:
- should state the version
- supplier
- accepted terms
- paying entity
- actual use
- transfer rights
- replacement plan
Counsel should review commercial scope, sectors, geography, users, training, fine-tuning, distillation, outputs, redistribution, attribution, source duties, audits, suspension, and termination.
Assignment and change-of-control terms need special attention. An offshore share sale may still trigger consent or termination under a model, cloud, data, or distribution contract.
Cloud review should cover:
- capacity
- location
- supplier data use
- subprocessors
- security
- deprecation
- price changes
- portability
- recovery
- exit support
Benchmarks create legal and claims risk. The target should prove:
- usage rights
- contamination controls
- test conditions
- model versions
- prompts
- exclusions
- publication approval
A critical dependency without consent or substitute can stop closing. A supplier email expressing comfort does not replace a binding consent.
Virtual assets, token structures, funds, and financial services
AI projects often add tokens, credits, pooled compute, model-revenue rights, or on-chain control. Those features require product-level classification.
Cayman requires a licence for virtual-asset custody and virtual-asset
trading platforms. Other covered services require registration unless a
statutory waiver applies. Virtual Asset (Service Providers) Act (2024 Revision), ss. 6 and 16.
BVI requires registration for a person carrying on a virtual-asset
service in or from the territory. Custody and exchange applicants face
added requirements. Virtual Assets Service Providers Act 2022, s. 7.
Bermuda regulates digital-asset business under the Digital Asset
Business Act 2018. The Bermuda Monetary Authority uses Class T, Class M,
and Class F licences. Unlicensed business can constitute an offence.
Digital Asset Business Act 2018, s. 10.
Jersey requires covered VASPs to register for AML supervision before
business starts. The activity definition appears in the Proceeds of
Crime (Jersey) Law 1999, Schedule 2, Part 4.
Jersey VASP registration does not itself prove authorization for investment, fund, deposit, trust, payment, or other financial business. Counsel must test the complete product.
Guernsey's Lending, Credit and Finance (Bailiwick of Guernsey) Law
2022 licenses covered virtual-asset, consumer-credit, peer-to-peer, and
crowdfunding activity from July 1, 2023.
A token can also be a share, debt claim, fund interest, derivative, electronic money substitute, deposit, or contractual right. The technology does not decide the classification.
Pooled capital used to buy compute, train models, or share revenue may form a fund or collective arrangement. Managed portfolios, custody, dealing, advice, and lending can trigger separate laws.
Counsel should inspect white papers, token terms, smart contracts, treasury controls, wallets, listings, market making, redemption, staking, voting and protocol-control rights, and promotional claims.
A sandbox admission, company registration, or AML registration does not equal full approval. The buyer should verify the public register and every licence condition.
AML, sanctions, and tax transparency
The offshore entity must identify customers, beneficial owners, controllers, counterparties, and source of funds where applicable. Regulated activity adds sector-specific duties.
Virtual-asset diligence should cover:
- wallet screening
- travel-rule processes
- transaction monitoring
- chain analytics
- mixers
- privacy coins
- sanctions
- suspicious-activity reporting
Sanctions analysis must use the local instrument. UK measures may extend to an Overseas Territory or influence a Crown Dependency, but local orders, laws, and licences control.
The review should screen directors, beneficial owners, controllers, banks, customers, suppliers, wallet addresses, destinations, and service types. Ownership and control can restrict an unlisted entity.
A sanctions warranty cannot replace current screening. The buyer should refresh results at signing, material interim dates, and closing.
CRS, FATCA, CARF, country-by-country reporting, and economic-substance filings need separate classification. An AI token or treasury product may create reporting duties absent from the operating product.
Cayman brought CARF and amended CRS rules into effect from January 1, 2026. Jersey's CARF regulations also took effect on January 1, 2026.
Counsel should reconcile tax filings with contracts, accounts, wallet activity, and public claims. Inconsistent records can affect substance, banking, audits, and purchase-price calculations.
Cybersecurity, incidents, and operational continuity
Security diligence should cover models, data, applications, infrastructure, wallets, keys, and suppliers. A conventional penetration test may omit model-specific threats.
The target should produce threat models, access lists, key controls, secure-development records, vulnerability reports, red-team tests, release approvals, monitoring, backups, and recovery tests.
Model-specific testing should address:
- prompt injection
- retrieval manipulation
- data poisoning
- model extraction
- unsafe tool use
- memorization
- weight leakage
Bermuda PIPA applies breach duties to personal information. Regulated digital-asset and financial entities also face sector security and incident rules.
Guernsey requires reportable personal-data breaches to reach the Data Protection Authority within 72 hours. Affected persons may also need notice.
Jersey enacted the Cyber Security (Jersey) Law 2026. A commencement
order was published on July 17, 2026. The exact provision-by-provision
start dates require a closing bring-down.
The Jersey cyber law addresses designated operators of essential services, security measures, incident notices, and regulatory directions. Covered sectors include:
- banking
- health
- transport
- energy
- water
- digital services
- public administration
Cayman and BVI regulated firms face sector cyber, operational, AML, and incident expectations. The exact rules depend on licence type and service.
The target should maintain one incident register. It should include:
- breaches
- unsafe outputs
- discrimination
- vulnerabilities
- outages
- fraud
- key loss
- wallet events
- regulator contact
Each record:
- should state discovery
- affected systems
- users
- jurisdictions
- containment
- notices
- insurance
- cause
- remediation
- recurrence testing
Personnel, premises, and local operations
Economic substance and business licensing depend on actual people and premises. Counsel should test the legal and practical location of work.
The personnel file should connect each contributor to an employer, entity, asset, and work product. It should include:
- assignments
- confidentiality
- prior-employer restrictions
- visas
- work permits
Local directors must exercise real judgment. A service provider that signs prepared minutes without understanding the business may not support the claimed management position.
The buyer should interview directors and key staff. Their answers should match minutes, contracts, technical approvals, and tax filings.
Immigration, local-business, population, housing, and employment rules can limit local operations. Cayman, BVI, Bermuda, Jersey, and Guernsey use different permission systems.
A post-closing migration can change substance and tax residence. Moving founders, repositories, approvals, or customer contracts may create a new legal position.
Key-person dependence needs a continuity plan. The target should identify:
- who can train
- deploy
- recover
- sign transactions
- access wallets
- explain critical systems
Contracts, revenue, insolvency, and transferability
Contract diligence must prove assent, performance, and transferability. A template does not prove which terms a customer accepted.
Counsel should obtain executed customer, reseller, API, cloud, data, employment, service-provider, fund, and token agreements. The file should identify each operative version.
AI terms should address:
- data use
- training
- prompts
- logs
- outputs
- confidentiality
- security
- incidents
- model changes
- documentation
- human review
- audits
- indemnities
- caps
- assignment
- exit
The terms must match conduct. A no-training promise is dangerous when support data feeds evaluation. An output-ownership promise may exceed the target's legal rights.
Revenue quality needs contract-to-ledger testing. Counsel should separate production revenue from pilots, credits, token sales, related-party receipts, minimum commitments, and contingent milestones.
The buyer should test:
- solvency
- distributions
- redemptions
- related-party payments
- statutory demands
- strike-off
- restoration
- creditor claims
Registered-agent resignation can become an operational risk. The target should disclose unpaid fees, incomplete KYC, filing defaults, and threatened resignations.
Continuations and mergers need entity-specific approval. A proposed migration may trigger creditor notices, tax consequences, licence consent, and contract termination.
Cayman Islands
Cayman diligence should start with the Companies Act (2026 Revision),
constitutional records, beneficial ownership, charges, and
registered-office files. The buyer should verify good standing and every
material filing.
The Beneficial Ownership Transparency Act (2026 Revision) requires a
current ownership record. Counsel should reconcile that record with the
cap table, trust documents, and sanctions analysis.
The International Tax Co-operation (Economic Substance) Act (2026 Revision) requires activity-level classification. An AI
intellectual-property company should identify all royalty, licence, and
connected-party income.
Cayman's Data Protection Act applies according to its territorial
provisions. Section 12 creates a direct diligence item for significant
automated decisions.
CIMA licensing must match actual digital-asset activity. Custody and trading platforms need licences from April 1, 2025. Other VASPs generally require registration.
The review should also test:
- mutual-fund
- private-fund
- securities-investment
- money-services
- banking
- trust
- company-management laws where product facts require them
Local operation may require trade-and-business, local-company-control, immigration, and work-permit analysis. An exempted company status does not answer those questions.
British Virgin Islands
BVI diligence should reconcile the BVI Business Companies Act 2004 records with VIRRGIN filings. The review should cover:
- directors
- members
- beneficial owners
- charges
- annual returns
- registered-agent records
All BVI companies and limited partnerships became subject to the 2024 beneficial-ownership filing regime from January 2, 2025. The target should prove timely and accurate filings.
Legitimate-interest access started on April 1, 2026. Counsel should identify:
- any request
- objection
- appeal
- disclosure
- exemption concerning the target
The economic-substance statute appears under inconsistent official
titles. The enacted instrument is No. 12 of 2018. Counsel should use the
original Act, amendments, and current rules rather than an unofficial
consolidation alone.
The Virtual Assets Service Providers Act 2022 took effect on February
1, 2023. Registration, authorized representation, audits, client-asset
protection, advertising, reporting, and control changes require
evidence.
BVI incorporation does not authorize financial or virtual-asset business. The buyer should verify the FSC register and inspect every condition or restriction.
The Data Protection Act 2021 belongs in the diligence perimeter.
Precise commencement, regulator practice, and remedies need confirmation
from the current official record for the target's facts.
Bermuda
Bermuda diligence should trace:
- authority
- ownership
- charges
- residence
- licences under the
Companies Act 1981and the target's entity statute
The Beneficial Ownership Act 2025 provides for the central register's
transfer to the Registrar of Companies. Counsel should confirm the
operative commencement, filings, discrepancies, and any suppression
request.
The Economic Substance Act 2018 and regulations require
activity-level proof. The 2026 amendment must be included in the
current-law review.
PIPA is fully operative. The target should produce its privacy officer record, privacy programme, notices, rights procedures, security measures, transfers, and breach history.
Digital-asset business requires the correct BMA licence. The file should identify:
- Class T
- Class M
- or Class F status
- permitted activities
- conditions
- expiry
- supervisory correspondence
Token issuance can require separate analysis under the Digital Asset
Issuance Act 2020. Insurance, funds, investment, banking, trust,
money-service, and corporate-service laws may also apply.
The buyer should verify the target against the live regulated-entity register. An expired, restricted, or mismatched licence can affect closing.
Jersey
Jersey diligence should start with the Companies (Jersey) Law 1991,
constitutional records, beneficial ownership, significant-person
filings, security, and solvency.
The Data Protection (Jersey) Law 2018 is current from April 1, 2026.
Article 38 requires a use-case record for solely automated decisions
with legal or comparable effects.
Jersey economic-substance laws cover companies and partnerships. High-risk IP companies face a presumption against compliance unless they produce sufficient evidence.
The buyer should compare Jersey board records with where product, pricing, licensing, and technical decisions occur. Records should show the actual governing body.
VASP activity requires JFSC registration before business begins. That registration addresses AML supervision. It does not replace any permit needed under other financial-services laws.
The Cyber Security (Jersey) Law 2026 creates a live status issue.
Counsel should confirm the commencement order's exact provisions and
dates before signing and closing.
Jersey sanctions apply under the Sanctions and Asset-Freezing (Jersey) Law 2019 and connected orders. The target should reconcile
sanctions controls with ownership and payment records.
Guernsey
Guernsey diligence must identify the relevant Bailiwick entity and island. Guernsey, Alderney, and Sark can differ on company, business, property, employment, and public-law matters.
The Companies (Guernsey) Law 2008 supplies the principal company
record for Guernsey companies. Beneficial ownership requires separate
review under the 2017 Law.
Economic-substance review should use the 2021 Regulations and applicable tax guidance. Partnerships need proof of residence, governing body, local decisions, and records.
The Data Protection (Bailiwick of Guernsey) Law 2017 applies to AI processing within its territorial reach. Section 24 and related duties require:
- review of automated decisions
- rights
- DPIAs
- security
- transfers
Established organisations processing personal data may need registration with the ODPA. The buyer should verify current registration, renewal, and contact details.
The Lending, Credit and Finance Law requires licences for covered
virtual-asset, credit, peer-to-peer, and crowdfunding business. The
Protection of Investors Law can apply to investment products and
services.
GFSC authorisation, AML rules, sanctions, ownership, and control approvals need product-level review. The public register should match the target's representations.
Findings and transaction protections
Each finding needs a legal rule, evidence status, business effect, and deal response. A colour alone does not answer whether the business can continue or transfer.
Stop-level findings include:
- missing title to a core model
- false ownership filings
- sham substance
- unlawful irreplaceable data
- unlicensed regulated activity
Other stop-level findings include:
- a struck-off entity
- absent mandatory consent
- sanctions prohibition
- frozen assets
- a non-transferable critical model or cloud right
Closing conditions fit curable defects. Common items include:
- restoration
- good standing
- lien releases
- assignments
- ownership updates
- licence approvals
- consents
- filing corrections
Substance remediation may require people, premises, revised decision processes, contracts, and tax filings. New minutes cannot retroactively prove work that occurred elsewhere.
Data and cyber conditions may require:
- notices
- impact assessments
- processor terms
- access cleanup
- incident remediation
- tested human-review procedures
Price adjustments, escrow, holdbacks, exclusions, and specific indemnities fit quantified legacy exposure. General warranties offer weak protection for a known defect.
Representations should cover:
- authority
- capitalization
- ownership
- substance
- tax reporting
- licences
- data
- intellectual property
- security
- incidents
- sanctions
- contracts
Disclosure schedules should identify exact entity, model, dataset, licence, and contract versions. Product names alone are inadequate.
Interim covenants should restrict new token activity, model releases, dataset changes, dividends, migrations, supplier changes, and unusual customer terms.
The closing bring-down should repeat good-standing, ownership, licence, sanctions, cyber, substance, and tax-reporting checks. Open items need an owner, evidence standard, and closing consequence.
Middle East
Middle East legal due diligence of an artificial intelligence project asks whether the target can lawfully own, train, deploy, sell, and transfer its systems across connected states and special economic zones. This memorandum states the transaction baseline for the United Arab Emirates, including mainland UAE, the DIFC, and ADGM; Saudi Arabia; Israel; Qatar, including the QFC; and Bahrain as of July 23, 2026. It focuses on corporate authority, data, cloud, cybersecurity, content controls, intellectual property, employment, regulated services, public procurement, foreign investment, exports, sanctions, and transaction protection. No target, sector, buyer, transaction structure, or data room was supplied. Every additional state connected through entities, workers, users, data, compute, customers, or regulated activity requires separate local-law review.
No reviewed jurisdiction has an operative general private-sector AI statute comparable to the EU AI Act. Existing company, data, intellectual-property, cybercrime, consumer, employment, financial-services, product, and sector laws supply the current tests.
Federal law, emirate law, and free-zone law can apply to one group. Mainland UAE, the DIFC, ADGM, Dubai VARA, and sector regulators require separate actor, licence, data, and forum analysis.
The Personal Data Protection Law requires express
notice for automated decisions. Where consent supplies the legal basis
for a solely automated personal-data decision, the consent must be
explicit. New technology and automated decisions can trigger a
data-protection impact assessment.
Privacy Amendment 13 has applied since August 2025. AI
linked to military, dual-use, cyber, autonomy, or defense know-how needs
early classification under the Defense Export Control Law.
The QFC and Bahrain grant specific rights concerning solely automated decisions. Qatar mainland law requires privacy-by-design and pre-processing review, but no general mainland automated-decision right was identified.
Public access does not prove a right to train. Copyright, database or compilation rights, privacy, contract, confidentiality, trade secrets, public-sector secrecy, and sector rules need separate proof.
No single regional data-localisation rule controls every project. Saudi cloud controls, financial-sector outsourcing rules, government-data terms, critical-system duties, remote access, and incident reporting require system-level mapping.
Credit, investment advice, insurance, healthcare, biometrics, identity, employment, education, transport, defense, public administration, and digital assets can require:
- licences
- approvals
- local hosting
- testing
- human review
- regulator access
Missing core title, unlawful irreplaceable data, unlicensed regulated activity, prohibited content or use, a blocking export or sanctions issue, or a non-transferable critical dependency can stop closing. Curable defects belong in conditions. Quantified legacy exposure belongs in price and specific protection.
Diligence perimeter and legal layers
The review must follow the target's actual operations. Incorporation establishes one legal connection. Users, workers, data subjects, data sources, compute, suppliers, public releases, and regulated customers create others.
The region contains overlapping legal systems. UAE federal law applies beside emirate rules and distinct financial free-zone laws. Qatar mainland law differs from QFC law. Public-sector, financial, healthcare, telecom, and critical-infrastructure rules can sit beside general commercial law.
Counsel should prepare linked inventories for legal entities, products, models, use cases, data, and third parties. Each item should identify:
- the responsible entity
- legal role
- version
- location
- use
- customer class
- supporting record
The model inventory should cover architecture, weights, checkpoints, fine-tunes, retrieval sources, safety layers, evaluations, and releases. The use-case inventory should distinguish intended purpose from actual customer use. Sales claims and implementation support can widen the legal perimeter.
The jurisdiction map should record each place of incorporation, establishment, work, sale, use, data collection, storage, remote access, technical support, and public procurement. It should identify the buyer and post-closing integration plan. Those facts can create investment, export, sanctions, tax, and transfer duties.
A regional entity can also face external law when it places products
or models abroad, targets foreign users, processes their data, employs
their workers, or uses controlled technology. Regulation (EU) 2024/1689,
art. 2; Regulation (EU) 2016/679, art. 3. The North American, EU and
EEA, United Kingdom and Swiss, and offshore modules remain relevant to
those connections.
Timing needs a separate obligations calendar. The calendar should distinguish current law, delayed provisions, consultations, policies, and regulator initiatives. A law that starts between signing and closing can change conditions, warranties, and interim covenants.
Corporate authority, foreign ownership, and asset location
The buyer must identify which entity owns each material asset and owes each material obligation. A group brand, common director, or shared repository does not prove legal ownership.
For each entity, counsel should obtain constitutional documents, commercial-register extracts, licences, shareholder and beneficial-owner records, capitalization, security interests, board authority, signing powers, and insolvency indicators. The review should include branches, representative offices, free-zone establishments, and nominee arrangements.
AI groups often split research, payroll, customer contracts, and intellectual property. The entity employing developers may lack a valid invention transfer. The entity invoicing customers may hold only an informal model licence. A cloud account may remain in a founder's name.
The asset map should connect each repository, model, dataset, patent, brand, domain, customer contract, and compute account to a legal owner. Every intercompany transfer, licence, services agreement, and cost allocation needs written terms.
Foreign-ownership rules require activity-level analysis. The UAE
generally permits full foreign ownership, subject to strategic-impact
and regulated activities. Saudi investment requires registration and may
need approval for excluded or restricted activities. Qatar permits
foreign investment under Law No. 1 of 2019, subject to sector and
approval limits. Bahrain and Israel also use activity-specific
restrictions and approvals.
Free-zone registration does not authorize mainland business or regulated services. A DIFC, ADGM, QFC, or other free-zone company may need a mainland licence, local distributor, branch, or regulator approval for the planned activity.
Change-of-control review should cover corporate approvals, regulator consent, government contracts, leases, work permits, public grants, security interests, and supplier contracts. An offshore or foreign parent sale can still trigger local consent.
Current AI-specific statutory position
No operative general private-sector AI act was identified in the reviewed jurisdictions. That finding does not create a legal gap. Existing statutes regulate the target's data, claims, content, decisions, products, workers, customers, and regulated services.
The UAE Cabinet approved creation of a federal Artificial Intelligence and Data Authority in June 2026. Its announced mandate includes national policy, proposed legislation, standards, and federal-entity compliance. The announcement did not create a general private-sector AI licence.
Saudi Arabia offers AI Service Provider Accreditation through the National Data Management Office platform. The process requires entity registration, an AI officer, a product questionnaire, and supporting files. Accreditation is an administrative service and evidence item. It should not be described as universal legal permission to offer AI services.
Israel has public AI institutions and defense AI programmes. They do
not replace the Protection of Privacy Law, sector law, competition law,
procurement rules, or export controls. Treaty commitments also need
domestic legal effect before they control a private transaction.
Qatar operates government AI programmes and sandbox initiatives. Bahrain launched a National AI Policy in 2025. The Bahrain policy mainly addresses government use and related public actors. Neither item was treated as a general private-sector statute.
Diligence should still require an internal approval record. The record should name who approves training data, model releases, high-impact uses, public claims, customer exceptions, and incident responses. Unassigned responsibility increases contract and regulator risk.
Data protection and automated decisions
AI data diligence should identify the controller, processor, purpose, lawful basis, data categories, recipients, retention, security, and transfer route for each processing operation. Training, fine-tuning, retrieval, evaluation, prompts, logs, support, and automated decisions require separate entries.
The UAE Personal Data Protection Law applies to specified processing
by UAE and foreign controllers. Federal Decree-Law No. 45 of 2021, art.
2. It requires fair and lawful processing, purpose control,
minimisation, accuracy, security, and controller accountability. Id.
arts. 5 and 7.
UAE data subjects may object to automated decisions, including
profiling, that have legal or adverse effects. Contract, law, and
prior-consent exceptions apply. The controller must protect the person's
rights and include human review upon request. Id. art. 18.
The DIFC uses a separate regime. DIFC Data Protection Law No. 5 of
2020, Article 38, governs solely automated decisions with legal or
comparably material effects. The 2025 amendment added a private right of
action through Article 64A. DIFC Data Protection Regulations, Regulation
10, addresses autonomous and semi-autonomous systems, including
generative AI and machine learning.
ADGM Data Protection Regulations 2021, section 20, creates a right
not to face a solely automated decision with legal or comparably
material effects, subject to statutory conditions. ADGM entities
processing personal data must also address data-controller registration
and transfer duties.
Saudi Arabia's Personal Data Protection Law applies to processing in
the Kingdom and specified processing of residents' data from abroad. The
Implementing Regulations require notice when the controller uses new
technology or automated decisions. The notice must state whether
decisions are solely automated. Implementing Regulations, art. 4(5).
Where consent supplies the legal basis for a solely automated
personal-data decision, Saudi controllers need explicit consent.
Implementing Regulations, art. 11(2)(c). A data-protection impact
assessment is required for specified high-risk processing, including new
technology, automated decisions, linked datasets, and continuous
monitoring. Id. art. 25.
Saudi law also requires a data protection officer for specified
public, systematic-monitoring, and sensitive-data operations. Id. art.
32. A qualifying breach must reach the authority within 72 hours. The
person must receive notice without undue delay where the regulatory test
is met.
Israel's Protection of Privacy Law, 5741-1981, as amended by
Amendment 13, has applied in its revised form since August 2025. The
amendment expanded enforcement and data-protection-officer duties for
specified bodies and processing. Privacy Protection Regulations (Data
Security), 5777-2017, require security controls and immediate reporting
of a severe security incident where the rule applies.
No general Israeli statutory right against automated individual decisions was identified in the reviewed primary record. Counsel should not import the GDPR test by analogy. Privacy, discrimination, consumer, credit, employment, contract, and sector law can still regulate the decision.
Qatar's Law No. 13 of 2016 requires fair and lawful processing,
consent or another permitted basis, privacy-by-design, security, and
review before specified new processing. The law does not contain the
same general automated-decision right found in the QFC.
QFC Data Protection Regulations 2021, Article 22, gives a person the
right not to face a solely automated decision with legal or significant
effect. Contract, law, and explicit written consent exceptions apply.
Contract and consent cases require human intervention, a chance to state
a view, and a right to contest.
Bahrain's Personal Data Protection Law, Law No. 30 of 2018, Article
22, addresses decisions based solely on automated processing that
evaluate work performance, financial status, creditworthiness,
behaviour, or trustworthiness. The person may request another decision
method, subject to the contract exception and required safeguards.
The diligence file should contain notices, impact assessments, consent records, transfer support, processing registers, security evidence, rights requests, and regulator contact. Automated-decision records:
- should identify inputs
- material factors
- model version
- validation
- human review
- overrides
- outcomes
Training data, intellectual property, confidentiality, and transfers
A dataset register must prove source, permission, purpose, and traceability. Public availability proves access. It does not prove:
- a right to copy
- train
- retain
- disclose
- commercialize
The register should cover pretraining, fine-tuning, retrieval, evaluation, red-team, prompt, log, feedback, and support data. Each entry should state the source, acquisition date, collector, method, licence, contract, personal-data content, location, retention, deletion, and downstream use.
Copyright, database or compilation rights, privacy, contract, confidentiality, trade secrets, and sector secrecy require separate answers. A customer may have authority to provide data but lack authority to license third-party content within it.
No broad statutory permission for commercial AI training is currently operative across the reviewed jurisdictions. Counsel should not treat research exceptions, temporary-copy rules, or fair-use concepts from another state as controlling.
UAE copyright review should use Federal Decree-Law No. 38 of 2021 and
its executive regulation. Saudi review should use the currently
operative copyright law until the new law published on February 13, 2026
becomes effective 180 days after publication. The closing review must
verify that transition.
The new Saudi law will add a specific exception for copying a
lawfully published and lawfully acquired work to develop AI products and
algorithms, limited to the stated purpose. Copyright Law, art. 26(4).
That provision has no current force before the law's commencement.
Israel's Copyright Law, 5768-2007, requires a fact-specific review of
copying, permitted uses, contracts, and market effects. Qatar and
Bahrain also require source-level analysis under their copyright
statutes and related civil or criminal rules.
Employee and contractor ownership depends on the governing employment and intellectual-property law. The buyer should obtain signed assignments from founders, employees, contractors, affiliates, universities, and grant participants. Moral rights and local formalities need separate treatment.
Trade-secret value depends on secrecy measures. Counsel should inspect repository permissions, confidentiality terms, model releases, publication history, device controls, logging, and offboarding. A public release can destroy secrecy in the released material.
Cross-border transfers require a system map. Storage location alone is insufficient. Remote administration, support, subprocessors, telemetry, model providers, and incident access can constitute transfers or disclosures.
Saudi transfers can use prescribed routes, including standard clauses, binding common rules, certifications, adequacy, or statutory exceptions. UAE, DIFC, ADGM, Qatar, QFC, Bahrain, and Israel use their own transfer tests. The contract must match the actual technical path.
Deletion and unlearning promises require technical evidence. The target should identify affected source files, checkpoints, embeddings, vector stores, caches, logs, backups, and customer copies. A deletion clause has little value when the target cannot locate the data.
Third-party models, software, datasets, and compute
The target needs a dependency register beyond a software bill of materials. It should cover:
- open-source code
- open-weight models
- hosted models
- datasets
- benchmarks
- APIs
- cloud
- accelerators
- security tools
- content filters
Each record should identify the exact version, supplier, accepted terms, paying entity, actual use, transfer rights, and replacement plan. Counsel should preserve the terms in force when the target accepted them.
The review should test:
- commercial scope
- field limits
- geography
- users
- training
- fine-tuning
- distillation
- outputs
- redistribution
- attribution
- source duties
- audit
- suspension
- termination
- assignment
- change of control
An open-source or open-weight label does not resolve the issue. The exact licence and integration method control. Acceptable-use terms can bar sectors, persons, locations, or content.
Cloud agreements need capacity, data location, supplier training, subprocessors, security, model changes, deprecation, price resets, suspension, portability, disaster recovery, and exit support. A target may own its application but lack transferable model or compute access.
Saudi cloud deployments require review under NCA Cloud Cybersecurity Controls CCC-2:2024 where applicable. Financial, telecom, health, government, and critical-system customers can impose added localisation, approval, audit, and outsourcing duties.
UAE cloud treatment depends on the entity, data, emirate, free zone, and regulated sector. DIFC, ADGM, financial regulators, health authorities, and government contracts can impose distinct requirements.
Benchmarks need the same discipline. The target should prove:
- usage rights
- test-set confidentiality
- contamination controls
- score methods
- model versions
- prompts
- exclusions
- publication approval
A critical dependency without consent or substitute can stop closing. Informal supplier comfort should not replace a binding consent or amended contract.
Cybersecurity and incident history
AI security diligence should cover models, data, applications, infrastructure, identities, and suppliers. Ordinary penetration testing may omit prompt injection, retrieval manipulation, poisoning, model extraction, unsafe tool use, and weight leakage.
Counsel should obtain threat models, secure-development records, privileged-access lists, key controls, model registries, dataset controls, supplier access, vulnerability reports, red-team results, release approvals, monitoring, backups, and recovery tests.
UAE cyber review should include Federal Decree-Law No. 34 of 2021 on
Countering Rumours and Cybercrimes. Unauthorized acquisition, use,
alteration, disclosure, or publication of personal and confidential
electronic data can create criminal exposure.
Saudi review should include NCA controls, the Cybercrime Law, sector
requirements, cloud controls, and incident channels. Applicability
depends on the entity, system, customer, and national-security
connection.
Israel's Privacy Protection Regulations (Data Security), 5777-2017,
classify databases and prescribe controls. Amendment 13 strengthened
enforcement. Defense, critical-infrastructure, health, and financial
systems can face added rules.
Qatar's National Cyber Security Agency regulates cybersecurity and
administers the mainland privacy statute. Government and critical-sector
contracts can impose security, hosting, audit, and incident duties
beyond Law No. 13 of 2016.
Bahrain financial institutions and their vendors must review the relevant Central Bank of Bahrain Rulebook module. Outsourcing, cloud, cyber resilience, incident notice, audit, and data access vary by licence class.
The target should maintain one incident register across legal, security, product, and operations teams. It should include:
- data breaches
- unsafe outputs
- discrimination
- vulnerabilities
- outages
- fraud
- prompt leakage
- weight leakage
- poisoning
- extraction
- regulator contact
Each incident entry should record discovery, affected systems, people, jurisdictions, containment, legal analysis, notices, customer communications, insurance, cause, remediation, and recurrence testing. An undisclosed incident can alter warranties, disclosure schedules, coverage, valuation, and closing.
Content controls, product claims, synthetic media, and children
AI outputs can trigger criminal, media, consumer, defamation, privacy, personality, copyright, public-order, and religious-content rules. The product should map:
- user inputs
- output categories
- moderation
- escalation
- geographic controls
The UAE cybercrime statute penalizes specified unlawful content and dissemination. Saudi, Qatar, Bahrain, and Israel also apply local criminal, media, public-order, and sector rules. A global moderation policy may not capture local prohibitions.
Marketing diligence should compare public claims with retained evidence. Claims about accuracy, bias, safety, privacy, security, training rights, human review, certification, output ownership, and benchmark rank need dated support.
The supporting file should identify the model version, test set, prompts, sample, exclusions, threshold, result, date, and approver. A disclaimer does not cure a contradictory headline, demo, procurement response, or sales script.
Synthetic media can engage consent, identity, voice, likeness, defamation, fraud, copyright, elections, and criminal law. Counsel should inspect labelling, detection, takedown channels, impersonation controls, and customer restrictions.
Children and vulnerable users require added review. The target should identify:
- actual audience
- age signals
- parental permissions
- profiling
- advertising
- retention
- crisis escalation
- human intervention
Arabic-language consumer, employment, government, and execution requirements need document-level review. UAE, Saudi, Qatar, and Bahrain official Arabic texts control where the official record so states. Israel requires review of the operative Hebrew text.
Employment, localisation, and workplace systems
Employment AI can trigger data, discrimination, contract, consultation, monitoring, and termination rules. The review should cover:
- recruitment
- ranking
- scheduling
- productivity scoring
- promotion
- pay
- discipline
- dismissal
Counsel should obtain feature lists, training sources, validation, subgroup testing, accessibility testing, notices, adverse outcomes, overrides, appeals, and vendor communications. Written policy should match actual manager conduct.
UAE employment review should address Federal Decree-Law No. 33 of
2021, free-zone employment rules, work permits, Emiratisation, wage
systems, and employee-data processing. DIFC and ADGM use distinct
employment laws.
Saudi review should address the Labour Law, work permits,
Saudisation, wage protection, employee monitoring, and assignment of
inventions. Localisation can also affect substance and licence
conditions.
Qatar and Bahrain apply local employment, immigration, wage, and nationalisation rules. The QFC uses separate employment regulations. Israel requires:
- review of labour
- privacy
- equality
- collective rights
- work-permit rules
A vendor cannot assign every discrimination duty to the employer. The developer's design, claims, limits, and known uses remain relevant. The employer still needs enough information to conduct lawful human review.
Regulated sectors and public procurement
Sector classification can determine whether the transaction is viable. The target should identify:
- every use in credit
- investment
- payments
- insurance
- healthcare
- medical devices
- telecom
- transport
- energy
- education
- government
- policing
- defense
- critical infrastructure
Financial AI can constitute investment advice, portfolio management, credit scoring, underwriting, fraud detection, payment processing, or outsourcing. Each function requires regulator and licence mapping.
Saudi capital-market rules now define a robo-advisory service involving algorithms and modern technical means. A product that manages client investments can require Capital Market Authority authorization and compliance records.
UAE financial services require separate Central Bank, Securities and Commodities Authority, DFSA, FSRA, and emirate-level analysis. A DIFC or ADGM permission does not authorize the same service throughout the UAE.
QFC financial services require QFCRA authorization where the activity is regulated. Bahrain financial services require the correct CBB licence. Israel and Qatar mainland also apply sector-specific authorization and outsourcing rules.
Healthcare AI needs intended-purpose, clinical, data, advertising, professional, device, and liability review. A wellness label does not control where claims or functions indicate diagnosis, treatment, or clinical decision support.
Public procurement can impose data location, Arabic terms, security clearance, local content, audit, source-code escrow, intellectual-property allocation, incident notice, and sovereign-rights clauses. The target should reconcile tender promises with product reality.
A sandbox admission, accreditation, innovation licence, or pilot approval does not prove full legal authorization. Counsel should identify:
- the exact scope
- period
- conditions
- customer class
- exit route
Digital assets, payments, and token structures
AI projects that issue tokens, credits, compute rights, revenue interests, or on-chain control need product-level financial classification. The technology does not determine the legal category.
Dubai's Virtual Assets Regulatory Authority regulates virtual-asset activities in Dubai outside the DIFC. The target should identify whether it needs a VARA licence and which rulebooks apply.
DIFC digital-asset activity falls within DFSA rules. ADGM uses FSRA rules for virtual assets, fiat-referenced tokens, and related activities. Each regime has distinct custody, market, capital, technology, and conduct duties.
Saudi digital-asset and payment activity requires review under Saudi Central Bank and Capital Market Authority rules. Qatar mainland, the QFC, and Bahrain use their own central-bank or financial-centre regimes.
Bahrain's CBB Rulebook includes a crypto-asset module, and the CBB introduced a stablecoin issuance regime in 2025. The buyer should verify the live licensing directory and every condition.
A token can also constitute a security, fund interest, debt claim, derivative, payment instrument, deposit, or contractual right. Pooled compute or shared model revenue can create collective-investment or managed-account exposure.
The diligence file should include:
- white papers
- token terms
- smart contracts
- treasury controls
- wallets
- listings
- market-making arrangements
- redemption
- staking
- voting
- protocol-control rights
AML and sanctions review should cover:
- customers
- beneficial owners
- wallets
- counterparties
- source of funds
- transaction monitoring
- suspicious-activity reporting
- mixers
- privacy-enhancing services
Competition, investment, exports, and sanctions
Competition review should cover:
- exclusivity
- most-favoured terms
- tying
- data access
- interoperability restrictions
- pricing tools
- information exchange
- talent restrictions
- customer concentration
- acquisitions
UAE Federal Decree-Law No. 36 of 2023 governs competition. Cabinet
Resolution No. 3 of 2025 sets a 40 percent dominance threshold and
concentration notification tests based on AED 300 million of relevant
UAE sales or a 40 percent transaction share. Cabinet Resolution No. 59
of 2026 takes effect on July 30, 2026 and requires a closing-date
update.
Saudi, Israeli, Qatari, and Bahraini competition laws can require merger filings or prohibit restrictive conduct. The buyer should obtain local turnover, market-share, transaction-value, and control information before signing.
Foreign-investment review depends on the activity, investor, ownership, government links, sensitive data, defense ties, and control rights. Registration alone does not resolve national-security or sector approval.
Israel requires early export classification when AI involves defense
equipment, defense know-how, defense services, military autonomy,
surveillance, cyber, or dual-use functions. Defense Export Control Law,
5767-2007. Marketing, brokering, and transfer can each require
authorization.
Other regional states also regulate military and dual-use items. United States, Union, United Kingdom, or supplier-country controls can follow chips, source code, encryption, model weights, or technical data through re-export rules.
Sanctions screening must cover parties, beneficial owners, controllers, banks, customers, suppliers, destinations, services, and payments. Local UAE, Saudi, Israeli, Qatari, and Bahraini measures require separate review from the buyer's home-country sanctions.
UAE targeted-financial-sanctions procedures can require immediate asset freezing where a listed person's ownership or control test is met. Screening must continue through closing because designations and ownership can change.
United Arab Emirates, DIFC, and ADGM
UAE diligence must state which legal zone controls each entity, contract, worker, data operation, and regulated service. Mainland UAE, DIFC, ADGM, and emirate-specific regimes are not interchangeable.
Mainland corporate review should use Federal Decree-Law No. 32 of
2021 on Commercial Companies, the relevant emirate licence, and activity
approvals. Strategic-impact activities can retain ownership or approval
limits.
Federal data law excludes specified government, security, judicial, and separately regulated health data. Those exclusions do not create unrestricted use. The governing sector or government rule must be identified.
Federal automated-decision rights under Article 18 require a
documented objection and human-review process. The target should test
whether its contract or consent exception is valid and whether review
can change the result.
DIFC entities need Article 38 classification and Regulation 10
evidence. The 2025 private right of action increases transaction
exposure. A June 2026 DIFC consultation had closed by the as-of date,
but no enacted amendment was verified.
ADGM entities need section 20 classification, controller
registration, processing records, transfer support, and Office of Data
Protection interaction. A financial entity also needs FSRA analysis.
Digital-asset activity requires the correct regulator. Dubai VARA, DFSA, FSRA, the Central Bank, and the Securities and Commodities Authority have different perimeters.
The buyer should confirm Arabic and English document status. Federal official English text states that Arabic prevails. DIFC and ADGM laws use their own official publication and court systems.
Saudi Arabia
Saudi diligence should connect each entity, licence, worker, server, data subject, customer, and government relationship to the operative statute and regulator. Registration and investment approval should match actual activity.
The PDPL file should include notices, explicit consents, impact assessments, DPO analysis, breach procedures, transfer mechanisms, and destruction evidence. Solely automated decisions require express treatment.
The target should distinguish AI accreditation from licensing. Accreditation may support procurement or market claims. It does not replace a financial, telecom, health, cloud, professional, or investment licence.
Cyber review should map NCA controls, data localisation, cloud tenancy, sector outsourcing, government requirements, and incident reporting. Supplier contracts should permit regulator access and evidence production where required.
Copyright diligence needs a transition calendar. The new Saudi
Copyright Law was published on February 13, 2026 and starts 180 days
after publication. Until then, the operative prior law controls. The
buyer should repeat the check at signing and closing.
Employment review should cover:
- Saudisation
- work permits
- wage protection
- employee inventions
- confidentiality
- local staffing required by licences or procurement
Israel
Israeli diligence should start with privacy, intellectual property, cybersecurity, defense exports, sector regulation, corporate authority, and employment. Product facts determine whether national-security agencies or sector regulators enter the review.
Amendment 13 increases the value of accurate database classification,
DPO analysis, security records, and incident reporting. A large
sensitive database may require notice to the Privacy Protection
Authority under the amended law.
The target should preserve processing inventories, transfer agreements, database-security classifications, access records, breach analyses, and regulator correspondence. No general automated-decision exemption should be inferred from the absence of a dedicated right.
Defense export classification should occur before technical diligence exposes controlled material to a foreign bidder or adviser. The data room may need access restrictions, clean teams, nationality screening, and licence conditions.
Copyright and trade-secret review should separate model ownership from training permission. Defense, university, incubator, and government funding can create publication, control, or transfer restrictions.
Qatar and the Qatar Financial Centre
Qatar diligence must separate mainland law from QFC law. Entity formation, data, employment, contracts, finance, insolvency, and courts can differ.
Mainland Law No. 13 of 2016 requires privacy-by-design and advance
review for new processing. The target should produce notices, consents,
processing reviews, security measures, breach decisions, and NCSA
correspondence.
QFC Article 22 requires a specific automated-decision process. The
file should show whether a decision is solely automated, which exception
applies, and how human intervention and contest rights work.
Foreign-investment approval should match the actual activity and customer base. A QFC registration does not authorize mainland regulated activity.
Government AI programmes and sandboxes should be recorded as procurement or policy facts. They should not be described as a general private-sector approval.
Bahrain
Bahrain diligence should connect the company, licence, data processing, workers, products, and customers to the operative statute and regulator. The National AI Policy is not a substitute for private-sector legal analysis.
Article 22 of Law No. 30 of 2018 creates a concrete
automated-decision workstream for employment, financial, credit,
behavioural, and trustworthiness evaluations. The target should document
requests for another method and the contract exception.
The privacy file should address the 2022 decisions on transfers,
security, impact assessment, breaches, notifications, sensitive data,
DPOs, and data-subject rights. The Ministry of Justice performs the
statutory authority's functions under Decree No. 78 of 2019.
Financial AI and virtual assets require CBB classification. The target should verify:
- the relevant Rulebook volume
- licence category
- outsourcing terms
- cloud controls
- incident duties
Contracts, revenue quality, and continuity
Contract diligence must prove assent, scope, performance, and transferability. A template does not prove which terms a customer accepted.
Counsel should obtain executed orders, clickwrap records, amendments, procurement terms, API terms, reseller agreements, research contracts, cloud contracts, and incorporated policies. The record should identify the operative version and order of precedence.
AI clauses should address:
- permitted use
- prohibited use
- customer data
- prompts
- logs
- training
- outputs
- confidentiality
- security
- incidents
- model changes
- documentation
- human review
- audits
- indemnities
- caps
- assignment
- termination
- transition
The terms should match actual conduct. A no-training promise is dangerous when support logs feed evaluation. A customer-control clause is weak when the target markets autonomous operation.
Revenue quality requires contract-to-ledger testing. Counsel should separate production revenue from pilots, free use, credits, related-party sales, minimum commitments, contingent milestones, and token proceeds.
Continuity depends on compute, models, data, suppliers, licences, and key people. The review should test:
- capacity
- minimum spend
- deprecation
- price changes
- suspension
- portability
- recovery
- concentrated know-how
Arabic execution, notarisation, legalization, apostille or consular steps, government templates, and local-signatory authority need contract-specific review. English-only documents may not control before every local court or authority.
Findings and transaction protections
Each finding needs a legal rule, evidence status, business effect, and deal response. A colour alone does not answer whether the activity can continue or transfer.
Stop-level findings include:
- missing title to a core model
- unlawful irreplaceable training data
- prohibited content or use
- unlicensed regulated activity
- absent mandatory investment or export approval
- a sanctions block
Other stop-level findings include a non-transferable critical cloud or model right, false licence representations, material hidden incidents, or a government contract that terminates at closing.
Closing conditions fit curable defects. Common items include:
- assignments
- consents
- licence approvals
- investment filings
- data assessments
- notices
- human-review procedures
- product suspension
- incident remediation
- supplier amendments
- access cleanup
Price adjustments, escrow, holdbacks, exclusions, specific indemnities, and post-closing covenants fit quantified legacy exposure. General warranties offer weak protection for a known defect.
Representations should cover:
- authority
- capitalization
- title
- data rights
- automated decisions
- product claims
- security
- incidents
- employment
- licences
- contracts
- sanctions
- exports
- investment review
- competition
- disputes
Disclosure schedules should identify exact entity, model, dataset, licence, policy, and contract versions. Product names alone are inadequate. The seller should distinguish verified facts, management assertions, disputes, and unresolved items.
Interim covenants should restrict material model releases, dataset changes, new high-impact uses, supplier changes, token activity, unapproved claims, and unusual customer exceptions. They should require prompt notice of incidents, complaints, regulator contact, and law changes.
Open items need an owner, due date, evidence standard, closing effect, and escalation route. The closing bring-down should repeat licence, data, cyber, sanctions, export, investment, competition, and law-status checks.
Asia-Pacific
Asia-Pacific hub legal due diligence of an artificial intelligence project asks whether the target can lawfully own, train, deploy, sell, and transfer its models, systems, data, products, and regulated services across Singapore, Hong Kong, Japan, South Korea, and Australia. This memorandum states the transaction baseline as of July 24, 2026. It tests corporate authority, data processing, automated decisions, training rights, cybersecurity, product claims, regulated uses, foreign investment, exports, and transaction protection. No target, sector, buyer, transaction structure, or data room was supplied. Every additional jurisdiction connected through entities, workers, users, data, compute, customers, or controlled technology requires separate review.
South Korea has an operative general AI statute. Japan has an AI promotion statute, a Cabinet plan, and statutory guidance. Singapore, Hong Kong, and Australia still regulate private AI mainly through privacy, intellectual-property, consumer, cyber, employment, product, and sector laws.
The AI Basic Act requires specified notices and
labels for high-impact and generative AI. It adds risk, documentation,
human-oversight, and domestic-representative duties for covered systems
and providers. The Personal Information Protection Act grants rights
concerning significant fully automated decisions.
The 2025 AI Act and the second AI Basic Plan promote
development and use rather than impose an EU-style pre-market conformity
regime. The final statutory AI guideline and the March 2026 AI Business
Guidelines remain central diligence evidence. A July 2026 privacy
amendment has delayed commencement.
The Personal Data Protection Act and the PDPC AI
advisory govern personal-data use. The Copyright Act permits
computational data analysis, including machine-learning training, when
statutory conditions and lawful access are satisfied. The amended
Cybersecurity Act has applied since October 31, 2025.
The Personal Data (Privacy) Ordinance applies beside
the PCPD AI model document. No general statutory automated-decision
right was identified. The critical-infrastructure computer-system
ordinance has applied since January 1, 2026. AI copyright reform remains
pending.
Existing privacy, consumer, discrimination, cyber,
product, and sector laws remain the current private-sector baseline. The
government guidance for AI adoption is voluntary. New privacy-policy
disclosures for significant computer-program decisions and the
Children’s Online Privacy Code are due on December 10, 2026.
The copyright answer is not regional. Singapore has a broad computational-data-analysis exception. Japan uses a purpose-limited non-enjoyment exception. South Korea relies on fair use and other specific exceptions. Hong Kong and Australia have not enacted a broad commercial text-and-data-mining exception.
Employment, lending, insurance, healthcare, medical devices, biometrics, education, public administration, critical infrastructure, and financial services require:
- separate licences
- notices
- testing
- human review
- security
- regulator-access analysis
Missing core title, unlawful irreplaceable data, unlicensed regulated activity, a prohibited use, a blocking investment or export issue, or a non-transferable critical dependency can stop closing. Curable defects belong in conditions. Quantified legacy exposure belongs in price and specific protection.
Diligence perimeter and legal connections
The review must follow the target’s operating facts. Incorporation answers only the internal-affairs question. Users, workers, data subjects, data sources, compute, support teams, and customers create separate connections.
Counsel should prepare six linked inventories. They should cover legal entities, products, models, use cases, data flows, and third parties. Each item needs:
- an owner
- version date
- location
- legal role
- supporting record
The model inventory should identify architecture, weights, checkpoints, fine-tunes, retrieval sources, safety layers, evaluations, and release history. The use-case inventory should distinguish intended purpose from actual customer use. Sales materials and implementation support may widen the target’s legal exposure.
The jurisdiction matrix should record each place of incorporation, work, sale, use, collection, storage, remote access, and support. It should include government procurement and regulated customers. It should also identify the buyer and post-closing integration plan.
External law may attach to a regional target. An Asia-Pacific company
can enter the EU AI Act through Union market placement or output use. It
can enter overseas privacy law through targeting, monitoring,
establishments, or local data subjects. The prior regional modules
remain relevant to those connections. Regulation (EU) 2024/1689, art. 2;
Regulation (EU) 2016/679, art. 3.
Timing requires a separate calendar. Counsel should distinguish current duties, enacted delayed duties, policy documents, consultations, and guidance. The closing analysis should track October 31, 2025, January 1, 2026, January 22, 2026, July 17, 2026, December 10, 2026, and later start dates discussed below.
Corporate authority, capitalization, and asset location
The buyer must identify the entity that owns each material asset and owes each material obligation. A common brand, shared director, or consolidated website does not prove ownership.
Counsel should obtain constitutional documents, registers, capitalization records, beneficial-owner information, board approvals, security interests, and insolvency indicators. The review should include:
- options
- convertibles
- side letters
- nominee interests
- promised equity
AI groups often separate research, payroll, customer contracting, and intellectual property. The entity employing developers may lack a valid invention transfer. The customer entity may have only an informal model licence. A founder may still control a cloud or code account.
The asset map should connect every repository, model, dataset, patent, brand, domain, customer contract, and compute account to a legal owner. Intercompany assignments, licences, services agreements, and cost allocations need written terms.
Change-of-control review should cover corporate approvals, licences, leases, government contracts, grants, security interests, and supplier consents. A share sale can trigger a consent even when the operating entity remains unchanged.
Foreign-investment review must start early. Singapore’s Significant
Investments Review Act applies ownership and control rules to designated
entities. It also grants powers concerning any entity that acts against
national-security interests. Japan uses FEFTA prior-notification and
review rules, with a 2026 amendment and draft implementing measures
requiring status checks. South Korea uses the Foreign Investment
Promotion Act and sector rules. Australia applies the Foreign
Acquisitions and Takeovers Act, including national-security business
concepts.
Current AI-specific statutory position
The region no longer supports one description of AI law. South
Korea’s AI Basic Act has applied since January 22, 2026. Japan’s Act No.
53 of 2025 has applied in full since September 1, 2025. The two statutes
have different legal designs.
South Korea imposes direct duties on covered providers. Article 31
addresses advance notice and AI-generated output labels. Articles 32 to
36 address specified safety systems, high-impact AI, human oversight,
documentation, and foreign-provider representation. Investigation and
corrective powers support the regime.
Japan’s statute directs national planning, research promotion, guidance, information collection, and public measures. It does not create a general pre-market conformity file or a cross-sector private AI licence. The second AI Basic Plan received Cabinet approval on July 14, 2026. The AI Strategy Headquarters adopted the statutory AI guideline on December 19, 2025.
Singapore, Hong Kong, and Australia have not enacted a comparable cross-sector private AI act. Their regulators use existing statutes, sector rules, and nonbinding AI documents. A policy, sandbox, assurance tool, or voluntary standard does not replace an applicable licence or statute.
The target still needs an internal responsibility record. It should identify who approves training data, model releases, high-impact uses, customer exceptions, product claims, and incident responses. The record should match board reporting and actual practice.
Personal data and automated decisions
Data diligence must identify the controller or equivalent business, processor, purpose, legal basis, data categories, recipients, retention, security, and transfer route. Training, fine-tuning, retrieval, evaluation, prompts, logs, and decisions need separate entries.
Singapore applies the Personal Data Protection Act 2012. Core duties
address consent or an exception, notice, purpose, access, correction,
accuracy, protection, retention, transfer limits, and breach notice. The
PDPC AI advisory explains how those duties apply to recommendation and
decision systems. It does not create a separate statute.
The reviewed Singapore Act does not contain a general standalone
right equivalent to South Korea’s Article 37-2. That absence does not
permit opaque or unfair use. Notice, consent, purpose, accuracy, access,
correction, and sector rules may still require explanation and human
review.
Hong Kong applies the Personal Data (Privacy) Ordinance, Cap. 486.
Its data-protection principles address collection, accuracy, retention,
use, security, openness, and access. The PCPD’s AI Model Personal Data
Protection Framework recommends risk assessment, human oversight,
testing, monitoring, incident response, and clear communication. The
document is guidance, not legislation.
The reviewed Hong Kong Ordinance does not contain a general statutory right against solely automated decisions. High-impact uses still engage purpose limits, accuracy, security, discrimination, consumer, employment, credit, and sector rules. Contractual human-review promises must match actual operations.
Japan applies the Act on the Protection of Personal Information and
sector rules. The current Act governs acquisition, purpose
specification, use, sensitive information, third-party provision,
security, breach notice, data-subject requests, and overseas transfers.
It does not create a general GDPR-style veto over automated
decisions.
Japan promulgated a major APPI amendment on July 17, 2026. Most provisions start on a date set by Cabinet Order within two years. The current-law file and the post-commencement readiness file should remain separate.
South Korea’s PIPA Article 37-2 gives a person rights concerning a
decision made entirely by an automated system when it materially affects
rights or duties. The person may object or seek an explanation. The
controller may need to stop applying the decision or reprocess it with
human involvement, subject to statutory exceptions. The controller must
disclose decision criteria, procedures, and personal-data handling.
Personal Information Protection Act, art. 37-2.
The Korea file should identify whether a human meaningfully participates. A rubber-stamp review remains an automated process in substance. Counsel should inspect authority, timing, information supplied, override rates, and appeal outcomes.
Australia applies the Privacy Act 1988 and the Australian Privacy
Principles to covered entities. Current duties address collection,
notice, use, disclosure, security, access, correction, overseas
disclosure, and eligible data breaches. The Act does not yet grant a
general right to reject an automated decision.
New APP 1.7 to 1.9 duties start on December 10, 2026. A covered
privacy policy must then describe specified computer-program decisions
that may materially affect individual rights or interests. It must
identify the personal-information and decision types. The duty applies
to relevant decisions from that date, even if the arrangement or data
predates it.
The privacy file should contain processing records, notices, consent or exception analyses, impact assessments, transfer records, processor terms, rights requests, and breach decisions. Automated-decision files should add inputs, material factors, validation, human review, overrides, and outcomes.
Training data, copyright, database rights, and confidential information
A dataset register must prove source, permission, purpose, and traceability. Public availability proves access. It does not prove:
- a right to copy
- retain
- train
- disclose
- commercialize
The register should cover pretraining, fine-tuning, retrieval, evaluation, red-team, prompt, log, feedback, and support data. Each entry should identify:
- source
- date
- collector
- method
- terms
- personal data
- location
- retention
- deletion
- downstream use
Copyright, privacy, contract, confidentiality, trade secrets, and sector secrecy require separate answers. A copyright exception does not cure an unlawful data collection. A customer contract cannot grant rights the customer does not hold.
Singapore’s Copyright Act 2021 defines computational data analysis
broadly. The permitted use includes text and data mining and
machine-learning training. Lawful access remains essential. Statutory
restrictions also govern retained copies and communications. Copyright
Act 2021, ss. 243-244.
Singapore’s exception does not authorize paywall circumvention or unrelated distribution. Counsel should preserve access records, licence terms, source copies, analysis purpose, and every onward disclosure. Contract and database restrictions remain separate.
Japan’s Copyright Act Article 30-4 permits use when the purpose is
not enjoyment of the thoughts or sentiments expressed in a work.
Information analysis falls within the provision. The use must remain
within the necessary extent and must not unreasonably prejudice the
rights holder’s interests.
The Japanese exception needs purpose-level evidence. A training use can fall outside the exception when enjoyment of expression forms part of the purpose. Output generation and market substitution need separate infringement analysis.
South Korea has no dedicated broad commercial TDM exception in the
reviewed current Act. Article 35-5 supplies a four-factor fair-use test.
Other specific exceptions may apply. The target should document purpose,
nature, amount, acquisition, output behaviour, and market effect.
Copyright Act, art. 35-5.
Hong Kong completed consultation on AI and copyright in 2024. The
2025 policy record states that the government was preparing a code and
legislative proposals. No enacted broad commercial TDM exception was
identified by the as-of date. Copyright Ordinance, Cap. 528, remains the
operative statute.
Australia’s Copyright Act 1968 remains in force in its April 2, 2026
compilation. Existing fair-dealing exceptions are purpose-specific. The
Attorney-General’s Department states that the government is not
considering a TDM exception. Each training source therefore needs a
licence, another statutory basis, or a defensible non-infringement
analysis.
Output diligence should separate subsistence, ownership, infringement, and contract allocation. Customer terms can allocate commercial risk. They cannot create statutory rights where governing law finds no protectable human authorship.
The buyer should inspect memorization and similarity testing. It should also inspect filters for confidential information, personal data, trade marks, voice, likeness, and false attribution. Complaints and takedowns need a versioned incident trail.
Employee and contractor ownership remains jurisdiction-specific. The target should produce signed assignments from founders, staff, contractors, affiliates, universities, and grant participants. Patent files should identify:
- human inventors
- conception records
- assignments
- disclosures
- funding restrictions
Trade-secret value depends on secrecy measures. Counsel should review repository permissions, model releases, publications, device controls, confidentiality terms, logging, and offboarding. A public release can destroy secrecy in the released material.
Third-party models, software, data, and compute
The target needs a dependency register beyond a software bill of materials. It should cover:
- code
- open-weight models
- hosted models
- datasets
- benchmarks
- APIs
- cloud
- accelerators
- safety tools
- identity services
Each entry should identify the exact version, supplier, accepted terms, paying entity, actual use, transfer rights, and replacement plan. Counsel should preserve the terms in force when accepted.
The review should test:
- commercial scope
- sectors
- geography
- users
- training
- fine-tuning
- distillation
- outputs
- redistribution
- attribution
- source duties
- audit
- suspension
- termination
- assignment
- change of control
An open-source or open-weight label does not answer those questions. The exact licence and integration method control. Acceptable-use terms may prohibit a sector, person, place, or content type.
Cloud agreements need capacity, data location, supplier training, subprocessors, security, model changes, deprecation, price resets, suspension, portability, disaster recovery, and exit support. A target may own its application while lacking transferable model or compute access.
Benchmarks need the same review. Counsel should verify rights, test-set confidentiality, contamination controls, model version, prompts, sample, exclusions, and publication approval. Unsupported rankings create consumer and contract risk.
A critical dependency without consent or a substitute can stop closing. An informal supplier statement does not replace a binding consent or amendment.
Cybersecurity, critical infrastructure, and incidents
AI security diligence should cover models, data, applications, infrastructure, credentials, and suppliers. Ordinary penetration testing may omit prompt injection, retrieval manipulation, poisoning, extraction, unsafe tool use, and weight leakage.
Counsel should obtain threat models, secure-development records, privileged-access lists, secrets controls, model registries, supplier access, vulnerability reports, red-team results, release approvals, monitoring, backups, and recovery tests.
Singapore’s amended Cybersecurity Act provisions began on October 31,
2025. The changes update CII oversight and add new regulated system
classes. Covered CII owners must report specified incidents within two
hours. The target should classify every essential service, virtual
system, and temporary critical system.
Hong Kong’s Protection of Critical Infrastructures (Computer Systems)
Ordinance, Cap. 653, began on January 1, 2026. It applies to designated
operators and critical computer systems. It imposes organizational,
preventive, reporting, and response duties. The buyer should obtain
designation notices, plans, audits, incident records, and Commissioner
correspondence.
Japan’s current cyber duties arise from the Basic Act on
Cybersecurity, sector rules, contracts, and economic-security measures.
The current Basic Act record flags additional provisions for October 1,
2026. METI issued an SCS assessment policy in March 2026. The scheme
targets a start around the end of fiscal 2026, so it remains a readiness
item.
South Korea requires a system-specific review under PIPA, the Act on
the Protection of Information and Communications Infrastructure,
financial rules, medical rules, telecom rules, and public-sector duties.
The AI Basic Act adds safety duties for systems above a statutory
compute threshold. Counsel should verify the current decree, threshold,
submission form, and system scope.
Australia’s Cyber Security Act 2024 and the Security of Critical
Infrastructure Act 2018 create separate workstreams. Covered ransomware
payments trigger reports under rules that began on March 3, 2025.
Critical-infrastructure entities may face risk-management, incident,
information, and government-assistance duties.
The target should maintain one incident register. It should include:
- data breaches
- unsafe outputs
- discriminatory outcomes
- vulnerabilities
- outages
- prompt leakage
- weight leakage
- poisoning
- model extraction
- regulator contact
Each entry should record discovery, systems, people, jurisdictions, containment, legal analysis, notices, customer communications, insurance, cause, remediation, and recurrence testing. An undisclosed incident can alter warranties, disclosure schedules, coverage, valuation, and closing.
Product claims, synthetic media, online services, and children
Marketing diligence should compare public claims with retained evidence. Websites, decks, demos, model cards, security pages, tender responses, and sales scripts all matter.
Claims about accuracy, bias, privacy, security, training rights, certifications, human review, output ownership, and benchmark rank need dated support. The file should identify:
- the model version
- test set
- prompts
- sample
- exclusions
- threshold
- result
- approver
Singapore’s Consumer Protection (Fair Trading) Act addresses unfair
practices in consumer transactions. Hong Kong’s Trade Descriptions
Ordinance prohibits false descriptions and specified unfair practices
for goods and services, including online sales. Australia’s Australian
Consumer Law prohibits misleading or deceptive conduct and false
representations. Japanese and Korean consumer and advertising statutes
apply to AI claims under their own tests.
A disclaimer does not cure a contradictory headline, demo, or salesperson statement. A model score should not appear as a guaranteed outcome. A certification claim should identify the issuing body, scope, version, and expiry.
South Korea’s Article 31 requires advance notice when a product or
service uses high-impact or generative AI. It also requires labels for
generative output. Realistic synthetic audio, images, and video need
clear notice, subject to the artistic-expression rule.
Other jurisdictions may regulate synthetic content through privacy, passing off, trade marks, defamation, fraud, elections, impersonation, online safety, and criminal law. The target should test:
- consent
- likeness and voice rights
- labels
- detection
- takedowns
- customer restrictions
Australia’s Children’s Online Privacy Code remained in draft after consultation closed on June 5, 2026. The final code must be registered by December 10, 2026. Covered online services likely accessed by children should prepare:
- age
- profiling
- marketing
- deletion
- notice
- best-interest records
Children’s products in every jurisdiction need a separate audience analysis. The review should cover:
- actual users
- age signals
- parental permissions
- profiling
- targeted advertising
- retention
- crisis escalation
- human intervention
Employment and high-impact decisions
Employment AI can affect recruitment, ranking, monitoring, scheduling, productivity, promotion, pay, discipline, and dismissal. Privacy, equality, labour, contract, and consultation duties may all apply.
Counsel should obtain feature lists, training sources, validation, subgroup testing, accessibility testing, notices, adverse outcomes, overrides, appeals, and vendor communications. The review should compare written policy with manager practice.
South Korea treats employment-related decisions within its
high-impact AI categories when the statutory test is met. PIPA Article 37-2 may also apply to fully automated decisions. The provider and
employer need separate actor analyses.
Singapore, Hong Kong, Japan, and Australia do not require one universal AI employment filing. Their discrimination, disability, privacy, labour, and workplace laws still apply. State and territory law adds to the Australian federal statutes.
A vendor cannot transfer every discrimination duty to the employer. The developer’s design, claims, known limits, and documentation remain relevant. The employer needs enough information to conduct real review and explain a decision where law or contract requires it.
Financial services, healthcare, and public uses
Regulated uses can decide transaction viability. The target should identify:
- every deployment in credit
- insurance
- investment
- payments
- healthcare
- medical devices
- education
- transport
- government
- policing
- defense
- critical infrastructure
Financial AI may constitute advice, dealing, portfolio management, credit assessment, underwriting, payment processing, or regulated outsourcing. Each function needs a licence and customer-status analysis. Sandbox participation does not grant permission outside its terms.
Singapore financial firms and service providers may face MAS licensing, technology-risk, outsourcing, conduct, and consumer duties. Hong Kong requires separate HKMA, SFC, Insurance Authority, and Mandatory Provident Fund analysis. Japan’s FSA and sector statutes control financial uses. Korea’s FSC and FSS rules apply to financial institutions and vendors. Australia requires:
- ASIC
- APRA
- credit
- payments
- financial-service analysis
Healthcare AI needs intended-purpose, clinical, privacy, professional, advertising, and device review. Singapore requires covered medical devices to be registered with HSA and meet applicable requirements. Its medical-device cyber label remains voluntary.
Japan, South Korea, and Australia regulate software as a medical device according to function and risk. Australia generally requires inclusion in the Australian Register of Therapeutic Goods unless an exclusion or exemption applies. AI evidence should identify:
- the model
- training and test data
- change controls
- clinical performance
- post-market monitoring
Public procurement can impose data location, security clearance, audit, source-code escrow, accessibility, incident notice, model-change, intellectual-property, and exit duties. The target should reconcile tender claims with product reality.
A public-sector pilot or innovation programme is not general approval. Counsel should identify:
- scope
- term
- customer
- statutory basis
- data rights
- publication rights
- transition after the pilot
Competition, investment, exports, and sanctions
Competition diligence should cover:
- exclusivity
- most-favoured terms
- tying
- data access
- interoperability limits
- pricing tools
- information exchange
- talent restrictions
- customer concentration
- acquisitions
The merger and investment analysis needs local turnover, assets, market shares, transaction value, buyer identity, government links, sensitive data, and control rights. Minority rights can matter even when legal control does not pass.
Singapore’s Significant Investments Review Act began on March 28,
2024. Japan’s FEFTA screening regime was amended in June 2026, with
draft regulations published in July. South Korea applies the Foreign
Investment Promotion Act and sector restrictions. Australia’s Foreign
Acquisitions and Takeovers Act remains current in its December 5, 2025
compilation.
Export review should classify chips, servers, encryption, source
code, weights, technical data, remote access, users, end uses, and
destinations. Singapore uses the Strategic Goods (Control) Act and
current control orders. Japan uses FEFTA, the Foreign Exchange Order,
and the Export Trade Control Order. South Korea uses the Foreign Trade
Act and strategic-item controls. Australia uses the Defence Trade
Controls Act 2012 and customs controls.
Sanctions screening must cover parties, beneficial owners, controllers, banks, customers, suppliers, destinations, services, and payments. Local measures need separate treatment from the buyer’s home-country rules. Screening should be refreshed at signing and closing.
Singapore
Singapore diligence should combine the Companies Act, PDPA, Copyright
Act, Cybersecurity Act, consumer law, sector licences, SIRA, export
controls, employment law, and contract law. The exact set depends on the
product and customer.
The PDPA file should identify every organization and data intermediary. It should link each purpose to notice, consent or exception, access, correction, retention, security, transfer, and breach records. The AI advisory should appear as evidence of the target’s interpretation and controls, not as an independent legal safe harbour.
The computational-data-analysis exception can support commercial training. The target still needs lawful access and compliance with the statutory use restrictions. Copies obtained through circumvention or breach of access controls create a serious defect.
Cyber classification should identify CII ownership, provider-owned virtual systems, STCC exposure, and licensed cybersecurity services. Incident procedures should meet the applicable two-hour or other statutory timeline.
A Singapore entity providing healthcare, financial, telecom, digital-payment, medical-device, or online services needs regulator-specific review. Corporate registration alone does not authorize the regulated activity.
Hong Kong
Hong Kong diligence should begin with the Companies Ordinance, PDPO,
Copyright Ordinance, Trade Descriptions Ordinance, employment
discrimination statutes, sector licences, strategic-commodity controls,
and Cap. 653 where applicable.
The PCPD AI model document gives a practical evidence list. The target should produce internal approval records, risk assessments, human-oversight decisions, validation, monitoring, incident response, staff training, and customer communications. Those records should map to the PDPO’s binding duties.
Training rights remain a priority defect area. The government has
announced a code and legislative proposals, but the current Copyright
Ordinance controls. Counsel should not assume that a proposed TDM rule
will protect historic copying.
Cap. 653 applies only after designation. The target should produce
every designation, critical-system list, code, plan, audit, incident
notice, and regulator direction. A non-designated vendor may still
inherit security and audit duties through customer contracts.
Product claims should be tested against the Trade Descriptions
Ordinance. It reaches goods, services, online traders, false
descriptions, misleading omissions, and other listed unfair
practices.
Japan
Japan diligence should separate binding law from the AI Act’s plan and guidance system. The 2025 Act supplies government powers and business cooperation expectations. It does not create a general product certification or CE-style mark.
The second AI Basic Plan was approved on July 14, 2026. The statutory AI guideline was adopted on December 19, 2025. The official list records revised AI Business Guidelines and an AI security technical guideline from March 2026. The target should state which documents it follows and preserve supporting tests.
The current APPI governs present processing. The July 2026 amendment belongs in a separate readiness schedule until its provisions commence. Contracts should allocate work needed for new notices, rights, records, or regulator procedures.
Article 30-4 can support training when the purpose and prejudice
limits are met. Counsel should inspect the acquisition path, training
purpose, dataset composition, access controls, output behaviour, and
market effects.
FEFTA review should cover inward investment, exports, technology release, and sanctions. The June 2026 FDI amendment and July draft regulations need a closing-date status check. Technical diligence may need access restrictions before the buyer reviews controlled material.
South Korea
South Korean diligence must classify each entity as an AI business
operator and each product as generative, high-impact, or subject to
Article 32. The analysis should use the current Act No. 21311 and
current Enforcement Decree.
Article 31 requires advance notice for products and services using
high-impact or generative AI. It also requires output marking and clear
synthetic-media notice. The target should preserve screenshots,
interface versions, API documentation, customer terms, and exception
analyses.
Article 33 requires a pre-assessment of high-impact status and
permits a confirmation request to the Ministry. Article 34 requires
covered measures addressing risk, explanation planning, user protection,
human oversight, and documentation. Article 35 encourages a
fundamental-rights impact assessment and affects public procurement
priority.
Article 32 applies additional lifecycle risk, incident, and reporting
duties to AI systems above the statutory compute threshold. Article 36
may require a qualifying foreign provider to appoint a domestic
representative. Counsel should verify group turnover, users, local
establishment, and decree thresholds.
Enforcement is not uniform across every duty. The Act grants investigation, corrective, and stop powers. Administrative fines apply to specified violations, including certain notice and representative failures. The diligence report should match each defect to the exact remedy.
PIPA Article 37-2 creates a separate automated-decision workstream. AI Basic Act compliance does not replace PIPA. The same system may need:
- notice
- explanation
- objection handling
- human reprocessing
- public disclosures
- high-impact documentation
Australia
Australian diligence should begin with current statutes, not the 2024 mandatory-guardrails proposal. The National AI Plan was published on December 2, 2025. The current government approach uses existing laws, regulator action, safety science, and voluntary adoption guidance.
The Guidance for AI Adoption creates no new legal duty. It can still become relevant through contracts, procurement, board decisions, or representations. The target should identify which voluntary controls it claims to follow and retain proof.
The Privacy Act governs current personal-information handling. The December 10, 2026 automated-decision disclosure rules require an implementation plan now. The target should identify:
- affected decisions
- data types
- privacy-policy changes
- ownership
- release timing
The Children’s Online Privacy Code remained a post-consultation
draft. Covered services should prepare for registration by December 10,
2026. The final text and commencement details require a closing
check.
Training data needs source-level copyright review. The Copyright Act
has no broad TDM exception. The government’s current work focuses on
licensing, AI-generated material, and enforcement, rather than a TDM
exception.
Consumer claims face Australian Consumer Law section 18 and specific
false-representation provisions. Biometric and facial-recognition uses
need privacy, consent, necessity, notice, and impact records. The 2026
Administrative Review Tribunal decision in the Bunnings matter
illustrates the evidentiary importance of notice and documented
assessment.
Cyber review should cover the Cyber Security Act, ransomware reporting, the SOCI Act, privacy breach notice, APRA standards, and sector contracts. Medical AI needs:
- TGA classification
- evidence
- registration
- change control
- post-market monitoring
Contracts, revenue quality, and continuity
Contract diligence must prove assent, scope, performance, and transferability. A template does not prove which terms the customer accepted.
Counsel should obtain executed orders, clickwrap records, amendments, procurement terms, API terms, reseller agreements, research contracts, cloud contracts, and incorporated policies. The record should identify the operative version and order of precedence.
AI clauses should address:
- permitted use
- prohibited use
- customer data
- prompts
- logs
- training
- outputs
- confidentiality
- security
- incidents
- model changes
- documentation
- human review
- audits
- indemnities
- caps
- assignment
- termination
- transition
The terms should match conduct. A no-training promise is dangerous when support logs feed evaluation. A customer-control clause is weak when the target markets autonomous operation.
Revenue quality requires contract-to-ledger testing. Counsel should separate production revenue from pilots, free use, credits, related-party sales, minimum commitments, contingent milestones, and token proceeds.
Continuity depends on compute, models, data, suppliers, licences, and key people. The review should test:
- capacity
- minimum spend
- deprecation
- price changes
- suspension
- portability
- recovery
- concentrated knowledge
Assignment and change-of-control clauses require dependency-level review. A model API, dataset, cloud commitment, distribution right, public grant, or government contract may terminate at closing.
Findings and transaction protections
Each finding needs a legal rule, evidence status, business effect, and deal response. A colour alone does not answer whether the activity can continue or transfer.
Stop-level findings include:
- missing title to a core model
- unlawful irreplaceable training data
- unlicensed regulated activity
- a prohibited use
- absent mandatory approval
- a sanctions or export block
Other stop-level findings include a non-transferable critical model or cloud right, false certification claims, material hidden incidents, or a government contract that ends at closing.
Closing conditions fit curable defects. Common items include:
- assignments
- consents
- licence approvals
- investment filings
- privacy assessments
- notices
- human-review procedures
- product suspension
- incident remediation
- supplier amendments
- access cleanup
Price adjustments, escrow, holdbacks, exclusions, specific indemnities, and post-closing covenants fit quantified legacy exposure. General warranties offer weak protection for a known defect.
Representations should cover:
- authority
- capitalization
- title
- data rights
- automated decisions
- AI classification
- product claims
- security
- incidents
- employment
- licences
- contracts
- sanctions
- exports
- investment review
- competition
- disputes
Disclosure schedules should identify exact entity, model, dataset, licence, policy, and contract versions. Product names alone are inadequate. The seller should distinguish verified facts, management assertions, disputed matters, and unresolved items.
Interim covenants should restrict material model releases, dataset changes, new high-impact uses, supplier changes, unapproved claims, and unusual customer exceptions. They should require prompt notice of incidents, complaints, regulator contact, and legal changes.
Open items need an owner, due date, evidence standard, closing effect, and escalation route. The closing bring-down should repeat licence, data, cyber, copyright, investment, export, sanctions, and commencement checks.
China & India
Mainland China and India legal due diligence of an artificial intelligence project asks whether the target can lawfully own, train, deploy, sell, and transfer its models, systems, data, products, and regulated services across both markets. This memorandum states the transaction baseline as of July 24, 2026. It tests corporate authority, AI-specific duties, personal-data processing, training rights, cybersecurity, content controls, licences, foreign investment, exports, and transaction protection. Mainland China excludes Hong Kong and Macao for this session. No target, sector, buyer, transaction structure, or data room was supplied. Each connected province, Indian state, regulated activity, and foreign market needs added review.
China regulates AI through layered binding measures rather than one omnibus cross-sector AI act. Product type, public availability, content function, social-mobilisation capacity, and user group determine the applicable duties.
Public-facing generative AI services need lawful training sources, intellectual-property and personal-information compliance, content controls, user terms, complaints, and regulatory cooperation. Security assessment and algorithm filing apply where the statutory test is met.
AI-generated and synthesised content needs explicit and metadata labels from September 1, 2025. Anthropomorphic emotional-interaction services face added child, dependency, safety, data, labelling, filing, and annual-verification duties from July 15, 2026.
The Personal Information Protection Law
regulates automated decisions, sensitive information, children under 14,
impact assessments, incidents, overseas controllers, and cross-border
transfers. Local storage, security assessment, contracts, or
certification may apply according to the actor and data volume.
India has no operative omnibus private-sector AI statute. Existing laws control current activity. The November 2025 national AI guidelines remain nonbinding, while the February 2026 synthetic-content amendments impose binding duties on covered intermediaries.
The Digital Personal Data Protection Act and 2025 Rules
use phased commencement. The Data Protection Board and selected
institutional provisions are active. Most controller, rights,
child-data, security, breach, and transfer duties start on May 13,
2027.
Public access does not establish a training right. Copyright, personal data, contract, confidentiality, trade secrets, content restrictions, and sector secrecy require separate proof for each dataset.
Cloud, telecom, financial, medical, geospatial, vehicle, education, public-sector, biometric, and critical-system products can require:
- licences
- filings
- local operation
- testing
- incident reporting
- regulator access
Missing core title, unlawful irreplaceable data, absent filings, unlicensed regulated activity, prohibited content, a blocking investment or export issue, or a non-transferable critical dependency can stop closing. Other defects need tailored conditions and price protection.
Diligence perimeter and legal connections
The review must follow the target's actual operations. Incorporation answers only the internal company question. Users, workers, data subjects, data sources, compute, suppliers, and regulated customers create separate legal connections.
Counsel should prepare linked inventories for entities, products, models, use cases, datasets, and third parties. Each item needs:
- an owner
- version date
- location
- legal role
- supporting record
The model inventory should identify architecture, weights, checkpoints, fine-tunes, retrieval sources, safety layers, evaluations, and releases. The use-case inventory should separate intended purpose from customer conduct. Sales materials, interface design, and implementation support can widen the target's exposure.
The jurisdiction map should record each place of work, sale, use, collection, storage, remote access, and technical support. China review should identify the relevant province, telecom authority, sector regulator, and public-facing status. India review should add each connected state or union territory where local labour, health, gaming, transport, police, or public-sector rules matter.
External law can attach to either target. A China or India company may enter the EU AI Act through Union market placement or output use. Overseas privacy, export, sanctions, and product laws may also follow foreign users, controlled technology, or buyer identity.
Timing requires a separate obligations calendar. It should distinguish operative duties, delayed provisions, draft measures, annual filings, permit renewals, and laws commencing before closing. The buyer should repeat these checks at signing, closing, and material product releases.
Corporate authority, capitalization, investment, and asset location
The buyer must identify which entity owns each asset and owes each obligation. A common brand, shared director, consolidated website, or group repository does not prove legal title.
Counsel should obtain formation records, constitutional documents, registers, capitalization instruments, beneficial-owner information, board approvals, security interests, and insolvency indicators. The review should include:
- options
- convertibles
- side letters
- nominees
- employee equity
- promised interests
AI groups often divide research, payroll, customer contracts, cloud accounts, and intellectual property among affiliates. The entity employing developers may lack an invention transfer. The customer entity may possess only a revocable licence. A founder may control a material account or signing key.
The asset map should connect every repository, model, dataset, patent, brand, domain, customer contract, and compute account to one legal owner. Intercompany assignments, licences, services agreements, and cost allocations need written terms.
China foreign-investment review starts with the 2024 nationwide
negative list and activity-specific rules. The Special Administrative
Measures for Foreign Investment Access (Negative List) (2024 Edition),
NDRC and MOFCOM Order No. 23, applies from November 1, 2024.
Telecommunications, internet content, news, publishing, audiovisual, and
other controlled activities need exact classification.
A consumer-facing AI platform may need an internet-content-provider
filing or a value-added telecommunications licence. Cloud, data-centre,
content-delivery, virtual-private-network, online data-processing, and
information-service functions require service-level review. The
Foreign-Invested Telecommunications Enterprises Provisions, as amended
in 2022, retain ownership limits unless another rule or pilot
applies.
Selected pilot areas relax foreign-ownership caps for specified value-added telecom services. The pilots do not remove content-sector exclusions. Entity location, infrastructure, service type, and licence conditions determine whether a pilot helps the target.
China's Measures for Security Review of Foreign Investment, NDRC and
MOFCOM Order No. 37, can reach a transaction that affects or may affect
national security. Buyer identity, control rights, sensitive technology,
data, critical information infrastructure, and sector ties need early
review.
India corporate diligence should reconcile Companies Act records,
beneficial ownership, charges, board authority, shareholder rights,
foreign investment, and sector caps. Press Note 2 (2026) announced
revised land-border beneficial-ownership treatment. S.O. 2174(E), dated
May 1, 2026, was issued to amend the Non-Debt Instruments Rules. Closing
counsel must verify the Gazette text and current rule before relying on
the relaxation.
The announced rule permits the automatic route for an investor incorporated outside a land-border country where non-controlling land-border beneficial ownership does not exceed 10 percent. Sector caps, conditions, reporting, and resident control requirements remain relevant. An investor incorporated in a land-border country remains subject to the government route.
Change-of-control review in both jurisdictions should cover corporate approvals, telecom and sector permits, government contracts, public grants, leases, security interests, data arrangements, and supplier consents. A share sale can trigger consent even when the operating entity remains unchanged.
Mainland China AI classification and public-facing services
China uses product-specific and function-specific AI rules. Counsel should classify every service before testing compliance. A research model, private enterprise tool, public generative service, recommendation engine, deep-synthesis service, and anthropomorphic companion may receive different treatment.
The Interim Measures for the Management of Generative AI Services
apply when generative technology supplies text, images, audio, video, or
similar content to the public in mainland China. Internal research and
non-public development fall outside Article 2, subject to other
laws.
A provider must use lawfully sourced data and base models. It must
respect intellectual property, obtain consent or another lawful basis
for personal information, and improve training-data quality. Interim
Measures, art. 7.
The provider also bears content-producer and personal-information
duties. It needs user terms, a stated service audience and use, controls
against minor dependence, protection for prompts and logs, complaints,
and a process for unlawful content. Interim Measures, arts. 9-15.
Services with public-opinion attributes or social-mobilisation capacity require a security assessment and algorithm filing. Id. art. 17. The filing and security record:
- should identify the exact model
- version
- service entity
- data sources
- function
- release
- material changes
Regulators can request explanations concerning training-data sources,
scale, type, labelling rules, and algorithm operation. Id. art. 19. The
target should maintain a regulator-ready record rather than reconstruct
one after an inquiry.
Algorithm recommendation providers with public-opinion attributes or social-mobilisation capacity must file within the prescribed period. Material changes and termination require change or cancellation filings. A filing does not constitute state approval or endorsement.
Deep-synthesis providers and technical supporters may face separate filing, labelling, identity, data, security, and content duties. Counsel should determine which entity supplies the technical function and which entity publishes or distributes the output.
The target should reconcile service descriptions across filings, app stores, licences, contracts, privacy notices, model cards, and public claims. Inconsistent descriptions can reveal an omitted filing or an inaccurate risk assessment.
China AI-generated content labels and distribution
The Measures for Labelling AI-Generated and Synthesised Content have
applied since September 1, 2025. They operate with the deep-synthesis
rules, generative AI measures, algorithm rules, and mandatory national
standard GB 45438-2025.
Covered providers must add explicit labels to specified text, audio,
image, video, virtual-scene, and interaction outputs. They must also add
metadata identifying the synthetic attribute, provider, and content
record. Measures for Labelling AI-Generated and Synthesised Content,
arts. 4-5.
Distribution services must inspect metadata and user declarations.
They must label confirmed, declared, or detected synthetic content
according to Article 6. They also need user-declaration tools and
propagation metadata.
App stores must ask whether an app offers AI generation and must
review its labelling materials. Service agreements must explain the
label rules. A provider that supplies an unmarked output at a user's
request needs an agreement allocating the user's labelling duties and
must retain specified logs for at least six months. Id. arts. 7-9.
Users may not maliciously remove, alter, forge, or conceal required
labels. Providers may not supply tools or services for that conduct. Id.
art. 10.
Diligence should test the output at creation, download, API delivery, compression, editing, reposting, and cross-platform distribution. Metadata that disappears during ordinary export or upload can create a current product defect.
The evidence file should contain interface screenshots, output samples, metadata extracts, app-store submissions, user terms, unmarked-output records, retention settings, and filing materials. Marketing claims about watermarking or detection should match measured performance.
China anthropomorphic AI and science-and-technology ethics review
The Interim Measures for the Management of Anthropomorphic AI
Interaction Services have applied since July 15, 2026. They reach
continuous emotional interaction services that simulate human
personality, thought patterns, and communication style for the mainland
public.
The provider must control unlawful or harmful content and prohibited
interaction design. It needs staff, safety systems, lifecycle controls,
training-data records, user procedures, and measures addressing
dependence and emotional risk. Interim Measures for the Management of
Anthropomorphic AI Interaction Services, arts. 8-13.
Minors receive added protection. The rules restrict simulated relatives and partners, require parental consent for users under 14, and call for a minor mode. Id. art. 14. The diligence record:
- should show age signals
- consent
- mode design
- content limits
- use reminders
- escalation
Interaction data receives special treatment. Providers must support
copy and deletion rights. Separate consent is required for specified use
of sensitive interaction information in training. Minor
personal-information handling needs a periodic audit. Id. arts.
16-17.
The interface needs AI identity disclosure, dependence reminders, and
time-use prompts. The provider must support exit, service cessation,
complaints, and emergency handling. Filing and annual verification apply
according to Article 26.
The Measures for AI Science and Technology Ethics Review and Services
(Trial), MIIT Joint Science [2026] No. 75, create a separate review
route for research and technical development that presents ethics risks.
The measure took effect on March 20, 2026.
Projects involving close human-machine integration, behavioural or emotional effects, public-opinion influence, or highly autonomous safety and health decisions may require expert review. The committee can approve, require revision, or reject. Tracking review may occur at intervals not exceeding 12 months.
The buyer should obtain committee composition, conflict records, submissions, minutes, decision letters, conditions, tracking reports, and suspension decisions. An internal product committee does not substitute for the statutory review where the measure applies.
China personal information, automated decisions, and cross-border transfers
The Personal Information Protection Law applies to processing in
China and specified overseas processing concerning people in China.
Overseas processors may need a mainland representative. Personal
Information Protection Law, arts. 3 and 53.
Each processing activity needs a lawful basis under Article 13.
Separate consent can apply to third-party provision, sensitive personal
information, and cross-border transfer. Children under 14 fall within
the sensitive-information rules. Id. arts. 23, 28-31 and 39.
Article 24 governs automated decision-making. The process must be
transparent, fair, and impartial. It may not impose unreasonable
differential treatment in transaction terms. Marketing must provide a
non-personalised option or an easy refusal route.
A person may request an explanation when automated decision-making produces a decision with a major effect on rights or interests. The person may refuse a decision made solely through automated processing. The target should preserve factors, rules, validation, notices, human review, overrides, and outcomes.
A personal-information protection impact assessment is required
before specified sensitive processing, automated decisions, entrusted
processing, third-party provision, public disclosure, export, and other
high-impact activity. Id. arts. 55-56. The assessment should match the
current system and model version.
Cross-border transfer needs a route under Articles 38 to 40. The
Provisions on Promoting and Regulating Cross-Border Data Flows,
effective March 22, 2024, create exemptions and volume-based routes.
A critical information infrastructure operator exporting personal information or important data generally needs a security assessment. A non-CIIO needs an assessment for important data, at least one million individuals' ordinary personal information, or at least 10,000 individuals' sensitive personal information during the calculation period.
A non-CIIO exporting between 100,000 and fewer than one million individuals' ordinary personal information, or fewer than 10,000 individuals' sensitive information, generally uses the standard contract or certification route. Lower-volume transfers may qualify for an exemption, subject to the facts.
Data that has not been identified or notified as important data does not require an important-data assessment solely on speculation. The target should still document its classification, sector notices, and changes.
The buyer should map local storage, remote access, support, telemetry, subprocessors, model providers, and foreign incident response. A mainland server does not resolve an export created by overseas administrator access.
Face-recognition deployments need separate treatment under the Face
Recognition Technology Application Security Management Measures,
effective June 1, 2025. The rules address necessity, separate consent,
alternatives, local-device storage, impact assessment, security, and
public-place deployment. Training and research fall outside the
measure's direct scope, but PIPL and other laws still apply.
China training rights, cybersecurity, licences, and controlled technology
Publicly available material does not become free training data. The target must prove:
- copyright permission
- personal-information lawfulness
- contract rights
- confidentiality
- trade-secret protection
- compliance with content and state-secrecy rules
China's Copyright Law does not contain a broad commercial
text-and-data-mining exception for AI training. Counsel should review
each source, licence, access route, copying act, model output, and
market effect. Internal policy cannot replace a statutory exception or
licence.
Employee and contractor title needs signed records. Patent files
should identify human inventors, service inventions, assignments,
disclosure, grants, and government or university rights. Trade-secret
protection depends on secrecy measures under the Anti-Unfair Competition
Law and the Commercial Secret Protection Provisions effective June 1,
2026.
The cybersecurity file should classify networks, data, important
data, critical information infrastructure, commercial cryptography, and
sector systems. The revised Cybersecurity Law has applied since January
1, 2026. The Network Data Security Management Regulations have applied
since January 1, 2025.
Regulated systems may need multilevel protection filings, security assessments, domestic storage, cryptography review, vulnerability processes, real-name controls, content records, and incident reports. The exact duty depends on the network, data, operator, and sector.
The target should maintain one incident record covering personal-information breaches, cyber incidents, unsafe outputs, illegal content, model leakage, data poisoning, prompt injection, extraction, outages, and regulator contacts. Each entry should state discovery, scope, containment, notices, cause, correction, and recurrence testing.
China export review should cover source code, model weights, training
methods, architecture, technical data, encryption, chips, servers,
remote access, research collaboration, and buyer diligence. The Export
Control Law, the Dual-Use Items Export Control Regulation, State Council
Order No. 792, and the current control lists apply according to item,
destination, end user, and end use.
The Catalogue of Technologies Prohibited or Restricted from Export was adjusted from July 15, 2025. A licence or technology-export contract process may apply even when no physical item leaves China. Data-room access can therefore require classification before disclosure.
Sector licences remain separate. Medical-device software, internet maps, autonomous vehicles, finance, education, news, publishing, audiovisual services, healthcare, and public procurement each need a dedicated workstream.
India current AI position and synthetic-content duties
India has no operative cross-sector private AI act. Existing statutes and sector rules govern present conduct. The national AI guidelines issued in November 2025 are:
- nonbinding and favour use of existing law
- sector action
- targeted changes
- voluntary controls
- testing arrangements
The target should identify every claim that it follows those guidelines. Board papers, risk records, testing, incident processes, and customer materials should support the claim. Voluntary guidance can become contractually relevant through tenders, policies, or warranties.
Binding AI-specific content duties now arise under the Information
Technology (Intermediary Guidelines and Digital Media Ethics Code)
Rules, 2021, as amended by G.S.R. 120(E). The amendment took effect on
February 20, 2026.
The amendment defines synthetic generated information by reference to algorithmically created or modified audio, visual, or audiovisual content that appears authentic. Routine good-faith editing, accessibility work, and document preparation can fall outside the definition when they do not materially misrepresent content.
An intermediary offering tools that can create synthetic generated information must use appropriate technical measures against specified unlawful content. It must prominently label other synthetic generated information and preserve metadata or provenance data where technically feasible.
The service should not facilitate removal of the required label, metadata, or unique identifier. Significant social-media intermediaries must obtain user declarations, deploy verification measures, and label content confirmed as synthetic under the amended rules.
Diligence should test creation, upload, distribution, re-encoding, download, reposting, and user removal. The file should contain:
- interface records
- model versions
- label specifications
- metadata samples
- user declarations
- verification tests
- complaint handling
- takedown records
Draft April 2026 amendments remain proposals. They should not appear as current defects. The buyer should track the final text where closing or integration extends into the consultation period.
India data protection and automated decisions
The Digital Personal Data Protection Act 2023 and Digital Personal
Data Protection Rules 2025 use phased commencement. The Data Protection
Board and selected institutional, definition, exemption, and procedural
provisions have applied since November 13, 2025.
Consent-manager registration duties begin on November 13, 2026. Most substantive processing duties begin on May 13, 2027. Those later duties cover:
- notice
- consent
- legitimate uses
- accuracy
- security
- breach notification
- deletion
- rights
- children
- significant data fiduciaries
- cross-border processing
The current diligence report should separate present compliance from readiness. A July 2026 failure to meet a May 2027 duty is not yet a statutory breach. It can still impair valuation or integration where the system cannot be remediated before commencement.
The DPDP Act does not create a general right to reject an automated decision. Other laws may require:
- reasons
- fair procedure
- human review
- or non-discrimination in credit
- employment
- insurance
- public administration
- consumer services
- regulated sectors
When the government designates a Significant Data Fiduciary, section
10 will require a data-protection officer, impact assessments,
independent audits, and due diligence concerning algorithms used to
process personal data. The target should model designation risk using
data volume, sensitivity, harm, sovereignty, electoral, security, and
public-order factors.
The readiness file should identify each data fiduciary and processor, purpose, notice, legal basis, child-data use, retention, security, transfer, and grievance route. It should include:
- consent records
- processor contracts
- technical deletion
- breach playbooks
- product changes needed by May 2027
India training rights, cybersecurity, telecom, and geospatial data
India's Copyright Act 1957 does not contain a broad commercial
text-and-data-mining exception. Section 52 fair dealing applies to
listed purposes, including private or personal use comprising research,
criticism or review, and current-event reporting. It does not create a
general commercial training licence.
Each training source needs a rights analysis. The target should document lawful access, copying, licence scope, confidentiality, personal data, output similarity, and market substitution. The November 2025 AI policy record itself identifies copyright reform as a possible future issue, not an enacted defence.
Copyright ownership and transfer require review under sections 17 to 19. The buyer should obtain founder, employee, contractor, university, affiliate, and grant assignments. Patent files should identify:
- inventors
- assignments
- government rights
- foreign-filing permissions
- prior disclosure
CERT-In's April 28, 2022 directions apply to listed service providers, intermediaries, data centres, bodies corporate, cloud providers, virtual private server and network providers, virtual-asset service providers, and government bodies. Covered cyber incidents must be reported within six hours after notice or detection.
The initial report may use the information then available, followed by supplements. A customer or vendor contract cannot transfer away the reporting duty. The target should retain incident timing, scope, communications, logs, root-cause work, and closure evidence.
Telecom and internet functions need classification under the
Telecommunications Act 2023 and the 2026 principal-service authorisation
rules. A pure software service is not automatically a telecom service.
Internet access, messaging, IoT, machine-to-machine connectivity,
network operation, numbering, or communication functions may require
authorisation.
Location and mapping systems need review under the 2021 geospatial guidelines. Those guidelines expressly cover AI-enabled geospatial technology. They distinguish Indian entities and regulate specified high-accuracy or sensitive datasets, acquisition, storage, and dissemination.
Foreign-owned or foreign-controlled structures need particular attention. Product design, data resolution, local storage, API access, street imagery, surveying, drones, and export functions can alter the answer.
Cloud contracts should cover data location, supplier training, subprocessors, security, deprecation, price changes, suspension, portability, incident cooperation, and exit support. Financial, telecom, health, defense, and government customers may impose added localisation and audit duties.
Regulated uses, product claims, employment, and children
Sector classification can decide transaction viability. Counsel should identify:
- every deployment in finance
- credit
- insurance
- healthcare
- medical devices
- telecom
- mapping
- transport
- education
- employment
- public administration
- policing
- defense
- critical infrastructure
China high-impact uses may trigger sector permits, security reviews, content duties, local storage, or state procurement terms. India sector regulators apply existing law and may use circulars, licence conditions, outsourcing rules, cybersecurity directions, and supervisory examinations.
India securities firms, exchanges, clearing corporations, mutual funds, and research analysts face SEBI rules or reporting duties concerning AI and machine learning. The exact regulated entity, model use, customer effect, outsourcing, and record must be identified.
India medical AI may qualify as software within the Medical Devices Rules 2017 when intended for diagnosis, prevention, monitoring, treatment, or alleviation. The file should contain:
- intended purpose
- risk class
- licence
- clinical evidence
- change control
- cybersecurity
- post-market records
Financial and insurance AI needs separate review in both jurisdictions. Credit scoring, underwriting, fraud detection, advice, portfolio management, payments, and collections can trigger licence, explanation, fair-treatment, model-risk, outsourcing, and recordkeeping duties.
Employment AI should cover recruitment, ranking, monitoring, scheduling, productivity, promotion, pay, discipline, and dismissal. The target should provide feature lists, validation, subgroup testing, notices, appeals, override records, and vendor communications.
A vendor cannot allocate every discrimination or employment duty to the customer. Product design, claims, known limits, and supported uses remain relevant. The employer still needs enough information to make a lawful decision.
Children's products need age analysis, parental processes, profiling controls, advertising limits, retention, crisis response, and human escalation. China imposes specific under-14 and minor-mode duties in several measures. India's child-data rules largely begin with the main DPDP commencement, while current child-protection, intermediary, criminal, and consumer laws still apply.
Marketing claims need dated support. Claims about accuracy, bias, privacy, training rights, security, certification, human review, output ownership, and benchmark rank should identify:
- the model
- test set
- prompts
- sample
- exclusions
- threshold
- result
- approver
A disclaimer does not cure a contradictory headline, demo, tender answer, or salesperson statement. Synthetic-content, AI-filing, licence, and certification claims should identify the exact authority, scope, version, and status.
Competition, investment, exports, and sanctions
China's merger-control thresholds use the State Council Provisions on
Thresholds for Notification of Concentrations of Undertakings, Order No.
773. Filing can arise when combined worldwide turnover exceeds RMB 12
billion and at least two parties each exceed RMB 800 million in China.
It can also arise when combined China turnover exceeds RMB 4 billion and
at least two parties each exceed RMB 800 million in China.
The State Administration for Market Regulation can investigate a below-threshold transaction that may restrict competition. The buyer should obtain turnover, market share, control rights, data concentration, compute access, platform links, and prior acquisitions.
India's Competition Act sections 5 and 6 create a suspensory merger
review. A transaction above INR 2,000 crore can trigger the deal-value
threshold when the target has substantial business operations in India.
Current asset, turnover, exemption, control, and connected-transaction
rules require a live calculation.
Foreign-investment review needs buyer ownership, beneficial ownership, government links, sector caps, sensitive technology, data, and control rights. An automatic-route filing does not resolve a sector permit, security concern, or land-border beneficial-owner issue.
Export review in both markets should occur before the buyer receives
controlled material. China uses the Export Control Law, dual-use
controls, technology catalogues, encryption rules, and sector
restrictions. India uses the Foreign Trade (Development and Regulation)
Act 1992, Foreign Trade Policy 2023 Chapter 10, and the current SCOMET
list.
The review should classify software, source code, weights, architecture, technical data, encryption, chips, drones, autonomous functions, military or dual-use capabilities, remote access, end users, and end uses. Buyer-home and supplier-country rules may impose separate re-export duties.
Sanctions and restricted-party screening should cover parties, beneficial owners, controllers, banks, customers, suppliers, destinations, services, and payments. Local law and the buyer's home-country law need separate tests. Screening should continue through closing.
Third-party dependencies, contracts, incidents, and continuity
The target needs a dependency register beyond a software bill of materials. It should cover:
- code
- open-weight models
- hosted models
- datasets
- benchmarks
- APIs
- cloud
- accelerators
- content filters
- identity services
- security tools
Each record should identify the version, supplier, accepted terms, paying entity, actual use, transfer rights, and replacement plan. The review should test:
- training
- fine-tuning
- distillation
- outputs
- redistribution
- attribution
- audit
- suspension
- termination
- assignment
- change of control
An open-source or open-weight label does not answer those questions. The exact licence and integration method control. Acceptable-use terms may bar a sector, person, location, or content category.
Contract diligence must prove assent, scope, performance, and transferability. Counsel should obtain executed orders, clickwrap records, amendments, procurement terms, API terms, reseller agreements, research contracts, cloud contracts, and incorporated policies.
AI clauses should address:
- customer data
- prompts
- logs
- training
- outputs
- confidentiality
- security
- incidents
- model changes
- documentation
- human review
- audits
- indemnities
- caps
- assignment
- termination
- transition
The terms should match conduct. A no-training promise is dangerous when support logs feed evaluation. A customer-control clause is weak when the target markets autonomous operation.
Revenue quality requires contract-to-ledger testing. Counsel should separate production revenue from pilots, free use, credits, related-party sales, minimum commitments, contingent milestones, and token proceeds.
Continuity depends on compute, models, data, licences, suppliers, and key people. The review should test:
- capacity
- minimum spend
- deprecation
- price changes
- suspension
- portability
- recovery
- filing continuity
- concentrated knowledge
Findings and transaction protections
Each finding needs a legal rule, evidence status, business effect, and deal response. A colour alone does not answer whether the activity can continue or transfer.
Stop-level findings include:
- missing title to a core model
- unlawful irreplaceable training data
- absent mandatory filing
- unlicensed regulated activity
- prohibited content or use
- a blocked foreign investment
- an export restriction
Other stop-level findings include a non-transferable critical model or cloud right, false regulatory claims, material hidden incidents, or a government contract that terminates at closing.
Closing conditions fit curable defects. Common items include:
- assignments
- consents
- licence approvals
- investment and merger filings
- algorithm filings
- security assessments
- privacy assessments
- labels
- human-review procedures
- incident correction
- supplier amendments
- access cleanup
Price adjustments, escrow, holdbacks, exclusions, specific indemnities, and post-closing covenants fit quantified legacy exposure. General warranties offer weak protection for a known defect.
Representations should cover:
- authority
- capitalization
- title
- data rights
- AI classification
- filings
- automated decisions
- product claims
- security
- incidents
- employment
- licences
- contracts
- sanctions
- exports
- investment review
- competition
- disputes
Disclosure schedules should identify exact entity, model, dataset, licence, filing, policy, and contract versions. Product names alone are inadequate. The seller should distinguish verified facts, management assertions, disputed matters, and unresolved items.
Interim covenants should restrict material model releases, dataset changes, new public-facing functions, new high-impact uses, supplier changes, unapproved claims, and unusual customer exceptions. They should require prompt notice of incidents, complaints, regulator contact, and legal changes.
Open items need an owner, due date, evidence standard, closing effect, and escalation route. The closing bring-down should repeat licence, data, filing, cyber, copyright, investment, merger, export, sanctions, and commencement checks.