{
  "id": 11006756,
  "title": "AI Is Changing How Buyers Assess Risk in Tech Deals",
  "url": "https://urgent.news/2026/09/30/ai-is-changing-how-buyers-assess-risk-in-tech-deals",
  "topic": "ai",
  "section": "AI",
  "published": "2026-09-30T18:12:36.000Z",
  "source": {
    "name": "Newsweek",
    "slug": "newsweek",
    "url": "https://www.newsweek.com/ai-is-changing-how-buyers-assess-risk-in-tech-deals-12467021"
  },
  "original_language": "en",
  "account": "When companies acquire software firms, the financial statements often only provide a partial view of the transaction. While revenues, margins, and liabilities are known quantities, the underlying technology can be far more complex. As artificial intelligence continues to play an integral role in software development, including code creation, buyers must expand their due diligence scope. The technology can bring licensing issues, security vulnerabilities, and technical debt—future costs stemming from suboptimal short-term solutions—to the forefront, potentially impacting the deal's execution post-closure.\n\nBuyers need to not only ascertain the type of technology being acquired but also the manner of its development and its ability to support the deal's assumptions. FossID, a software audit firm, reports that startups are increasingly requesting code audits before acquirers approach, enabling them to validate the defensibility of their intellectual property and address potential issues prior to the due diligence process. This growing emphasis on code provenance, especially in the context of AI-assisted development, underscores its pivotal role in M&A transactions.\n\nBlack Duck, a software security provider offering tools for open-source software analysis and risk assessment, highlights that software due diligence emerges as a way for buyers to identify legal, security, and operational risks before the transaction finalizes. Recent research by Black Duck reveals that open-source software is present in 98% of its audited software projects and in every M&A transaction reported. Notably, license conflicts were identified in 94% of transactions, while 97% contained unpatched vulnerabilities. These findings underscore the breadth of potential issues buyers may encounter during the evaluation of the technology behind a software business.\n\nJoris Limousin, founder of DueDelta—a tech due diligence firm—observes that investors are increasingly focusing on the implications of technical findings for the investment itself. Due diligence is shifting from merely identifying a list of problems to understanding their significance for the investment case, encompassing architecture, security, technical debt, engineering teams, and third-party components. The impact of AI introduces additional complexity, prompting buyers to question how AI tools are governed, the data shared with external models, and whether generated code has undergone the same scrutiny as other software.\n\nSoftware audit firms aid buyers in identifying open-source dependencies, licensing risks, and security vulnerabilities without exposing proprietary source code. For sellers, conducting technical diligence before the acquisition talks commence offers an opportunity to rectify vulnerabilities before the buyer initiates its formal review. Ultimately, early detection of these risks enables buyers to allocate necessary post-closure resources or negotiate more favorable contractual safeguards, while sellers can resolve vulnerabilities before the buyer's formal assessment begins.",
  "summary": "AI and increasingly complex software are making it harder for buyers to establish exactly what technology they are acquiring.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}