AI Diligence

What strangers ask about your AI, and what an organization must be able to show them

For fifty years, a buyer's questions about a target's technology arrived through familiar channels. Intellectual property. Privacy. Cybersecurity. Contracts. Whatever the technology was, it could be routed into one of those lanes and examined by someone who had examined a hundred like it.

Artificial intelligence does not route cleanly. A model drifts without a line of code changing. Training data carries obligations no one inventoried. An agent built by an enthusiastic colleague runs in production without anyone in IT having known. And AI has broadened the field of organizations facing these questions far beyond private firms in the middle of a transaction.

The legal profession noticed first, and responded the way it responds to any durable change in risk, by writing down what to ask. The clearest statement of that checklist comes from Danny Tobey, Sean Fulton, and Coran Darling of DLA Piper, whose December 2025 framework sets out, area by area, what buyers and their counsel now look for in a target's AI. It is thorough, it is in use, and it is not going away.

published work

Cover of the Center for Trustworthy AI whitepaper "Strangers at the Gate: AI Diligence and the Organizations That Survive It," showing a lit sandstone arch under a starry night sky.

This project takes up the other side of the table. Strangers at the Gate argues that AI diligence is an assessment of AI maturity performed by strangers, under time pressure, with an organization's valuation, legal status, or existence at stake, and that every item on counsel's list is either an artifact a well-run AI program already produces in the ordinary course of its work, or evidence that no such program exists. Counsel is not really asking about the AI. They are asking how the organization runs.

The paper covers:

  • Four theses on what the legal frameworks leave to the technology side, among them the materiality inversion: why thin AI use warrants a harder question rather than a lighter look

  • Three on-ramps to a single target state, for organizations facing diligence in weeks, in eighteen months, or not at all

  • The evidence stack: what must exist inside an organization regardless of who asks, and when

  • Who owns what, and how the technology side works with counsel rather than around them

  • An appendix crosswalking counsel's demand areas to the dimensions of Centru and to the artifacts each one calls for

The full crosswalk behind that appendix is maintained as part of this project and encoded into Centru, the Center's openly published strategic reference model, where it is versioned as the model and the law move.

© Center for Trustworthy AI. This site is hosted by Cloud Lighthouse Limited for the Center for Trustworty AI.