In this Post...

When the EU AI Act entered into force on 1 August 2024, it did not instantly make every AI-related obligation applicable. But it did make AI governance a real M&A issue.

For deal teams, that distinction matters. A draft law, a political agreement, and an enacted regulation are not the same thing. By August 2024, Regulation (EU) 2024/1689 had been published in the Official Journal and had entered into force. The European Commission stated that the AI Act would become fully applicable two years later, on 2 August 2026, with certain exceptions applying earlier. The regulation introduced a risk-based framework for AI systems and created a new governance context for organizations that develop, deploy, buy, sell, or integrate AI-enabled businesses.

In M&A, the immediate implication was not that every transaction suddenly required a full AI Act compliance audit. The more practical point was that AI was no longer only a technology diligence topic. It became a governance, risk, compliance, data, operating model, and integration topic.

AI moved from product feature to diligence workstream

Before the AI Act, many deal teams treated AI in one of three ways. In technology deals, they reviewed AI as part of product and IP diligence. In non-technology deals, they often treated AI as a productivity tool or innovation theme. In commercial diligence, they assessed whether AI could affect market positioning, cost structure, or competitive advantage.

The AI Act forced a broader question: what AI systems does the target use or provide, what risks do they create, who is responsible for them, what data do they rely on, what documentation exists, and what obligations may apply over time?

This is particularly important because AI risk is rarely isolated. It can touch data protection, employment processes, customer communications, regulated products, cybersecurity, vendor contracts, model governance, auditability, and post-close integration.

What M&A teams needed to ask in 2024

A historically safe 2024 diligence approach should have focused on inventory and governance rather than pretending that later obligations were already fully in force. The right questions included:

  • Which AI systems are used internally, embedded in products, or provided to customers?
  • Who owns AI governance, documentation, testing, approval, and monitoring?
  • Which data sets are used, and are there restrictions on how confidential, personal, or customer data may be processed?
  • Are any AI systems likely to fall into higher-risk categories under the regulation?
  • Are vendors, model providers, or subprocessors involved, and what contractual rights exist?
  • Can outputs be explained, challenged, audited, or overridden by responsible humans?
  • What remediation, documentation, or integration work may be needed after closing?

Those questions can be grouped into four practical diligence buckets:

  • AI inventory and use cases;
  • data sources and processing permissions;
  • risk classification and human oversight;
  • post-close remediation and integration actions.

AI governance is also an integration issue

The AI Act did not only affect whether a target was compliant at signing. It also affected how the buyer could integrate the target after closing. If the buyer has its own AI policies, data architecture, model-risk framework, procurement process, or customer commitments, the target's AI systems must be mapped into that environment.

This is where M&A teams often underestimate complexity. AI tools may sit inside functions, products, customer support processes, sales workflows, HR systems, analytics platforms, or third-party SaaS tools. A clean integration plan requires more than a list of tools. It needs ownership, permissions, data-flow mapping, risk classification, documentation status, and human approval points.

How to keep the analysis proportionate

Not every deal requires the same depth of AI diligence. A software company selling AI-enabled products needs a different review from an industrial company experimenting with internal productivity tools. But every serious M&A team should know whether AI is material to the target's value, risk profile, operating model, regulatory exposure, or integration plan.

The most useful 2024 approach was proportionate governance: identify the AI estate, classify materiality, assess data and vendor risk, define open issues, and assign responsibility for follow-up before and after closing.

Where smartmerger.com fits

smartmerger.com's positioning around structured data, permission-based collaboration, and human verification is directly relevant to AI governance in M&A. AI cannot be responsibly applied to confidential transaction work if the underlying information is chaotic, access is uncontrolled, or decisions cannot be traced back to evidence.

In an end-to-end M&A workspace, AI-related diligence can be handled as part of a governed process: requests, answers, source documents, findings, risk classification, ownership, legal review, integration actions, and approval points can be connected. That supports the central principle for AI in M&A: AI may assist analysis and workflow, but professional judgment, legal review, and deal accountability remain human responsibilities.

Want to turn fragmented M&A work into a governed end-to-end process?

Talk to smartmerger.com

A practical AI governance workstream

For a 2024 transaction, a proportionate AI governance workstream could be built around five artifacts. First, an AI inventory that identifies systems used or sold by the target. Second, a data-use map showing what information those systems process. Third, a vendor and model-provider overview. Fourth, a risk and materiality assessment tied to the deal thesis. Fifth, an action log for remediation, documentation, policy alignment, or integration decisions after closing.

This should not be treated as a compliance-only exercise. AI can affect value. A target with strong AI governance may have more defensible products, better customer trust, and clearer scalability. A target with weak governance may carry hidden remediation cost, customer-contract exposure, employee-relations risk, or integration friction. The deal team should therefore connect AI governance to valuation, representation and warranty review, operating model planning, and post-close controls.

For the deal team, the output should be simple:

  • what is known;
  • what is assumed;
  • what is not yet verified;
  • what must be owned before or after closing.

What not to overstate

It would be historically wrong to write a 2024 post as though all AI Act obligations were already fully applicable. It would also be wrong to imply that every use of AI creates the same risk. The stronger editorial position is more disciplined: the AI Act made governance visible, and M&A teams needed to start building the diligence questions and data structures that would allow them to respond as obligations phased in.

The practical takeaway

The EU AI Act made AI governance part of the M&A agenda because it changed the questions deal teams needed to ask. The winning response was not panic and not hype. It was structured diligence: know which AI systems exist, understand who controls them, assess how they use data, document what remains uncertain, and carry unresolved issues into signing, integration, and post-close governance.

Michael Klawon

Michael Klawon

CEO and Founder of smartmerger.com

View Profile

Article Topics

EU AI Act
M&A Governance
AI in M&A
Regulation