AI Risk Considerations in Pre-Investment Diligence
9/30/20263 min read
Most businesses now use AI in their daily operations. Some applications pose minimal risk, while others may be legally questionable. What should investors evaluate during pre-investment diligence?
What matters most is how the company uses AI. High-risk uses invite regulatory and civil liability, and when risks are identified, investors need to understand how the company’s governance mitigates them.
Examples of High-Risk Uses of AI
The categories below track the risk tiers in the EU AI Act, which is a useful benchmark even for companies with no EU footprint. They also overlap with many of the AI rules emerging in the US. Under this framework, some practices are prohibited outright, some are classified as high-risk and carry heavy compliance duties, and others (such as chatbots and deepfakes) mainly trigger transparency obligations.
Retail
Ø Biometric systems used for remote identification, such as monitoring for shoplifting or scoring in-store customers.
Ø Untargeted scraping of facial images.
Advertising and Marketing
Ø Heavy use of chatbots, AI agents, customer service bots, or virtual avatars where users do not always know they are talking to a machine.
Ø Emotion-recognition AI, such as a call center analyzing customer tone.
Ø Subliminal or manipulative techniques.
Ø Publishing deepfakes, meaning synthetic images, audio, or video that resemble a real person.
Banking and Insurance
Ø AI used to evaluate eligibility for credit or to assess insurance risk, where the decision materially affects someone’s access to services.
Ø AI used to target vulnerabilities tied to age, disability, or socio-economic circumstances.
Infrastructure
Ø AI used as a safety component in managing or operating critical infrastructure, such as energy, water, or transport networks, where failure could endanger life or the environment.
Education and Vocational Training
Ø AI used for admissions or access decisions, evaluating learning outcomes, assessing the appropriate level of education for someone, or monitoring students for prohibited behavior during tests, which may include AI detection software.
Human Resources
Ø AI used in recruitment, such as screening or ranking candidates.
Ø AI used in decisions affecting the terms of employment, promotion, or termination.
Ø AI used for task allocation and monitoring of workers.
Healthcare and Life Sciences
Ø AI used for diagnosis, triage, or treatment recommendations, or embedded in medical devices.
Ø AI trained on patient data without a clear legal basis or adequate de-identification.
Essential Public and Private Services
Ø AI used to determine eligibility for public benefits, housing, or other essential services.
Ø AI used to triage or prioritize emergency calls and responses.
Generative AI and Intellectual Property (All Sectors)
Ø Models trained on copyrighted, scraped, or otherwise unlicensed content.
Ø Code-generation tools that may introduce open-source license obligations into proprietary software.
Ø Employees pasting confidential, client, or personal data into public AI tools.
Questions to Ask in Diligence
Once you identify a high-risk use, probe these areas to gauge how well the company understands AI risk and what it is doing to mitigate it. The same questions apply to any company that uses AI.
Ø Inventory. Does the company maintain a current list of every AI system it builds, buys, or embeds, including tools adopted informally by individual teams?
Ø Classification. Has each system been assessed against applicable risk categories, and is that assessment documented?
Ø Data provenance. What data trained and feeds each system? Was it collected lawfully, with the consents and licenses needed for that use?
Ø Vendors and models. Which third-party models and APIs does the business depend on? What do the contracts say about liability, data use, audit rights, and continuity if a provider changes terms or exits?
Ø Governance and oversight. Who owns AI risk? Are there written policies, human review of consequential decisions, and a clear escalation path?
Ø Testing and monitoring. Has the company tested for bias, accuracy, and drift, and does it keep records that would stand up to a regulator or plaintiff?
Ø Transparency. Are customers, employees, and applicants told when AI is involved in a decision or interaction, and can they contest the outcome?
Ø Incident and complaint history. Have there been regulatory inquiries, customer or employee complaints, litigation, or internal incidents involving AI?
Ø Jurisdictional footprint. Where are the affected people located? EU rules can reach non-EU companies, and a growing set of US state and local laws may also apply.
Ø Intellectual property. Who owns AI-generated output, and is the company exposed to claims over training data or open-source licensing?
Ø Security. How are models, prompts, and training data protected against leakage, poisoning, and misuse?
The Bottom Line
The goal is not to avoid AI. It is to understand where it creates risk and where it creates value. A target with a clear inventory, sound governance, and well-documented data practices shows a commitment to good governance, and that discipline can be a genuine strength in an investment case.
How ESG Administration Can Help
ESG Administration (ESGA) helps companies develop AI policies that identify high-risk areas and show how the company's governance mitigates them. ESGA uses the ISO 42001 framework to create cost-effective, plain-language policies that IT teams and senior management can implement quickly.
To learn more about ESGA, contact Joe Holman at joe.holman@esgadmin.com.How ESG Administration can help
ESGA Outsourcing
ESGA seamlessly manages your financial responsibilities and reporting obligations, allowing you to focus on growing your core business.
INQUIRIES
© 2026. All rights reserved.