You Are Buying a Model You Cannot Retrain
Most defects found after closing are expensive. A training-data defect is different: it lives inside the asset, and the only remedy is to rebuild the thing you just paid for. Ask early whether that is even possible.
If a provenance problem surfaces eighteen months from now, can this model be retrained without it?
A yes makes provenance an indemnifiable cost you can size. A no makes it an existential question about the asset, because there is no remediation at any price — and the answer is no far more often than buyers expect, because early-stage teams do not retain corpora they never anticipated having to defend.
Seven Requests a Standard IP Checklist Omits
Conventional technology diligence was built around code, contracts and registrations. It handles those well and is largely blind to the artefacts that carry AI value — the corpus, the weights, the labels and the dependency. Each request below has a characteristic finding attached, because these are patterns rather than possibilities.
Corpora assembled early with no records, scraped sources under terms prohibiting automated collection, and a licensed dataset whose terms cover research but not commercial deployment.
This is the only defect you cannot engineer around after closing. Everything else is a cost; this is a question of whether the asset is what it was described as.
Weights whose training run cannot be repeated — the corpus was not retained, the pipeline drifted, or the key engineer left with the tacit knowledge.
If a provenance problem is found later, remediation requires retraining. A model that cannot be rebuilt has no remediation path at any price.
No-training clauses, prohibitions on cross-customer benefit, and deletion commitments that reach derived artefacts including embeddings and evaluation sets.
These commitments transfer with the contracts and can invalidate the data-advantage thesis behind the valuation.
Purpose statements written narrowly, no mention of model training, and no contemplation of transfer for a buyer's different use.
The permission you inherit is the one given at collection. A current notice that has been broadened does not retroactively license the existing corpus.
A product whose margin depends on one provider's pricing, with termination for convenience, no version pinning and no change-of-control consent.
A dependency the seller manages by relationship becomes a commercial exposure the moment ownership changes and the relationship does not transfer.
Acceptable-use restrictions binding downstream users, pass-through obligations, and conditions that engage above a scale threshold the buyer already exceeds.
Compliance can be satisfied by the target and breached by the acquirer on day one, without anyone changing a line of code.
Contractor agreements missing assignment language, and platform terms where the labelling vendor retains rights in the annotations.
Labels are often the genuinely proprietary asset. Ownership gaps here are cheap to find now and expensive to discover during a later financing.
Representations That Breach Cleanly
A representation is only as useful as the argument it forecloses. General adequacy language survives negotiation because it costs the seller little to give — and it costs the buyer everything when the dispute arrives, because both sides can argue about what was necessary or material. Representations tied to a schedule do not have that problem.
The company owns or has a valid right to use all intellectual property necessary to conduct its business.
The datasets listed on Schedule X constitute all data used to train, fine-tune or evaluate the models listed on Schedule Y, and the company holds the rights described for each.
The first is satisfied by a good-faith belief. The second breaches the moment an unscheduled dataset appears, and points at a specific artefact.
The company complies in all material respects with applicable privacy laws.
No customer or personal data has been used to train or fine-tune any model except as identified on Schedule X, and each such use was permitted by the privacy notice and contract terms in force at the time of collection.
Compliance representations are argued about. A specific factual statement about training inputs is verified or not.
The company's software does not infringe the rights of any third party.
The third-party model and licence terms on Schedule Z are complete, unmodified and in force, and the company's use complies with each, including any acceptable-use and scale-based conditions.
Names the actual instrument. Scale-based conditions are the term most likely to be breached by the buyer rather than by the seller.
The company maintains its technical records in the ordinary course.
The models on Schedule Y can be reproduced from materials in the company's possession, including retained training data, pipeline code and configuration.
Converts remediation feasibility from an assumption into a warranted fact — which is what makes any indemnity on provenance meaningful.
Diligence Can Destroy Your Own Coverage
Representation and warranty insurance covers unknown breaches. It excludes known risks by design, and underwriters have started treating training-data provenance and generative-output infringement as areas requiring specific diligence evidence before they will follow.
That produces an uncomfortable dynamic. Thin diligence invites a broad exclusion. Thorough diligence that identifies a provenance gap and then leaves it unresolved converts a coverable unknown into an uncovered known. The way through is to resolve what you surface — obtain the licence, remove the dataset, or price it — and where it cannot be resolved, deal with it directly through a specific indemnity with dedicated escrow sized to the cost of retraining, rather than assuming a general cap will absorb it.
The Post-Closing Failure Nobody Schedules
A quieter failure mode arrives at integration. The target's data was collected under notices and contracts describing its service. The buyer, reasonably, wants to combine it with existing datasets, apply it to adjacent products or use it for training at group scale. None of that is authorised by the permission that came with the data, and the integration plan usually assumes it is. Ask during diligence what the buyer intends to do with the data after closing, then check that intention against the notices as they existed at collection — before the number in the model depends on an answer nobody has verified.
Related Reading
- Source code escrow for AI models — the same reproducibility question, asked by a customer instead of a buyer.
- What happens to your data when an AI vendor fails — an involuntary transfer with the same permission problem.
- Acquihires and merger review — the regulatory half of the same transaction.
Buyers Read Your Site Before Your Data Room
Claims about proprietary datasets, model ownership and privacy commitments live across product pages, trust centres and old posts — and they are compared line by line against your disclosure schedules.
See every claim your site makes in one pass. Run a free scan before someone builds a diligence question out of one.
This article is general information and not legal advice. Transaction structures, applicable law, licence terms and insurance products vary substantially, and nothing here should be relied on as a statement of what any agreement or policy provides. Consult qualified transactional counsel before relying on any conclusion here.