You Bought the Model, Not the Company. The Violation Came Anyway
An asset purchase is the structure people reach for when the target's compliance history looks uncertain. It works better for debts than for data. When the asset is a model, a training corpus or a scoring system, the thing that created the exposure is the thing you just bought and switched on.
The default, and the four ways past it
A buyer of assets generally does not inherit the seller's liabilities. The exceptions are long-settled and, read next to a typical AI acquisition, uncomfortably well-fitted.
The agreement says you take it, or the conduct around closing says so. Assuming the seller's customer contracts wholesale can drag in the obligations those contracts created about how customer data may be used.
This is the exception most within your control and the one most often lost in a schedule nobody re-read after the third markup.
Continuity of enterprise, management and ownership, the seller ceasing operations, and the buyer assuming the obligations needed to keep the business running. Paying in buyer equity and absorbing the founders points hard at this.
Courts weigh substance over the label on the document. A transaction that leaves nothing of the seller behind but a name is a candidate regardless of what the cover page says.
One enterprise carrying on under new ownership: same product, same team, same customers, same model in production, different letterhead.
Acquihires of AI teams are close to the archetype. The more of the target you needed in order to make the asset work, the more this exception is available to a claimant.
A sale arranged to put assets beyond the reach of creditors or claimants, particularly at less than reasonably equivalent value while claims were pending or foreseeable.
A known regulatory inquiry at the target, a fast close and a price that ignores it is the pattern that invites this argument — and the inquiry is exactly what diligence is for.
Some liabilities are contractual. Some are the asset.
The distinction that decides how much the deal structure helps you is whether the liability is a claim against the seller or a defect inside the thing being sold. An asset purchase is good at leaving the first kind behind and bad at the second, because you keep using the defective thing after closing.
Biometric records collected without consent
Travels. The statutory defect is in how the records were obtained and retained; possession passes to you along with the retention and destruction duties. This is the single most common inherited AI exposure in US deals.
A hiring or lending model with no validation record
Travels. The claim is about the decisions it makes, and it will make them for you. Absence of a validation study is also the fact that makes the claim hard to defend.
Training corpus of uncertain provenance
Travels, in the practical sense that the rights problem is embedded in the weights you now run. Contractual indemnities help only while the counterparty exists.
Privacy notices that never disclosed the AI use
Travels to the extent you keep processing the same personal data for the same purpose. The consumers whose data you acquired were told something, and it was not about you.
An unpaid compute bill or a disputed vendor invoice
Does not travel, ordinarily. This is the liability class the asset-purchase structure genuinely handles.
A pending administrative inquiry into the seller
Depends entirely on structure and on whether the conduct continues. It is also the finding that should move price rather than be papered over with a rep.
The closing mechanics that do real work
Representations allocate risk between two parties. They do not bind the regulator or the class, and they are worth what the seller is worth at the moment you need them. The protections that survive a wind-down are the ones that hold money or change what you bought.
1. Escrow or holdback sized to the data risk, not the deal
The relevant number is the plausible per-record or per-claimant exposure of the dataset you are buying, which is frequently a multiple of the purchase price in biometric deals.
2. A survival period that outlasts the statute
A twelve-month survival on a data rep is theatre when the underlying limitation period runs for years. Negotiate survival against the claim, not against the calendar.
3. Specific indemnities, separately capped
Provenance, biometric consent and model validation should each have their own indemnity outside the general cap and basket. Folded into the general cap, they are rounding error.
4. Take the data you can defend, leave the rest
The cheapest remediation is not acquiring the records. Buy the model and the pipeline, exclude the corpus whose consent record is missing, and rebuild from data you sourced yourself.
5. Make the seller deliver the record, as a closing condition
Consent artefacts, dataset lineage, validation studies, vendor terms for every third-party model in the stack. After closing, the people who know where these live have already moved on.
6. Re-publish your own disclosures on day one
The privacy notice, the AI-use disclosure and the accessibility statement on the acquired product become yours the moment the domain redirects. They are the first thing a regulator reads and the cheapest thing on this list to get wrong.
Why this gets missed
AI diligence checklists are written by people assessing whether the technology works. They ask about benchmark performance, inference cost, model lineage and key-person risk. The compliance questions live in a different workstream, get answered by the seller's engineers rather than its counsel, and are frequently closed out with "we use a standard vendor" — a sentence that describes a purchase, not a consent record. The gap is not legal sophistication. It is that nobody in the room owns the question.
The acquired product's public pages are yours now
On the day the domain points at you, the target's marketing site, sign-up flow and policy pages become your compliance surface — and accessibility exposure is the one form of it that a stranger can test from outside in fifteen seconds, which is why demand letters start there. Scan the acquired site free, before someone else does.
Scan the Acquired Site for Free →Frequently Asked Questions
Is not the whole point of an asset purchase that liabilities stay behind?
That is the default rule, and it holds most of the time. It is a default, not a shield: courts recognise exceptions — express or implied assumption, a transaction that is a de facto merger, a buyer that is a mere continuation of the seller, and a transfer arranged to escape liability. AI deals sit awkwardly close to several of those exceptions because what is being bought is often the operating substance of the business rather than severable equipment.
Which liabilities are the ones that actually follow an AI asset?
The ones tied to data and to people. Biometric-consent exposure travels with the dataset, because the defect is that the records were collected without the notice and consent the statute required, and buying them does not cure that. Hiring and lending discrimination exposure travels with the model, because the claim is about the decisions the model produces and it produces them the same way for you. Training-data provenance travels with the weights. Compare that with an unpaid vendor invoice, which is an ordinary contractual liability an asset purchase agreement can leave behind cleanly.
Can we retrain or fine-tune our way out of an inherited dataset problem?
Sometimes, and it is worth taking seriously, but treat it as an engineering project with a documented outcome rather than a legal conclusion. The question a regulator or plaintiff asks is whether the unlawfully obtained material still has effect in the deployed system. If you cannot describe what was removed, how you verified it and what the resulting model was trained on, you have a story rather than a remediation.
The seller gave us a broad rep and an indemnity. Are we covered?
Against the seller, to the extent the seller still exists and is solvent. That is the weak point in most AI asset deals: the entity that gave the rep is frequently a startup that distributes the proceeds and winds down, and an indemnity from a dissolved company is a claim in a queue. The protections that survive that are structural — escrow, a holdback, representation and warranty insurance where it is available, and a purchase price that assumes the risk you actually took.
Does hiring the seller's team change the analysis?
It makes the continuity exceptions more available, yes. Same engineers, same model, same customers, same product name, under a new entity is the fact pattern the mere-continuation and de facto merger doctrines were written for. That is not a reason to avoid hiring the team — the team is often the asset — but it is a reason not to assume the deal structure carries the protection its label implies.
What is the single most useful thing to do before signing?
Get the provenance and consent record for every dataset and the validation record for every model that makes a decision about a person, and treat their absence as a finding rather than an inconvenience. A seller who cannot produce them has not proven a violation, but you can no longer price the risk — and unpriced risk in this category is the kind that arrives as a class complaint after you have integrated the system into your own product.