[codicts-css-switcher id=”346″]

Global Law Experts Logo
ai act m&a due diligence germany

EU AI Act and M&A Due Diligence in Germany 2026: What Buyers and Sellers Must Know

By Global Law Experts
– posted 1 hour ago

AI Act M&A due diligence Germany has moved from a theoretical compliance concern to a live transactional risk as the EU AI Act (Regulation (EU) 2024/1689) enters its phased application. For buyers, sellers, private equity sponsors, in-house counsel and deal lawyers working on German transactions, the arrival of a binding, risk-based regulatory regime for artificial intelligence changes what must be disclosed, warranted and indemnified when an AI-enabled business changes hands. This guide translates the AI Act’s obligations into a practical due diligence workflow, provides annotated sample representations, warranties and indemnities tailored to German deal practice, and sets out a reproducible technical and data-risk checklist. Read on for a buyer-and-seller playbook designed for the enforcement era.

Who this guide is for: M&A buyers (private equity and corporate acquirers), sellers preparing the data room, in-house counsel and deal lawyers. It explains the practical implications of the EU AI Act for German transactions and delivers a buyer/seller diligence workflow, sample reps, warranties and indemnities, and a practical AI technical and data-risk checklist.

EU AI Act: A Quick Primer and Application Timeline, Practical Implications for M&A

The EU AI Act establishes a horizontal, risk-based framework for artificial intelligence. Rather than regulating a sector, it classifies AI systems by the level of risk they pose and attaches obligations accordingly. The European Commission’s regulatory framework for AI describes four broad tiers: unacceptable-risk practices that are prohibited outright; high-risk systems subject to stringent conformity, documentation and oversight obligations; limited-risk systems subject to transparency duties; and minimal-risk systems that fall largely outside the regime. For deal teams, this taxonomy is the starting point of any AI Act M&A due diligence Germany exercise, because the target’s regulatory exposure, and therefore its liability profile, depends entirely on where its systems sit within it.

The phased application of the Act matters for transactional timing. The Regulation entered into force in 2024, with different obligations becoming applicable in stages: prohibitions on certain practices and AI-literacy duties apply first, followed by obligations for general-purpose AI models and the governance framework, and then the more demanding requirements for high-risk systems, which apply over a longer transition. As these obligations become applicable and national competent authorities begin to exercise their supervisory powers, the practical effect for buyers is that undisclosed non-compliance can crystallise into administrative penalties, remediation costs and reputational damage after closing. Sellers, in turn, face a heightened disclosure burden.

Because the application dates are phased and subject to Commission and national implementation guidance, deal teams should verify the specific dates applicable to the target’s systems against the primary materials before finalising deal language.

What Counts as an “AI System” for M&A Purposes

Correctly identifying which of a target’s technologies fall within scope is the threshold question. The AI Act adopts a functional definition of an “AI system” as a machine-based system designed to operate with varying levels of autonomy that may generate outputs such as predictions, recommendations or decisions influencing physical or virtual environments. In practice, diligence teams should not rely on how the target markets its products. A system labelled “analytics” or “automation” may nonetheless meet the statutory definition, while a component described internally as “AI” may fall outside it. The consequence is that scoping must be evidence-based: buyers should map every candidate system, its function, its deployment context and its human-oversight arrangements before assigning a risk classification.

This mapping exercise underpins the entire AI Act M&A due diligence Germany process and should be completed early, because it determines the depth of technical review required.

Key Compliance Obligations Buyers Must Be Aware Of

For high-risk systems, the Act imposes a cluster of obligations that buyers should treat as diligence checkpoints:

  • Technical documentation. Providers must maintain a technical file evidencing how the system meets the Act’s requirements, including its design, development and testing.
  • Conformity assessment. High-risk systems must undergo conformity procedures before being placed on the market, a process functionally analogous to CE-marking regimes for regulated products.
  • Risk management and data governance. Providers must operate a documented risk-management system and demonstrate appropriate governance over training, validation and testing data.
  • Record-keeping and logging. Systems must generate logs enabling traceability of operation, which are critical evidence in any post-closing dispute.
  • Human oversight and transparency. Providers must build in oversight measures and provide clear information to deployers.

Each obligation maps to a document request or verification step in diligence. Where the target cannot produce the technical file, conformity records or logs, the buyer faces a material information gap that should be reflected in the risk allocation. Because the intersection of the AI Act with data-protection law is significant, buyers should also assess controller and processor roles and any required data-protection impact assessments in line with European Data Protection Board guidance, and consider German technical security standards published by the Federal Office for Information Security (BSI).

Buyer Due Diligence: A Step-by-Step Workflow for AI Act M&A Due Diligence in Germany

A disciplined AI Act M&A due diligence Germany workflow proceeds in defined phases, escalating the depth of review in proportion to the regulatory risk of the systems concerned. The objective is not merely to catalogue AI assets but to quantify regulatory and product-liability exposure with enough precision to inform price, structure and contractual protection.

The workflow begins with scoping and classification: identify every AI system in the target’s portfolio, classify each against the Act’s risk tiers, and triage them into diligence tiers. Tier 1 comprises high-risk systems requiring full legal, technical and data review. Tier 2 covers limited-risk systems where transparency compliance is the focus. Tier 3 covers minimal-risk systems requiring only confirmatory review. This triage prevents diligence resources being spread evenly across systems of unequal importance.

Next comes information gathering through targeted questionnaires and data-room requests, followed by substantive review of the documentation produced. For Tier 1 systems, this review should be supplemented by independent technical assessment, and in appropriate cases by red-team testing and third-party audits. Finally, where material compliance questions arise, buyers may consider regulatory engagement, assessing whether the target has open or foreseeable proceedings with a national competent authority. Sample diligence requests for AI-enabled targets include:

  • A complete inventory of AI systems, with function, deployment context and internal risk classification.
  • The technical file and conformity assessment records for each high-risk system.
  • Documented risk-management and data-governance policies.
  • System logs and records demonstrating operational traceability.
  • Details of training, validation and testing datasets, including provenance and licensing.
  • An inventory of third-party and open-source models or components, with associated licences.
  • Data-protection impact assessments and records of controller/processor arrangements.
  • Correspondence with, or notifications to, any supervisory or competent authority.
  • Human-oversight procedures and transparency notices provided to users.
  • Incident logs, complaints and any records of malfunction, bias or harm.

Legal and Regulatory Review Checklist

The legal review confirms whether the target has met the substantive obligations attaching to each system’s risk tier. Reviewers should verify that high-risk systems have completed conformity assessment, that the technical file is complete and current, and that logging and record-keeping obligations are being met. They should confirm registration where required, examine transparency compliance for limited-risk systems, and check for any prohibited practices. Crucially, the legal review should identify contractual chains: where the target relies on upstream providers of AI systems or components, the allocation of regulatory responsibility between provider and deployer must be traced.

National implementation and the designation of German competent authorities should be confirmed against current guidance from the relevant German federal ministries and any designated market-surveillance authority, as the domestic supervisory architecture is being finalised.

Technical and Model Risk Assessment

Legal review alone cannot assess whether a model performs as documented. For Tier 1 systems, buyers should procure expert reports evaluating model robustness, accuracy, and susceptibility to failure under real-world conditions. Technical assessment should probe whether the system’s documented performance matches its actual behaviour, whether monitoring is effective, and whether known weaknesses, adversarial vulnerability, drift, or degradation, have been identified and managed. Where the target’s systems make or materially influence decisions affecting individuals, explainability and the adequacy of human oversight warrant particular scrutiny. Involving technical experts early, rather than after legal review concludes, is a recurring theme of effective AI Act M&A due diligence Germany because model risk frequently drives the most significant valuation and indemnity questions.

Data Provenance and Privacy Checks

Data is where regulatory, intellectual-property and privacy risks converge. Diligence must trace the lineage of training and testing data: where it originated, whether it was lawfully obtained, whether appropriate rights and licences exist, and whether personal data was processed in accordance with data-protection law. The European Data Protection Board guidance on data minimisation, impact assessments and controller/processor roles is directly relevant, because AI systems trained on unlawfully sourced or inadequately governed data expose the acquirer to overlapping AI Act and data-protection liability. Buyers should treat undocumented data provenance as a material red flag warranting specific indemnity protection.

Seller Obligations: What to Disclose and How to Prepare Schedules

For sellers, the enforcement era transforms preparation of the data room from an administrative task into a strategic exercise in liability management. Incomplete or inaccurate disclosure of AI systems, data and compliance status is a significant driver of post-closing exposure, because buyers who discover undisclosed non-compliance after closing will pursue warranty and indemnity claims. Well-prepared sellers can substantially reduce this risk by disclosing comprehensively and by negotiating balanced risk-allocation provisions from a position of transparency.

Sellers should assemble a dedicated AI disclosure schedule that mirrors the buyer’s likely diligence structure: a system inventory with risk classifications, the compliance documentation supporting each classification, and a candid statement of any known gaps or open issues. A considered redaction strategy protects genuinely sensitive proprietary information, model architectures, source code and trade secrets, while preserving the completeness of compliance disclosure. Where compliance gaps exist, sellers should consider pre-closing remediation, since curing a defect before signing is often cheaper than compensating for it afterwards.

Essential Documents Sellers Must Have Ready

To disclose credibly and defend valuation, sellers should have the following ready before the process begins:

  • Technical files for each high-risk system, complete and current.
  • Risk assessments and risk-management documentation evidencing an operating governance framework.
  • System logs demonstrating traceability and operational history.
  • Training-data provenance records, including sources, rights and licences.
  • Third-party component and model inventories, with the licences governing their use.
  • Conformity assessment records and registration evidence where applicable.
  • Data-protection documentation, including impact assessments and processing records.

Negotiation Tactics to Limit Post-Closing Exposure

Sellers can legitimately limit exposure through the structure of the transaction documents. Knowledge qualifiers narrow representations to matters within the seller’s actual awareness; disclosure against warranties converts known issues into agreed risk rather than breach; and carefully drafted carve-outs exclude matters the parties agree the buyer accepts. Financial limitations, caps, baskets and shortened survival periods, cabin the seller’s residual liability. However, sellers should recognise that under German law liability for fraudulent misrepresentation (arglistige Täuschung) and intentional breach cannot ordinarily be excluded, and that overly aggressive limitation of core AI-compliance representations may simply shift the negotiation to price or escrow. The most durable outcomes come from full disclosure paired with proportionate, clearly drafted limitations.

Reps, Warranties and Indemnities: Negotiating Deal Language for AI Act M&A Due Diligence Germany

The transaction documents are where AI regulatory risk is ultimately allocated. The drafting objective is to translate the findings of AI Act M&A due diligence Germany into representations that surface known and unknown non-compliance, warranties that stand behind key facts about data and intellectual property, and indemnities that channel identified risks to the party best placed to bear them. In German share and asset deals, note that statutory warranty concepts differ from Anglo-American practice, so the parties typically agree an independent, self-contained guarantee regime (selbständige Garantien) under section 311(1) of the German Civil Code (BGB). The clauses below are drafting starting points only.

Draft clauses, for negotiation only. Tailor to the transaction and to local law; review by qualified counsel is required.

  • (a) AI compliance representation. “The Company and each of its AI systems comply in all material respects with all applicable requirements of the EU AI Act and all related national implementing measures, and the Company holds all technical documentation, conformity assessments and records required thereunder.”
  • (b) Absence of known regulatory proceedings. “There are no pending or, to the Seller’s knowledge, threatened investigations, proceedings or enquiries by any competent authority in respect of any AI system operated by the Company.”
  • (c) Data provenance and IP warranty. “All datasets used to train, validate or test the Company’s AI systems were lawfully obtained, and the Company holds all rights and licences necessary for such use, and such use does not infringe the intellectual-property or data-protection rights of any third party.”
  • (d) Specific AI Act indemnity. “The Seller shall indemnify the Buyer against all losses arising from any breach of the AI compliance representation, including administrative penalties, remediation costs and third-party claims, save to the extent fairly disclosed in the Disclosure Schedule.”
  • (e) Escrow / holdback for remediation. “An amount of [●] shall be retained in escrow for [●] months to fund any remediation of AI systems found to be non-compliant during the retention period.”
  • (f) Cap and basket note. Consider whether AI-specific indemnities should sit outside the general warranty cap given the potential scale of regulatory penalties, and whether a separate, higher cap is warranted for core compliance representations.

Survival and Knowledge Qualifiers

Survival periods (in German practice, contractually agreed limitation periods for guarantee claims) determine how long representations remain actionable after closing. Because AI Act non-compliance may only surface once a national competent authority acts, buyers should press for extended survival of core AI-compliance representations, ideally aligned with the limitation periods for regulatory enforcement. Knowledge qualifiers are the principal battleground: sellers seek to limit representations to matters within actual awareness, while buyers prefer flat, unqualified representations for the most fundamental facts. A common compromise reserves unqualified treatment for representations on data provenance and the existence of conformity documentation, while permitting knowledge qualifiers on forward-looking or third-party matters.

Financial Remedies and Escrow

Where diligence identifies a specific, quantifiable compliance gap, a targeted holdback or escrow funds its cure without requiring the buyer to litigate a warranty claim. Escrow is particularly well suited to defined remediation programmes, for example, completing a conformity assessment or regenerating a dataset with clean provenance. Price adjustments offer an alternative where the risk is best resolved at signing. The choice between escrow, holdback and price reduction turns on whether the remediation cost is known, contingent or speculative.

Insurance and Carve-Outs

Warranty and indemnity insurance can transfer residual risk to a third-party insurer, but insurers will scrutinise the depth of AI-specific diligence and may exclude known issues or areas of thin diligence. Buyers should therefore expect that gaps left in the diligence process will translate directly into policy exclusions, reinforcing the value of thorough technical and data review. Fraud and intentional breach typically fall outside insurable cover and remain with the seller.

Diligence topic Buyer focus / remedy Seller focus / mitigation Contract levers
AI Act compliance status Unqualified compliance representation; specific indemnity Knowledge qualifiers; disclosure against warranty Indemnity trigger; extended survival; separate cap
Data provenance and licensing Warranty on lawful sourcing; IP indemnity Carve-out for disclosed datasets Escrow for dataset remediation
Open regulatory proceedings Absence-of-proceedings representation Full disclosure of known enquiries Specific indemnity for disclosed matters
Model performance and safety Expert report; product-liability protection Documented testing and monitoring Holdback tied to remediation milestones
Third-party components Warranty on licences and pass-through obligations Inventory and licence disclosure Price adjustment; indemnity for licence defects

Evaluating Technical and Data Risks: A Practical Scoring Checklist

To make risk comparable across systems, buyers should apply a reproducible scoring matrix that rates each identified risk by impact and likelihood. Scoring each dimension on a simple scale and multiplying the two produces a composite score that ranks systems for attention and informs contractual protection. The dimensions to score include model transparency, dataset provenance, bias and fairness, robustness, third-party and open-source dependencies, supply-chain reliance and the adequacy of ongoing monitoring. A system scoring high on both impact and likelihood across several dimensions is a candidate for specific indemnity, escrow and, potentially, price adjustment. Best-practice governance standards articulated in the OECD AI Principles provide a useful normative benchmark for what “good” looks like across these dimensions.

Data Lineage and IP Risk

Data lineage risk captures the possibility that training data was unlawfully obtained, inadequately licensed or contaminated with third-party rights. Because a defect in data lineage can render an entire model legally compromised, this dimension frequently attracts the highest scores. Buyers should assess whether provenance is documented end-to-end, whether licences permit the specific use, and whether any personal data was processed lawfully.

Explainability and Documentation

Explainability risk reflects the gap between what a system does and what its operators can demonstrate about how it does it. Where documentation is incomplete or the technical file cannot be reconciled with actual behaviour, both regulatory compliance and defensibility in a dispute are undermined. High scores here signal that the target may struggle to evidence conformity, exposing the acquirer to enforcement risk.

Third-Party Models and Open-Source Components

Modern AI systems are rarely built in isolation. Reliance on third-party models or open-source components introduces licence-compliance risk, supply-chain dependency and uncertainty about upstream conformity. Buyers should score the extent of such dependencies, verify that licences permit commercial use, and assess whether the allocation of AI Act responsibility between the target and its upstream providers is clear and enforceable.

Post-Closing Obligations and Integration: Remediation, Monitoring and Regulatory Engagement

Closing does not end the compliance exposure. Acquirers should implement a post-closing roadmap that operationalises any agreed remediation plan, integrates the acquired systems into the group’s compliance and monitoring framework, and manages ongoing product and consumer-liability exposure. Where diligence identified reporting obligations, the acquirer should ensure timely notifications to the relevant competent authority, and should exercise any negotiated post-closing audit rights and transitional support arrangements to complete outstanding technical documentation. Treating post-closing compliance as a project, with defined owners, milestones and escalation paths, converts contractual protections into practical risk reduction.

Conclusion: Practical Next Steps for AI Act M&A Due Diligence in Germany

The application of the EU AI Act makes AI Act M&A due diligence Germany a core discipline rather than a specialist add-on. Buyers should scope and classify every AI system early, escalate technical and data review for high-risk systems, and translate their findings into tailored representations, warranties, indemnities and escrow mechanics. Sellers should prepare comprehensive disclosure schedules, complete their compliance documentation, and negotiate proportionate, clearly drafted limitations from a position of transparency. Both sides benefit from involving technical experts and specialist counsel at the outset. For deal teams building this capability, further guidance is available through the Germany Compliance practice area.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Markus Bauer at RITTERSHAUS Rechtsanwalte PartmbB, a member of the Global Law Experts network.

Sources

  1. European Commission, Regulatory framework for AI
  2. EUR-Lex, Regulation (EU) 2024/1689 (EU AI Act)
  3. OECD, Recommendation of the Council on Artificial Intelligence (AI Principles)
  4. European Data Protection Board (EDPB)
  5. BSI, Federal Office for Information Security

FAQs

How does the EU AI Act change what buyers should request in AI Act M&A due diligence Germany?
Buyers should now request each system’s risk classification, technical file, conformity records, data-provenance evidence and any regulatory correspondence, verified against the AI Act’s requirements as set out in the European Commission and EUR-Lex materials.
Sellers should disclose AI models, the datasets and pipelines used to train and test them, third-party and open-source components with their licences, technical documentation, risk assessments and any known compliance gaps or authority enquiries.
An unqualified AI-compliance guarantee combined with a specific indemnity for AI Act breaches offers strong protection. See the annotated sample clauses above, which should be tailored and reviewed by counsel before use.
Sellers can negotiate caps, baskets and limitation periods, but under German law liability for fraudulent misrepresentation and intentional breach cannot ordinarily be excluded, and buyers commonly seek a separate, higher cap for core AI-compliance representations.
Early, and especially for high-risk systems. Model performance, data provenance and explainability frequently drive the largest valuation and indemnity questions, so expert input should precede rather than follow legal review.
d&o insurance criminal investigations austria
By Global Law Experts

posted 21 minutes ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

EU AI Act and M&A Due Diligence in Germany 2026: What Buyers and Sellers Must Know

Send welcome message

Custom Message