AI-generated code in due diligence: the questions buyers ask and how sellers answer
In due diligence on AI-generated code, buyers ask which AI coding tools engineers used, under what terms, where AI-assisted code sits, how it was reviewed, and whether ownership and open-source obligations are clean. Sellers answer with a written tool policy, plan and settings records, and the pull-request review trail. That human-authored engineering history is also what AI developers license.
What buyers ask about AI-generated code
Buyers want to know whether AI coding tools changed what they are buying. In practice the topic comes down to five questions: which tools were used and on what terms, where AI-assisted code sits in the product, how it was reviewed, whether the company owns it, and whether it brought in open-source obligations. A seller who answers with documents rather than estimates keeps the subject out of the special indemnities in the purchase agreement.
A typical data request might read: list each AI coding assistant used since a given date, the plan or license tier, the repositories where it was enabled and the written policy that governed it. Sellers who can produce that in a day look organized; sellers who reconstruct it from memory invite a deeper review.
The six areas of AI-code diligence
| Area | Typical buyer question | Evidence that answers it |
|---|---|---|
| Provenance | Where did AI tools contribute, and since when? | Tool rollout dates, repository settings, team-level usage records |
| Tool terms | Which plans and terms applied, and who owns outputs under them? | Copies of the terms in force, plan invoices, admin console settings |
| Ownership | Is there enough human authorship and review to support the company's ownership position? | Pull-request reviews, design documents, commit history by named engineers |
| Open source | Could suggestions have reproduced licensed code? | Open-source scan reports, filter settings, remediation records |
| Security and quality | Did AI-assisted code add vulnerabilities or untested paths? | Static analysis results, test coverage history, incident records |
| Disclosure | What will the seller represent about AI use? | A disclosure schedule drafted with deal counsel |
The buyer's technical advisers will check these answers against the repositories directly. The CTO due diligence interview questions show how that conversation tends to run and what to rehearse.
Why ownership questions are harder for AI-assisted code
Copyright vests initially in the author of a work, and for a work made for hire the employer is treated as the author and owns the rights unless a signed writing says otherwise (17 U.S.C. 201). That framework assumes a human author. The US Copyright Office's AI initiative has published a report part on the copyrightability of AI outputs and a pre-publication report on generative AI training (Copyright Office, Copyright and Artificial Intelligence), and buyers' counsel draw on that body of guidance when they frame questions about how much human authorship sits in a codebase.
The practical response is evidence of human contribution: design documents, review comments, refactoring commits and tests written by named engineers. Leave opinions on copyright status to counsel rather than offering them in a management meeting.
This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting.
How advisors prepare a software seller before the data room opens
- Inventory the tools. List every AI coding assistant, its plan tier, who approved it and when it was enabled.
- Collect the terms in force. Save the tool terms and admin settings that applied in each period, not only today's version.
- Write or update the policy. If no written policy exists, adopt one now and date it honestly; never backdate it.
- Map heavy-use areas. Identify services built mainly with AI assistance and the reviewers who approved the changes.
- Run an open-source scan. Document findings and fixes before the buyer runs its own scan.
- Draft disclosure language with counsel. Agree what the company will represent about AI use, consistent with the CIM.
- Brief the CTO. Rehearse the questions with the evidence on screen.
Illustrative: a fictional 140-person B2B software company enabled an AI assistant for all engineers two years before going to market but only wrote its policy during sale preparation. Its advisor had the CTO export the admin console's rollout history, select ten representative pull requests showing review comments on AI-suggested changes, and state the policy date plainly in the disclosure schedule. The topic took one follow-up call rather than a negotiation over indemnities.
If the CIM needs a line on AI use, see how to address AI risk in a CIM, and fix the records problems in deal killers in due diligence before buyers find them.
Why human-authored engineering history is what AI developers license
The records that prove human authorship in diligence are the records AI developers license to train and evaluate coding agents: pull requests with review threads, tickets linked to the commits that closed them, design discussions and postmortems. They capture how engineers reason, disagree and correct course, which finished public code does not show. Epoch AI researchers project that, if current trends continue, language models will fully use the effective stock of public human-generated text between 2026 and 2032 (Epoch AI), one reason non-public, permissioned work records have become a scarce input.
| Record | What it shows | Provenance question a data buyer asks |
|---|---|---|
| Pull request and review thread | Reasoning, critique and revision | Which changes were human-written and which AI-suggested? |
| Ticket linked to commits | A task and how it was completed | Is the history complete across tool migrations? |
| Design document or RFC | Trade-offs weighed before building | Who wrote it, and was any of it generated? |
| Postmortem | What failed, why, and what changed | Can customer details be removed? |
| Review policy history | How engineering standards evolved | When did AI tools enter the workflow? |
Provenance matters on both sides of the table. Records generated with AI in order to sell them are a red flag that rules a dataset out, while genuine work histories that include some identified AI-assisted commits are assessed case by case. For how buyers on the data side think, read what an AI data buyer is.
What it means for an M&A advisor with software clients
When a software client prepares for a sale, the engineering history gathered for diligence is the core of a possible license. Raise the license after the evidence is collected rather than mid-way through confirmatory diligence, and coordinate it with the sale process. Software companies that fit have 50+ full-time employees at peak (contractors excluded), years of repository and ticket history, clear rights to license it and an owner, CEO or CFO willing to sponsor the decision; who qualifies lists the full baseline, and the M&A advisor referral overview covers the mechanics of an introduction.
Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 per referred company, payable only after the buyer pays and SourceX receives its fee. No reward is guaranteed, and the advisor never exports or handles the code or tickets.
Limits and open questions
- The law on AI outputs is still developing, and the Copyright Office's training report is a pre-publication version, not law.
- No standard method measures what share of a codebase AI wrote, so treat any percentage claim with caution.
- Tool terms change; what matters is the version in force when the code was written.
- A license needs the same clean ownership a buyer expects, so unresolved contractor or AI-tool questions delay both.
Next step
Take the software client you know best through the company fit checker once its diligence evidence is assembled. A good result is a reason to register as a partner and introduce the company, or to share your referral link so the CEO can apply at sourcex.si/apply.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
Do buyers expect a seller to measure what share of its code AI wrote?
Usually not as a precise number, because no reliable standard exists for measuring it. Buyers care more about where AI-assisted code sits, which tools and terms applied, and whether it went through normal review. A credible description backed by rollout dates, settings and reviewed pull requests carries more weight than a percentage that cannot be verified.
Can a company keep using AI coding tools after signing an LOI?
Generally yes, but check the interim operating covenants with deal counsel, and keep usage consistent with the written policy and what was disclosed. Switching tools, changing plans or loosening review rules during exclusivity can raise questions late in the process. If a change is needed, tell the buyer before making it rather than after.
Does heavy use of AI coding tools lower a software company's valuation?
There is no reliable public data showing a standard discount. What tends to affect price is what diligence finds: gaps in ownership evidence, security problems, unreviewed code or undisclosed tool use. Well-documented use with normal review and a clear policy is easier for a buyer to accept than uncertainty about how the code was produced.
Who owns code written with an AI coding assistant?
It depends on the tool's terms, the level of human contribution and the employment or contractor agreements involved, and the law is still developing. Buyers' counsel look for evidence of human authorship and review alongside the terms that applied when the code was written. Ask your own counsel for a view on the specific codebase before making any representation.
Can engineering records that include AI-assisted commits still be licensed?
Often they can be considered, provided the AI-assisted portions are identified and the company holds the rights to the history. What disqualifies a dataset is content generated with AI in order to sell it. Real work records from teams that used assistants as part of normal engineering are assessed case by case, with provenance documented during the inventory.
Related pages
- CTO due diligence interview questions in a software sale, and how to prepare answers
- How to address AI risk in a CIM with evidence instead of reassurance
- Deal killers in due diligence, and the records problems behind them
- What is an AI data buyer?
- Which US businesses are a fit for a SourceX data licensing introduction
- Referral opportunities for M&A advisors
Free resources
- EBITDA calculator — Reported and adjusted EBITDA from net income.
- MOIC calculator — Multiple on invested capital from realized and unrealized value.
- PDF bank statement to CSV converter — Turn Chase, Bank of America or Wells Fargo PDF statements into CSV, privately in your browser.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment