AI washing in due diligence: how to test a target's AI and proprietary data claims

AI washing due diligence checks whether a target's claims about its AI and its proprietary data survive evidence. Test capability claims with architecture and vendor records, and test data claims on three proofs: the company has rights to the records, the history is as deep as stated, and someone can export it today. Unproven claims belong in the price.

What AI washing means in a deal

AI washing is describing a product, process or dataset as more AI-driven or more proprietary than the evidence supports. In a sale process it shows up in two forms: capability claims ("our platform uses AI to route every order") and asset claims ("we own a proprietary dataset no competitor can match"). Most deal teams test the first with a technical review and accept the second on the strength of a slide.

That gap matters because an asset claim is the harder one to repair after closing. A feature can be rebuilt; a decade of records the company never had rights to, or lost in a migration, cannot. This guide gives deal teams a short test for proprietary data claims, built on the same three questions asked before any data license: rights, history and exportability.

Which AI claims show up in CIMs and management presentations?

Expect most AI language in the teaser, the growth section of the CIM and the management presentation. Translate each claim into the evidence that would prove it.

Claim as writtenWhat it often turns out to beEvidence to request
AI-powered platformA feature that calls a third-party model through an APIArchitecture diagram, model vendor contracts and invoices, list of features that call a model
Proprietary modelsA tuned open model, a rules engine or a vendor defaultTraining run records, who trained it, on what data, where the weights live
Proprietary dataset or data moatCustomer data held under contracts that limit its useData inventory by system, customer data-use clauses, privacy policy history
Ten years of dataA partial archive left after a system migrationOldest exportable record per system, migration and retention logs
AI cut handling timeA pilot result from one team over a short windowBaseline period, measurement method, results across all teams
We train on our customers' dataA practice the customer contracts may not permitTerms of service, DPAs, consent records, the date each clause changed

For revenue attributed to AI products, rebuild the numbers rather than accept a summary. The ARR bridge guide shows how to separate new, expansion and churned revenue so an AI upsell story can be checked line by line.

The three-proof test for proprietary data claims

A data claim passes only when the target can prove all three. Ask for documents, not reassurance in a management meeting.

Proof 1: rights

  • The records were created by the company's own employees in the course of their work, or contractors assigned their rights in writing
  • Customer contracts allow use of the records beyond delivering the service, or the records contain no customer content
  • Privacy notices and terms in force when the data was collected permit the claimed use
  • No exclusive license of the same records has already been granted to someone else

Commitments made to customers are the most common failure point. FTC staff wrote in January 2024 that a company's promises not to use customer data for undisclosed purposes such as training models are enforceable, whether made in a privacy policy, terms of service or promotional material. A target that says it trains on customer data should show where customers agreed to that.

Proof 2: history

  • The oldest record in each named system, with the date confirmed by an export rather than a recollection
  • Gaps explained: migrations, mergers, tool changes, retention policies that deleted data
  • Archived systems listed, including ones no longer licensed or running

Proof 3: exportability

  • A named person with admin rights who can run a complete export
  • Exports include metadata such as timestamps, authors and status changes, not just text
  • Vendor contracts and current subscriptions still allow bulk export

Once the three proofs are met, the data quality due diligence checklist goes deeper on completeness and consistency.

How the test mirrors a data licensing screen

The three proofs are the questions a data licensing review asks, so diligence and any later license can share one vocabulary and one evidence file.

Diligence questionLicensing screen equivalentWhat a pass looks like
Does the company own what it calls proprietary data?Rights to license the recordsEmployee-created records, clean contractor assignments, customer terms that allow it
Is the history as long as claimed?Several years of documented operationsConfirmed oldest records across several systems, gaps explained
Can the data actually be used?Someone can export the dataA tested export with metadata from each core system
Is it more than one dataset?Data breadth across systemsEmail, chat, CRM, finance, support, engineering and operations records that link to each other

SourceX qualifies companies on size, history, data breadth and rights. A target that passes the three proofs and has 50+ full-time employees at peak (contractors excluded) often holds the raw material for a license; the who qualifies page lists the full baseline. Sector diligence follows the same pattern: in project-based services firms, the backlog and book-to-bill review leans on proposal and project records that also count as work records.

Why this matters after the deal closes

For an operating partner, a tested data claim is either an asset to use or a line to remove from the value creation plan. Records that pass can be licensed to AI labs and data buyers for a one-time payment while the company keeps ownership; SourceX handles inventory, buyer review, contracting and delivery. Claims that fail should come out of the equity story before the next buyer finds the same gap. The playbook for private equity operating partners covers how to screen a whole portfolio.

Buyer interest follows quality. The Copyright Office's report on generative AI training, released as a pre-publication version in May 2025, notes that model performance depends heavily on the quality of training data. That is why data buyers ask the same rights and history questions a careful acquirer does. The page on the race for proprietary training data covers the demand side.

Example: testing one claim (Illustrative)

Illustrative, fictional scenario. A 140-person freight software company's CIM claims "nine years of proprietary shipment exception data". The test finds:

  • Rights: exception tickets were written by the company's support staff, but the three largest customers' contracts limit data use to service delivery.
  • History: the support desk export confirms tickets back eight years; an earlier help desk was retired without an export.
  • Exportability: the support lead can export tickets with status history and resolution codes.

Result: a partial pass. The claim is restated as eight years, the three restricted customers are excluded, and the remaining records become a candidate for a later license once the deal closes.

Limits of the three-proof test

The test checks data claims, not model performance, cybersecurity or disclosure obligations. It also does not cover how securities regulators treat AI claims in disclosures. A separate technical review should test what any model actually does, and counsel should advise on representations, warranties and any regulatory exposure from past marketing claims. This is general information, not legal, tax or financial advice. Confirm with your own counsel before relying on it in a transaction.

Next step

Run the three proofs on the next target that claims proprietary data, and use the company fit checker for a preliminary, non-binding read on whether a portfolio company could license its records. To introduce a qualifying company, register as a partner.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

Is AI washing only a risk with software targets?

No. Services, logistics and manufacturing targets increasingly describe routing, scheduling or quality processes as AI-driven, and many claim proprietary operational data. The same split applies: test capability claims with technical evidence, and test data claims for rights, history and exportability. Non-software targets often have stronger records than their AI language suggests, and weaker AI than it claims.

Who on the deal team should test proprietary data claims?

Split the work. Legal diligence reviews customer contracts, privacy notices and contractor assignments for the rights proof. The technology diligence provider confirms the oldest records and runs a sample export for the history and exportability proofs. The operating partner owns the conclusion, because it feeds the value creation plan and any later licensing decision.

Can a target fix a failed data claim before closing?

Sometimes. A history gap can be narrowed by restoring archives or restating the claim. An exportability gap can be closed by preserving exports before subscriptions lapse. A rights gap is harder, because customer consent or new contract terms take time and retroactive changes to privacy terms carry their own risk. Restating the claim accurately is usually faster than repairing it.

Does a proven data asset change how a buyer should value the company?

It can support the equity story, but treat it as an option rather than run-rate value. A data license is typically a one-time payment for an agreed dataset, and nothing is binding until the company agrees price and terms. Value it on evidence of rights and depth, not on comparisons with publicly reported licensing deals involving very different companies.

What documents prove a company owns its operational records?

Employment agreements and handbooks showing work product belongs to the company, signed IP assignments from contractors, customer contracts with their data-use clauses, the privacy notices in force over time, and vendor agreements for the systems that hold the records. Together they show who created the records and what the company promised about how they would be used.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment