Europe · Technology and digital assets

Legal Due Diligence of Technology Companies Before Investment

Erich Rath14 min read

Mainstream

A technology company’s due diligence is not just a document audit. It is an assessment of how protected the technology and business model is from legal and regulatory risks that could nullify the investment.

The question is not whether the product is good. The main question is whether a government agency can ban its use, whether a competitor can block sales because of an IP breach, and whether the company will become a target for a regulatory fine comparable to annual turnover.

Effective due diligence begins with three checks:

  • Is there an unconditional right to the technology and data on which the business is built?
  • Does the product comply with current and projected EU regulations?
  • What hidden liabilities and liability risks will pass to the investor after the transaction closes.

If these three issues are not resolved before the SPA is signed, the buyer risks not acquiring the asset but a future lawsuit, fine or termination claim.

When Legal Due Diligence of a Technology Company is Necessary

A thorough legal review becomes critical if:

  • The fund or strategist plans to acquire a stake in an AI startup.
  • The investor participates in the financing round of the growth-stage of the technology company;
  • M&A deals are being prepared in the field of artificial intelligence, big data, SaaS, cybersecurity or digital assets.
  • The company owns a platform with user-generated content or algorithmic recommendations.
  • The technology is potentially subject to the EU AI Act, GDPR, MiCA, NIS2, DSA or DMA regulation.
  • The business model relies on crypto-assets, tokens, or decentralized protocols.
  • Key assets are datasets, trained models, proprietary code and know-how created by a distributed team.
  • there are doubts about the purity of the data origin or compliance with software licenses;
  • It is necessary to check the company’s readiness to pass conformity assessment for high-risk AI systems.
  • It is planned to enter the EU market or scale up within the EU.

The mistake most investors make

Many people start with the question:

“What is the company’s valuation and how fast is revenue growing?”

This is the wrong first question for legal review.

The right question is:

What legal risks could wipe out the value of this business after the transaction?

Sometimes the best technology is not protected by incorrectly designed rights to invention. Sometimes a brilliant AI product is trained on data obtained without a legitimate basis, making it illegal to commercially use. Sometimes, a blockchain project issues tokens that the EU regulator will consider as financial instruments requiring a MiFID II license.

Technology due diligence does not require a list-by-list auditing approach, but a strategic analysis of the regulatory landscape, technology rights, and liability scenarios.

Step 1. Check the corporate structure and share rights

A technology company is not just about code and model. They are the bearers of rights and obligations.

Key provisions for verification:

  • the corporate structure and jurisdiction of creation;
  • Proper issuance of shares, options, convertible loans;
  • Vesting schedules of founders and key employees;
  • Shareholder agreements and possible restrictions on the transfer of shares;
  • deadlock provisions, tag-along/drag-along
  • consent of third parties or government authorities to the transaction;
  • Signatories’ powers and protocols of corporate decisions;
  • No hidden obligations or collateral for shares.

If the IP ownership structure is not transparent, or key developers are not bound by the vesting, the deal could result in a loss of control over the technology after the founders leave.

Step 2. Checking Intellectual Property and Technology

This is the central stage. The investor does not acquire shares in the company, but the right to the technology and its future cash flows.

It should be established:

  • who created the technology – staff, consultants, outsourcers;
  • Whether there are written agreements on the transfer of exclusive rights (assignment of IP);
  • Whether the algorithms are patented or kept as trade secrets
  • Have you audited the open source code: What open source components are used and whether virus licenses (GPLs, AGPLs) impose obligations to disclose proprietary code;
  • Whether third party libraries, APIs, SDKs and data are licensed;
  • Possession of rights to training datasets and model results;
  • whether trademarks and domains are registered in the target markets of the EU;
  • Freedom to operate: whether there is infringement of third party patents.

Weakness in the IP rights chain is the most expensive post-deal find.

Step 3. Checking data and GDPR compliance

If a technology company processes personal data of EU residents, GDPR becomes a critical factor in value.

The analysis includes:

  • legal grounds for data processing (consent, legitimate interest, performance of the contract);
  • Data Protection Impact Assessment (DPIA) for AI systems and profiling
  • the status of the company – controller, joint controller or processor;
  • Standard Contractual Clauses (BCR) (Adequacy Decision)
  • Notifications and consents, especially for sensitive data and automated decisions;
  • procedures for responding to requests from data subjects (access, deletion, portability);
  • history of data leaks, notifications to supervisory authorities and fines;
  • The role of data in model training – whether the legality of collection was ensured by web scraping, through third-party providers or by its own users.

GDPR penalties are 4% of the annual global turnover. A detected systemic violation can not only stop the product, but also lead to administrative liability and reputational damage.

Step 4. Assessing AI’s regulatory risks under EU law

Even if the AI Act is not fully enforced, its requirements must already be taken into account in due diligence. The investor evaluates how ready the product is for future compliance.

Key areas:

  • Classification of AI-systems by risk levels - unacceptable risk (prohibited), high-risk, limited risk, minimal risk;
  • Responsibilities for high-risk systems: data quality, technical documentation, transparency, human supervision, registration in the EU database;
  • availability of conformity assessment and CE marking;
  • General purpose AI (requirements for fundamental models) – disclosure of training data, assessment of systemic risks;
  • Transparency of interaction with the AI system (the user should know that he is communicating with the machine);
  • future responsibility for AI decisions (relationship with the proposed AI liability directive)

Ignoring the AI Act in the hope that it will be finalized does not negate the fact that a product without a compliance strategy may be banned from sales in the EU.

Step 5. Check the regulation of digital assets (MiCA and related acts)

If a company issues utility tokens, stablecoins, provides services of crypto exchange, custodial storage or DeFi protocols, the MiCA Regulation and the national law of the EU Member States apply.

The inspection will determine:

  • Whether the token is defined as a crypto-asset by MiCA or is a financial instrument under MiFID II
  • Whether a crypto-asset white paper has been prepared and notified;
  • Whether a Crypto-Asset Service Provider (CASP) license is required and in which EU jurisdiction
  • Compliance with asset-referenced tokens and e-money tokens
  • AML/KYC (Anti-Money Laundering, Transfer of Funds Regulation)
  • Marketing restrictions and consumer protection rules.

An error in the classification of the token can lead to the fact that all the activities of the company will be unlicensed and subject to termination.

Step 6. Testing the cybersecurity and sustainability of digital products

European regulation is increasingly demanding that technology be safe by default.

The following shall be checked:

  • Compliance with the NIS2 Directive if the company is the operator of critical or critical infrastructure;
  • Incident response plans and notifications to national CSIRTs are available.
  • Requirements for products with digital elements (proposed by the Cyber Resilience Act) – vulnerability management and security updates
  • Certification under the EU Cybersecurity Act (e.g. for cloud services and 5G);
  • A history of successful cyberattacks, lessons learned and remediation.

Low cyber resilience poses a risk not only for the company itself, but also for its customers, which entails liability up to product liability.

Step 7. Analyze commercial contracts and responsibilities

Contracts with B2B clients, partners and cloud providers contain key risks that pass to the customer.

The analysis covers:

  • conditions on limitation of liability, compensation of losses and guarantees;
  • SLA, uptime, disaster resistance;
  • rights to data received from customers and to the results of AI;
  • indemnification for violation of IP rights of third parties;
  • provisions on change of control and possible termination of contracts in the transaction;
  • Exclusivity and non-compete;
  • applicable law and jurisdiction in contracts with clients from different EU countries.

A portfolio of contracts can both protect and bury the economics of a deal if it turns out that key customers will leave when the owner changes or that the company is held liable for AI failures.

Step 8. Assess export controls and sanctions risks

Many AI, encryption, drones, sensors, and biometrics technologies fall under dual-use mode.

Checked:

  • Is the product subject to the EU Dual-Use Regulation (Regulation 2021/821)?
  • Whether an export license is required for sales to certain countries
  • whether there are sanctioned persons in the supply chain or among customers;
  • Whether components subject to US export restrictions (ITAR, EAR) are used, which may have an extraterritorial effect for a European company;
  • compliance with the EU sanctions regimes, imposed, for example, against Russia and Belarus.

Even a fully European AI company could face contract lockdown due to the encryption algorithm exceeding the threshold set by export controls.

Step 9. Checking the employment and authorship relationship

Often, the key technology is not created by employees, but by freelancers, researchers, or outsourcing teams without proper enshrining of rights.

It is necessary to check:

  • availability of contracts with developers, data scientists and ML engineers;
  • Whether the transfer of exclusive rights to the created objects (work-made-for-hire, assignment of future IP) is prescribed;
  • Is the relationship with universities settled if the technology has grown out of the academic environment?
  • Whether the right to remuneration of authors of utility inventions is respected under the laws of the relevant EU countries;
  • Whether post-termination restrictive covenants (non-compete, non-solicit) apply to key employees.
  • Whether trade secrets and know-how are protected after the departure of staff

A dispute over IP ownership with a former co-founder a year after the investment is a classic scenario that could bring down the value of the company.

Step 10. Integrate conclusions into the structure of the transaction

Due diligence does not protect the investor. It only protects how the conclusions are turned into the mechanisms of the transaction.

Tools:

  • Representations & Warranties – precise wording about IP rights, no GDPR violations, correct classification under the AI Act, data licenses and open source.
  • Indemnities – specific, with triggers, limits and time limits, for example, in case of a patent infringement claim or a GDPR fine.
  • Special indemnity for identified but not eliminated risks prior to the transaction.
  • Deferred consideration / Earn-out – linking part of payments to the achievement of regulatory compliance.
  • Escrow and holdback – reserve part of the price in case of claims.
  • Warranty & Indemnity Insurance (W&I) covers risks, but carefully excludes cyber and regulatory components that insurers do not always accept.
  • Closing conditions – requirements that must be met before closing: obtaining licenses, eliminating critical open source components, DPIA registration.

Comparison of key EU regulatory regimes for tech due diligence

Regulatory fieldWhich companies are affectedThe main risks of due diligenceEffects of consequences
GDPRAll processing of personal data in the EUIllegal data collection for AI, lack of DPIA, weak processing groundsFine up to 4% of annual turnover, prohibition of data processing, claims
AI ActDevelopers and users of AI systems in the EUHigh-risk classification without preparation, violation of transparency, unacceptable risk (e.g. social scoring)Product ban, fine up to 6% turnover, recall from the market
MiCACryptoasset Issuers and Service ProvidersAbsence of white paper, unlicensed activity, incorrect qualification of the tokenProhibition of Offerings, Fines, Criminal Liability in Some Member States
NIS2Critical infrastructure operators and important organizationsLack of cybersecurity policy, failure to report incidentsLarge fines, suspension of activities, personal responsibility of management
DSA / DMADigital platforms, search engines, gatekeepersNon-transparency of algorithms, lack of risk management, unfair conditionsFine up to 6% of turnover, obligation to change business model
Export controlsDual-use software developersLack of licenses, supply to sanctioned jurisdictions, encryption technologiesCriminal liability, blacklisting, loss of contracts

How to strengthen your position before a deal

The best due diligence doesn’t start in the seller’s data room, but in the target selection stage.

It is advisable:

  • Conduct a preliminary evaluation of the company’s open source (SCA) before signing Term Sheet;
  • include in the main terms of the transaction the seller’s obligation to provide a complete register of IP and data flows;
  • agree on the right to interview with CISO, DPO and CTO;
  • Request a list of all AI models used and developed;
  • to specify to Term Sheet that the detection of regulatory violations gives the right to withdraw from the transaction without loss;
  • Consider structuring the acquisition as a purchase of a business (assets) rather than a stock if the legal risks are too high but the technology is needed.
  • ensure that the EU’s technology regulatory team is involved from day one of due diligence.

Common Mistakes in Legal Due Diligence of Technology Companies

  1. Ignore the origin of the data for model training. Even the best AI model can be poisoned legally if data is collected without legal basis.
  2. Do not audit open source code. One component with a GPL license can infect the entire product by requiring the source code to be disclosed.
  3. GDPR does not apply to B2B SaaS. GDPR protects the personal data of customer representatives and employees in the same way as consumer data.
  4. Only review the current AI Act, without considering its implementation acts and future harmonisation standards. The EU market will move towards strict standardization.
  5. Rely on the assurances of the founder: "We're clean, we've checked." Without a documentary IP rights chain, it costs nothing.
  6. Missing the rights to inventions of consultants and freelancers, especially in international teams. The applicable labor and copyright laws may differ greatly.
  7. Classify tokens solely on the basis of the white paper project. The regulator looks at the economic substance, not the name.
  8. Do not check the history of cybersecurity incidents and user complaints. It is an indicator of future problems.
  9. Delay due diligence for the last weeks before closing. There is no time left to eliminate critical findings.
  10. Do not structure specific industries for regulatory risks. Standard SPA warranties rarely cover GDPR or AI Act fines.

Investor checklist: 15 critical issues

  1. Who is the author and copyright holder of the key technology and AI models?
  2. Have all developers and consultants signed agreements to transfer exclusive IP rights?
  3. Have open source components been audited and have virus licenses been identified?
  4. What legal grounds are the data collected and used for AI training?
  5. Does the company have registered rights to inventions (patents) in the main jurisdictions?
  6. Has the Data Protection Impact Assessment been carried out for AI and analytics related processes?
  7. Does the product fall under the AI Act high risk category and is the documentation ready?
  8. Does the company require a CASP license or other MiCA authorization?
  9. Are the requirements of NIS2 and national cybersecurity laws complied with?
  10. Are export control restrictions applicable to the product or its components?
  11. Do commercial contracts contain change of control clauses and potential grounds for avoidance?
  12. Have there been any data breaches and what measures have been taken?
  13. Does the algorithms violate the DSA’s transparency and antitrust laws?
  14. Are there employee options or third party rights to share in the company that are not reflected in the cap table?
  15. What representations & warranties and indemnities does the seller offer to cover regulatory and IP risks?

What is a Legal Due Diligence Strategy?

A strong strategy is usually built on five levels:

1. Technology & IP Assessment: An in-depth analysis of the rights chain for algorithms, code, datasets and know-how. The freedom to use technology without infringing on the rights of third parties.

2. Regulatory Mapping & Gap Analysis – a continuous scan of applicable EU regulations (GDPR, AI Act, MiCA, NIS2, DSA, DMA, Dual-Use Regulation) and an assessment of the gaps between the current state of the company and the required level of compliance.

3. Contractual & Liability Exposure: Identification of hidden liabilities, product liability risks, contract transitions, and vulnerabilities in commercial contracts.

4. Corporate & HR Housekeeping Checks corporate cleanliness, IP rights of staff, vesting and employment agreements that exclude future disputes.

5. Deal Structuring & Risk Mitigation Transformation of Due Diligence Findings into Transaction Mechanisms Special assurances, targeted loss recovery, closing conditions, insurance and post-closing undertakings.

Without the fifth tier, the first four remain merely a statement of problems, not a tool to protect an investment.

FAQ

What is the peculiarity of due diligence of an AI company compared to classical IT?

Beyond standard IP verification, it is critical to investigate the source and legitimacy of training data, assess the system’s classification under the AI Act, and the risks of algorithmic bias that could lead to discrimination claims.

Is it necessary to take into account the EU AI Act if it has not yet fully entered into force?

Yes, I will. The investment is designed for years to come. A product that is not ready for AI today may be outlawed tomorrow. Due diligence should include a forward-looking assessment and a roadmap for compliance.

How to verify data rights for machine learning?

The data chain is analyzed: from open sources (taking into account the conditions of use of the sites and prohibitions on scraping), from users (with informed consent, compliant with the GDPR), from third-party providers (with guarantees of purity of rights). Particular attention is paid to datasets containing personal data.

Can a single, infected open source library stop a deal?

Yeah. If a product includes a component under a GPL or AGPL license and is distributed as a whole, it may require the company to disclose all source code. For the investor, this means losing the exclusivity of the technology, which is often fatal.

What should I do if I find a serious violation of GDPR?

The scope, enforcement risk and the possibility of elimination before the transaction should be assessed. The structure of the SPA includes special indemnities, holding part of the price (holdback) until full compliance, as well as the obligations of the seller to interact with the supervisory authority.

How important is export control for an AI startup in the EU?

It is critical if the technology is associated with encryption, geospatial data analysis, biometric identification, or can be used for military purposes. Lack of a license can paralyze exports to the U.S. and other countries, and create a risk of criminal liability for management.

Will W&I insurance protect you from regulatory penalties?

W&I insurance covers some of the unknown risks, but often excludes penalties and penalties under public law. Therefore, you can not rely only on insurance – you need structural protection in the transaction.

More importantly: Check patents or freedom of action?

For investors, freedom to operate is more important. The presence of a patent with the company does not guarantee that the product does not infringe other people's patents. It is necessary to look for encumbrances and risks of blocking the rights of third parties.

Related services

  • Corporate M&A and Venture Capital (Tech Focus)
  • Intellectual Property & Technology Transactions
  • Data Protection, Privacy & GDPR Compliance
  • AI & Digital Regulation (EU AI Act, DSA, DMA)
  • Fintech, Crypto-Assets & MiCA
  • Cybersecurity, NIS2 & Digital Resilience
  • International Sanctions & Export Controls
  • Regulatory Investigations & Tech Compliance
  • Cross-Border Tech Investment Structuring

Related material

  • What is the EU AI Act and how to prepare a tech company for its entry
  • GDPR and machine learning: Five main requirements for a European startup
  • Open Source Audit in an M&A transaction: How to Avoid Losing Exclusive Code Rights
  • MiCA in action: Guide for Investors in Crypto Projects in the EU
  • Due Diligence of Intellectual Property: From the chain of rights to freedom of use
  • How to Protect Data and AI Models When Investing in a European Company
  • Structuring the acquisition of technology business: stock
  • Cybersecurity and NIS2: Why it is important for investors to check the digital sustainability of the target
  • Export control of software in the European Union: What you need to know before a deal

Conclusion

Legal review of a technology company before investing in Europe is not a formal procedure, but strategic intelligence. It determines whether brilliant technology will turn into a secure, scalable asset or a source of lockdowns, fines and lawsuits.

In the context of multi-layered EU regulation – from GDPR and AI Act to MiCA and NIS2 – the winner is not the one who closed the deal faster, but the one who identified regulatory gaps in advance, impeccably enshrined rights to the technology and distributed risks in the transaction structure. This is what distinguishes a successful investment from a costly litigation.

Have a question about the topic of this article?

Write to us and we will respond within one business day.