5 min readSanitized AI Team

The AI Controls Investors Now Probe in Technical Diligence

Data SecurityAI GovernanceLLM SecurityRiskData Privacy

A term sheet is on the table, and the acquirer's technical team asks a question your CTO didn't rehearse for: "How do you prevent your engineers from pasting source code, architecture diagrams, or unpublished research into public AI tools?" A shrug — or a policy PDF nobody follows — is now a diligence finding. For a deep-tech or biotech company whose valuation is its IP, that answer can move the number or stall the deal.

Diligence has caught up to how engineering actually works in 2026. The people closest to your crown-jewel IP — the founding engineers, the lead scientists, the platform architects — are also the heaviest AI users, because AI makes them faster. Investors know this, and they've started probing the exact seam where velocity and confidentiality collide.

Why AI usage moved onto the diligence checklist

Diligence is a search for value that might not survive contact with reality. A patent that turns out to be unenforceable, a trade secret that was never actually secret, a data practice that invites regulatory exposure — each is a discount waiting to be applied. Generative AI created a new category of all three.

The usage numbers are why. Gartner's 2026 survey found that 88% of employees with enterprise AI access also use personal AI tools for work, and 69% of organizations suspect or have evidence of prohibited public GenAI use. LayerX's 2025 data puts it more bluntly: 77% of AI users paste data into prompts, and 82% of that comes from unmanaged personal accounts. When your most technical staff are among that majority, an acquirer has to assume some of your IP has already passed through a public tool — unless you can show otherwise.

And the diligence team knows something founders sometimes gloss over: once data is submitted to a public AI tool, it cannot be recalled. It may be retained, processed by sub-processors, or used to train the provider's models. Pasted content becomes subject to the provider's terms of use, which can grant broad rights to retain and use it. There is no clawback clause for a prompt.

The scenario that shows up in a data room

Picture a machine-learning engineer six months before a raise. She's debugging a training pipeline that encodes the company's core modeling approach — the thing the whole valuation rests on. She pastes a 200-line block into a public chatbot to get help untangling a stack trace. It works. She ships the fix by lunch. Nothing breaks, no alert fires, and the moment is forgotten.

Now replay it during diligence. The acquirer's counsel asks whether any pre-patent inventions or proprietary algorithms have been disclosed to third parties. The honest answer is: nobody knows, because there's no record of what left. That uncertainty is the finding. It doesn't matter that the engineer had good intentions or that the fix was elegant — what matters is that the company cannot demonstrate the disclosure didn't happen.

This is where the abstract risk becomes concrete money. A trade secret depends on reasonable efforts to keep it secret. In Trinidad v. OpenAI (N.D. Cal., Jan 2026), a trade-secret claim was dismissed because developing the alleged secrets through ChatGPT counted as voluntary disclosure — secrecy was lost. The case is early and directional, not settled law, but it names the exact mechanism a diligence team is looking for: value that evaporated the moment it entered a public prompt box.

What acquirers actually want to see

The reassuring answer isn't a ban. Investors know bans fail — Samsung banned ChatGPT company-wide in 2023 only after engineers had already pasted source code, a defect-detection algorithm, and a meeting transcript into it within about 20 days of allowing the tool. A prohibition on paper tells a diligence team you identified the risk and then relied on hope.

What holds up is evidence of a working control. Three things, specifically:

  • Visibility. Can leadership see where AI is being used across engineering and where risk concentrates? IBM's 2025 report found 63% of organizations have no AI governance policy at all — so simply having usage visibility already puts you ahead of most of what a diligence team sees.
  • A control that acts before submission. The only place to protect an invention is before the prompt leaves — because after submission there's nothing left to control. IBM found only 17% of organizations have technical controls to redact or block sensitive data at the point of entry. Being in that 17% is a differentiator you can point to.
  • A record that the control worked. Not a log of what your engineers typed, but a record that sensitive content was caught before it could leave. That's the artifact that converts "trust us" into demonstrable diligence.

The last one matters most in a data room. "We don't allow it" is a claim. "Here is the record of our control catching and stopping proprietary content before it reached a public tool" is proof — and it lets your engineers keep working at full speed instead of routing around a policy that slows them down.

The through-line to valuation

The shadow-AI cost isn't only a future breach. IBM's 2025 figures put IP at $178 in cost per record and found breaches involving high levels of shadow AI cost about $670K more on average. But in a transaction, the sharper cost is the discount an acquirer applies to IP they can't confirm is still exclusive. Uncertainty is priced. You want your engineers fast and your inventions provably intact — and those two goals only coexist when the control lives at the prompt, not in a policy document.

This is the principle Sanitized AI is built on: sensitive data — source code, pre-patent inventions, proprietary research — is caught and redacted before a prompt reaches the AI tool, and the event is recorded without capturing what the person typed. Governance that keeps the velocity, and produces the evidence a diligence team asks for.

Before your next raise or acquisition, ask the question your acquirer will: if an engineer pasted our core IP into a public tool last month, would we even know? If the answer is no, that's the control to put in place this quarter — well before it becomes a line item in someone else's diligence report. Request a demo to see what that record looks like.

See how Sanitized AI stops sensitive data from leaving the prompt box.