Skip to main content

AI in M&A: Use Cases, Confidentiality Risks, and a Safe Workflow

Where AI helps across an M&A process, where confidentiality makes it unacceptable, and the workflow controls a deal team needs before anything touches the data room.

Maximilian BetzPublished 26 August 202613 min read

Evidence base

Sources behind this article

This article supports its claims with 4 sources. Key sources include:

All 4 sources and access dates

AI helps most in M&A where the work is high volume reading and assembly: diligence document review, extracting terms from contract sets, building comps from approved data, and producing committee packs from controlled sources. It helps least, and creates the most exposure, in exactly the place people are tempted to use it first, which is pointing a general purpose tool at a data room.

The reason is not model quality. It is that M&A has a confidentiality structure unlike almost any other business process, and most AI tooling was not designed with that structure in mind.

Let me set out where the line sits.

What makes M&A different

Three properties, and any one of them would justify special handling.

Information is compartmented by design. Deal teams are separated from each other deliberately. Wall crossing is a documented event. Who knows what, and when, is not an administrative detail, it is the control structure.

Undertakings run to third parties. A non disclosure agreement with a counterparty may restrict who may access material, where it may be processed and what happens to it if the deal breaks. A tool decision can breach a contract that your firm signed, and the counterparty is the one harmed.

Material may be price sensitive. Where inside information is involved, an inadvertent disclosure is not just embarrassing. It attracts a different category of consequence entirely.

Any AI deployment in this environment has to respect all three, and it has to respect them structurally rather than by asking people to be careful at two in the morning during a diligence sprint.

Where AI genuinely helps

Diligence document review at scale. The strongest use case in the whole process. A contract set of several thousand documents, read against specific questions: change of control provisions, assignment restrictions, termination rights, exclusivity, most favoured nation clauses, unusual liability caps. The requirement is that every finding carries a citation to the source document and page, and that the system reports what it could not find rather than reporting nothing.

Term extraction into a structured table. Turning a contract set into a comparable data set. Enormously faster than manual review and verifiable, because each row points at a source.

Comparable company and transaction tables. From approved data with as of dates. Mechanical, high volume, checkable.

Management presentation and committee pack assembly. From controlled sources into the approved template, with native charts carrying their data.

Diligence finding synthesis. Turning workstream findings into a structured issue list with severity, owner and status. Useful because the source findings exist and can be checked.

Quality checking the document set. Number consistency across the pack, defined term usage, cross references, missing schedules, unit and currency consistency. Read only, immediate value, catches the errors that erode credibility in a committee.

Data room index and gap analysis. What was requested, what was provided, what is missing. Mechanical and tedious, which is the profile that automates well.

Where it must not go

The investment thesis and the valuation view. These are the judgements the deal team is accountable for. Drafting support around a decision that people have made is fine. Making the decision is not, and a committee that cannot identify which human formed a view has a governance problem regardless of the tool.

Legal conclusions. Whether a clause is enforceable, whether a change of control provision is triggered, whether a regulatory approval is required. Extraction and flagging, yes. Conclusion, no.

Anything crossing a deal boundary. This is a hard structural limit, not a policy preference.

Material touching inside information without the controls that framework demands. If your compliance function has not specifically approved the workflow for that category, it is not approved.

Unreconciled numbers in a committee pack. Every figure a committee sees should resolve to a source. A plausible number in a professionally formatted deck gets acted on.

The confidentiality architecture

This is the part that determines whether any of the above is safe, so I want to be specific.

Deal team isolation is absolute. Each transaction gets its own workspace. Retrieval never crosses a boundary. Not with a warning, not with a permission prompt. It returns nothing, and it does not indicate that anything exists.

The agent runs with the user's entitlements. Never a service identity with broad read access. This is the shortcut that makes demos impressive and creates a privilege escalation path with a friendly interface.

Test the boundary adversarially, before the deal. Create a user outside a deal team. Phrase a request designed to encourage retrieval across the wall. Confirm the answer is silence. Run the test through the main interface, search, export, share links and any API, because the failure is almost always in a surface other than the main one.

Check the tool against the NDA, not just against your policy. Where a confidentiality undertaking restricts processing locations, sub processing or access, the tool has to comply with the undertaking your firm signed. Counsel should confirm this before the tool touches counterparty material.

Deletion has to be real and demonstrable. When a deal breaks, the material has to go. Uploads, prompts, retrieval indexes, drafts, generated files, logs and backups. Ask the vendor to demonstrate a deletion before you start, not after.

The GDPR position in diligence

Personal data in M&A diligence is constant and frequently underestimated. Employee lists with compensation. Management assessments. Customer records. Contracts naming individuals. Litigation files. Pension data, which is often special category.

Four things need a decision rather than an assumption:

Lawful basis. For processing counterparty employee data in diligence, this needs to be identified and documented, and it is rarely consent.

Minimisation before upload. Redact, aggregate, or exclude. The safest personal data is the data the AI workflow never receives, and diligence is one of the easiest places to over collect because the data room provides everything at once.

Processor arrangement. An Article 28 agreement with the tool vendor, where they act as processor, with terms that match the actual data flows.

Retention after the transaction. What happens to personal data when the deal closes, and when it breaks. This is the question nobody asks at the start and everybody needs the answer to at the end.

The safe workflow

Before the deal opens. Approve the tool for this transaction category. Confirm the processing chain, the training position and the deletion capability. Check compatibility with the NDA. Create an isolated workspace. Define the prohibited inputs. Brief the team on what may and may not be uploaded.

During diligence. Minimise at source before upload. Use the tool for reading and extraction, with citations required on every finding. Keep findings traceable to source documents and pages. Never let an extracted term become a legal conclusion without counsel review.

During pack production. Assemble from controlled sources into the approved template. Native charts carrying their data. Source references on every material figure. Gap markers where evidence is missing, and no release while markers remain.

Before the committee. Reconcile automatically: totals, cross document consistency, units, currencies, defined terms, cross references. Then a human reviews the argument and the judgement, which is what their time is for.

At close or break. Freeze the final versions with their source sets. Execute deletion across every location. Confirm it. Archive what must be retained under your own record keeping obligations, and only that.

The deal team checklist

Checklist
  • The tool is approved for this transaction category, in writing, before use.
  • The processing chain is documented, including support access and backup locations.
  • Inputs are contractually excluded from model training.
  • The workspace is isolated per transaction, and the boundary has been tested adversarially.
  • The agent runs with user entitlements, never a shared service identity.
  • Tool use is compatible with the confidentiality undertakings given to the counterparty.
  • Personal data is minimised before upload, with a documented lawful basis for what remains.
  • Every diligence finding carries a citation to source document and page.
  • Every figure in a committee pack resolves to a source with an as of date.
  • Legal and valuation conclusions are formed by named people, not extracted from output.
  • Deletion capability has been demonstrated by the vendor before the deal started.
  • Retention and deletion at close or break are defined and executed.

The EU AI Act, briefly

The AI literacy obligation under Article 4 has applied to deployers since 2 February 2025. In a deal team context that is not a formality: someone using a document review system without understanding how it fails cannot exercise meaningful judgement over its output, and the characteristic failure here is a confident finding with no basis.

Transparency obligations under Article 50 have applied since 2 August 2026. Annex III high risk obligations were deferred to 2 December 2027 by Regulation (EU) 2026/1744.

A diligence review tool is usually not a high risk system, but reach that conclusion through documented assessment, particularly where output touches employment matters.

What actually changes for a deal team

The realistic picture, based on what holds up in practice rather than what is promised.

Diligence reading compresses substantially. A contract review that consumed a week of associate time compresses considerably, and the quality often improves, because a system reads every document consistently while a tired human skims the last two hundred.

Pack production compresses. Assembly, formatting, chart building and reconciliation are mechanical.

Judgement does not compress, and should not. The time saved should go into asking better questions of the findings, testing the thesis harder, and spending more of the process on the two or three issues that will actually determine whether the deal works.

The failure mode to watch for: a team that reads less because the summary was good. A generated issue list is a starting point for investigation, not a substitute for it, and the issues that kill transactions are rarely the ones that summarise well.

Where offgen fits

offgen keeps deal material in native PowerPoint and inside workspace boundaries that map to your deal teams. Retrieval runs with the user's entitlements, and an unmatched request produces a marked gap rather than an invention. Source references and record identifiers survive into the pack, which matters when a committee questions a figure.

Our trust center, security overview and data processing agreement provide the material for the assessment described above, including processing locations, subprocessors and the contractual position on training.

The rule I would hold to in this sector: the boundary is not a policy, it is a property of the system. If your confidentiality depends on people being careful during a diligence sprint at two in the morning, you do not have a boundary. You have a hope.

Frequently asked questions

Where does AI genuinely help in an M&A process?

Document review at scale in diligence, extracting terms and obligations from contract sets, building comparable company and transaction tables from approved data, assembling management presentations and committee packs from controlled sources, synthesising diligence findings into issue lists, and quality checking the final documents.

Can you put confidential deal information into an AI tool?

Only where the tool is contractually and technically approved for that material, the processing chain is documented, inputs are not used for training, the data stays inside the deal team boundary and confidentiality undertakings to the counterparty permit it. That assessment must happen before the tool is used, not after.

What is the biggest AI risk specific to M&A?

Cross deal leakage through retrieval. An AI system with broad access to a firm's document estate can surface material from one transaction while someone works on another. That is a confidentiality failure and potentially a market abuse issue, and it must be prevented by the system rather than by user care.

Does the GDPR apply to M&A diligence with AI?

Yes, wherever personal data is processed, which in diligence is constant: employee lists, management data, customer records, contracts naming individuals. You need a lawful basis, minimisation before upload, a processor arrangement and a clear position on retention after the deal closes or breaks.

Should AI write the investment thesis?

No. The thesis is the judgement a deal team is accountable for. AI can assemble the evidence, structure the argument and draft the supporting pages. The conclusion, the valuation view and the risk assessment belong to named people who will answer for them.

How do you handle AI outputs when a deal breaks?

Deletion has to reach everything: uploads, prompts, retrieval indexes, drafts, generated files, logs and backups. Test that the vendor can actually do it before the deal starts. A tool that cannot demonstrate deletion is a tool that keeps your failed transaction indefinitely.

Sources

  1. 01Regulation (EU) 2016/679 (General Data Protection Regulation) EUR-Lex, 2016-04-27. Accessed 26 August 2026.
  2. 02Regulation (EU) 2024/1689 (Artificial Intelligence Act) EUR-Lex, 2024-07-12. Accessed 26 August 2026.
  3. 03Trust Center offgen. Accessed 26 August 2026.
  4. 04Data Processing Agreement offgen. Accessed 26 August 2026.

Related articles

Maximilian Betz

About the author

Maximilian Betz

Co-Founder and CEO, MD

Max writes about management consulting, enterprise adoption, data protection, and the operating controls required for AI in regulated organisations.