AI diligence findings into Dutch SPA and BV document architecture
Category: InsightsHow AI risks move from diligence reports into warranties, indemnities, disclosure, governance and closing mechanics
AI diligence findings in Dutch M&A transactions are the legal and commercial findings about a target’s use, development, dependency on or exposure to artificial intelligence that must be translated into the SPA, disclosure schedules, indemnities, covenants, escrow mechanics and Dutch BV governance documents.
The issue is no longer whether artificial intelligence is relevant to transactions. The more important deal question is where AI-related risk belongs in the document architecture. Some findings belong in due diligence only. Some belong in the seller warranties. Some require specific disclosure. Some justify a special indemnity, escrow or holdback. Others require post-closing covenants, board oversight or changes to the target’s governance framework.
For earlier insights on this topic, see AI & Dutch Transactions, AI due diligence in Dutch M&A transactions, AI reps and warranties in Dutch M&A and VC deals and Indemnities in Dutch M&A transactions.
AI diligence is not a separate workstream if it affects value
In many Dutch transactions, AI is still reviewed as part of IP, IT, data protection or compliance diligence. That may be enough where AI use is incidental. It is not enough where AI is embedded in the target’s products, software development, customer delivery, pricing, underwriting, recruitment, customer support, fraud detection or internal operations.
The buyer’s legal team should ask a practical question: if this AI finding is wrong, unresolved or under-documented, how does it affect enterprise value or buyer exposure?
If the answer is “materially”, the finding should not remain buried in the diligence report. It should be converted into a drafting position. That may mean a warranty, a disclosure requirement, a closing condition, a covenant, a specific indemnity, an escrow or a governance obligation.
Which AI findings belong in warranties?
AI warranties are appropriate where the buyer wants the seller to stand behind statements about the target’s AI position. These warranties may cover ownership or lawful use of AI systems, training data, customer data, third-party tools, output use, compliance policies, material AI incidents, contractual restrictions, IP claims and the absence of undisclosed AI dependencies.
The drafting should be specific. A broad warranty that “the company complies with all applicable AI laws” may look protective, but often does little to address the actual diligence issue. If the concern is that the target uses third-party AI tools to generate customer-facing output, the warranty should address that use case. If the concern is that customer data has been used for model training, the warranty should focus on rights, restrictions, consents and disclosure.
In Dutch SPA practice, AI warranties should also be aligned with the ordinary warranty limitations. The buyer should consider whether AI warranties are subject to knowledge qualifiers, materiality, disclosure, de minimis thresholds, baskets, caps and survival periods.
Which AI findings belong in disclosure schedules?
Disclosure is where many AI issues become negotiation-heavy. Sellers will want to disclose enough to prevent warranty claims. Buyers will want disclosures to be specific enough to reveal the risk, not so broad that the warranties become meaningless.
A useful AI disclosure should not merely say that the target “uses AI tools”. It should identify the relevant tools, business processes, data categories, contractual restrictions, governance gaps, incidents, customer dependencies or vendor risks.
For a Dutch SPA, the disclosure schedule should connect clearly to the warranty it qualifies. If the seller discloses a third-party AI tool, the buyer should understand whether the issue is IP ownership, data use, regulatory exposure, operational dependency, customer contract breach, cybersecurity, confidentiality or model performance.
A vague disclosure may reduce clarity for both sides. It may also create later disputes about whether the buyer had sufficient knowledge of the relevant risk.
When AI findings require a specific indemnity
A specific indemnity is appropriate where diligence has identified a known AI-related issue that is too specific, too material or too uncertain to leave within the ordinary warranty package.
Examples may include a known claim about AI-generated output, unresolved ownership of AI-assisted software, breach of customer data-use restrictions, use of prohibited data for model training, regulatory investigation, known vendor failure, or a material AI deployment without adequate contractual rights.
In Dutch SPA drafting, the indemnity should be ringfenced. It should define the risk, the covered losses, the claim process, the survival period, any cap, any interaction with insurance and whether mitigation or remediation costs are included.
For sellers, the negotiation focus is to prevent an AI indemnity from becoming a broad backdoor warranty. For buyers, the focus is to ensure the indemnity actually covers the economic exposure identified in diligence.
Escrow, holdback and RWI carve-back planning
AI issues may also affect recourse architecture. If a buyer relies on warranty and indemnity insurance, AI findings may be excluded, limited or treated as known risks depending on the underwriting process and policy wording.
That matters for Dutch SPA drafting. If an AI risk is excluded from W&I or RWI coverage, the buyer may need seller recourse, escrow, a holdback or a special indemnity. If the seller wants a clean exit, the parties may need to price the risk, remediate it before closing or structure a limited ringfenced recourse package.
The drafting should avoid gaps. A known AI risk should not fall between the SPA, the disclosure schedule and the insurance policy without clear allocation.
AI governance after closing
Some AI findings are not primarily damages claims. They are governance issues. If the target lacks AI policies, vendor controls, data-use approvals, board reporting, customer disclosure procedures or incident response processes, the buyer may prefer post-closing governance covenants or integration steps.
For Dutch BV companies, this can affect board reporting, reserved matters, compliance policies, management instructions and investor monitoring rights. If the buyer is a PE sponsor or VC investor, the shareholders’ agreement may need to address AI governance as part of broader information rights and board oversight.
The practical question is simple: who controls AI risk after closing?
Dutch BV document architecture
AI risk can sit in several documents at once:
The SPA may contain warranties, disclosure, indemnities, covenants, conditions and claims mechanics. The disclosure letter or disclosure schedules qualify the seller’s statements. The shareholders’ agreement may include governance, information rights and reserved matters. The articles of association may need to support shareholder approvals or share rights if the AI issue arises in an investment round. Board resolutions and internal policies may implement the operational controls.
A strong Dutch transaction structure does not treat these documents separately. It connects diligence findings to the right document and the right remedy.
FAQ
What is AI diligence in Dutch M&A?
AI diligence is the review of how a Dutch target develops, uses, licenses, governs or depends on AI systems, data, tools, vendors and AI-generated output.
Are standard IP and IT warranties enough for AI risks?
Often not. Standard warranties may miss AI-specific issues around training data, model use, output ownership, vendor dependency, customer restrictions and internal governance.
When should AI risk become a specific indemnity?
When diligence identifies a concrete known issue that is too material or uncertain to leave within the general warranty framework.
Can AI findings affect Dutch BV governance?
Yes. AI use may require board reporting, reserved matters, investor consent rights, policies, vendor controls or post-closing remediation covenants.
About Dirk de Waard
Dirk de Waard is a Dutch corporate / M&A lawyer, partner at Venture Lawyers in Amsterdam, and advises buyers, sellers, investors, founders, management teams and international counsel on Dutch M&A, VC, PE and governance issues, including AI-related transaction risk.
Are AI diligence findings properly reflected in the deal documents?
AI diligence has little value if the findings are not translated into warranties, disclosure, indemnities, escrow, holdback, governance or post-closing implementation.
Dirk de Waard advises buyers, sellers, investors and international counsel on AI-related risk allocation in Dutch SPAs, investment agreements and Dutch BV governance documents. Contact Dirk de Waard at dirk.dewaard@viottalaw.com to align AI diligence findings with the Dutch transaction document architecture.
