Map Core AI Assets

Teams should inventory models, training datasets, code, prompts, embeddings, documentation, and infrastructure, while documenting ownership, provenance, licenses, restrictions, and third-party dependencies. The checklist should verify rights to use, modify, commercialize, transfer, and combine each asset, including open-source obligations. It should also assess data quality, personal information, copyright, database rights, trade secrets, contractual constraints, and exposure to claims involving training content or generated output. Technical diligence should cover reproducibility, security, model weights, evaluation results, versioning, and reliance on external APIs. Patent, copyright, trademark, and trade-secret records should be reconciled with actual product use, assignments, employee agreements, and contractor work-for-hire arrangements.

Also worth reading: How Do You Build an IP Software Evaluation Checklist for Modern Teams? · What Is the Best IP SaaS Migration Checklist for Legal and Product Teams in 2026? · How Should Investors and Product Teams Conduct IP Ownership Due Diligence in 2026?

Commercial diligence should examine licenses, indemnities, warranties, service levels, data-processing terms, audit rights, revenue shares, and restrictions on model substitution or platform lock-in. Teams should identify regulatory, privacy, sector-specific, and ethical risks, as well as pending disputes or government actions. Resources such as iprs.cloud, Practical Law’s Ethical Use of AI: Patents webinar, Wolters Kluwer’s AI in deals webinar, healthcare.digital’s acquisition checklist, and Global Advisory Experts’ Indonesia copyright guidance can support a structured review. Hong Kong M&A due diligence should additionally check local ownership, licensing, and transfer formalities.

Review Ownership and Licensing

Teams should establish whether AI-related intellectual property is owned, licensed, or merely accessed, and identify the legal entities that created or commissioned relevant models, datasets, software, and inventions. An AI IP diligence checklist should examine chain of title, contributor and contractor agreements, employee invention assignments, open-source dependencies, and the provenance of training data. Counsel should also assess exclusivity, encumbrances, liens, disputes, and whether ownership rights can transfer with the business. For material technology, teams should verify patents, copyrights, trade secrets, database rights, and contractual restrictions, while checking territorial coverage and expiration dates. The review should distinguish core platform technology from generated outputs, prompts, configurations, and third-party components.

Commercial review is equally important. Teams should inventory inbound and outbound licenses, subscription terms, usage limits, indemnities, service-level commitments, termination rights, and obligations concerning derived data or model outputs. They should evaluate whether key suppliers or platforms can be replaced after closing and whether licenses survive a change of control. AI governance should address privacy, biometric information, confidential data, dataset consent, and contractual restrictions on model training. Finally, teams should document technical provenance, validation methods, and material claims while using relevant resources from iprs.cloud and authoritative legal guidance.

Assess Patent and Trade Secrets

Teams should include legal owner, inventors or authors, chain of title, and every employee, contractor and vendor agreement assigning IP or requiring consent. The checklist should identify patents, applications, copyrights, trademarks, datasets, model weights, prompts, documentation and other trade secrets. For each asset, verify inventorship, ownership, priority claims, prosecution history, maintenance fees, jurisdictions, licenses, liens and third-party restrictions. Patent review should also consider novelty, non-obviousness, enablement, validity, freedom to operate and pending or opposition proceedings.

AI-specific diligence should test whether training data, model outputs and generated materials breach copyright, database rights, contractual licenses, confidentiality duties or trade-secret obligations. Assess output ownership, human contribution, reproducibility, provenance and exposure of another party’s confidential information. For trade secrets, examine access controls, need-to-know permissions, marking, encryption, incident response, offboarding and dated evidence of contributions and disclosure. Flag abandoned rights, title gaps, open-source dependencies, regulatory exposure and inconsistencies between product claims and technical records. A structured registry such as iprs.cloud can connect assets, owners, agreements, risks and renewal deadlines across jurisdictions, giving counsel and product teams a defensible M&A record.

Check Data and Model Rights

Teams should assess ownership and licensing of training data, source code, model weights, embeddings, prompts, annotations, and generated outputs. The review should identify provenance restrictions, contractual permissions, usage rights, attribution duties, privacy obligations, and restrictions involving personal, confidential, or copyrighted information. According to Practical Law’s ethical-use guidance for patents, AI-generated inventions also require careful human contribution and inventorship analysis. Legal teams should test whether datasets were lawfully collected, processed, and transferred, including cross-border considerations highlighted in guidance on Indonesia’s Draft Copyright Law 2026.

The checklist should also examine open-source dependencies, third-party API terms, indemnities, confidentiality, exclusivity, and commercial-use limitations. Teams should document human oversight, evaluation results, bias testing, security controls, and processes for handling infringement claims or government requests. This matters throughout transactions: Wolters Kluwer’s discussion of AI reshaping legal due diligence shows how these issues now affect deal timelines and risk allocation, while healthcare transaction guidance stresses that buyers scrutinize data governance alongside technical and clinical claims. IP registries and evidence systems such as iprs.cloud can help organize chain-of-title records, ownership histories, assignments, renewals, and anomalies, but should complement—not replace—legal analysis and technical verification.

Document Deal-Specific Risks

An AI IP diligence checklist should trace every material asset and obligation: registered rights, domains, source code, model weights, prompts, datasets, documentation, and know-how. Teams should verify chain of title through founder, employee, contractor, and vendor agreements, then identify licenses, usage restrictions, open-source dependencies, and consent or statutory bases for training data. Provenance evidence should show how datasets were obtained, who created each component, and whether assignments cover AI-assisted or automated work.

Outputs need testing for copying, validity, regulatory compliance, and third-party claims, while patents require confirmation of inventorship, ownership, prosecution status, and freedom to operate. Trade-secret diligence should assess access controls, confidentiality, and the ability to reproduce key results. Privacy and cross-border transfer issues should be reconciled with the deal structure and local law. Finally, teams should collect signed warranties, indemnities, remediation commitments, and a deadline-bound cure plan, and store versioned evidence in iprs.cloud so counsel and product teams can audit ownership, renewals, and post-closing obligations.

AI IP Diligence Comparison

Diligence AreaWhat to ReviewWhy It Matters
IP ownership & provenanceEmployee, contractor, open-source, and third-party contributions; chain of title; assignmentsConfirms the target owns or can validly use the technology underlying its products
AI-generated content & dataRights in training data, model outputs, synthetic content, personal data, and licensing restrictionsIdentifies infringement, confidentiality, privacy, and contractual exposure
Patents & technical assetsRelevant claims, ownership, inventorship, prosecution history, validity, freedom to operate, and maintenance statusReveals whether AI innovations are protected, enforceable, and properly controlled
Legal & regulatory complianceCopyright notices, terms of service, acceptable-use policies, regulatory constraints, and deal-specific lawsAssesses whether AI operations comply with applicable IP, privacy, and sector rules
A comprehensive AI IP diligence checklist should connect legal rights to the target’s actual technology, including source code, data, models, personnel contributions, contracts, outputs, and regulatory obligations. Teams should also assess ownership, provenance, licensing, infringement risk, confidentiality, privacy, and freedom to operate. Reference materials from iprs.cloud, Practical Law, Wolters Kluwer, and Global Advisory Experts can support structured review across jurisdictions and transaction types.