What Buyers Now Diligence in AI and Autonomy Deals: Lessons from Apple's AI Acquisition
Introduction
The acquisition of AI companies has become one of the most consequential deal categories in technology. Global investment in generative AI surged to $25.2 billion in 2023, and the global AI market is projected to reach $407 billion by 2027. With that growth has come a wave of acquisitions by major technology companies seeking to add AI capabilities to their platforms, and with those transactions has come a rapidly evolving diligence playbook.
This article is part of a twelve-week series on autonomous systems, physical AI, and patent strategy. In our prior articles, we established an expanded taxonomy of patentable inventions across the physical AI landscape, presented a comprehensive IP strategy playbook for autonomous systems companies, and examined the data on whether patent filings help physical AI companies raise capital. Here, we turn to the buyer’s side of the equation: what do acquirers now diligence in AI and autonomy deals?
In a 2021 article, we examined this trend through the lens of Apple’s AI acquisitions. From 2016 to 2020, Apple acquired more AI companies than any other buyer, including several with technology applicable to autonomous vehicles (AVs) and electric vehicles (EVs): Drive.ai, Emotient, Vilynx, Xnor.ai, Lighthouse AI, Spectral Edge, and Spektral. The data revealed a striking pattern. The three companies Apple acquired for over $100 million, including Drive.ai ($200M, 19 patent assets), Xnor.ai ($200M, 20 patent assets), and Emotient ($100M, 22 patent assets), each had approximately 20 U.S. patent assets and went from founding to acquisition in just four years. Companies with materially smaller portfolios commanded lower valuations and took longer to be acquired. Patent portfolios, in short, appeared correlated with both acquisition value and speed to exit.
That finding remains relevant today, but the buyer’s diligence playbook has expanded dramatically. AI acquisitions in the autonomy and physical AI space now demand investigation across six critical pillars that go well beyond counting patent assets.
1. Proprietary Data: The New Crown Jewel
The original article focused on patents as the key asset driving acquisition value. Today, proprietary data has emerged as an equally critical, and in many cases more important, diligence target. As the cost of programming AI-powered algorithms and large language models comes down, buyers are looking beyond pure engineering talent and seeking to confirm that the target controls unique and proprietary datasets. It’s no longer just about the algorithms and large language models; it’s about having access to proprietary data that no one else can get, and the ability to use that data in the AI system in the manner desired.
For AI companies, the real value often lies in intangible assets, including layered, multifunction algorithms, large language models, and exclusive access to proprietary datasets that together produce valuable answers and drive monetization. Buyers conducting diligence must now trace the “genealogy of the data, from its origin to the assignment to the buyer” and confirm that the seller is transferring contractual rights sufficient to use the data for the buyer’s intended purpose.
In practice, this means diligence teams should ask: What can each party do with the data? Are there confidentiality obligations? Use restrictions? Geographic storage location considerations? If insights from the data lead to innovations, who owns those? If the data leads to incorrect conclusions, who is on the hook? These questions are especially critical in the autonomous systems context, where data pipelines may involve automated labeling, active learning, data compression for high bandwidth sensor streams, privacy-preserving collection, and federated learning across distributed fleets.
2. Patent Assets: From Counting to Characterizing
Our 2021 analysis demonstrated a correlation between patent portfolios and acquisition outcomes. That finding holds, but the diligence inquiry has become more sophisticated. Buyers today are not simply counting patent assets. They are characterizing them.
Patent diligence should now assess claim scope, validity, enforceability, infringement risk, freedom to operate, third-party challenges, ownership, chain of title, inventor assignments, and maintenance fee status. For AI-specific patents, diligence teams should examine whether claimed inventions disclose sufficient technical detail rather than functioning as “black box” claims, including architecture, training methods, inputs, preprocessing, inference, runtime updates, and concrete technical improvements.
In the autonomous systems space, as established in the first article in this series, the patentable technology stack has expanded to cover perception and sensor fusion, AI and ML models and training methods, planning and decision-making systems, edge computing architectures, simulation and testing, safety and redundancy systems, human and machine interfaces, fleet and swarm management, and data pipeline innovations. Filing strategy should also be aligned with product development and funding milestones, and the portfolio should be organized by product line, technology area, and geography.
At the pre-exit stage, acquirers should confirm that patent assignments are recorded, inventor declarations are complete, maintenance fees are current, and ownership chains are clean. Patent ownership risk is acute in this space because development frequently involves cross-functional teams, university labs, government research institutions, open-source communities, specialized consultants, joint development partners, and pre-existing founder IP.
Detectability is another critical factor in valuing AI patents. Features visible in product operation, user interfaces, or product documentation are easier to detect and enforce; features retained solely in cloud infrastructure may be better maintained as trade secrets.
3. Technical Authenticity: Guarding Against “Fake AI”
A risk that did not feature prominently in our 2021 analysis is the problem of “fake AI.” Technical diligence should test whether the AI solution is authentic, robust, scalable, and aligned with business objectives. Without thorough technical diligence, investors face exposure to misrepresented solutions lacking genuine capabilities, potentially leading to substantial financial losses.
The rise of “AI Washing” is the intentional overstating of a product or service’s AI capabilities to make it appear more innovative than it actually is. This practice has drawn significant enforcement attention. In March 2024, the SEC brought its first-ever settled charges against two investment advisers, Delphia and Global Predictions, for misrepresenting their use of AI to attract investors. Both companies claimed to use AI technologies they did not actually possess. Delphia paid a civil penalty of $225,000, and Global Predictions paid $175,000.
For buyers in AI and autonomy deals, the lesson is clear: diligence must go beyond reviewing marketing materials and pitch decks. Technical diligence should independently evaluate algorithms and models, actual AI functionality and deployment, data privacy and security measures, and compliance with relevant regulations. Buyers should also ensure that public statements about AI capabilities have been reviewed by legal counsel and are accurate.
4. Regulatory Exposure: A Rapidly Expanding Landscape
In 2021, the regulatory landscape for AI was sparse. It is no longer. According to the Stanford University AI Index Report, the number of AI-related regulations in the U.S. rose from just one in 2016 to 25 in 2023, growing by 56.3% in 2023 alone. The count of U.S. regulatory bodies crafting AI regulations climbed to 21 in 2023, up from 17 in 2022, with newcomers including the U.S. Department of Transportation, the U.S. Department of Energy, and OSHA.
On the international front, the EU AI Act has established the world’s first comprehensive AI regulatory framework, classifying AI systems into four risk levels (unacceptable, high, limited, and minimal), each with corresponding compliance obligations. At the same time, antitrust officials at the DOJ, FTC, European Commission, and the UK’s Competition and Markets Authority have pledged to remain vigilant regarding AI’s risks to competition.
For AI acquisition diligence, this means buyers need to understand where the target operates and where users can access the product in order to determine the breadth and scope of applicable laws. Key regulatory areas include data privacy (GDPR, CCPA, HIPAA), algorithmic bias, ethical AI standards, antitrust scrutiny, and industry-specific regulations. AI acquisitions are facing special scrutiny from antitrust and competition regulators, who are concerned with not only monopolistic practices and anti-competitive behavior but also the effect of AI on jobs.
Purchase agreements should reflect this regulatory complexity with tailored representations and warranties covering ownership, noninfringement, data privacy compliance, cybersecurity integrity and maintenance, and disclosure of known risks or limitations. Buyers may further seek indemnities, holdbacks, escrow arrangements, and increasingly, third-party insurance to manage post-closing regulatory risk.
5. Cybersecurity: A Growing Attack Surface
As autonomous systems become more connected, cybersecurity diligence has become a standalone pillar of AI acquisition analysis. According to a 2023 report by Upstream, automotive cyberattacks spiked by 380% in just one year, from 2021 to 2022, affecting telematics, infotainment systems, electronic control units, and remote keyless entry systems. As the number of computing devices, sensors, and communication interfaces increases, so does the attack surface available to malicious actors.
AI-specific cybersecurity risks extend beyond conventional threats. Adversarial data, meaning subtle, almost unnoticeable changes to training data, can undermine how an AI algorithm works and cause unexpected outcomes, destroying the positive impact of AI. It is critical that companies ensure the security of their training data and their software. Bad data, adversarial inputs, compromised sensors, or weak connected infrastructure can affect not only privacy and IP, but also safety and real-world system behavior.
Buyers should assess security by design, secure development and networking practices, product testing, vulnerability monitoring, incident response programs, and supplier security controls. Importantly, cybersecurity is not the same as compliance: while compliance with data privacy regulations is necessary, it may not always be sufficient to protect data. Companies should implement security measures beyond minimum regulatory requirements, including eliminating vulnerabilities at the design stage and continuously monitoring for emerging threats.
6. Rights to Use Training Data: The New IP Frontier
Perhaps the most significant shift since our 2021 article is the emergence of training data rights as a freestanding diligence category. Many AI models have been trained on third-party data without appropriate authorization or consent from copyright owners, resulting in potential downstream liability to end users of such models.
Buyers should examine whether the target’s training data was lawfully collected and whether the target has contractual rights sufficient for the buyer’s intended use. Diligence should review existing agreements to determine whether customer or third-party data may be used for training vendor systems or improving the vendor’s own products. Copyrights associated with training materials should be confirmed as properly licensed or excluded.
The regulatory trajectory further underscores this risk. Proposed legislation like California’s AB2013 would require developers of AI systems to publish documentation of the datasets used to train those systems. As transparency requirements expand, gaps in training data provenance that might have gone unnoticed in an earlier era could become material liabilities.
Conclusion: A New Diligence Framework for AI and Autonomy Deals
When we published our original article in 2021, patent assets were the primary lens through which buyers evaluated AI acquisition targets. The data from Apple’s acquisitions, as discussed in our 2021 article, illustrated the value of a deliberate patent strategy: companies with approximately 20 patent assets commanded valuations exceeding $100 million and exited within four years.
That finding endures, but it is no longer sufficient. As AI companies move from research projects to production systems that operate in the physical world, the risk profile for AI-centric business models is so different from acquisitions of other technology businesses that a new approach is required. Buyers today must conduct a retargeted due diligence investigation that spans proprietary data, patent characterization, technical authenticity, regulatory mapping, cybersecurity assessment, and training data rights.
For AI companies developing AV/EV related technology, or any physical AI system, a strong patent portfolio remains a powerful signal of innovation and proprietary technology that can multiply valuation. But the companies best positioned for acquisition will be those that can demonstrate not only patent strength, but also clean data provenance, genuine technical capabilities, regulatory readiness, robust cybersecurity, and defensible rights to the data that trains their systems. In our next article in this series, we ask where the physical AI patent wars may begin, as autonomy expands from vehicles into drones, robotics, defense systems, industrial automation, and AI-enabled hardware.
* * *
DISCLAIMER: The information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.