MICKAI®ArticlesCan bidders use AI on data room m…
Article · 21 July 2026

Can bidders use AI on data room material in M&A due diligence?

Only after reading the NDA and data room terms; the defensible pattern is AI inside the confidentiality perimeter with a sealed processing record.

Author
Micky Irons
Published
21 July 2026
Follow Micky Irons
LinkedInX
sovereign aim&adata sovereigntyaudit trailon-premise ai

Read the NDA and the data room terms first, because for most deals the honest answer is: not through a public cloud AI service. Uploading data room documents to a cloud AI service is typically a disclosure to a third party that the NDA does not contemplate, and in public company deals much of the material is inside information whose mishandling creates market abuse and confidentiality exposure. The defensible pattern is AI that runs on infrastructure the bidder or the data room provider controls, inside the confidentiality perimeter, with a sealed record of exactly what was processed.

The question is urgent in 2026 because deal teams are already running diligence documents through AI, quietly and at scale, while most data room rules were written before that was possible. The gap between practice and paperwork is where liability lives.

What do NDAs and data room terms actually say about AI?

Usually nothing, and the silence cuts against the bidder. A standard NDA permits disclosure to defined categories of representatives, advisers and affiliates, each bound to confidentiality. An AI provider rarely falls within those categories, and uploading a document to its service places the content on systems the provider operates under its own terms, which may include retention, logging and human review. Where the NDA restricts copying or requires material to stay within specified systems, routine AI upload sits badly against the drafting. The safe reading is that cloud AI processing is a disclosure requiring consent, not a private working method.

Why does inside information raise the stakes?

Data rooms in public company transactions hold material non-public information. UK MAR and EU MAR restrict unlawful disclosure of inside information and require it to be handled on a controlled basis, which is why insider lists and clean team protocols exist. Moving that material onto a third party's AI infrastructure adds an uncontrolled node to the picture: another organisation, another retention estate, another attack surface, none of it on the insider list. That does not automatically breach the rules, but it creates risk that is hard to defend if the deal leaks and a regulator reconstructs who could have accessed what.

What is the defensible pattern for a bidder?

Bring the model to the documents rather than the documents to the model. AI running on hardware the bidder controls, inside the same confidentiality perimeter as the deal team, can summarise agreements, extract change of control clauses, map liabilities across hundreds of contracts and flag anomalies, without any document crossing an organisational boundary. The perimeter is zero-egress: nothing the model reads can leave. Every document the AI touches is written to an append-only, cryptographically sealed processing record, so the team knows precisely what was processed, when, and by which model version. Mickai is a Sovereign Intelligence Operating System, a SIOS, built for this shape of work: it runs offline on operator-owned hardware, every action is sealed to a post-quantum signed audit ledger, and each agent in a review carries a per-action identity.

What should sellers change in their data room rules?

Sellers should address AI explicitly rather than rely on silence. A modern set of data room rules states:

  • Whether AI processing of data room material is permitted at all, and under what conditions.
  • That any permitted AI must run on infrastructure the bidder or the data room provider controls, with no transfer to public AI services.
  • That the bidder must be able to produce, on request, a record of what was processed by AI and where the processing ran.
  • How AI-derived work product is treated on deal termination, alongside the usual return and destruction obligations.

Explicit rules protect the seller's information and give serious bidders a clear rulebook instead of a grey zone.

What should a bidder be able to evidence if asked?

Three things, from its own records rather than a vendor's. Where the AI ran, meaning the hardware and perimeter that processed the material. What it processed, as a document-level record sealed at the time of processing. Where the outputs went, showing that summaries and extractions stayed within the clean team. A bidder that can produce that record has turned AI diligence from a hidden liability into a demonstrable control. A bidder relying on a cloud provider's assurances is asserting rather than evidencing.

Does staying inside the perimeter mean losing the speed advantage?

No. The speed of AI diligence comes from the model reading faster than people, not from the cloud. A sovereign deployment reviews the same corpus at the same pace with the same quality of extraction, and cross-model consensus can be applied to high-stakes reads, requiring more than one model to agree before a red flag or a clean finding is recorded. What the cloud offers is convenience of setup. What the perimeter offers is the ability to answer the seller's questions about AI use without hesitation.

In due diligence the AI should come to the documents; the documents should never go to the AI.

How the perimeter, the sealed ledger and the review studios fit together is set out at /sovereign-ai, and the film at /film shows the interface in operation.

Frequently asked questions

Can I upload data room documents to ChatGPT for due diligence?

Check the NDA and the data room rules first; most were not drafted with AI upload in mind, and uploading typically places confidential material on a third party's infrastructure under that party's terms. In public company deals the material may be inside information, which raises market abuse considerations. The conservative position is that public cloud AI services sit outside the permitted disclosure group unless the seller consents.

Is using AI on deal documents a breach of the NDA?

It depends on the drafting and on where the AI runs. Processing on systems the bidder already controls, within the permitted representative group, is usually within the NDA's contemplation. Transferring documents to an external AI provider is a disclosure to a party the NDA likely does not cover, which creates risk rather than certainty. Legal review of the specific terms is the only safe answer.

What is a sovereign AI deployment for M&A diligence?

AI that runs on hardware the bidder or the data room provider owns, inside the confidentiality perimeter of the deal, with no outbound path for documents and a cryptographically sealed record of everything processed. It delivers the reading speed of AI diligence while keeping the material within the group the NDA already permits.

Should sellers ban AI in their data rooms?

A blanket ban is hard to police and pushes AI use underground. The stronger position is explicit rules: permit AI only on controlled infrastructure inside the confidentiality perimeter, prohibit transfer to public AI services, and require bidders to evidence what was processed on request. That preserves diligence speed while keeping disclosure within the contemplated group.

How do I prove where my AI diligence ran if the seller asks?

From a sealed processing record created at the time: the hardware and perimeter the model ran on, the documents it touched and where the outputs were delivered. An append-only ledger with per-action identity provides that record from the bidder's own systems. If the evidence lives only in a vendor's logs, the bidder is asking the seller to trust a party outside the deal.

Subscribe
Get every new Mickai article by email.

Long-form essays on sovereign AI from Micky Irons. One email per article. No tracking, no marketing, no third parties. Every email includes a one-click unsubscribe link.

Prefer RSS? Subscribe at /articles/feed.xml.

Originally published at https://mickai.co.uk/articles/can-bidders-use-ai-on-data-room-material-in-m-and-a. If you operate in a regulated sector or want sovereign AI on your own hardware, the audit form on mickai.co.uk is the entry point.
More articles