An AI-enabled target can pass every conventional technical check — clean architecture, good test coverage, no license contamination, SOC 2 in hand — and still be worth two turns less than the ask. Five things determine that, and none of them appear on a standard tech DD checklist.
35% WEIGHT CORE MOAT
Data Gravity
Does the target own data a competitor cannot buy, license, or scrape? Proprietary corpus volume, customer contract rights to train on it, and whether the feedback loop compounds or just accumulates. This is the heaviest weight because it's the only moat that survives the next model release.
Stress Test: Zero-shot frontier model disintermediation.
25% WEIGHT WRAPPER RISK
Wrapper Immunity
What percentage of the product's actual logic is a call to someone else's API? I audit the call ratio against the codebase, not the architecture diagram. A target where a foundation-model provider can ship the core feature for free in one release is a different asset than the one in the CIM.
Stress Test: API deprecation & native OS-level feature release.
20% WEIGHT GOVERNANCE
Deterministic Governance
What happens when the model is wrong? I look for hard runtime gates, human verification checkpoints, and override telemetry — not eval scores. In regulated workflows, an ungoverned failure surface is a liability line item, not a technical footnote.
Stress Test: Adversarial injection & silent hallucination liability.
10% WEIGHT UNIT ECONOMICS
Unit Economics Under Load
I model inference cost per transaction at 5x current volume. Industry benchmarks put AI-native gross margins near 52% against 80–90% for traditional SaaS, and ICONIQ's 2026 survey found inference cost rising as a share of spend — from 20% to 23% — as products mature. Margin compression at scale is the most commonly missed adjustment in AI-target underwriting.
Stress Test: 5x volume spike & token pricing shifts.
10% WEIGHT COMPLIANCE & IP
IP & Compliance Integrity
Copyleft contamination in the model-serving path, incomplete invention assignments, customer DPAs that block post-close training, and sector mandates (CMS-0057-F, FDA Part 11, FINRA 3110) the target has to meet on a clock.
Stress Test: Open-source audit & regulatory enforcement horizon.
Each dimension is scored against evidence in the data room and stress-tested against a specific failure scenario. The composite maps to a moat tier, and the tier maps to a defensible position on the entry multiple. In the engagements I've run, most targets claiming proprietary AI have been thinner than represented.