PE OperationsMarket & Strategy

    AI Due Diligence: How Investors Re-Underwrite Software Deals in 2026

    Dr. Oliver Gausmann · July 28, 2026 · 8 min read

    Summarize with AI

    ClaudeChatGPTPerplexity
    Steel structure seen from below, an image for AI due diligence in software deals

    For the past two years I've kept a private list of German B2B software deals, 78 capital events since early 2024. This spring the conversations around those deals changed. The first question investors ask about a software asset now concerns revenue durability under AI pressure. Growth comes second.

    AI due diligence answers that first question. It tests how much of a software company's current revenue stays defensible once agents take over tasks and application budgets get reallocated. The urgency shows in the deal market: tech deal value fell 70% from Q4 2025 to Q1 2026 because investors have stopped trusting software valuations under AI uncertainty [1]. Buyout portfolios, meanwhile, marked their software positions down roughly 8% through March [1]. That spread between public fear and private book value is where deals die right now. Closing it is underwriting work, and it starts long before an exit.

    Why did software deal-making stall?

    Public markets moved first. By early 2026 the North American software index had lost more than 20%, trailing the broader market by a wide margin [3]. Bain counts the AI-driven software rout among the three shocks of this half-year, alongside private credit stress and the energy price spike [1].

    The demand-side math explains the anxiety. Gartner puts the enterprise application spend exposed to agentic AI at $234 billion through 2030, about 20% of SaaS spending, and expects 40% of enterprise apps to embed task-specific agents by the end of 2026, up from under 5% a year earlier [2][6]. The mechanism cuts into the operating model itself: agents deliver outcomes past the user interface, which decouples user growth from revenue growth [2].

    Private marks have barely moved by comparison, and secondary buyers have noticed. Funds heavy in software now face tougher scrutiny when stakes change hands [4]. A book value nobody wants to transact against is a warning, whatever the quarterly report says.

    The regional split matters, too. Europe marked down less, 4.2% against 8.9% in the US [1]. European processes will feel the re-rating later.

    For boards, the sluggish marks are the uncomfortable part. Distributions as a share of net asset value have sat at record lows for four years [1], so the pressure to transact keeps building while confidence in software marks keeps falling. An asset that can't pass an AI due diligence won't transact, and the book value becomes an opinion.

    There's a credible counterargument. S&P Global Market Intelligence calls the sell-off possibly overdone and finds little evidence so far that enterprises actually replace their major SaaS vendors with home-built AI [3]. Both camps can be right, asset by asset. That's precisely why blanket discounts and unchanged marks are equally lazy answers, and why the work moves to the individual company, its contracts and its customers.

    What goes into an AI due diligence?

    At Convios we break the question into four fields. All four need discipline and raw data that classic processes rarely request. The work also needs two profiles: a deal team for contracts and numbers, and someone who has actually run software operations for delivery, data flows and day-to-day AI use inside the target. Without the second profile, the exercise stays a spreadsheet.

    1. Revenue durability under agent load means dissecting the contract base. Net revenue retention can hide shrinkage when AI add-on revenue papers over declining seat counts. Gross revenue retention by customer cohort and product module tells the honest story. The single most useful number is the share of revenue tied to human user counts, because that's the revenue Gartner's decoupling hits first [2]. Take a vendor at $60 million ARR with 65% of revenue tied to seats: if agents trim those seats by just 15% over five years, roughly $6 million of recurring revenue disappears, call it $30 million of enterprise value at a five-times multiple (own calculation).
    2. The second field is the moat beneath the AI feature. Any vendor can ship an AI feature by next quarter. What stays defensible sits underneath: owning the customer's workflow, operating data that only exists because of the product, and regulatory depth a generalist can't shortcut. In my own review of German B2B software deals since 2024, these are the patterns that keep showing up at the companies being acquired or heavily funded (own analysis, 78 cases).
    3. The target's internal AI maturity sets the future cost base. How much of engineering runs AI-assisted, how much of support is automated, how fast changes reach production. Two vendors with identical ARR can sit worlds apart here, and the gap compounds because the more mature operator ships faster and cheaper every quarter.
    4. The fourth field, governance and auditability, looks boring and carries price. A vendor using AI in product and operations has to show regulated customers what data flows where and how outputs get checked. The company that can produce those records sells into industries where competitors never get past procurement. Guardrails are what let a business run AI at speed, which makes them a valuation input.

    Notice what's missing from the list: the choice of base model. Models get better and cheaper every month, and every vendor can buy them. A diligence report that spends ten pages on model choice and one on the four fields above is testing the wrong layer.

    The output translates into price mechanics directly. Seat-bound revenue without a moat underneath gets a shorter amortization profile and a lower multiple. Revenue sitting on workflow ownership, proprietary data or regulatory depth keeps yesterday's valuation tomorrow. Drawing that line cleanly inside a target's numbers is the hard part, and it's where most processes currently fall over.

    Classic software due diligence versus AI due diligence
    FieldClassic due diligenceAI due diligence
    Revenue qualityNRR and ARR growthGRR by cohort and module, seat-dependent revenue share
    CompetitionFeature comparison and market shareMoat depth: workflow ownership, proprietary data, regulation
    Cost baseBenchmark marginsAI maturity across engineering, service and operations
    RiskCustomer concentration and churnReplaceability by agents and in-house builds, per module
    ManagementTrack recordDemonstrated internal AI use plus governance evidence

    How do you start AI due diligence across a portfolio?

    Start inside your own portfolio before the market forces the question. Four steps, each with results in weeks.

    1. Quantify the seat-dependent revenue share for every holding. The contract data sits in CRM and billing systems, and a focused week produces a first map.
    2. For the next board meeting, gross revenue retention by cohort and product module goes on the list. A management team that can't produce the number has handed you a finding already. The conversation about the missing data usually tells you more than the number itself.
    3. Grade every moat on one page per asset: workflow ownership, proprietary data, regulatory depth, each claim backed by evidence. Management's self-assessment doesn't count as evidence. One page forces choices, and choices are the point of the exercise.
    4. That leaves delivery-side AI maturity: share of AI-assisted engineering, support automation rate, change lead time to production. The first numbers will be uncomfortable, which is exactly what makes them useful. Repeat the measurement a quarter later, because direction beats the starting point.

    Sellers should run the same play in reverse. A company planning a process within 12 to 24 months should re-underwrite itself now, before a buyer does it on less friendly terms. A data room that answers the four fields upfront shortens negotiations and defends price at the exact spot where buyers currently apply their steepest discounts.

    Buyers gain time, too. Much of the four-field work runs before exclusivity, on public data, customer references and product access. Teams that wait for the data room give away the information edge that currently sets the price in this market.

    My Take

    Honestly, I think the freeze is the opportunity. Bain counts around 32,000 unsold portfolio companies worth $3.8 trillion [5], at holding periods near seven years [5], exit value already jumped 47% to $717 billion as the pressure to return capital grew [5], and $1.3 trillion in dry powder is waiting for conviction [5]. The first buyers who can underwrite software credibly under AI uncertainty will pick assets with little competition. I've sat on both sides of the deal table, selling my own company into an integration and then running four integrations for the buyer, and what carried price every time was workflow ownership, data and replaceability.

    One more thing from my German deal list: a third of the capital events since 2024 were changes of ownership, 26 out of 78, with an industrial group taking a minority stake nine more times (own analysis). Consolidation is how the AI question reaches Germany's software mid-market, and buyers will ask it before founders do. The window won't stay open forever, either. Once two or three credible AI due diligence playbooks circulate among deal teams, the uncertainty discount that's freezing the market today turns back into ordinary competition.

    How a software company digs the moat beneath its AI feature is the subject of how niche vendors dig their moat. What agent protocols change for software portfolios is covered in MCP and B2B software business models. On how longer hold periods change the arithmetic across a portfolio, see hold periods and the buy-and-build platform.

    FAQ

    What does an AI due diligence test in a software company?

    Four fields: how much revenue depends on human user counts, what sits beneath the AI feature (workflow ownership, proprietary data, regulation), how maturely the company uses AI internally, and what governance evidence it can produce for regulated customers.

    Why is net revenue retention no longer enough?

    AI add-on revenue can paper over declining seat counts. Gross revenue retention by customer cohort and product module shows the durability of the contract base more honestly.

    Does AI pressure lower every software valuation?

    No. Companies that own the customer workflow, hold proprietary operating data or carry regulatory depth defend their valuations. Blanket discounts are as wrong as unchanged marks, the individual asset decides.