EXECUTIVE SUMMARY
You grade three of the four AI ROI lenses yourself. Operational, financial, experiential — you set the standard and you mark the paper. The fourth one works differently. Someone outside your firm sets the standard for custodial ROI, and you learn what it is when their diligence team arrives.
Nobody can tell you today what that standard will be. No survey tracks how acquirers price AI governance, and we will not pretend otherwise. What the record does show is how a risk category becomes a diligence workstream — awareness first, then a marquee loss, then a regulatory regime, then a standard line item. Cyber ran that path between 2014 and 2023. Verizon's 8-K documents it to the dollar.
Build the answer before the question arrives. The Monday morning action is one request: ask a single portfolio company to complete an AI custody register — four questions per tool, one named owner, one estimate of how long a wrong output would run before anyone caught it. Then read the owner and detection columns yourself. What comes back, and how fast, tells you more than the register does.
THE PROBLEM
I. What We Know, and What We Are Guessing
You have closed deals where nobody asked for an AI tool inventory. Start there, because that objection is correct and most writing on this subject talks straight past it.
What nobody can prove today: that acquirers are currently repricing deals over AI governance. No survey tracks it. No published deal has been marked down for an undocumented AI dependency. An operating partner who says *"I have closed forty deals and nobody has ever asked me for an AI tool inventory"* is describing the market accurately. Any article that talks past that objection earns the dismissal it gets.
What the record does show is how a risk category moves from something everyone acknowledges to something every buyer asks about. It happened inside the last decade, in a category that occupied the same position this one does, and the paper trail is public.
In July 2014, Freshfields surveyed 214 global dealmakers. Eighty-seven percent said cyber security diligence was typically folded into a general review of a company's IT systems, "but not treated as a risk category in its own right." Seventy-eight percent said it was not analysed in depth or specifically quantified at all.
Those dealmakers were not ignorant. Eighty-three percent believed a deal could be abandoned over a breach, and ninety percent believed a breach could reduce value. They knew it mattered. They had no process for it.
That is where AI governance sits in 2026. Not unrecognized — unprocessed.
Then came the forcing events. In February 2017, Verizon and Yahoo amended their purchase agreement: the price dropped by $350 million, from roughly $4.83 billion to $4.48 billion. Yahoo kept 100 percent of the shareholder and SEC liabilities and split certain other investigation liabilities with Verizon fifty-fifty. The breaches behind that markdown had been known internally since 2014 and reached the investing public in 2016, mid-deal. In April 2018 the SEC fined the successor entity $35 million — widely read by securities counsel as the first enforcement action against a company for failing to disclose a breach.
Then came the regime that made inherited exposure expensive. GDPR applied from May 2018 and set penalties of up to 2 percent of global turnover for failing to secure personal data, with a higher tier reaching 4 percent for breaches of core processing principles. The security tier is the lower one, and it was still enough to turn an inherited weakness into a number.
Marriott is the case worth reading closely, and worth reading accurately. In October 2020 the UK regulator fined Marriott £18.4 million over a breach that began inside Starwood in July 2014, more than two years before Marriott acquired the company in September 2016. The regulator did not fine Marriott for weak pre-deal diligence; it said so explicitly, making no finding of infringement for the period between the acquisition and GDPR taking effect. It fined Marriott for failing to secure the systems it had inherited, once the obligation applied — noting only that a controller's duty here "is not time-limited or a 'one-off' requirement."
The narrow reading is the sharper one. Nobody was punished for buying badly. Marriott was punished for owning something it had not examined, on a clock that started the day the rule did. In July 2023 the SEC adopted rules requiring public companies to disclose material cyber incidents within four business days and to describe their risk-management processes annually.
Nine years from "not a risk category in its own right" to a mandatory disclosure regime and a standing diligence workstream. Awareness, then a marquee loss, then a liability regime, then a line item.
THE DIAGNOSIS
II. Where AI Sits on That Path — and the One Piece That Is Missing
AI governance sits at the 2014 position on some of those markers and not others. Which ones matters.
Awareness: present. No sponsor reading this thinks AI carries zero risk.
Prescriptive practitioner guidance: present, and early. Osler published recommended AI-specific representations and warranties in January 2025 — training-data provenance, IP ownership, AI governance practices. Skadden wrote in January 2026 that AI assets "often require tailored diligence, including by specialized third-party diligence firms," and that buyers "may request that specific AI-related representations be categorized as fundamental." In August 2026 Fasken described representation and warranty insurers contemplating exclusions for losses arising from a target's AI systems, and listed what sellers should expect to produce: privacy compliance, IP ownership, training-data provenance, model testing, internal governance policies.
Read that language carefully. *May request. Often require. Contemplating.* This is what 2014 sounded like — named firms publishing what buyers should ask, before any buyer routinely asks it.
The marquee loss: not yet. There is no AI equivalent of the Yahoo markdown. No deal has been publicly repriced over an AI governance failure.
The liability regime: incomplete, and this is the real gap. Cyber diligence did not become standard because dealmakers grew wiser. It became standard because GDPR and the SEC put a price and a deadline on getting it wrong, and neither was optional. AI has no equivalent in force. The EU AI Act is the candidate — its general-purpose obligations began applying in August 2025 and its high-risk obligations phase in between December 2027 and August 2028, dates that fall inside a typical hold — but it is narrower than GDPR, it is territorial, and the US has no federal counterpart. No regulator has yet penalized an acquirer for inheriting an AI governance failure.
A second open question is where the analogy is most likely to break. GDPR's decisive property was that exposure travelled with the asset. Much AI exposure today is contractual rather than regulatory — vendor terms, IP indemnities, training-data provenance — and contractual exposure transfers differently. If AI liability never acquires that successor property, this path stalls.
So the honest claim is not that buyers price this today. It is this: two of the four conditions that institutionalized cyber diligence are already in place for AI, and the other two are events, not trends. Events arrive on their own schedule, and rarely a convenient one. Yahoo's 2014 intrusion reached the investing public in 2016 and the purchase price in 2017.
Which sets up the only question that actually matters to a sponsor, and it is not a prediction question. It is an asymmetry question. If the standard never arrives, what did you spend? On our estimate, about a week of one person's time per company, and two weeks of calendar. If it arrives during your hold, what did you avoid? A diligence scramble under deal pressure, at the one moment when every unanswered question converts into either a delay or a discount.
You do not need to believe the forecast to take that trade.
WHY THE ANSWER DOESN'T EXIST YET
III. Two Gaps, and the Second One Is the Expensive One
The first gap is the one the market already talks about. Employees run AI tools nobody approved. In a November 2025 survey of 2,000 employees across the UK and US at companies with more than 500 employees, 49 percent reported using AI tools their employer never approved, and 51 percent said they had connected an AI tool to a work system without IT approval. A third had put enterprise research or datasets into an unapproved tool, and 23 percent had entered company financial information.
Treat that as context, not as the argument. Every security vendor publishes this data and most sell a product that finds unsanctioned tools. If that were the whole problem, you could buy your way out this quarter.
The second gap is the one nobody sells against.
Ninety percent of enterprises have funded AI governance. Fifty-seven percent maintain a formal AI governance policy. Forty-four percent have an incident response procedure written specifically for AI systems — which tells you that most organizations, when an AI system produces something wrong, will reach for a plan built for a different kind of failure.
Now hold the two gaps side by side. The unapproved tool with no owner is a security exposure, and a security product will find it. The *approved* tool with no owner is something else entirely. It cleared procurement. It sits in the contract schedule. It is demonstrably load-bearing in a workflow. And no name attaches to its output. Discovery software finds nothing here, because nothing is hidden — the company documented it well enough to buy and never well enough to answer for.
That is the half that survives an audit.
One number here deserves care rather than confidence. Seventy-four percent of enterprises believe they could pass an AI compliance audit. Twenty-seven percent rate their own program as fully mature. Schellman, an audit firm, publishes that pair under the headline that only 27 percent actually are audit-ready.
We would put it less strongly than they do, and the reason matters. Both figures come from the same respondents rating themselves, so the distance between them measures self-confidence against self-assessment rather than against any external standard. It hints. It does not prove. The external standard is the one that has not arrived yet — which is the whole argument of this article, and the reason we will not borrow a firmer number than the data supports.
THE METHOD
IV. Exposure-to-Ownership Attribution
A policy states an intention. It does not produce the register a buyer asks for, and it does not catch a wrong output.
The diagnostic discipline we run at AWSM LABS for custodial ROI is Exposure-to-Ownership Attribution: reconcile what a company believes it is running against what it is actually running, then attach a named owner and a detection path to every item on the real list. Four questions per AI tool with real usage, sanctioned or not. What follows is what a sponsor hands to a portfolio company — not a task list for your own team.
What is actually running? The procurement record is the starting point, not the answer. The real inventory comes from three sources the company's finance and IT teams already hold: expense reports and corporate card transactions, SSO and identity logs, and browser extension or app-integration records. Each source catches what the others miss. Expense data finds the individually-expensed subscription. SSO logs find the tool someone authenticated into with a work identity. Extension records find the thing that never generated a transaction at all. Run all three and the list stops being a procurement record.
What data moves through it? For each tool: what class of data enters it, where that data goes, and what the vendor's terms permit at the tier the team actually uses — not the tier the contract describes. A tool handling meeting transcripts and a tool handling customer financial records carry different exposure at identical price points. Most inventories record cost and seat count. Data class is the field the Fasken piece puts near the top of what a seller should expect to produce.
Who owns it — by name? Not which department. Which person. A department, a committee, or "IT" is not an owner. The test: if this tool produced a damaging output, whose name goes on the answer. Write that name down, then tell the person. An owner who has not been told is not an owner.
Who catches a wrong output, and how fast? For each tool: if it produced a materially wrong output tomorrow — a mispriced quote, a fabricated citation in a client memo, a compliance summary that dropped a disclosure — what mechanism catches it, who operates that mechanism, and how many days pass before it surfaces. If the honest answer is "the client would tell us," the tool is not governed. Someone deployed it and hoped.
Each row then ends in one of four decisions: sanction the tool, govern it, redesign the workflow around it, or retire it before the next renewal.
Run this and you get four things a spend report cannot give you. The true inventory, with the delta from the sanctioned list stated plainly. A data-class map showing which tools touch regulated, customer, or financial data. An ownership register: one name per tool. And, for each tool, how many days a wrong output would run before anyone caught it.
That last number needs a caution, and the caution is the point. It estimates a hypothetical rather than measuring an event. The person closest to the tool produces it, and it is only as honest as they are. One reading starts a conversation. The same tool read across three quarters, and the direction it moves, is the signal.
WHAT IT SURFACES
V. A Composite, and What a Buyer Would Do With It
What follows is a composite. It describes no single client. Every element here is in the list because it recurs in this kind of reconciliation, not because it is dramatic.
Picture a specialty lender, $150M–$250M revenue. Six hundred employees, a sponsor two years into the hold, a CFO you have asked twice this year what the AI spend is buying.
The sanctioned inventory lists four tools. The enterprise Microsoft agreement with Copilot on roughly 200 seats. A document-summarization tool in the credit function. A call-transcription product the sales team bought. A portal chatbot marketing procured eighteen months ago that nobody mentions any more.
The reconciled inventory lists nineteen.
The additional fifteen are unremarkable. A senior credit analyst pays for a reasoning model out of pocket because it handles borrower financial statements better than the sanctioned tool, and expenses it under software, misc. Two people in FP&A run a spreadsheet extension through their work Google account. A regional sales director has a note-taker joining client calls that compliance has never heard of. HR drafts performance review summaries in a consumer chat product. None of it appears anywhere.
Nothing here is malicious. Each made a defensible local decision, and several are solving a problem the sanctioned stack does not.
The data-class map is where it turns. Six of the nineteen touch customer financial information. Three of those six sit on tiers whose terms permit training on submitted content. The note-taker records client conversations subject to retention rules it has no mechanism to satisfy. The HR summaries contain compensation data. No risk register holds any of this, because nobody ever asked a risk register to.
The ownership column is shorter than the inventory. Four of nineteen tools have a named accountable person. The other fifteen have a purchaser — a different thing entirely.
Then the detection column, which produces the finding that lands hardest. Take the sanctioned document-summarization tool in the credit function. Proper procurement, real contract, completed security review. The honest answer to "who catches a wrong output" is that the credit committee would catch a materially wrong number if it were large enough to look implausible. Nothing catches a plausible wrong number. Estimated detection latency: one quarter, or the next time a loan performs differently than the file predicted.
That is the row that matters, and it is the governed one. Fifteen undocumented tools are a cleanup exercise — a weekend of procurement work and a policy memo. One load-bearing tool inside the credit workflow, with no owner and a detection path measured in quarters, is a different object: every credit file it touched in those quarters carries an error nobody looked for. That goes to the underwriting itself. That is what the next buyer is paying for.
THE FRAMEWORK
VI. Four Phases, and What to Measure at Each
Treat custody the way you treat a bank reconciliation: something that runs on a cadence, not something you file. Four phases.
FIGURE 1 · THE AWSM LABS CUSTODIAL ROI FRAMEWORK
| Phase | Objective | Key Actions | What to Measure |
|---|---|---|---|
| Inventory | Build the real list, not the sanctioned one | Reconcile procurement records against expense and card data, SSO and identity logs, and browser extension or app-integration records | Total tools in use; delta from the sanctioned list; share on free or consumer tiers |
| Trace | Establish what data moves through each tool and where it goes | For every tool, record the data class entering it, its destination, and what the vendor's terms permit at the tier actually in use | Tools touching regulated, customer, or financial data; how many of those sit on terms permitting training on inputs |
| Assign | Attach a named accountable person to each tool | Separate purchaser from owner; assign one person per tool who answers for its output, not its invoice — and tell them | Share of tools with a named owner; share where the purchaser became the owner by default |
| Detect | Establish who catches a wrong output, and how quickly | For each tool, define the failure mode, the review mechanism, who operates it, and the expected lag | Estimated detection latency per tool, in days; tools where the honest answer is "the client would tell us" |
Inventory and Assign produce a document, and a document feels like progress. Detect produces a number that is frequently embarrassing, which is why it is the one worth re-reading each quarter.
FIGURE 2 · WHAT A SPONSOR TRACKS ACROSS THE PORTFOLIO
| Metric | Why it earns a line in the portfolio review |
|---|---|
| Companies with a current AI custody register | Decides whether a diligence request takes days or weeks to answer |
| Sanctioned-to-actual inventory delta, by company | A wide delta means the company does not know what it depends on |
| Share of AI tools touching customer or financial data with a named owner | Ownership is the field the AI representations those firms are drafting turn on |
| Median detection latency across load-bearing tools | Separates a documented dependency from an unmonitored one |
| Companies with an AI-specific incident response procedure | Fewer than half of enterprises have one — a gap you can close before anyone asks |
| Exposure patterns repeating across more than one company | A repeated pattern is a portfolio-level policy gap, not a company-level lapse |
In the Schellman survey, 54 percent of organizations report AI governance to their board or executive leadership on a regular basis, and 36 percent discuss third-party AI risk at board level. Those are not governance statistics. They describe how much of the portfolio's AI exposure never reaches the seat where capital decisions get made.
FAILURE PATTERNS
VII. Four Ways Sponsors Misread This
FIGURE 3 · FOUR CUSTODIAL ROI TRAPS
| Trap | Observable Symptom | The Real Problem |
|---|---|---|
| Treating it as a security question | AI governance sits with the CISO and reports through the security review | Security asks whether the company is safe. A buyer asks whether the company can prove what it depends on. Different documents, different owners |
| Governing the sanctioned list | "Four AI tools, all four passed security review" | The four are governed. The fifteen nobody reconciled carry the same data — and the governed four may still have no owner |
| Purchaser as owner by default | Every tool has someone who bought it | The person who expensed a subscription is not the person who answers when its output is wrong. Someone assigns ownership deliberately, or nobody owns it |
| Waiting for the standard to arrive | "We'll deal with this when buyers start asking" | Cyber diligence went from 87 percent-not-a-category to mandatory disclosure in nine years. The companies that were ready were ready before the question, not because they predicted it |
The pattern underneath all four: companies govern the record they wrote instead of the system they run — and a sponsor inherits the difference at the moment they can least afford to price it.
"The exposure is not the tool nobody approved. It is the tool nobody would notice failing."
There is a nearer cost than exit, and it arrives on a schedule sponsors already watch. Gartner projects that more than 40 percent of agentic AI projects will be cancelled by the end of 2027, and attributes it to escalating costs, unclear business value, and inadequate risk controls. That forecast covers agents rather than the copilots and assistants most portfolio companies run today, so treat the number as directional. The direction is what matters: an initiative nobody owns is an initiative nobody defends when the budget question comes.
MONDAY MORNING
VIII. Ask One Company for the Register
You do not need a portfolio-wide program, and you do not need to run the reconciliation yourself. Four steps, one company, two weeks.
1. Pick the company. The one where AI is most load-bearing — where a wrong output reaches a customer, a regulator, or a credit decision. Not the largest. The most exposed.
2. Send the register and one sentence. Download the sheet, send it to the CEO or CFO, and set the deadline at two weeks. The sheet carries its own instructions: one row per AI tool with real usage, eight columns, four questions — what is actually running, what data moves through it, who owns it by name, and how many days a wrong output would run before anyone caught it. Twelve rows to a sheet, and most companies need more than one. That overflow is itself a result.
3. Read two columns yourself. Owner and detection. Count the rows with no name. Find the longest latency attached to a tool that touches customers or money.
4. Time the response. Two weeks from the ask, and watch the clock as closely as the content.
Three things can come back, and each is an answer. A complete register — a document you can hand a buyer, and a reason to run the same request across the portfolio. A thin one, where the gap between what they reported and what a real reconciliation would surface is the finding. Or nothing in two weeks, which is the cheapest answer you will ever get, because nothing about this request becomes easier under deal pressure.
CONCLUSION
IX. Build the Answer Before the Question
Three of the four AI ROI lenses tell you how the business is running. This one tells you what you can prove about it, and proof has an audience.
Nobody in 2014 was wrong to say that no buyer had ever asked them for a security posture document. They were describing the market accurately. What changed it had nothing to do with what dealmakers believed and everything to do with a $350 million markdown and a regulation.
AI governance sits where cyber sat in 2014, with two of the four conditions already met. Whether the other two arrive during your hold is not knowable, and this article has not pretended otherwise. What is knowable is the cost of being ready: one company, one register, two weeks. Against a downside you cannot size and would not choose to discover in a data room.
AI ROI ASSESSMENT · ANALYSIS TOOL
The AI Accountability Gap
Find out where your AI program really stands — and where the need is greatest.
9 QUESTIONS · ~2 MINUTES · INSTANT TAILORED REPORT
WORKS CITED
BlackFog. Shadow AI Threat Grows Inside Enterprises. BlackFog, January 2026. Survey of 2,000 employees at organizations with more than 500 employees, split evenly between the UK and US, fielded November 2025 by Sapio Research.
Fasken. When AI Meets RWI in M&A: What Impact Will AI Have on Representation and Warranty Insurance? Fasken, August 2026. Practitioner commentary; describes emerging underwriting practice, not measured adoption.
Freshfields Bruckhaus Deringer. M&A Cyber Security Report. Freshfields, July 2014. Survey of 214 global dealmakers (63% North America, 34% Europe, 3% rest of world).
Gartner. Gartner Predicts Over 40% of Agentic AI Projects Will Be Canceled by End of 2027. Gartner, 2025.
Information Commissioner's Office. Marriott International Inc: Monetary Penalty Notice. ICO, 30 October 2020. The contravention period found runs 25 May–17 September 2018; the notice makes no finding of infringement for the period between the acquisition and GDPR taking effect.
Osler, Hoskin & Harcourt. M&A Transactions Involving AI Companies: Representations and Warranties. Osler, January 2025. Practitioner commentary; recommended practice, not established market standard.
Schellman. 2026 State of AI Governance Report. Schellman, July 2026. Survey of 525 U.S. professionals at organizations with 500+ employees and $100M+ annual revenue, fielded April 13–May 11, 2026 by Researchscape. Maturity and audit-readiness ratings are respondent self-assessments.
Skadden, Arps, Slate, Meagher & Flom. M&A in the AI Era. Skadden, January 2026. Practitioner commentary.
U.S. Securities and Exchange Commission. Altaba, Formerly Known as Yahoo!, Charged With Failing to Disclose Massive Cybersecurity Breach; Agrees To Pay $35 Million. SEC Press Release 2018-71, April 2018.
U.S. Securities and Exchange Commission. SEC Adopts Rules on Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure by Public Companies. SEC Press Release 2023-139, July 2023.
Verizon Communications Inc. Form 8-K. Filed with the SEC, February 21, 2017. Purchase price reduced by $350 million to approximately $4.48 billion; amendment agreed February 20, 2017.
AWSM DSPTCH
Get the dispatch.
Perspectives on AI activation — ROI, frameworks, and lessons from the frontier — sent when we publish. No noise.




