A new question is entering serious diligence conversations.
Most owner-operators have not heard it yet.
When they cannot answer it, buyers do what buyers have always done.
They price the risk.
Call it an AI risk review.
The label may vary. The question does not:
Has AI made this business stronger, or has it quietly created new risk nobody is managing?
This is not just a technology-company issue.
Manufacturers, distributors, industrial services firms, and other operations-heavy businesses are already using AI in quoting, pricing, scheduling, customer service, reporting, forecasting, sales, and internal workflows.
That may create leverage.
It may also create dependency, data exposure, key-person risk, and new transferability problems.
Buyers are not afraid of AI.
They are afraid of unmanaged dependency.
That is where discounts begin.
Here are the four areas an AI risk review should cover.
1. Model Dependency
The first question is simple:
Is this business running on AI tools it does not own and cannot control?
Think about the systems your team uses every day.
A CRM that scores leads. A quoting tool that estimates materials from prior jobs. Pricing software with an AI layer built in. A scheduling platform that optimizes routes. An AI-assisted service tool your operations manager added last year.
Each one may be useful.
Each one may also be an operational dependency nobody deliberately chose.
Buyers are not concerned because you use software. Every business does.
They become concerned when an AI-powered vendor is critical to revenue, margin, customer response, production flow, or decision-making — and nobody can answer basic questions.
What does the tool touch?
What happens if the model changes?
What happens if the vendor raises prices?
What happens if access disappears?
What data has the business fed into it?
What protections exist around that data?
A business with documented fallbacks, data protections, and operational alternatives is defensible.
A business that has quietly become dependent on several AI-powered vendors without understanding the exposure is fragile.
Fragility becomes a risk discount.
What buyers want to see: a clear inventory of AI tools, the processes they affect, the data they access, the manual fallback, and the contractual protections around each one.
Most businesses do not have that inventory.
If you do not know what belongs on the list, a buyer may assume the worst.
2. Data Moat Strength
This one cuts both ways.
The upside is real.
A business that has accumulated rare, proprietary, well-organized operating data may be worth more than one that has not.
Decades of job-costing data. Customer reorder patterns. Defect rates by supplier. Equipment performance by product line. Margin history by job type. Lead times by customer segment.
That is not just old information.
Handled correctly, it is operational IP.
It may be difficult for a competitor to reproduce. It is also what makes AI genuinely useful inside the business.
Not generic AI.
AI informed by your specific operating reality.
The downside is just as important.
If pricing data, customer data, production data, or quoting history has been fed into third-party AI tools without clear data rights, the business may not control what it thinks it controls.
Worse, that information may now sit inside vendor platforms in ways nobody can fully trace.
Buyers are beginning to ask a sharper question:
Is the data that makes this business defensible protected, organized, and transferable — or scattered across systems the company does not control?
That matters.
A spreadsheet on one manager’s laptop is not a moat.
A decade of clean, organized, protected operating data that a buyer can use on day one is.
What buyers want to see: documentation of what proprietary data exists, where it lives, who controls it, how it is protected, and what agreements govern its use inside AI-powered tools.
Extra value appears when the business has already used that data to build something transferable:
A pricing model. A forecasting tool. A job-costing method. A margin dashboard. A production intelligence system.
Most owners have never framed their operating history as a data asset.
Buyers are starting to.
That means they may value it before you do.
Or discount it because you failed to protect it.
3. Agentic Substitution Risk
This is the uncomfortable one.
Agentic AI refers to systems that do more than answer questions.
They act.
They can book appointments, draft communications, process orders, manage workflows, update systems, qualify leads, monitor exceptions, and run multi-step processes with less human oversight.
So buyers are asking:
How much of this business’s current value depends on work that AI may replace in the next few years?
That question affects value in two directions.
First, buyers will examine headcount.
If the business is priced as though current margins require current staffing, but a buyer believes much of that work can be automated after close, they will not pay you for the margin they expect to create.
That improvement belongs to them.
Not you.
Second, buyers will examine expertise.
Some work cannot be easily automated because it depends on judgment, pattern recognition, relationships, field experience, or technical nuance.
That can be a moat.
But only if it is documented and transferable.
If the expertise lives in one person’s head, it is not a moat.
It is key-person risk wearing a hard hat.
Buyers discount both problems.
They discount work they believe they can automate.
And they discount expertise that disappears when the owner or one key employee leaves.
What buyers want to see: a clear view of which functions are AI-exposed, which functions require genuine human judgment, and whether that judgment has been documented in a way that transfers.
A defensible business can say:
Here is what AI may change.
Here is what it cannot easily replace.
Here is what we have documented.
Recommended by LinkedIn
Your AI Agents Are Already Employees Without the… Balaji Krishnamoorthy 1 week ago
Your AI Agent Problem Is Not Sprawl. It Is Delegated… Geoff Hancock CISO CISSP, CISA, CEH, CRISC 1 month ago
The Term That Will Define Your Next Inspection — And… Anastacia Edwards-Kurianova, MBA 1 month ago Here is how the next owner inherits it.
A business that cannot answer is guessing.
Buyers price guesses as risk.
4. AI Talent Concentration
Every business now has someone who figured out the tools.
Maybe it is the operations manager.
Maybe it is a salesperson.
Maybe it is the controller.
Maybe it is the owner.
That person built the prompts, connected the apps, created the workflows, tested the automations, and quietly made the business faster.
Good.
Also dangerous.
AI talent concentration is the new version of key-person risk.
The old version is familiar.
One person owns the customer relationships, the technical knowledge, the vendor history, or the operational judgment.
The AI version is newer.
One person owns the prompt library.
One person understands the automation logic.
One person knows which tools are connected.
One person knows what breaks when the system misfires.
One person controls the accounts, settings, workflows, and tribal knowledge.
When that person leaves, the business does not just lose an employee.
It loses operational leverage.
If nobody else understands the system, the buyer sees a fragile asset.
What buyers want to see: AI-enabled processes that are documented, transferable, and understood by more than one person.
The basics need to be clear.
Which tools are being used?
Who owns them?
Where are the workflows documented?
Who can troubleshoot them?
What happens if the primary person leaves?
If your best answer to “Who understands how your AI tools work?” is one name, you have concentration risk.
Buyers will find it.
Why This Matters Now
These questions are not designed to punish businesses for using AI.
They are designed to expose hidden structural risk.
Buyers have always priced risk.
AI has simply created another category of it.
The issue is not the technology.
The issue is unmanaged dependency, undocumented processes, uncertain data ownership, and operational knowledge trapped inside one person.
Those are transferability problems.
Buyers have always discounted transferability problems.
The mechanism may be new.
The reaction is not.
Discount.
The Self-Assessment That Matters
Ask four questions.
Honest answers only.
1. Could I list every AI tool touching my business today?
Not just ChatGPT.
Every AI-powered tool in sales, quoting, pricing, customer service, production, scheduling, finance, HR, reporting, or operations.
The list should include what data each tool can access and what the contract says about that data.
2. Could I describe the proprietary data my business has accumulated?
Not “we have customer records.”
What patterns does the business know that others do not?
What job, customer, margin, defect, supplier, pricing, or production data would be difficult for a competitor to recreate?
Is it organized?
Or scattered?
3. Could I explain which parts of my business AI may change in the next three years?
Which roles are exposed?
Which processes are exposed?
Which margins may change?
Which parts of the business are defensible because they require judgment, trust, field expertise, or deep operating context?
And is that documented?
4. If the person who manages most of our AI tools left tomorrow, what would break?
How long would it take to rebuild?
Who else understands the workflows?
Where are the prompts, automations, settings, and vendor relationships documented?
If that answer makes you uncomfortable, good.
That is the point of the exercise.
The Real Issue
AI is not the hero.
AI is not the villain.
Transferability is.
Can the next owner understand the systems?
Can they trust the data?
Can they keep the business running without depending on one employee, one vendor, or one undocumented workflow?
That is what buyers care about.
Not effort.
Not intentions.
Not how many AI tools you use.
Buyers pay for reduced risk.
The businesses that can answer these questions before diligence begins will protect more value.
The businesses that cannot will be trying to explain themselves after the buyer has already started applying discounts.
Get Your Hidden Risk Score (10 Minutes).
— Steve Duke, Lucensys Group