For decades, due diligence (DD) was primarily a labor-intensive process involving teams of lawyers, accountants, and consultants manually reviewing contracts, financial records, corporate filings, and operational documents. In complex transactions, particularly cross-border mergers and acquisitions, this process often consumed months of professional time while still leaving room for material risks to remain undiscovered.
In 2026, however, the due diligence paradigm has fundamentally changed. Artificial intelligence has transformed Virtual Data Rooms (VDRs) from passive document repositories into intelligent risk-identification platforms capable of analyzing millions of pages of information within hours. Simultaneously, legal due diligence for technology companies has expanded beyond traditional intellectual property reviews into sophisticated software code audits designed to uncover hidden licensing risks, cybersecurity vulnerabilities, and ownership defects within proprietary software assets.
As Thailand intensifies corporate transparency requirements, strengthens PDPA enforcement, and expands scrutiny of ownership structures and source-of-funds verification, AI-assisted due diligence is rapidly becoming a strategic necessity rather than a competitive advantage. Modern transactions increasingly depend upon the ability to identify legal, regulatory, and technological risks before signing rather than litigating them afterward.
The Evolution of Virtual Data Rooms: From Document Storage to Autonomous Risk Detection
The traditional Virtual Data Room served a relatively simple purpose: centralizing transaction documents for review by investors, lawyers, auditors, and advisors. Modern AI-enabled VDRs now function as intelligent due diligence ecosystems capable of performing automated legal and financial analysis at unprecedented scale.
Advanced natural language processing (NLP) systems can review thousands of supplier agreements, customer contracts, financing arrangements, employment agreements, and shareholder documents simultaneously. These systems identify material legal provisions that historically required extensive manual review, including Change of Control clauses, termination rights, exclusivity obligations, non-compete restrictions, indemnity provisions, assignment limitations, and regulatory compliance obligations.
For acquisition teams, this capability dramatically alters transaction execution. Rather than relying solely on sampling methodologies, AI platforms can conduct near-complete reviews of contractual populations, significantly reducing the probability that critical liabilities remain undiscovered until post-closing.
The implications are particularly significant in Thailand's current regulatory environment. Recent measures introduced by the Department of Business Development (DBD), including enhanced verification requirements regarding beneficial ownership and source-of-funds documentation, have increased the importance of identifying inconsistencies across corporate records and shareholder documentation. AI-powered systems are increasingly capable of detecting anomalies across thousands of corporate filings and supporting documents that might otherwise escape traditional review processes.
More importantly, modern VDR analytics no longer focus solely on document retrieval. They generate transaction-specific risk heat maps, probability-based liability assessments, and predictive analyses that help acquirers prioritize negotiation points, adjust valuation models, and redesign warranty and indemnity protections.
The result is a fundamental shift from reactive due diligence toward predictive risk intelligence.
Code Audits and the Emergence of Software-Centric Legal Due Diligence

For technology companies, software is often the most valuable asset being acquired. Yet historically, legal due diligence focused largely on patent registrations, trademark portfolios, copyright ownership, and commercial agreements while paying comparatively limited attention to the actual source code underlying the business.
This approach is no longer sufficient.
In 2026, sophisticated acquirers increasingly conduct code audits as a core component of legal due diligence. Specialized intellectual property lawyers now work alongside software engineers and cybersecurity professionals to analyze source code repositories, software architecture, dependency structures, and open-source integrations.
The primary objective is ownership verification.
Many technology companies rely heavily on open-source software components. While open-source technologies can accelerate development and reduce costs, certain licenses impose conditions that may create significant legal consequences if not properly managed. For example, some copyleft licenses may require derivative works to be distributed under the same licensing terms, potentially undermining the exclusivity and commercial value of proprietary software.
From an acquisition perspective, undisclosed licensing obligations can materially affect enterprise valuation. A target company claiming ownership of proprietary technology may, after forensic code review, be discovered to have incorporated third-party code in ways that limit commercialization rights or create compliance obligations.
Modern code auditing tools can automatically scan millions of lines of code, identify open-source dependencies, detect licensing conflicts, map software provenance, and generate detailed compliance reports. These analyses allow legal teams to quantify intellectual property risks with a level of precision previously unavailable during M&A transactions.
Consequently, software due diligence is increasingly viewed not merely as a technical exercise but as a critical legal and valuation discipline.
AI, Data Governance, and PDPA Risk Assessment
A second major development in AI-assisted due diligence involves data governance reviews.
As Thailand's Personal Data Protection Act (PDPA) enters a more mature enforcement phase, personal data has become both a strategic asset and a significant liability. Regulators have demonstrated an increasing willingness to impose penalties and corrective measures for non-compliance, particularly in relation to consent management, data retention, cybersecurity controls, and cross-border transfers.
Consequently, modern due diligence exercises now extend beyond contractual analysis into comprehensive data-mapping assessments.
AI systems are capable of scanning databases, data repositories, cloud environments, customer relationship management platforms, and internal records to identify:
- Personal data inventories
- Sensitive data processing activities
- Cross-border data transfer mechanisms
- Consent deficiencies
- Third-party processor relationships
- Data retention irregularities
- Potential cybersecurity vulnerabilities
For acquirers, these findings can significantly influence transaction economics. A target company possessing millions of customer records may initially appear highly valuable. However, if those datasets were collected without appropriate legal basis, contain inadequate consent documentation, or fail to satisfy PDPA requirements, the same asset may represent substantial regulatory exposure.
As a result, data governance due diligence is increasingly treated as a financial risk assessment exercise rather than merely a compliance review.
The Future of Due Diligence: From Information Gathering to Continuous Risk Intelligence

The most significant transformation is not technological but strategic.
Historically, due diligence focused on collecting information. The objective was to determine whether a transaction should proceed. Today, AI-assisted due diligence increasingly focuses on quantifying risk, forecasting liability exposure, and supporting dynamic valuation adjustments.
The future transaction team will likely consist of lawyers, accountants, cybersecurity specialists, software engineers, forensic investigators, and AI systems operating in parallel. Virtual Data Rooms will evolve into continuously monitored intelligence platforms capable of updating risk assessments in real time as new information emerges.
For Thai businesses preparing for investment, fundraising, or acquisition, this evolution carries an important lesson. Due diligence readiness can no longer be achieved by organizing documents shortly before a transaction. Companies must maintain ongoing governance over contracts, software assets, shareholder records, personal data, and compliance documentation.
In the era of AI-assisted M&A, hidden risks rarely remain hidden for long. The competitive advantage increasingly belongs not to organizations that can explain problems during due diligence, but to those that can demonstrate from the outset that the risks have already been identified, monitored, and controlled.

