Alexandru Stănescu
Partner

Alexandru Stănescu is a Partner at Lexters and leads the firm’s FinTech work through its Tech & DeepTech practice. He advises crypto exchanges, custodians, payment providers, asset managers, token issuers and technology companies on MiCA, product structuring, cross-border investments, venture capital and M&A. Chambers FinTech 2026 ranks Alexandru in Band 1 for FinTech Legal in Romania, marking his third year in the guide.

A Fulbright scholar, Alexandru holds an LL.M. from Columbia Law School. He is admitted to the Bucharest and New York Bars and regularly speaks on international arbitration, blockchain and financial regulation.

Alexandru is known for a business-oriented approach. He works closely with clients to understand the commercial context of each matter, translating complex regulation into clear options and workable solutions. His advice combines rigorous legal analysis with commercial judgment and practical execution, helping clients advance new products, transactions and cross-border projects with confidence.

Simina Negulescu
Partner

Simina Negulescu is a Partner at Lexters, where she advises technology companies, founders and investors on corporate law, venture capital, cross-border transactions and disputes. With more than a decade of experience, including nine years focused on the IT sector, she supports businesses from formation and financing to international expansion and group consolidation.

Simina combines transactional judgment with litigation instinct. Her early career in disputes, followed by experience as a fractional chief legal officer for a technology company, allows her to understand how legal risk develops and how businesses make decisions. She anticipates pressure points, structures workable solutions and remains closely involved through execution.

Her practice covers financing rounds, governance, commercial contracts, regulatory compliance, legal audits and due diligence. Clients value her can-do approach, meticulous preparation and ability to turn complex issues into clear commercial decisions.

Patricia Gorici
Senior Associate

Simina Negulescu is a Partner at Lexters, where she advises technology companies, founders and investors on corporate law, venture capital, cross-border transactions and disputes. With more than a decade of experience, including nine years focused on the IT sector, she supports businesses from formation and financing to international expansion and group consolidation.

Simina combines transactional judgment with litigation instinct. Her early career in disputes, followed by experience as a fractional chief legal officer for a technology company, allows her to understand how legal risk develops and how businesses make decisions. She anticipates pressure points, structures workable solutions and remains closely involved through execution.

Her practice covers financing rounds, governance, commercial contracts, regulatory compliance, legal audits and due diligence. Clients value her can-do approach, meticulous preparation and ability to turn complex issues into clear commercial decisions.

ARTIFICIAL INTELLIGENCE AS A NEW RISK CATEGORY IN M&A DUE DILIGENCE: A ROMANIAN PERSPECTIVE

1. Introduction: A New Regulatory Risk Enters the Deal Room

In a merger or acquisition, the value of a target is determined not only by its assets, revenues and market position, but also by the regulatory risks attached to its business. The scope of due diligence therefore evolves whenever a new regulatory framework turns what was previously regarded as a manageable operational issue into a source of material legal, financial and transactional exposure.

The General Data Protection Regulation (“GDPR”) illustrates that process. Before its adoption, data protection was often addressed within broader IT or regulatory compliance reviews. Following it, privacy compliance developed into a distinct due diligence workstream capable of affecting deal valuation, contractual risk allocation, closing conditions and the insurability of transactional risk.

The regulatory landscape surrounding Artificial Intelligence appears to be following a comparable trajectory. Rather than merely adding compliance obligations, Regulation (EU) 2024/1689 (“AI Act”) establishes an entirely new framework governing the development, deployment and use of Artificial Intelligence (“AI”) systems. Depending on the level of risk associated with a particular system, organisations may be required to implement measures relating to risk management, data governance, technical documentation, transparency, human oversight, accuracy, robustness, cybersecurity and post-market monitoring.

This article argues that the AI Act is likely to establish AI compliance as a distinct category of M&A due diligence, much as the GDPR established data protection as an independent area of transactional review. It considers why the risk is already live, where the exposure concentrates, how a buyer should structure an AI review and how the findings feed into transaction documentation. Because the AI Act is a Regulation, it applies directly and uniformly throughout the European Union, and the substantive analysis that follows is therefore common to every Member State. The vantage point, however, is Romanian: the observations below are drawn from our experience with M&A transactions on the Romanian market, where the questions this framework raises are already being asked in practice.

  1. The GDPR Precedent: A Transactional Blueprint

The significance of the GDPR did not lie solely in new compliance obligations or in the possibility of administrative fines of up to 4% of worldwide annual turnover. Its transformative effect resulted from the combination of extensive substantive obligations, an accountability-based compliance model, significant documentation requirements and the possibility that historical non-compliance could generate substantial post-closing liability. Data protection therefore ceased to be merely an operational matter and became a legal risk capable of affecting enterprise value, negotiations and the allocation of post-closing liability.

Privacy compliance evolved into a dedicated workstream requiring buyers to assess not only the target’s policies, but its underlying data governance framework: lawful bases for processing, international data transfers, processor agreements, security measures, data breach history, regulatory investigations and internal compliance programmes. In technology-intensive transactions, these reviews were supplemented by specialised cyber and data privacy assessments, and the findings were carried through into the transaction structure itself.

More fundamentally, the GDPR demonstrated how regulation can change what due diligence examines. Traditional legal due diligence focused on existing rights, obligations and liabilities. The GDPR required buyers to test whether the target had appropriate internal systems, governance structures and compliance mechanisms to manage an ongoing regulatory risk. Its importance therefore lies less in its substantive rules than in the transactional model it created – and that model is the natural starting point for assessing the AI Act.

  1. AI as an Object of Due Diligence, Not Only a Tool

AI is already transforming the M&A process itself. AI-powered tools are increasingly used to analyse large volumes of documents, identify material contingencies and inconsistencies, cross-reference information across data rooms and prioritise findings according to risk. Their use is not costless: inaccurate or hallucinated outputs, systemic bias and excessive reliance on automated analysis make human review and professional judgment essential.

More importantly for present purposes, AI is increasingly becoming an object of due diligence in its own right. At target level, the buyer must determine what AI systems the target uses, how they are governed, what data they rely upon, what regulatory classification applies and whether the required compliance framework has in fact been implemented.

  1. Timing and Enforcement: Why the Risk Is Already Live

Although the AI Act applies generally from 2 August 2026, its provisions become applicable progressively. Article 113 provides that Article 6(1) and the corresponding obligations apply from 2 August 2027, while other provisions – including the penalties regime in Chapter XII – have applied since 2 August 2025. This phased application does not postpone the transactional relevance of AI risk. The classification and governance of systems already used by a target affect the assessment of its legal and commercial risk today, particularly where those systems fall, or may fall, within the high-risk framework.

The enforcement framework is substantial. Under Article 99(3), non-compliance with the prohibited AI practices in Article 5 may attract administrative fines of up to €35 million or 7% of total worldwide annual turnover for the preceding financial year, whichever is higher. Under Article 99(4), other infringements – including breaches of the obligations applicable to providers and deployers – may attract fines of up to €15 million or 3% of turnover. By comparison, Article 83(5) of the GDPR provides for a maximum of €20 million or 4% for the more serious categories of infringement. From an M&A perspective, the relevant question is therefore not only whether a particular obligation is already applicable, but whether the target’s business model, technology infrastructure and compliance framework may expose the buyer to material regulatory liability following closing.

The ceilings are set by the Regulation, but enforcement is national. In Romania, the Government adopted a memorandum on 12 March 2026 designating ANCOM, the national communications regulator, as market surveillance authority and single national point of contact, operating alongside sectoral regulators, while the legislation meant to operationalise that institutional framework remains under discussion. Romania has not pursued substantive departures from the Regulation, so the exposure inherited on closing is the exposure the AI Act itself creates; what is still taking shape locally is the supervisory practice through which it will be enforced.

  1. Where the Exposure Concentrates: Fintech and Insurtech Targets

The exposure is most acute where AI systems produce legal or economic effects for individuals. Annex III, point 5(b) of the AI Act classifies as high-risk AI systems intended to evaluate the creditworthiness of natural persons or to establish their credit score, except where the system is used for the purpose of detecting financial fraud. Point 5(c) separately covers AI systems intended for risk assessment and pricing in relation to natural persons in the case of life and health insurance.

Article 27 reinforces the regulatory significance of these use cases. Deployers of the AI systems referred to in Annex III, points 5(b) and 5(c) – alongside public bodies and private operators providing public services – must carry out a fundamental rights impact assessment before the system is put into use, covering the categories of persons likely to be affected, the specific risks of harm to them, the human oversight measures in place and the steps to be taken should those risks materialise. For a fintech or insurtech target, whether such an assessment exists and has been implemented is a direct due diligence question.

A target whose core business depends on AI-assisted credit scoring, creditworthiness assessment, or insurance risk assessment and pricing therefore carries AI regulatory exposure at the heart of its business model. An inadequate AI compliance framework may expose an acquirer not only to regulatory enforcement and significant administrative fines, but also to contractual, operational and reputational liabilities arising after closing. The point is not confined to the financial sector: Annex III also covers employment, education, essential public services and law enforcement, so targets well outside fintech may carry comparable exposure through the tools they use internally.

  1. The Anatomy of an AI Due Diligence Exercise

AI due diligence cannot be reduced to a conventional technology audit. It requires the buyer to reconstruct the target’s AI ecosystem, determine the regulatory status of its systems, identify the target’s role in relation to each of them and test whether the corresponding governance mechanisms are actually functioning. In practice, the exercise proceeds through seven connected enquiries.

Identification: AI may be embedded in internal decision-making tools, customer-facing products, third-party software, cloud services or automated processes without ever being recorded within the company’s compliance framework. The exercise must therefore begin with an inventory of the target’s AI systems and AI-enabled technologies, whether developed internally, acquired from third-party providers or incorporated into existing products and services.

Classification: Classification determines the intensity of the applicable obligations and, consequently, the level of legal and financial risk a buyer may inherit. Due diligence must establish how each system is classified, why it falls within that classification and whether the target has documented the basis for its own assessment.

Role in the AI value chain: The AI Act distinguishes between categories of actors, most notably providers and deployers, and the applicable obligations depend significantly on the role performed. A target may develop and place its own system on the market while simultaneously deploying third-party systems internally. A general assurance that the target complies with the AI Act is therefore of limited value. In our experience with Romanian transactions, this is the point most often mishandled. Many local targets are subsidiaries of foreign groups running AI systems developed centrally, so the deployer obligations sit with the Romanian entity while the provider documentation sits with a group company abroad and rarely reaches the data room without being specifically requested.

Evidence of compliance: For providers of high-risk systems, the review may address conformity assessment, technical documentation, quality management systems, registration, record-keeping and post-market monitoring. For deployers, the focus shifts towards appropriate use of the system, human oversight, input-data governance, monitoring, record-keeping and, where applicable, fundamental rights impact assessments. As the GDPR experience demonstrates, the existence of policies alone is not sufficient: transactional relevance lies in implementation and evidentiary basis.

Third-party dependencies: Where the target relies on external AI providers, the review should extend to the contractual framework supporting its AI infrastructure, including the allocation of regulatory responsibilities, audit and information rights, data usage, intellectual property, security, service continuity, liability limitations and termination rights. Concentration risk deserves particular attention, as dependence on a single vendor who cannot readily be replaced is both an operational and a transactional vulnerability.

Data governance: Where AI systems rely on training, validation or operational data, the buyer should assess the provenance, quality and legal basis for its use, particularly where personal data, confidential information or third-party intellectual property may be involved. The question is whether the target can demonstrate a defensible legal and governance framework for the data on which its material systems depend.

Regulatory history: Buyers should examine complaints, investigations, enforcement actions and other regulatory scrutiny relating to AI systems, together with material incidents or deficiencies identified internally. Previous findings may indicate both historical non-compliance and weaknesses in the broader governance framework, while the absence of disclosed enforcement action should not be equated with the absence of exposure.

  1. From Findings to Deal Terms

The ultimate significance of this development is transactional. Once AI-related risks are identified through due diligence, they must be addressed through mechanisms capable of allocating them between buyer and seller. The findings may therefore shape AI-specific representations and warranties, dedicated disclosure schedules, targeted indemnities, pre-closing remediation obligations and, where appropriate, purchase price adjustments or escrow arrangements. Where remediation is required before closing, the parties should also address who bears its cost and on what timetable, since bringing a high-risk system into compliance may involve documentation and conformity work that cannot be completed quickly. As AI-related risks become increasingly relevant to a target’s regulatory and operational profile, they may also affect the scope, pricing and availability of Warranty & Indemnity insurance, further integrating AI compliance into the risk allocation framework of the transaction.

  1. Conclusion: An M&A Issue Hiding in a Product Regulation

That AI now demands legal attention is no longer a proposition that needs defending. What is less obvious is where that attention is owed. The AI Act is usually discussed as a product-compliance and governance regime, and therefore as a matter for engineering, compliance and regulatory functions. It is also, and far less visibly, an M&A instrument. Nothing in the Regulation is addressed to acquirers, yet its obligations attach to systems, to roles and to documentation that a buyer inherits in full on closing.

The consequences for transactional practice are practical rather than theoretical. Buyers should treat AI as a standing due diligence workstream rather than a subheading within the IT or intellectual property section; ask about AI systems even where the target does not describe itself as an AI business; confirm the target’s role, provider or deployer, system by system, because the obligations differ materially; and test implementation rather than policy. Sellers should expect these questions and prepare an AI inventory, a classification rationale and a compliance file before the data room opens.

The GDPR took several years to become a standard heading in every due diligence report. AI is likely to take less. The transactions being negotiated today will close into a regime whose principal obligations bite in 2026 and 2027, and whose penalties already do. The risk in overlooking AI compliance is not that it will prove irrelevant, but that it will prove relevant later – after signing, when the cost of the omission falls on whoever failed to ask. On the Romanian market, where a substantial share of deal flow involves subsidiaries operating group-level or vendor-supplied technology, that cost is easily underestimated.