Blog Post

AI Governance Across a Private Equity Portfolio

August 31, 2026

Table of Contents

A sponsor holding twelve companies holds twelve AI programs of unknown maturity. Some have a policy and an inventory. Some have a chief technology officer who has read about the EU AI Act. At least one has employees pasting customer data into consumer assistants and no record of it.

The standard prescription is to issue a unified AI policy across the portfolio, appoint a review board and roll out monitoring. The approach works in a single operating company and does not survive a portfolio, because a forty million dollar software business and a two billion dollar manufacturer cannot run the same program. Mandating one produces documentation in the small companies and resistance in the large ones.

What a Sponsor Can Require

The leverage a sponsor holds is over reporting rather than over process. What appears in the quarterly pack is enforceable. How a management team achieves it is not, and attempting to specify it wastes the leverage on something unenforceable.

Attributes travel across companies of different sizes and sectors in a way frameworks do not. A business with three AI tools and one with three hundred can both answer the same short set of questions, and the answers remain comparable, which is what matters at portfolio level.

Five Questions That Work at Any Size

  • What AI Is in Use: A count of tools and systems, separating sanctioned from discovered, with the discovery method stated.
  • What Decisions It Touches: Which systems influence hiring, credit, pricing, safety or anything affecting customers.
  • Who Owns It: A named individual per consequential system, not a function.

The remaining two are exposure and regulatory position. A modeled figure for what an AI-related incident would cost the company, and which regimes reach its systems given where its customers and employees are. Five answers, quarterly, from every company regardless of size. Defining what counts as one system is what stops the first question producing incomparable counts.

Twelve Maturity Assessments Do Not Add Up

Sponsors that do ask about AI governance usually get maturity ratings back, and the results are unusable in aggregate. A company scoring three against one framework and another scoring two against a different one cannot be summed, ranked or traded off, and the fund has no answer to the only question that matters at its level.

Entity list showing modeled annual loss and extreme loss per company alongside each one's security profile assessment
Expressing each company's exposure in the same unit is what makes a portfolio comparable, and it frequently shows that posture and exposure rank differently.

Expressed as modeled loss, the same twelve become additive. The portfolio has a figure, individual companies can be ranked within it, and remediation capital goes where it reduces the most exposure rather than to whichever management team is most persuasive. The same reasoning explains why portfolio optimization on the cyber side works from figures rather than from scores.

Posture and Exposure Rank Differently

A useful and counterintuitive result appears when this is done. The company with the weakest controls is frequently not the one carrying the most exposure, because exposure scales with what a business has to lose. A well-run company with substantial revenue and sensitive data can outrank a poorly run one with little at stake, which changes where a sponsor should spend.

Fund-Level Concentration Is Invisible From Inside

Every portfolio company assesses its own vendors. None of them can see that eight of the twelve depend on the same model provider, the same AI-enabled platform or the same underlying infrastructure region.

Aggregate exposure across a portfolio of entities showing average annual loss, extreme loss and the correlation factor applied between them
Aggregating with correlation applied produces a fund-level figure that summing individual company exposures cannot reach.

The correlation belongs to the sponsor because only the sponsor can see it. A provider outage or a model-level failure affecting eight companies simultaneously is a fund event rather than twelve unrelated incidents, and it barely affects the average while substantially affecting the extreme case. Concentration examined across a portfolio behaves the same way whether the shared dependency sits under one company or twelve.

Collect the Vendor List, Not the Vendor Assessment

The practical ask is simpler than a diligence questionnaire. Require each company to report which AI providers and platforms it depends on for anything material, then look across the list. The concentration finding requires no assessment of any individual vendor, only the overlap.

Diligence Has No Standard Artifact Yet

Cyber diligence has settled into recognizable form, with penetration test results, control assessments, insurance schedules and incident history. AI diligence has no equivalent, so a sponsor asking about AI at acquisition receives whatever the target happens to have and cannot compare it to the last three deals.

Four questions produce comparable answers across targets regardless of what documentation exists. Which AI systems influence decisions about people. Whether ownership of training data and fine-tuned weights is established in writing. Whether any system was built on a model whose license restricts commercial use or use for training. Whether the company operates in a jurisdiction where its AI use already carries obligations completes it, since the applicable regime follows where affected individuals live rather than where the company sits.

The Intellectual Property Question Is the Expensive One

A target whose product depends on a fine-tuned model, without documented rights to the training data, carries an exposure that surfaces during the sponsor's own exit rather than at acquisition. It is cheap to ask about and expensive to discover later, which is the profile of the questions worth adding to a checklist.

Exit Is What Forces the Discipline

A buyer's diligence will ask about AI governance, and increasingly it asks in detail. The answer has to exist per company, in a form somebody outside can verify, at a moment when there is no time to build it.

Sponsors standardizing the five attributes across the hold period arrive at a sale with a comparable record and a defensible figure. Those that do not spend the diligence period assembling one under time pressure, which tends to surface as either a price adjustment or a delay. The same dynamic already applies on the cyber side, where cyber risk in a transaction moves faster when the record predates the process.

The Sponsor Sits on the Board

One further consideration applies to the sponsor rather than to the companies. Partners holding board seats carry the oversight responsibility that attaches to any director, and AI investment approved without governance expectations is a familiar position for a board to be in.

Asking the five questions quarterly discharges a real part of that, provided the answers are recorded and the trend is examined rather than filed. A sponsor that can show it asked, received answers and acted on them occupies a different position from one that delegated the question to twelve management teams and did not follow up. What directors need to see applies to a portfolio board as much as to a single company.

Standardize the Question, Not the Answer

A portfolio cannot run one AI program, and a sponsor attempting to mandate one spends its leverage on something unenforceable. What travels across companies of any size is a short set of attributes reported on a cycle, expressed in a unit that aggregates. The result is a fund-level figure, exposes the concentration no individual company can see, and leaves a record that survives contact with a buyer's diligence. Kovrr's private equity portfolio analysis already works this way for cyber exposure, and AI risk quantification extends the same unit to AI.

To see aggregate AI and cyber exposure across a portfolio rather than twelve separate assessments, book a demo with our risk experts.

Yakir Golan

CEO

Portfolio AI Governance FAQs

Speak to an Expert

Can a sponsor mandate one AI policy across a portfolio?

What should portfolio companies report about AI?

Why don't maturity assessments work at portfolio level?

What concentration risk exists at fund level?

What should AI diligence ask at acquisition?

Why does exit force the discipline?