
Blog Post
AI Governance Across a Private Equity Portfolio
August 31, 2026
A sponsor holding twelve companies holds twelve AI programs of unknown maturity. Some have a policy and an inventory. Some have a chief technology officer who has read about the EU AI Act. At least one has employees pasting customer data into consumer assistants and no record of it.
The standard prescription is to issue a unified AI policy across the portfolio, appoint a review board and roll out monitoring. The approach works in a single operating company and does not survive a portfolio, because a forty million dollar software business and a two billion dollar manufacturer cannot run the same program. Mandating one produces documentation in the small companies and resistance in the large ones.
What a Sponsor Can Require
The leverage a sponsor holds is over reporting rather than over process. What appears in the quarterly pack is enforceable. How a management team achieves it is not, and attempting to specify it wastes the leverage on something unenforceable.
Attributes travel across companies of different sizes and sectors in a way frameworks do not. A business with three AI tools and one with three hundred can both answer the same short set of questions, and the answers remain comparable, which is what matters at portfolio level.
Five Questions That Work at Any Size
- What AI Is in Use: A count of tools and systems, separating sanctioned from discovered, with the discovery method stated.
- What Decisions It Touches: Which systems influence hiring, credit, pricing, safety or anything affecting customers.
- Who Owns It: A named individual per consequential system, not a function.
The remaining two are exposure and regulatory position. A modeled figure for what an AI-related incident would cost the company, and which regimes reach its systems given where its customers and employees are. Five answers, quarterly, from every company regardless of size. Defining what counts as one system is what stops the first question producing incomparable counts.
Twelve Maturity Assessments Do Not Add Up
Sponsors that do ask about AI governance usually get maturity ratings back, and the results are unusable in aggregate. A company scoring three against one framework and another scoring two against a different one cannot be summed, ranked or traded off, and the fund has no answer to the only question that matters at its level.

Expressed as modeled loss, the same twelve become additive. The portfolio has a figure, individual companies can be ranked within it, and remediation capital goes where it reduces the most exposure rather than to whichever management team is most persuasive. The same reasoning explains why portfolio optimization on the cyber side works from figures rather than from scores.
Posture and Exposure Rank Differently
A useful and counterintuitive result appears when this is done. The company with the weakest controls is frequently not the one carrying the most exposure, because exposure scales with what a business has to lose. A well-run company with substantial revenue and sensitive data can outrank a poorly run one with little at stake, which changes where a sponsor should spend.
Fund-Level Concentration Is Invisible From Inside
Every portfolio company assesses its own vendors. None of them can see that eight of the twelve depend on the same model provider, the same AI-enabled platform or the same underlying infrastructure region.

The correlation belongs to the sponsor because only the sponsor can see it. A provider outage or a model-level failure affecting eight companies simultaneously is a fund event rather than twelve unrelated incidents, and it barely affects the average while substantially affecting the extreme case. Concentration examined across a portfolio behaves the same way whether the shared dependency sits under one company or twelve.
Collect the Vendor List, Not the Vendor Assessment
The practical ask is simpler than a diligence questionnaire. Require each company to report which AI providers and platforms it depends on for anything material, then look across the list. The concentration finding requires no assessment of any individual vendor, only the overlap.
Diligence Has No Standard Artifact Yet
Cyber diligence has settled into recognizable form, with penetration test results, control assessments, insurance schedules and incident history. AI diligence has no equivalent, so a sponsor asking about AI at acquisition receives whatever the target happens to have and cannot compare it to the last three deals.
Four questions produce comparable answers across targets regardless of what documentation exists. Which AI systems influence decisions about people. Whether ownership of training data and fine-tuned weights is established in writing. Whether any system was built on a model whose license restricts commercial use or use for training. Whether the company operates in a jurisdiction where its AI use already carries obligations completes it, since the applicable regime follows where affected individuals live rather than where the company sits.
The Intellectual Property Question Is the Expensive One
A target whose product depends on a fine-tuned model, without documented rights to the training data, carries an exposure that surfaces during the sponsor's own exit rather than at acquisition. It is cheap to ask about and expensive to discover later, which is the profile of the questions worth adding to a checklist.
Exit Is What Forces the Discipline
A buyer's diligence will ask about AI governance, and increasingly it asks in detail. The answer has to exist per company, in a form somebody outside can verify, at a moment when there is no time to build it.
Sponsors standardizing the five attributes across the hold period arrive at a sale with a comparable record and a defensible figure. Those that do not spend the diligence period assembling one under time pressure, which tends to surface as either a price adjustment or a delay. The same dynamic already applies on the cyber side, where cyber risk in a transaction moves faster when the record predates the process.
The Sponsor Sits on the Board
One further consideration applies to the sponsor rather than to the companies. Partners holding board seats carry the oversight responsibility that attaches to any director, and AI investment approved without governance expectations is a familiar position for a board to be in.
Asking the five questions quarterly discharges a real part of that, provided the answers are recorded and the trend is examined rather than filed. A sponsor that can show it asked, received answers and acted on them occupies a different position from one that delegated the question to twelve management teams and did not follow up. What directors need to see applies to a portfolio board as much as to a single company.
Standardize the Question, Not the Answer
A portfolio cannot run one AI program, and a sponsor attempting to mandate one spends its leverage on something unenforceable. What travels across companies of any size is a short set of attributes reported on a cycle, expressed in a unit that aggregates. The result is a fund-level figure, exposes the concentration no individual company can see, and leaves a record that survives contact with a buyer's diligence. Kovrr's private equity portfolio analysis already works this way for cyber exposure, and AI risk quantification extends the same unit to AI.
To see aggregate AI and cyber exposure across a portfolio rather than twelve separate assessments, book a demo with our risk experts.
Portfolio AI Governance FAQs
Speak to an ExpertCan a sponsor mandate one AI policy across a portfolio?
Not in practice. A portfolio spanning a forty million dollar software business and a two billion dollar manufacturer cannot run the same AI program, and mandating one produces documentation in the small companies and resistance in the large ones. The leverage a sponsor holds is over reporting rather than over process. What appears in the quarterly pack is enforceable, while how a management team achieves it is not, and specifying the method wastes the leverage on something unenforceable.
What should portfolio companies report about AI?
Five attributes that travel across companies of any size. What AI is in use, as a count separating sanctioned from discovered with the discovery method stated. What decisions it touches, meaning which systems influence hiring, credit, pricing, safety or anything affecting customers. Who owns each consequential system, named as an individual rather than a function. A modeled figure for what an AI-related incident would cost. And which regulatory regimes reach its systems given where its customers and employees are located.
Why don't maturity assessments work at portfolio level?
Because they are not comparable. A company scoring three against one framework and another scoring two against a different framework cannot be summed, ranked or traded off, so the fund has no answer to the question at its own level. Expressed as modeled loss the same companies become additive, the portfolio has a figure, and remediation capital can go where it reduces the most exposure rather than to whichever management team argues most persuasively for it.
What concentration risk exists at fund level?
Every portfolio company assesses its own vendors and none can see that eight of twelve depend on the same model provider, AI-enabled platform or infrastructure region. The correlation belongs to the sponsor because only the sponsor can observe it. A provider outage or model-level failure affecting eight companies at once is a fund event rather than twelve unrelated incidents, and it barely affects the average while substantially affecting the extreme case. The practical ask is a vendor list from each company rather than a vendor assessment.
What should AI diligence ask at acquisition?
Four questions that produce comparable answers across targets regardless of what documentation exists. Which AI systems influence decisions about people. Whether ownership of training data and fine-tuned weights is established in writing. Whether any system depends on a model whose license restricts commercial use or use for training other models. And whether the company operates where its AI use already carries obligations, since the applicable regime follows where affected individuals live rather than where the company is headquartered.
Why does exit force the discipline?
Because a buyer's diligence asks about AI governance in detail, and the answer has to exist per company in a form an outsider can verify, at a point when there is no time to build it. Sponsors standardizing a short attribute set across the hold period arrive at a sale with a comparable record and a defensible figure. Those that do not assemble one under time pressure during diligence, which tends to surface as either a price adjustment or a delay to the process.



