In 2016, Marriott acquired Starwood. Dormant in the legacy reservation systems sat an undetected intrusion — ultimately affecting nearly 383 million customer records. It hadn't been identified in due diligence. Marriott inherited it at closing, and with it, an 18.4 million pound GDPR fine.
The decisive point isn't the amount. It's the rationale: the UK authority explicitly faulted Marriott for a failure to verify at the time of acquisition. In other words: "you bought the risk, you should have looked at it." Regulatory liability isn't negotiated with the seller — it attaches to the asset and passes to the buyer.
GDPR is the antechamber to the AI Act. Tomorrow, the inherited asset won't be a poorly secured database — it'll be an AI system classified high-risk (Annex III) with no Article 11 documentation, no Article 14 human oversight, no Article 9 risk management. The buyer who hasn't characterized it in due diligence will inherit it the way Marriott inherited Starwood — with exposure that can reach 35 million euros or 7% of worldwide turnover (Article 99).
The defense is known, and it has changed since 2016: you can now characterize that exposure before signing. The D7™ score reads the asset the way the authority will read it after closing — by looking for what's missing. It's the due diligence the ICO faulted Marriott for not having done.