February 2017. Verizon is about to acquire Yahoo for 4.83 billion dollars. Then two massive data breaches surface mid-due-diligence. Verizon doesn't leave the table — it recalculates. The deal closes at 4.48 billion. 350 million dollars erased, because a regulatory risk that had been dormant in the asset had just become visible.
This is the principle every sophisticated buyer applies: whatever is attached to the asset passes to the acquirer at closing. Marriott learned it the hard way by acquiring Starwood — it inherited an undetected breach and an 18.4 million pound GDPR fine, with the UK authority explicitly faulting a failure to verify at the point of acquisition.
In both cases, the mechanics are identical: the data and its regulatory compliance travel with the company. The buyer who hasn't priced them discovers them later — when it's too late to negotiate anything other than a discount or a holdback.
What held true for personal data now holds for artificial intelligence. The obligations of Articles 9 to 15 of Regulation (EU) 2024/1689 — risk management, technical documentation, human oversight, robustness — attach to the system. The penalties of Article 99 reach 35 million euros or 7% of worldwide turnover. A non-compliant AI asset is a Yahoo in waiting: a repricing biding its time.
The only difference from 2017: today, you can measure it before the deal room. That's exactly what the D7™ score does — characterize an asset's AI Act exposure, dimension by dimension, before a buyer does it for you.