MB AI · Intelligence Brief · Value gap · June 10, 2026

−$350M: The Verizon-Yahoo Lesson AI Buyers Never Learned

An undetected regulatory risk doesn't disappear at signing. It changes hands — and it gets paid for.
David Roux · MB AI Value Intelligence · SKEMA

February 2017. Verizon is about to acquire Yahoo for 4.83 billion dollars. Then two massive data breaches surface mid-due-diligence. Verizon doesn't leave the table — it recalculates. The deal closes at 4.48 billion. 350 million dollars erased, because a regulatory risk that had been dormant in the asset had just become visible.

−$350M
Cut to the Yahoo price after the breaches surfaced · CNN / TechCrunch, Feb. 2017

The risk belongs to the asset, not the seller

This is the principle every sophisticated buyer applies: whatever is attached to the asset passes to the acquirer at closing. Marriott learned it the hard way by acquiring Starwood — it inherited an undetected breach and an 18.4 million pound GDPR fine, with the UK authority explicitly faulting a failure to verify at the point of acquisition.

In both cases, the mechanics are identical: the data and its regulatory compliance travel with the company. The buyer who hasn't priced them discovers them later — when it's too late to negotiate anything other than a discount or a holdback.

The EU AI Act is replaying exactly this script

What held true for personal data now holds for artificial intelligence. The obligations of Articles 9 to 15 of Regulation (EU) 2024/1689 — risk management, technical documentation, human oversight, robustness — attach to the system. The penalties of Article 99 reach 35 million euros or 7% of worldwide turnover. A non-compliant AI asset is a Yahoo in waiting: a repricing biding its time.

The only difference from 2017: today, you can measure it before the deal room. That's exactly what the D7™ score does — characterize an asset's AI Act exposure, dimension by dimension, before a buyer does it for you.

Don't be the next −$350M
D7™ score across 7 dimensions · established then defended by MB Shield™
AI Act M&A due diligence →
Sources: CNN Money, Feb. 21, 2017 · Cybersecurity Dive (Marriott / GDPR) · Regulation (EU) 2024/1689, Art. 9-15 & 99.
MB AI Value Intelligence · mb-ai.frD7™ · EU AI Act + GDPR · © 2026