AI & Verification

When the due diligence report itself is the red flag.

A polished background report used to be reassuring. In 2026 it is one of the first things we look at twice. Auto-generated dossiers are now common — fluent, well-structured, and very hard to source-verify. Here is how we read them, and what a real review does instead.

10 June 2026·5 min read·By KYA Axiom

Two years ago, an unprompted "background report" arriving with a counterparty pitch was rare and meant something. Today it is common. Generative models will produce a credible-looking dossier on almost any company in a few minutes — and many of the ones we now see attached to proposals were produced exactly that way.

The problem is not that they are written by a machine. The problem is that the document looks like evidence and is not. It is plausible writing, presented in a format that signals diligence, without anything underneath that a third party could check.

Three patterns we look for

1. The citation salad

The report references "industry sources", "regulatory filings", and "press coverage" without naming a single document, URL, filing number, or publication date. The vocabulary of evidence is present. The evidence is not.

2. The anachronistic frame

The report uses language and policy references that don't match the year. A regulation is cited that was superseded eighteen months ago. A market position is described that has not been true since 2023. The dossier is confident, fluent, and quietly out of date — because the model that produced it has a knowledge cutoff and was not given fresh inputs.

3. The missing dates

Real diligence is dated work. A genuine record has an "as of" stamp, a source, and a retrieval date. Generated dossiers tend to be timeless — they describe a company as if it always was and always will be. That timelessness is the tell.

Plausible writing is not the same as verified fact. The two used to feel similar from across the room. They no longer do.

Why this matters for small deals

The counterparties most likely to send an unprompted dossier are also the ones least likely to have commissioned a real one. The dossier is a substitute for the conversation a diligence review would otherwise generate. It is meant to close down questions, not open them.

That is the inversion worth noticing. A real review surfaces unknowns. A synthetic one resolves them on paper without doing the work.

Treat as red flag

If a counterparty proactively provides a "due diligence report" they commissioned themselves — read it carefully, then ignore it as evidence. It is, at best, a marketing document. Verify the underlying claims independently before any commitment.

What a real review does differently

  1. Every claim has a source line. If we can't cite where we found it, we can't make the claim.
  2. Every source has a retrieval date. A filing that was true in 2023 is not necessarily true in 2026.
  3. Every gap is named. Where we couldn't find something, we say so — explicitly, in the report.
  4. The risk rating is explained. Not a colour-coded badge, but a sentence describing why.

None of that is glamorous. All of it is auditable. That is what makes a review usable as a basis for a real decision instead of as cover for one already made.

A quick test you can run today

The next time a counterparty sends a "background report" with their proposal, ask three small questions:

  • "Who produced this report?"
  • "On what date were the underlying sources retrieved?"
  • "Can you forward two of the cited sources directly?"

The response — its speed, its specificity, its willingness — is itself a signal worth recording.

Need an independent read on a vendor or counterparty dossier?

Send us what you've been given. We'll tell you what holds up, what doesn't, and what's missing — in plain language, in writing.