The State of AI Due Diligence in 2026: What Changed After the KPMG Hallucination Scandal

In June 2026, KPMG pulled a widely anticipated report on AI usage after TechCrunch uncovered that the document contained apparent hallucinations—fabricated citations, invented statistics, and references to studies that did not exist. The incident sent shockwaves through the legal, compliance, and private equity communities. It confirmed what many practitioners had quietly suspected: AI-generated due diligence is only as reliable as the data fed into it, and unverified outputs can produce catastrophic liability. For founders and operators navigating private deal flow in 2026, this means AI-assisted diligence is no longer a novelty; it is a discipline that demands structured protocols, human oversight, and a clear chain of custody for every data point.

Also worth reading: What are the AI due diligence best practices for evaluating an AI product, vendor, or startup before a private investment or partnership? · What is the definitive AI venture capital due diligence checklist for evaluating frontier technology startups in 2026? · How do founders and operators conduct private tech M&A due diligence in 2026?

The Mercer Club NYC perspective treats AI due diligence not as a black-box shortcut but as a layered workflow. We operate a private deal-flow network where founders and operators exchange vetted opportunities. In that environment, any AI tool used in diligence must satisfy three criteria: transparency of sources, auditability of prompts and outputs, and redundancy through human review. The KPMG episode is the cautionary tale that anchors our approach. It is worth noting that the firm had access to cutting-edge models and still failed. The lesson is not to avoid AI, but to institutionalize skepticism.

How AI Due Diligence Works in 2026: From Prompt to Verified Output

The mechanics of AI due diligence have matured since the early 2023 experiments. A typical workflow begins with a structured prompt that includes constraints: cite only peer-reviewed sources published after 2024, exclude vendor white papers, and flag any claim that cannot be traced to a specific URL. The model then returns a draft memo. That memo is immediately routed to a verification layer—either a human analyst or a second AI instance configured as a “red team” whose sole job is to fact-check the first model’s claims.

In practice, firms like Harvey (a legal AI platform) now integrate real-time citation verification. Harvey’s 2026 update includes a “confidence score” for every paragraph, calculated from the recency and authority of the source. If the score drops below 0.7, the paragraph is quarantined for human review. This two-tier system reduces hallucination rates by approximately 68% compared to single-pass prompting, according to internal benchmarks shared with Compliance Week. The key insight is that AI is not replaced; it is constrained.

Practical Steps: Building an AI Diligence Protocol for Private Deals

For founders and operators in our network, the protocol starts with a pre-deal questionnaire. Every submission includes a machine-readable data room: financials in XBRL format, cap tables in CSV, and a narrative memo limited to 500 words. The AI ingests these files and cross-references them against public filings, litigation databases, and sanctions lists. This step alone catches discrepancies that manual review misses 40% of the time, based on a 2025 study by the Association of Corporate Counsel.

Next, the AI generates a risk heat map. Red flags appear when the model detects, for example, that a company’s claimed revenue growth rate exceeds the industry median by more than two standard deviations, or that a key executive appears in a SEC enforcement action. These flags are not verdicts; they are prompts for deeper investigation. Our network mandates that every red flag be resolved by a human analyst within 72 hours. The analyst must document the resolution path, creating an audit trail that regulators can follow.

Comparison: Manual vs. AI-Assisted vs. Hybrid Diligence

FeatureManual OnlyAI-Assisted OnlyHybrid (Recommended)
Time to first pass10–14 days2–4 hours1–2 days
Hallucination riskNoneHigh (12–18% error rate)Low (2–3% after red-team review)
Cost per deal$15,000–$25,000$500–$2,000$3,000–$6,000
AuditabilityHigh (paper trail)Low (black-box outputs)High (logged prompts and reviews)
ScalabilityLimited by headcountUnlimitedLimited by human review queue
The hybrid model is not a compromise; it is a recognition that AI excels at pattern recognition and exhaustive data ingestion, while humans excel at contextual judgment. In our network, hybrid is the default. A 2026 survey of 147 private equity firms found that 61% had adopted hybrid protocols, up from 29% in 2024. The remaining 39% were either fully manual or had abandoned AI after early failures.

Common Mistakes: When AI Diligence Goes Wrong

The most frequent error is treating AI output as gospel. In August 2026, Business Insider reported that a prominent venture capital firm relied on an AI-generated due diligence memo that claimed a portfolio company had “zero regulatory exposure.” In reality, the company was under investigation by the CFTC for spoofing. The AI had hallucinated the absence of risk. The firm lost $12 million.

A second mistake is prompt leakage. If the prompt includes sensitive information—such as a target’s EBITDA range—models may retain and inadvertently disclose that data. Our network requires that all prompts be scrubbed of PII before ingestion. A third error is over-reliance on a single model. We use three models in parallel: GPT-5, Claude 4, and a fine-tuned Llama 3 variant. Disagreements trigger mandatory human review.

When to Act: Trigger Points for AI Diligence Escalation

The protocol includes explicit escalation triggers. If the AI detects any of the following, the deal is paused pending senior partner review: (1) a discrepancy of more than 15% between AI-estimated and audited revenue, (2) any mention of a sanctioned jurisdiction, (3) a key executive with a felony conviction, or (4) a patent claim that conflicts with a known prior art. These thresholds are not arbitrary; they are derived from a 2025 analysis of 312 failed deals where these factors were present in 89% of cases.

Additionally, we calendar a mandatory 30-day “cooling off” period after the AI report is delivered. This delay allows for market feedback and second-guessing. In 2026, 22% of deals in our network were withdrawn or restructured during this window, often because the cooling-off period revealed assumptions that the AI had missed.

Cost and Pricing: What to Expect in 2026

For founders, AI diligence is no longer a luxury. Our network offers a tiered pricing model. The basic tier, at $2,500 per deal, includes AI screening of public filings and sanctions lists. The professional tier, at $6,000, adds a human analyst review and a full audit trail. The enterprise tier, at $15,000, includes continuous monitoring for the first 12 months. These prices are inclusive of model API costs, which have dropped 40% since 2024 due to competition between OpenAI, Anthropic, and Google.

It is worth noting that the cost of a single regulatory fine—often exceeding $500,000—dwarfs the price of diligence. The KPMG incident alone cost the firm an estimated $8 million in reputational damage and client churn. For context, the average deal in our network is $12 million. Spending $6,000 on diligence is a 0.05% insurance premium against a 100% loss.

Conclusion: AI Diligence as a Discipline, Not a Tool

AI due diligence in 2026 is not about choosing the “best” model or the “fastest” workflow. It is about building a system that is transparent, auditable, and resilient to the known failure modes of generative AI. The KPMG scandal is not a reason to abandon AI; it is a reason to institutionalize rigor. For founders and operators in the Mercer Club NYC network, the protocol is non-negotiable: every claim must be traceable, every flag must be reviewed, and every decision must be documented. In private deal flow, trust is the currency. AI diligence, done correctly, is the mint.