Table of Contents
- The Agentic Threat Landscape
- The PE Imperative: Why Diligence Must Change
- The Scoring Model: Four Dimensions of Exposure
- How to Score a Target
- Diligence Questions That Reveal the Real Risk
- Using the Score to Price Risk and Structure Deals
- Post‑Close: From Risk to Resilience
- Summary and Next Steps
The Agentic Threat Landscape
Private equity deal teams are accustomed to underwriting market risk, management risk, and leverage risk. But a new, faster-moving threat is rewriting the diligence playbook: agentic AI substitution. Unlike the predictive models and chatbots that dominated the first AI wave, today’s agentic systems—built on models such as Claude Opus 5, Sonnet 5, and Fable 5 from the Claude 5 family, alongside competitors like GPT‑5.6 Sol and Terra, Gemini 3, and Kimi K3—can plan, reason, use tools, and execute multi‑step workflows autonomously. They don’t just answer questions; they complete tasks, negotiate with APIs, and manage entire business processes end‑to‑end.
For a portfolio company that derives a material share of its revenue from services that can be decomposed into repeatable cognitive steps, the arrival of capable agents isn’t a theoretical future risk—it’s an active underwriting variable today. A company that bills for insurance claims adjudication, customer onboarding, financial operations reconciliation, or even mid‑market marketing campaign execution may find its unit economics hollowed out within a holding period. The models are ready: Claude Sonnet 5 and Opus 5 each carry a 1‑million‑token context window, enough to ingest entire policy manuals, regulatory frameworks, or years of transactional data and act on them. Fable 5, the most capable widely released model, can orchestrate complex tool‑calling chains that mimic junior knowledge workers. Haiku 4.5 delivers this capability at speed and low cost, making high‑volume automation economically inevitable.
This shift demands a structured, repeatable way to underwrite AI disruption risk—not as a vague qualitative concern, but as a quantifiable factor that can alter a deal’s return profile. That’s what this framework delivers.
The PE Imperative: Why Diligence Must Change
The traditional private equity diligence process—financial, commercial, operational, and IT due diligence—was designed for a world where competitive advantage eroded gradually. A target’s revenue base could be stress‑tested against customer concentration, pricing power, and market growth. Agentic AI compresses that timeline dramatically. A business that looks stable on a three‑year projection can become structurally impaired in 18 months if its core workflows are susceptible to substitution by an agent that costs a fraction of a fully loaded employee.
Deal activity data underscores the urgency. Industry figures for H1 2026 reveal a striking split: EY reported a 10% decline in deal volume, while PwC’s methodology pointed to a 34% contraction—a divergence driven by different denominator definitions and which transaction types each firm includes. Beneath the headline numbers, Oliver Wyman’s analysis of tech deal value contraction highlights that buyers are already repricing assets where AI exposure is ambiguous. For PE firms executing roll‑ups and portfolio value creation plays, the message is clear: a target’s exposure to agentic substitution must be underwritten with the same rigor as its debt capacity or customer retention curve.
This is where a dedicated AI strategy and readiness assessment becomes a deal‑making capability. PADISO’s CTO as a Service practice regularly steps into due diligence processes for mid‑market brands and PE‑backed portfolios, providing the technical depth to distinguish between a genuine data moat and a workflow that Claude Fable 5 could replicate in a weekend. The scoring model that follows is built from that frontline experience, adapted for deal teams and operating partners who need a fast, defensible way to quantify agentic disruption risk.
The Scoring Model: Four Dimensions of Exposure
We evaluate a target’s vulnerability to agentic substitution across four dimensions, each scored on a 1–5 scale (1 = highly resistant, 5 = highly exposed). The aggregate score, weighted for revenue concentration, becomes the Agentic Exposure Index (AEI). The dimensions are:
- Revenue Type Exposure
- Workflow Depth
- Data Moat Durability
- Switching Cost and Customer Lock‑in
1. Revenue Type Exposure
Not all revenue is equally susceptible. We classify revenue into three categories:
- Transaction‑based revenue (per‑claim, per‑report, per‑transaction): Highly automatable. An agent can process a claim, generate a compliance report, or reconcile a payment stream with minimal human intervention.
- Subscription or recurring service revenue: Partially automatable. If the service is a bundled “black box” of expertise, the risk is moderate; if it’s a predictable, rule‑based service, the risk is high.
- Advisory, relationship‑driven, or custom project revenue: Lower immediate risk. Trusted advisor roles, bespoke consulting, and high‑stakes judgment calls resist substitution—though agentic augmentation can still compress billable hours.
Scoring: Assign 5 if more than 60% of revenue is transaction‑based; 3 if a mix of transaction and subscription; 1 if primarily advisory or custom project work with deep client relationships.
For example, a portfolio company providing AI for insurance—claims automation, conduct risk monitoring, underwriting AI—might score a 4 if its own revenue depends on processing claims on behalf of carriers. The very technology it sells could be turned inward by its clients using off‑the‑shelf agents.
2. Workflow Depth
This dimension measures how many discrete, repeatable steps a company’s core service delivery comprises, and how many of those steps are already well‑handled by current models. A workflow with 20 sequential steps, each requiring nuanced judgment, is harder to automate end‑to‑end than a workflow with five steps that are essentially data transformation and routing.
We break workflow depth into three tiers:
- Shallow workflows (≤5 steps, mostly data movement and rule application): Claude Haiku 4.5 can handle these today at negligible cost. Score 5.
- Moderate workflows (6–15 steps, some branching logic, occasional tool use): Within reach of Sonnet 5 or GPT‑5.6 Sol with careful prompt engineering and tool integration. Score 3.
- Deep, context‑heavy workflows (15+ steps, extensive domain reasoning, multi‑stakeholder coordination): Still defensible, though Opus 5’s 1M‑context window is shrinking the gap. Score 1.
A target that provides financial services AI—for instance, APRA CPS 234 and ASIC RG 271 compliant monitoring—might involve deep workflows that span regulatory interpretation, transaction surveillance, and reporting. That depth initially suggests a lower score, but if the monitoring itself can be reduced to an agentic pipeline, the risk rises.
3. Data Moat Durability
A durable data moat can protect a company even if its workflows are automatable. The question is whether the target possesses proprietary data that agents cannot easily replicate or access. We assess:
- Proprietary data generation: Does the company create unique data as a byproduct of its operations (e.g., transaction logs, behavioral patterns, industry benchmarks)?
- Data network effects: Does the value of the data increase with more customers?
- Regulatory or contractual exclusivity: Is the data protected by law or long‑term agreements?
If the target’s entire value proposition rests on applying AI to publicly available datasets or generic industry knowledge, the moat is shallow. Score 5. If the company has amassed a decade of proprietary, structured, and labeled data that would take a competitor years to replicate, score 1.
During diligence, platform engineering assessments often reveal whether a target’s data infrastructure is genuinely a moat or just a collection of siloed spreadsheets. A target that has invested in a modern data platform—multi‑tenant SaaS with embedded analytics, for instance—may have a structural advantage that agents cannot easily erode.
4. Switching Cost and Customer Lock‑in
Even a highly automatable business can survive if its customers face prohibitive switching costs. We evaluate:
- Integration depth: Is the target’s product embedded in the customer’s ERP, CRM, or core banking system?
- Contractual stickiness: Are there multi‑year commitments, early termination penalties, or regulatory hurdles to switching?
- Retraining and change management costs: Would replacing the service with an agent require the customer to re‑engineer internal processes?
A target with deep platform development in New York—low‑latency data platforms, SOC 2‑ready architecture, multi‑tenant SaaS—likely enjoys high switching costs. Score 1. A target offering a standalone, API‑callable service with monthly contracts and no integration depth scores 5.
How to Score a Target
For each target, assign a score of 1–5 on each dimension, then calculate a weighted composite:
- Revenue Type Exposure: 35% weight
- Workflow Depth: 30% weight
- Data Moat Durability: 20% weight
- Switching Cost: 15% weight
The weights reflect the primacy of revenue structure and workflow automation risk. The resulting AEI score ranges from 1.0 (minimal agentic risk) to 5.0 (severe, imminent risk).
Interpreting the Score:
| AEI Range | Risk Level | Implication |
|---|---|---|
| 1.0–2.0 | Low | Business model is structurally resilient to agentic substitution in the medium term. |
| 2.1–3.5 | Moderate | Some revenue segments are exposed; post‑close transformation can mitigate risk. |
| 3.6–5.0 | High | Core revenue is highly automatable; thesis must account for significant margin compression or revenue displacement. |
This scoring exercise isn’t an academic exercise. It directly informs valuation, hold‑period assumptions, and the post‑close value creation plan. A target scoring 4.2 on the AEI demands a very different capital structure and operational playbook than one scoring 1.8.
Diligence Questions That Reveal the Real Risk
The scoring model is only as good as the information fed into it. Below are the diligence questions deal teams should ask—and the artifacts they should request—to populate each dimension accurately.
Revenue Type Exposure
- What percentage of revenue is tied to transactional, per‑unit pricing versus recurring subscriptions or fixed‑fee advisory?
- Can the customer achieve the same outcome by purchasing a software license and deploying an agent internally?
- Request a revenue bridge that maps each revenue stream to the underlying unit of value (e.g., per claim processed, per report generated).
Workflow Depth
- Map the top three revenue‑generating workflows step by step. How many steps are rule‑based versus judgment‑based?
- Have any clients already experimented with replacing parts of this workflow using GPT‑5.6 Terra or open‑weight models?
- Request process documentation, SOPs, and any internal automation roadmaps. Ask the target’s engineering lead: “If you had unlimited access to Claude Opus 5 and a tool‑use framework, how much of this workflow could you automate in six weeks?”
For PE firms that lack in‑house technical bench strength, bringing in a fractional CTO in San Francisco or a CTO advisory in Dallas during diligence can turn these questions from guesswork into a rigorous technical assessment.
Data Moat Durability
- What proprietary datasets does the company own that are not publicly available or easily licensable?
- How is the data structured, labeled, and maintained? Is it accessible via modern APIs or locked in legacy systems?
- Does the data improve with scale (network effects) or is it a static asset that degrades over time?
- Request a data catalog, data lineage documentation, and any third‑party data licensing agreements.
Switching Cost and Customer Lock‑in
- What is the average customer tenure and net revenue retention?
- How many customers have integrated the target’s solution into their core infrastructure (e.g., via API, embedded analytics, or workflow automation)?
- What would it cost a typical customer in time, money, and operational disruption to replace the target’s service with an agent‑based alternative?
- Review the top 10 customer contracts for termination clauses, auto‑renewal terms, and integration dependencies.
Using the Score to Price Risk and Structure Deals
Once the AEI score is calculated, it should flow directly into the deal model. A high AEI doesn’t necessarily kill a deal—it changes the price and the structure.
- Valuation adjustment: For a target with an AEI above 3.5, model a revenue haircut of 15–30% over the hold period, reflecting the probability that agentic alternatives compress pricing or capture share. This can be applied as a discount to the terminal multiple or as a lower base‑case revenue growth rate.
- Earn‑out and contingent consideration: Tie a portion of the purchase price to the successful execution of an AI transformation plan that reduces the AEI score within 24 months. This aligns incentives and transfers some execution risk back to the seller.
- Hold‑period assumptions: A high‑AEI business may require a shorter hold period (3–4 years) with an aggressive transformation sprint in year one, rather than a 5–7 year steady‑state hold. Alternatively, it may be a candidate for a roll‑up where the combined entity can build a defensible data moat faster than any standalone company.
For PE firms running roll‑up strategies, the AEI framework doubles as a screening tool. A platform acquisition with a low AEI can absorb add‑ons with moderate AEI scores, provided the combined entity can extend its data moat and switching costs across the acquired customer base. PADISO’s venture architecture and transformation practice has guided multiple portfolio companies through exactly this kind of tech consolidation for efficiency and EBITDA lift.
Post‑Close: From Risk to Resilience
Underwriting the risk is only half the battle. The real value creation comes from executing a deliberate program to reduce the AEI score over the first 12–24 months of ownership. This typically involves three workstreams:
1. Agentic Self‑Disruption
If a portfolio company’s workflows are automatable, the best defense is to automate them first—capturing the margin uplift before a competitor does. This means deploying agents internally to deliver the same service at lower cost, then passing a portion of the savings to customers in exchange for longer contracts and deeper integration. Using models like Claude Sonnet 5 with tool‑use capabilities, a company can re‑engineer its cost structure while simultaneously raising switching costs.
2. Data Moat Acceleration
Invest aggressively in proprietary data generation, structuring, and productization. This might involve building a platform development capability in Australia or the US that ingests operational data from customers, creates benchmarks, and delivers insights that are only possible with scale. The goal is to make the data moat deeper and wider with every new customer.
3. Compliance and Trust Moat
In regulated industries—financial services, insurance, healthcare—compliance itself can be a moat. Achieving SOC 2 or ISO 27001 audit‑readiness via Vanta and embedding agentic governance frameworks from Microsoft’s guidance on governing AI agents and the Singapore IMDA Model AI Governance Framework for Agentic AI can create a regulatory barrier that pure‑play agentic startups struggle to cross. The NIST AI Risk Management Framework and the OECD AI Principles offer additional scaffolding for building trustworthy AI systems that enterprise buyers demand.
A portfolio company that combines a low‑cost agentic operating model with a hard‑to‑replicate data moat and a compliance‑grade trust posture doesn’t just survive agents—it becomes a platform that other companies integrate into, rather than a service they replace.
Summary and Next Steps
Agentic AI is not a future scenario; it’s a present underwriting variable that PE deal teams can no longer afford to ignore. The four‑dimension scoring model—Revenue Type Exposure, Workflow Depth, Data Moat Durability, and Switching Cost—provides a structured way to quantify a target’s vulnerability, ask the right diligence questions, and price risk appropriately.
The firms that move fastest will be those that integrate technical due diligence into their deal processes as a standard workstream, not an afterthought. Whether that means engaging a fractional CTO in Melbourne or Sydney for an Australian roll‑up, or bringing in AI advisory services to pressure‑test a target’s automation roadmap, the capability to underwrite agentic risk will increasingly separate top‑quartile PE returns from the rest.
Next steps for deal teams and operating partners:
- Apply the AEI framework to your current pipeline. Score each live deal and compare the results to your initial investment thesis. Where are the blind spots?
- Build a technical diligence bench. If you lack in‑house AI expertise, establish a relationship with a CTO as a Service partner who can execute rapid technical assessments and provide a defensible point of view on agentic exposure.
- Pressure‑test your portfolio. Run the AEI model on existing portfolio companies. For those scoring above 3.5, launch a 90‑day sprint to design an agentic self‑disruption plan that reduces the score before the next fundraising or exit process.
- Stay current on model capabilities. The gap between what Claude Fable 5 can automate today and what Opus 5 will automate tomorrow is shrinking. Resources like the Berkeley CLTC Agentic AI Risk Management Profile, the EU AI Act regulatory framework, and Stanford HAI’s research provide ongoing insight into both capabilities and constraints.
PADISO works with PE firms and portfolio companies across the US, Canada, and Australia to underwrite, price, and execute AI transformation with measurable ROI. From case studies that demonstrate real results to platform development in Melbourne that modernizes regulated monoliths, our team brings the operator mindset that diligence demands. If you’re evaluating a target and need a technical partner who can quantify agentic risk and design the post‑close roadmap, start a conversation.