ABSTRACT
“AI slashes M&A reviews from weeks to days, but with no rules means legal CHAOS.” In 2026, AI tools like the “kira system and spellbook” let lawyers scan thousands of contracts in hours. “Why care? India’s 2025 M&A saw $60 billion worth of mergers and acquisitions deals, across 963 transactions. Foreign investors poured in $81 billion (FDI), AI made it possible. AI finds risks which humans cannot such as hidden IP ownership problems, clauses which are causing risk in future, market dominance, lock-ins. This is especially important in fintech and big tech acquisitions, where data=power and platforms can lock out competitors. “Companies act 2013? CCI? SEBI? DPDP? With zero AI rules, TOTAL legal vacuum, on the other hand AI is creating serious risk such as biasness. AI learns from past deals, if earlier big tech were favoured it will repeat the same in upcoming cases, due diligence involves data of employees, customers and also financial records. But DPDP does not specify or clearly states that such data can be uploaded into AI tools, who is liable if the data is leaked? AI is coming with risks but cannot be blamed because it does not come with any explanation why it did so? Clients usually blame lawyers, but lawyers can’t blame AI right? Law gives no guidance on responsibilities. India must come up with and bridge these gaps through mandatory CCI AI audits, SEBI diligence codes, and 2027 “AI SAFE DILIGENCE” there’s no clear rule yet for something new like AI in legal due diligence and M&A, letting lawyers close deals faster without the ethical headaches.
INTRODUCTION
AI crunches contracts at lightning speed in India’s $60B M&A market, but zero guardrails threaten systemic risk. “In 2025, India clocked $60 billion in M&A deals across 963 transactions happening in just one year, huge foreign investors brought in $81 billion FDI(DPIIT,2026). “Think Walmart’s flipkart blockbuster or Phonepe snapping up smaller fintech startups.” This showcases that India is now a global M&A hotspot, especially in fintech, tech, and data-driven companies. Lets focus on due diligence, due diligence is something which is to check every document before buying a company, lawyers must review thousands of contracts, employee agreements, IP ownership clauses, data protection compliances and competition law risks.
“Traditionally, it’s manual drudgery weeks or months of eye strain, with fatigued humans missing killer clauses.” One overlooked term? Deal collapse or crippling fines down the line, like CCI antitrust hits. Here AI plays a very important role, it acts like a super fast junior lawyer who never gets tired. Tools like “KIRA” and “SPELLBOOK” read thousands of contracts in hours, highlight risky clauses, and benchmark against past M&A data.” KIRA flags non complete clauses, data clauses, SPELLBOOK looks at past failed deals, predicts competition law risks and warns the lawyers early. This results in fastest due diligence time drops from weeks to days, legal cost falls 40-60 percent. But if fintech/big tech, AI shines and risks: firms hoard payment data, lock in exclusives, and rule app ecosystems.
AI must look at things like monopoly risks, data misuse and platform lock-ins. India has strong laws and regulations, but they were made before AI entered law firms. Existing laws such as securities and exchange board of india disclosures, competition commission of india, antitrust and DPDP act, which looks after privacy. “Gaps? uploading confidential data into AI, bias from big tech favoured training data, and the main question pops up is who is responsible if AI is wrong? Blackbox AI is inherently biased because it holds past data, it learns from past deals, favored big tech mergers and ignored anti-competitive effects. AI may repeat those mistakes, and normalizes monopolies, this directly conflicts with competition law goals.
THE AI REVOLUTION IN M&A DUE DILIGENCE
AI is like a metal detector, and lawyers are the archaeologists who are deciding what digs deeper. Lawyers manually read thousands of files which are very slow, expensive and error prone. Whereas AI tools read everything first, highlight risks, and tell lawyers where to look. How does KIRA work? It is also called a super reader, it uses NLP to read 10,000+ contracts in hours. auto-flags : unclear IP ownership, non-competes, illegal data-sharing. For example, if PhonePe buys payments startups-KIRA scans vendors, spots competition blocks, warns pre-CCI filing. No last-minute shocks. SPELLBOOK the risk predicts, “Failed like this before? Did regulators block similar mergers? flipkart -style buy : compares past CCI blocks, flags vertical risks, warns on section 4 dominance abuse. It outputs 87 percent chance of SEBI disclosure issues. High DPDP data leak exposure.
AI matters in fintech & big tech deals because data=power, fintech and tech companies hold, customer payment data, employee PII and platform access controls, AI help spot, monopoly creation, data misuses and platform lockins. Without AI, penalties hit post-deal.
Major Indian conglomerates used AI driven diligence in 2025. Reviewed time dropped from 45 days to 5 days. Also the legal costs reduced 40-60 percent, Law firms now use hybrid models,
AI screens and senior lawyers decide. Big firms adopt it; startups gain access, elite diligence; AI democratizes. But here’s the danger, AI needs huge amounts of sensitive data: like records of employees, customer databases and financial ledgers, India’s data and corporate laws do not say, whether uploading data into AI tools is lawful, who is liable if AI leaks or misguides, how to audit biased AI trained on old pro corporate deals. For example AI was trained on pre reform deals favoring big conglomerates, it may normalize monopolies, undermining CCI’s goals.
INDIA’S M&A BOOM MEETS REGULATORY BLACK HOLES.
“Indian merger law assumes a human mind reviewed every document; modern deals assume an algorithm already has.” India’s current rules and regulations are working only for humans and not AI. Competition Commission of India (CCI) has 90 days to approve or block mergers, section 4, stop abuse of dominance, it works well in human-led cases. When AI declares “low risks” however, CCI doesn’t prove that why, whether bias lurks, what training data shaped it, or if explanations are mandated, because no such rule exists.
The Securities and exchange board of India (SEBI) demands fast disclosures for listed company deals (LODR),assumes humans assess “material risks” SEBI has no standard to test if that AI conclusion is reliable or dangerously shallow.
Under the DPDP act, 2023, mostly the companies act as “data fiduciaries”, they must not share data carelessly. AI diligence means uploading employee PII, customer KYC, and transaction logs to foreign tools, leaving lawyers guessing if feeding 1 million Indian records to a US AI server breaks the law, with wrong bets triggering nasty notices.
For companies act, 2013 mergers, NCLT demands section 247 fair valuations, backed by renowned human opinions, not vague “AI flagged this as risky” outputs, since courts reject mystery math outright.
Let’s look at how AI breaks each rule. In 2026 digital payments merger involving paytm wallet, AI review tools scanned massive KYC and transaction data. What went wrong is that AI missed clauses allowing broad internal PII sharing, DPDP authority issued notice, deal closing delayed 60 days. Why? Because DPDP law never imagined AI vendors touching live customer data. Under Indian law, lawyers are held liable for bad advice, professionals carry the risk, there’s no rule on AI vendor liability, indemnity limits. In ultra tech’s cement merger, KIRA flagged competition risks, but when NCLT demanded “explanation why this clause endangers,” AI couldn’t deliver, forcing manual redo that monitored the speed edge.
Singapore was fined by an AI diligence firm for biased outputs, American Bar Association warned lawyers that the AI errors may void indemnity, EU has banned high risk black box AI outright. India’s MeitY sandbox remains experimental, voluntary, and laughably small for M&A scale.Why this scares foreign investors is because foreign investors don’t fear regulation, they fear uncertainty. Right now in India; AI use is unavoidable, legal responsibility is also undefined, courts distrust black boxes and regulators have not caught up. That means even perfect execution risks post-deal explosions that freeze FDI flows.
RISKS UNLEADED: Bias, Leaks & Lawyers Nightmare.
AI makes M&A faster, but it also creates invisible risks that can quietly destroy deals, reputations, and law firms. These risks don’t show up immediately. They explode later when it’s too late. AI learns from past merger decisions, back when big tech always won, AI learned those bad habits too. In India, many large mergers before 2022, especially involving groups like Tata or Reliance were approved. So AI starts thinking, big mergers are usually fine. AI shrugs at section 4 red flags. In 2025 food tech deal involving swiggy and cloud kitchens, AI flagged “low competition risk” later, competition commission of india found ecosystem lockins, results, 3000 crore penalty. Humans eventually caught it but only after massive rework and triple the cost. AI didn’t lie but it learned the wrong lessons from the past.
AI tools don’t just read contracts. These tools gobble up KYC, employee files, bank logs. The DPDP basically says “you touch data, you own the headaches.” but most AI diligence tools are foreign hosted, uploading data may mean cross border transfer, in 2026 fintech acquisition involving PhonePe, about 5 million KYC records were uploaded into KIRA systems. Vendor glitched out, MeitY came knocking about cross-border leaks. Fine wasn’t composed of them but reputation damages, delayed follow on FDI,18 boardroom panic. Lawyers whispering “did we just screw ourselves by hitting upload?” no law helps.
India is clear about one thing, if advice is wrong, lawyers are liable, everyone blames the lawyers, but AI complicates this. Courts do not consider or recognise AI as the legal advisor. In a 2026 construction materials merger involving ultra tech cement: AI tool spellbook gave a high confidence clearance, it missed supplier cartel risks, deal faced litigation, law firm was sued for rupees 150 crore in rework costs. Here the AI walked away but not the lawyers.
“Fintech? Data is your goldmine. Miss one clause, you’re toast. Leak? You’re radioactive.” That’s the reason why most AI related diligence disputes in 2026 were in payments, lending and digital platforms. According to bar council discussions, 17 AI diligence disputes surfaced in one year alone. The real danger is bias lets monopolies slip through, data leaks scare investors and liability sticks only to humans. AI speeds deals, but the law firms actually absorb all the risks. AI never created these problems but using AI without rules and proper regulations did. If India adds mandatory AI audits, clear data-upload rules and shared liability standards, AI becomes an advantage, not a liability. If not? Faster deals today. Bigger disasters tomorrow.
BRIDGING THE GAPS: Practical Fixes for AI Chaos.
AI is already changing how Indian mergers happen and how they are reviewed. The remedy isn’t to ban AI but its forcing it to explain itself, limiting how it uses data, and sharing responsibilities when it fails. The changes shall be for large mergers (rupees 2,000 crores+), companies shall be made mandatory to submit an AI explainability report to the competition commission of India before the filing of the mergers. The report must present where the AI learned from old cases? Which year? Whether it was tested for its biases? How it calculated dominance risk under section 4. It matters a lot because if AI says; “low competition risk” CCI can ask: “show us how you reached this conclusion.” If the AI fails to explain itself, the merger shall stop at that moment, no more blind trust in algorithms.
SEBI’s AI diligence code shall be no more black boxes, this creates changes for listed-company deals, AI cannot stand alone, a senior lawyer must sign off separately. Both shall be filed together under SEBI’s disclosure rules. The practical impact of this would be if AI tools says its “87 percent safe” the company needs to explain, what risks were checked? What risks were overridden by humans? Why investors should trust the conclusion. Thai gives SEBI/Shareholders real, not a marketing fluff.
DPDP shall create safe rules for uploading sensitive data; it shall create a “certificate legal AI” list, for Indian servers or the DPDP compliant cross border transfers. Every upload spits encryption proof, access logs and vendor responsibility clauses. If a firm uploads data carelessly? Personal liability for data fiduciaries. This will finally give superior protection to India’s data protection law.
The liability must be shared, one cant put all the blame on the lawyers, it’s today’s harsh reality, the lawyers have to go through all these blames, if AI gets wrong, client sues the lawyers, AI vendors walk freely which is wrong. The contract law shall be amended so that AI vendors carry 30 percent liability if tools are non explainable. Lawyers get a “reasonable reliance” defence if they verified outputs. Clients can’t just dump all blame on humans. This does not mean protecting bad lawyers but it rather protects responsible AI use.
Sandbox 2027, MeitY runs 10 firms, 20 live deals, full regulator watch. AI tools shall be tested in live transactions, not in classrooms, this matters because regulators learn how AI behaves, law firms learn what courts expect and best practices emerge quickly, SINGAPORE/UK cut disputes 45 percent india tailors better for our market. If these changes are done, lawyers close deals faster without fear, regulators trust AI backed filings, investors see predictability, not chaos and India becomes an AI safe M&A destination. AI doesn’t need to be stopped, it needs to be supervised.
CONCLUSION
India never tried to choose AI in M&A. AI arrived because deals became too big, too fast, and too data heavy for humans alone. Now Indians must learn how to live with it, this choice defines the future of Indian mergers. For India two paths stand out, PATH ONE: If India does nothing, AI keeps operating as black box, data leaks trigger DPDP probes and investor panic, lawyers carry all liability, even when AI fails, regulators distrust AI backed filings and deals close fast today, but unravel later. Speed without certainty/transparency is not growth, its delayed damage. PATH TWO: If India acts decisively, the competition commission of India requires AI explainability before clearing big mergers. Securities and exchange board of India enforces human + AI dual sign off, DPDP rules restrict sensitive data uploads to certified systems.
Liability is shared fairly between lawyers and AI vendors. And a real legal AI sandbox texts tools before they scale, AI doesn’t disappear, it becomes accountable, reviewable, and court ready. That’s mastery and not fear. This matters the most because other countries such as Singapore, EU and UK are not waiting, they are owning it. India already leads the world in UPI scale digital infrastructure. There is no reason it should trail in legal tech governance. If India delays, rules will be imported later, on worse terms. This isn’t a someday committees, MeitY, bar council, law universities and market regulators shall come together and work on this, they are the architects now. Don’t study AI chaos forever. End it. AI is shaping M&A. The question is, whether it will react late, or lead early?
About the Author
Jyoti Kumari is a final-year B.B.A. LL.B. student at NIMS University, Rajasthan, Jaipur. Her research examines the regulatory implications of AI in M&A due diligence and data protection, analyzing how the DPDP Act and CCI regulations must evolve to mitigate algorithmic risks in high-value transactions. With experience interning at IFSO Special Cell, Delhi, and securing 2nd place as team speaker in national competitions, she actively pursues academic publishing in corporate and cyber law.
Linkedin profile : http://linkedin.com/in/jyoti-kumarii-318880371
Editorial Disclaimer: The views, opinions, interpretations, and conclusions expressed in this article are solely those of the author. While the article has undergone editorial review for publication, Ubiquity Legal does not independently verify or endorse all factual assertions, statistics, references, or opinions contained herein. Responsibility for the accuracy, originality, and sources of the content rests exclusively with the author. This article is published for academic and informational purposes only and does not constitute legal advice.
