Health Policy
Digital Health M&A's New Challenge: How to See Through 'AI Washing' to Identify Real Value?
How to Identify AI Washing in Medical Technology M&A? Key Difficulties in Due Diligence of Digital Health AI Assets and Analysis of New FDA Regulations, Covering CDS Guidelines, NAMs, and Clinical Trial Innovation.
Introduction
When a digital health startup claims to be an “AI company,” is it describing its core technology, or adopting a fashionable valuation label? In M&A transactions, “AI washing” is becoming a phenomenon that buyers must guard against—some target companies package simple third-party API wrappers as proprietary foundation models in pursuit of disproportionately high premiums. But this fog is now being dispelled by both investors and regulators.
Industry Background
According to the latest report “Vital Signs: Digital Health Law Update” released by medical technology law firm Jones Day, cross-border and domestic transactions in the digital health sector remain active, but the complexity of evaluating AI assets and post-merger integration far exceeds that of traditional software. Defining an AI company’s true moat—from proprietary foundation models to data assets—has become the core of deal negotiations. Many target companies claim to possess AI technology, yet only have prompts and an API layer. From an industry perspective, this is not merely a valuation issue; it can also evolve into liability risks.
Key Developments
AI Due Diligence: Risk Quantification over Perfect Liquidation
Truly valuable AI assets are often built on clean, clearly sourced proprietary data, such as patient interaction logs, annotated clinical datasets, or health knowledge bases. However, buyers cannot conduct exhaustive audits of training data within a conventional transaction timeline. Legal professionals believe that merely obtaining access to HIPAA-protected records or EHR API usage rights through partnerships with healthcare systems does not mean acquiring the right to use that data for commercial model training. If the data sources are not lawful, the algorithm may face regulatory penalties or even forced destruction.
As a result, the industry is shifting from “problem elimination” to “risk quantification.” Buyers need to assess the magnitude of risk, the probability of occurrence, and potential liability, then allocate risk through customized representations, warranties, and indemnification provisions. Notably, discovering data issues does not mean the deal is dead—unlike rewriting an entire codebase, machine learning models can usually be remediated through retraining, fine-tuning, or isolating the problematic components. Both “isolation + retraining” before closing and “phased release of consideration” after closing are viable options.
Regulatory Developments: FDA and EMA Draw Clearer Boundaries for AI HealthcareIn early 2026, regulators noticeably accelerated the pace of rule updates. On January 6, the FDA issued the final guidance “General Wellness: Policy for Low Risk Devices,” clarifying the scope of regulatory exemptions for low-risk health products. On January 29, the updated “Clinical Decision Support Software” guidance further refined the “non-device” criteria for clinical decision support software and adjusted “time-critical decisions” from an automatic exemption to a risk consideration factor, providing greater flexibility for CDS tools aimed at clinicians.
On the transatlantic front, the EMA and FDA jointly released the “Good Practice Principles for AI in Drug Development” on January 14, offering a shared regulatory vision for the use of AI in drug development. On March 18, the FDA also issued a draft guidance on “new approach methodologies” (NAMs), encouraging human-relevant methods such as organ chips, organoids, and computational modeling to replace certain animal experiments—an important implementation step following the FDA Modernization Act 2.0.
In addition, a warning letter to a manufacturer of HIV home test kits has reignited debate over the future direction of laboratory-developed test (LDT) regulation. After that regulation was struck down by the courts in 2025, the FDA has been seeking enforcement entry points, including through hardware components. Meanwhile, on April 28, the FDA announced the launch of a proof-of-concept for real-world clinical trials (RTCT), exploring new models of clinical trials driven by AI and real-time data.
Market Impact
For buyers in digital health, these developments mean the dimensions of investment decisions must expand: not only does the clinical value of the algorithm need to be assessed, but also the legality of its data chain, the depth of model defensibility, and future compliance costs. The funding narrative for medical AI startups will also shift—simply showcasing algorithm performance will no longer be persuasive. Investors will ask, “Where did the training data come from?” and “How should proprietary models be valued?” Companies with clean proprietary data and explainability tools will more easily command a premium. Meanwhile, hospitals and health systems should be more cautious when signing joint development agreements, clearly specifying whether they authorize real-world data to be used for commercial AI training; otherwise, they may face legal recourse from partners in the future.
Challenges and Risks
One challenge that cannot be ignored is that the training data sources for large AI models are overly complex, potentially including copyrighted materials, personal information obtained without sufficient authorization, and data restricted by contracts. Even if the algorithm performs well, the “fruit of the poisonous tree” hazard can still lead to infringement claims and forced removal of future versions. In addition, there is a vacuum between outdated privacy policies and emerging regulatory frameworks. With AI principles for drug development already in place and industry-specific rules on the horizon, companies must track multiple jurisdictions at the same time.
Future OutlookOver the next 3–5 years, it is foreseeable that AI assets in digital health M&A will gradually develop a standard process similar to an “environmental review”—data supply chain review, model-defense assessment, and retraining-risk pricing, all entering transaction documents. Regulators have already achieved cross-agency coordination on AI applications in drug R&D, and the next step is highly likely to extend to medical devices and diagnostic tools. The FDA’s interest in real-time clinical trials may push clinical trials from “retrospective analysis” toward more dynamic adaptive designs, thereby accelerating the validation of digital therapeutics. On the capital side, companies that only package concepts will see their valuations corrected, while those that provide strong data moats and compliance resilience will truly benefit.
Conclusion
The next chapter of healthcare technology M&A will belong to players who turn “AI” from a slogan into an asset and use compliance as their moat. Regulators’ technological neutrality and buyers’ increasingly pragmatic risk pricing are jointly shaping a healthier digital health market.
Reader cross-check · medtechdaily
medtechdaily frames this note through Digital Health / AI Healthcare / Medical Devices - Source links should be opened before the summary is reused. dates, names and status changes still need checking; Digital Health / AI Healthcare / Medical Devices explains the local editorial angle.