Guide

AI for private equity portfolio companies: a 100-day plan

AI creates value in a private equity portfolio company when it is aimed at a line in the value creation plan: revenue, gross margin, operating cost or working capital. A 100-day plan screens the company's work against those lines, builds two or three uses in the company's own systems, measures them against a baseline the finance team owns, and puts in light governance that every company in the fund shares. By day 100 the operating partner should have measured results, a decision on each use, and a write-up the next portfolio company can reuse. Usage figures and pilot counts are not value creation.

AI value creation plan. A plan that ties each use of AI in a portfolio company to a line in its value creation plan, with a baseline the finance team owns, a measured result and a decision on whether to repeat it across the fund.

Checked . The government and regulator sources this page cites were read on each publisher's own site on this date. Rules and guidance change, and this page is not legal advice.

Where AI pays back in a portfolio company

Start with how little is usually running. In the US Census Bureau's business survey (14 December 2025 to 3 May 2026), 37% of firms with at least 250 employees reported using AI in their business operations, and in the period ending 3 May 2026, 32% of firms with 100 to 249 employees did. Among firms that do use it, a Census working paper found that 57% use it in three or fewer business functions. So a new portfolio company is usually close to the start, which is useful: the first uses can be picked for value instead of inherited from whoever got excited first.

I screen uses against the value creation plan, not against a list of what AI can do. If a use does not move a line the board already tracks, it is a nice-to-have, and nice-to-haves are how a portfolio ends up with a drawer full of pilots and no change in EBITDA. The table is the screen I would run in the first three weeks.

Where AI tends to pay back in a portfolio company, by value creation lever, with the number that should move and the check to run before funding it
DimensionWhere AI tends to helpThe number that should moveCheck before you fund it
RevenueSales and marketing work: account research, proposal and quote drafting, follow-up on stalled deals, pricing analysis.Win rate, sales cycle length or revenue per salesperson, against the same measure last period.Whether the CRM data is good enough to act on. If the sales team does not log activity, a model has nothing to read.
Gross marginCost to serve: customer support, case handling, scheduling, quality checks.Cost per case, or cases handled per person, at the same or a better quality score.A quality measure agreed before launch, so a cheaper answer that is wrong does not count as a saving.
Operating costFinance and back office: invoice matching, month-end close preparation, contract review, reporting packs.Hours per close, cost per invoice, or days to produce the board pack.Who approves what the system produces. Finance output needs a named reviewer, not a spot check.
Working capitalBilling and collections: chasing overdue invoices, resolving disputes, cash forecasting.Days sales outstanding, and the share of invoices paid on first request.Whether messages to customers need legal or brand review before the first one goes out.
Engineering capacitySoftware companies: coding tools for the engineering team, test writing, moving old code to new platforms.Cycle time from ticket to release, and the change failure rate, so speed does not arrive with more outages.Licence and usage cost per engineer, and whether the codebase has tests a coding agent can run.

Two uses often look good on a slide and disappoint in the P&L. One is a general assistant switched on for everyone with no training, no workflows and no measure attached. The other is a customer-facing chatbot put in front of a support process nobody has fixed. Both can be worth doing later, done properly. Neither belongs in the first 100 days.

Why AI programmes stall across a portfolio

The usual failure has little to do with the technology. A pilot gets chosen because someone senior saw a demonstration, it runs on sample data in a vendor's account, it reports usage instead of money, and nobody in the company owns it once the outside help leaves. Six months later it is still a pilot. Repeat that across a portfolio and the fund has paid for the same lesson several times.

Chosen by enthusiasm
The use came from a demonstration rather than the value creation plan, so nobody can say which line it should move.
No baseline
Nobody measured the work before the change, so the result is an opinion.
No owner in the business
The people who run the process were not asked, and they do not use the output.
Measured on usage
Log-ins and prompts per week show that people tried it. They say nothing about margin.
Every company starts from scratch
Each portfolio company picks its own tools, negotiates its own terms and writes its own policy, so the fund learns nothing it can reuse.

A 100-day AI plan for a portfolio company

Treat the phases as a shape to hold the work to. Access to systems and data sets the real pace far more often than engineering does, so the access requests go out in the first week. The plan assumes a company that has closed and has a value creation plan. For a company still in diligence, the questions further down this page come first.

A 100-day AI plan for a private equity portfolio company: what each phase produces, what the operating partner should see, and the warning sign
DimensionWhat the phase producesWhat the operating partner should seeWarning sign
Days 1 to 20: screen and baselineA ranked list of uses tied to value creation levers, access requests sent, and a baseline for the top two or three.The screen, with the lever, the measure and the owner for each use, signed off by the company's CEO and CFO.A long list with no measures, or a baseline the finance team has not seen.
Days 21 to 50: first working usesTwo or three uses running in the company's own systems on real data, even if they are rough.A live run on cases the company chose, with the code and configuration in the company's own accounts.A demonstration on a vendor's sample data, or a scope that has grown before anything works.
Days 51 to 80: measure and governResults against the baseline, the first controls on access, approval and logging, and a short AI policy the board has adopted.The numbers, failures included, with the cost of running each use taken off the benefit.Usage statistics offered in place of the measure agreed at the start.
Days 81 to 100: decide and packageA decision on each use: scale it, change it or stop it. What worked is written up so another portfolio company can reuse it.A written recommendation with the evidence attached, and a plan and budget for the next two quarters.A request for more time with no new evidence.

Days 1 to 20: pick uses the board already tracks

Run the screen with the CEO, the CFO and the people who do the work. Sign-off runs in that order and usefulness runs the other way: the people doing the work know where the hours go, and the CFO knows which of those hours show up in the numbers.

Then measure the work as it runs today, on whatever the chosen measure is: time per case, cost per case, error rate or days sales outstanding. Take the baseline from the company's own systems where you can, and have finance agree it in writing. Everything you claim at day 100, and possibly at exit, gets compared with this number.

Send the access requests in the first week. Accounts, data extracts and security reviews take longer than the build, and a plan that asks for them in week four has already lost a month.

Days 21 to 80: build in the company's own systems, then measure

Build each use against real data in the company's own environment, and keep the code, prompts and test cases in the company's own repositories and cloud accounts. That matters more in a portfolio than anywhere else, because the company will be sold, and whatever it depends on has to go with it.

Build the controls with the first working version rather than after it: who can use it, what it can read and change, which actions need a person's approval, and a log of what it did. Our write-up of the pattern where the model proposes and a deterministic check decides shows one way to build the approval step.

Then measure against the baseline, on the measure agreed at the start, and take the cost of running each use off its benefit: licences, usage charges and the hours people spend reviewing its output. A use that saves time but costs more than the time it saves is a hobby.

Measuring AI value creation so it survives diligence

Somebody will test your AI numbers: the investment committee, a lender or, at exit, the buyer's diligence team. Build the measurement to pass that test from the first week, because rebuilding a baseline after the fact is close to impossible.

A baseline finance owns
Measured before the change, from the company's own systems, and agreed by the CFO in writing.
One measure per use
Chosen at the start, tied to a value creation lever, and not swapped later for one that looks better.
Adjusted for volume
Compare cost per case or time per case rather than totals, so a quiet quarter does not pass for an AI saving.
Net of running cost
Licences, usage charges, support and the reviewers' time come off the benefit.
Recurring or one-off
Clearing a backlog once is not a recurring saving. Label every benefit as one or the other.
Hours turned into money honestly
Time saved is only a saving if the hours go to other work or a role is not refilled. Say which, for each use.

Be as careful with the story as with the numbers. In March 2024 the SEC announced settled charges against two investment advisers for false and misleading statements about their purported use of AI. In September 2024 the FTC announced Operation AI Comply, five law enforcement actions against deceptive AI claims, and said there is no AI exemption from the laws on the books. An AI claim in a portfolio company's marketing, a fund's investor materials or an exit document needs the same evidence as any other claim. This is not legal advice: have counsel review the claims before they go out.

AI due diligence: what to check before you sign

AI due diligence has two sides for a deal team. One is using AI in the diligence itself, to read a data room faster. That is a tooling decision, and the usual rule holds: a person checks what the model summarised before anyone relies on it. The other side is what AI means for the target, and that is the one that moves value. These are the questions I would add to the diligence list.

What the target claims
Which products or processes it says use AI, and whether they do. Ask to see them running on real work.
Where its data goes
Which AI vendors process customer or employee data, on what terms, and whether its customer contracts allow it.
Dependence on one vendor
Which products stop working, or stop making money, if one AI vendor changes its price, its terms or its model.
Decisions about people
Whether AI plays a part in decisions about hiring, pay, lending, housing, education or healthcare, which state rules such as California's are starting to cover.
Spend and ownership
What it spends on AI each month, who holds the accounts, and whether code a supplier built for it belongs to the company.
Revenue at risk
Which parts of its revenue come from work that AI tools are starting to do more cheaply, and what management plans to do about it.

Governance sized for a portfolio company

A portfolio company of a few hundred people does not need an AI ethics board. It needs a short policy its board adopts, a register of every AI use, a few risk tiers and controls on the risky uses. The fund's job is to write those once and let each company adopt them, instead of paying for the same document in every company.

For US companies, the NIST AI Risk Management Framework makes a sensible common spine. NIST describes it as intended for voluntary use. It has four functions, Govern, Map, Measure and Manage, with Govern running across the other three, and NIST says version 1.0 is being revised as part of the White House AI Action Plan. A shared policy mapped to those four functions gives every company the same structure without pretending they are the same business.

What a private equity firm should set once for the portfolio, and what each portfolio company should own
DimensionSet once by the fundOwned by each company
PolicyA short template policy and the risk tiers.Adoption by its own board, plus anything its sector needs.
Register of AI usesThe format, and a quarterly roll-up to the fund.The register itself, kept current by a named owner.
Vendors and termsA list of reviewed vendors and the contract terms to insist on.Its own accounts and contracts, so they transfer with the company at exit.
ControlsThe minimum controls for each risk tier.Building them into its own systems, and keeping the evidence they produce.
MeasurementThe measurement template and the definition of each measure.The baselines and results, owned by its finance team.
ReuseA library of what worked, written up by use and by lever.Deciding whether a proven use fits its own business.

State rules apply company by company, and they are moving. In California, rules on automated decisionmaking technology (ADMT) were approved on 22 September 2025. A business subject to them that uses ADMT to make a significant decision about a consumer must comply with the ADMT requirements by 1 January 2027. The regulation defines a significant decision as “a decision that results in the provision or denial of financial or lending services, housing, education enrollment or opportunities, employment or independent contracting opportunities or compensation, or healthcare services.” The same rules made risk assessments a requirement from 1 January 2026. Ask counsel which state laws reach each company. This is not legal advice.

Where 1AYM fits

1AYM has worked with private equity, and the plan above is the shape I would bring to an operating partner. For one portfolio company, the first paid piece is usually our AI Opportunity & Feasibility Sprint: a fixed scope of two to four weeks that produces the scored opportunity map, a current-state analysis of the work and an investment case, which covers the screen in days 1 to 20 of the plan. A fixed-scope build can start within a day of the scope being signed. For a programme across several companies, a retained implementation team owns the shared architecture and builds alongside each company's own people.

Rolling out AI work tools and coding tools across a company, with the training, controls and measurement that make them pay, is core work for us, and our documented rollout across a global agency shows what that involves. If the fund already has a scoped job and needs it staffed, 1AYM can resource it on contract from the collective of associates who work with the firm, held to the same standard. US portfolio companies can contract with 1AYM's US entity. If you are planning the first 100 days for a new platform company, book a call below.

For engineers: a shared AI platform each portfolio company can take with it

What a technical lead at the fund or in a portfolio company should check. The rule behind all of it: each company will be sold on its own, so nothing it depends on can live only in a shared fund account.

Tenancy
One tenant per portfolio company for every AI vendor, cloud account and data store. A shared fund tenant makes a carve-out slow and mixes data between separate legal entities.
Identity
Each company's own identity provider grants access, with a service identity per AI component scoped to its workflow. Fund staff get guest access that can be removed in one step.
Shared code, separate deployments
Templates, the evaluation harness and the approval-gate library live in a fund repository as versioned packages. Each company deploys its own copy from its own repository, so an upgrade is a pull request rather than a migration.
Evaluation
A test set of real cases for each use, with thresholds committed next to the code. Any change to a prompt, model or rule that drops a score below its threshold fails the build.
Cost attribution
Tag every model call and licence by company and by use, so the measurement template can take running cost off each benefit without a spreadsheet exercise.
Logging
One structured record per action: input reference, model and prompt version, check results, approver and timestamp. Keep it in the company's own account and treat it as sensitive data.
Vendor abstraction
A thin interface between each workflow and the model provider, so a company can change vendor on price or terms without rewriting the workflow.
Exit pack
For each use: the repository, the runbook, the evaluation set, the vendor contracts and the register entry. A buyer's technical diligence will ask for these.

Sources

  1. [1]US Census Bureau, Large Firms With at Least 20 Employees Biggest AI Users (26 May 2026), read 29 September 2026
  2. [2]US Census Bureau, The Microstructure of AI Diffusion: Evidence from Firms, Business Functions, and Worker Tasks, working paper CES-WP-26-25 (April 2026), read 29 September 2026
  3. [3]NIST, AI Risk Management Framework (AI RMF 1.0 released 26 January 2023), read 29 September 2026
  4. [4]NIST AI Resource Center, AI RMF Core: Govern, Map, Measure and Manage, read 29 September 2026
  5. [5]SEC, press release 2024-36: SEC Charges Two Investment Advisers with Making False and Misleading Statements About Their Use of Artificial Intelligence (18 March 2024), read 29 September 2026
  6. [6]FTC, FTC Announces Crackdown on Deceptive AI Claims and Schemes (25 September 2024), read 29 September 2026
  7. [7]California Privacy Protection Agency, California Finalizes Regulations to Strengthen Consumers' Privacy (23 September 2025), read 29 September 2026
  8. [8]California Privacy Protection Agency, rulemaking page: CCPA Updates, Cybersecurity Audits, Risk Assessments, Automated Decisionmaking Technology (ADMT), and Insurance (records approval by the Office of Administrative Law on 22 September 2025), read 29 September 2026
  9. [9]California Privacy Protection Agency, approved text of the CCPA regulations on cybersecurity audits, risk assessments and ADMT (sections 7001 and 7200), read 29 September 2026

Frequently asked questions

How are private equity firms using AI?

In two places. Inside the fund, for sourcing, diligence and reporting, where AI speeds up reading and analysis. And inside portfolio companies, where it changes revenue, margin and cost. The second is where value creation happens, and it is what this guide covers. Many mid-sized US companies are still early: in the US Census Bureau's survey, 32% of firms with 100 to 249 employees said they used AI in their business operations, as of 3 May 2026.

What should the first 100 days of AI in a portfolio company deliver?

Two or three uses running in the company's own systems, measured against a baseline the finance team agreed, with basic controls in place and an AI policy the board has adopted. By day 100 each use should have a decision, to scale it, change it or stop it, and what worked should be written up for the next company.

How do you measure AI value creation?

Against a baseline taken before the change and agreed by the CFO, on one measure per use tied to a value creation lever, adjusted for volume, and net of the cost of running the AI. Keep recurring savings separate from one-off gains, and say whether the hours saved went to other work or a role was not refilled.

Does the fund need an AI operating partner?

It helps once several companies are running AI work at the same time, because someone has to own the shared policy, the vendor list and the measurement template, and carry what worked from one company to the next. Before that, a clear owner inside each company plus outside help for the first 100 days is usually enough. What does not work is nobody owning it.

What should AI due diligence cover?

Whether the target's AI claims are true, where its data goes and on what terms, how dependent it is on one AI vendor, whether it uses AI in decisions about people that state rules cover, what it spends and owns, and which of its revenue AI tools could undercut. Using AI to read the data room is a separate question: useful, provided a person checks what it summarised.

Do state AI laws apply to our portfolio companies?

They can, and it depends on each company's business and where its customers and staff are. In California, a business subject to the new rules that uses automated decisionmaking technology to make significant decisions, such as decisions about employment, lending or housing, must comply with them by 1 January 2027. This is not legal advice: ask counsel to map the laws that reach each company.

Further

  • AI strategy and roadmap · The fixed-scope sprint behind the screen in days 1 to 20: a scored opportunity map, a current-state analysis and an investment case.
  • AI implementation: the first 30 days · What each week of a single build should produce, and the warning signs to watch for.
  • AI governance framework · A short AI policy to copy, with each rule mapped to its control, owner and evidence.
  • AI readiness assessment · 13 questions on ownership, data, systems and controls, scored on the page, to run on each portfolio company.
  • AI platform enablement · The documented engagement: AI, data and automation enablement across a global agency.

We build these systems for a living. See the engagement files for what that looks like in practice, or write to us if yours is the next one.

Last reviewed · 1AYM