Appendix E: Buying a Company — The Acquiring CTO’s Guide
Appendix D prepares the CTO to be evaluated. This appendix is its mirror image: the CTO as buyer. Chapter 16 describes acquisition from inside the company being bought, and a CTO who has lived that, or imagined it honestly, is well placed to run the other side.
John Chambers, who made Cisco the defining serial acquirer of the 1990s, stated the stakes in 1997: "In our industry, you are acquiring people. And if you don’t keep those people, you have made a terrible, terrible investment."[1] Across about 4,000 US high-tech startup acquisitions, 33% of acquired employees left within a year, against 12% of comparable regular hires.[2] Most of what follows is about beating that number, and about what AI has changed since 2023.
|
AUTHOR: Your buy-side experience, if any, and how being evaluated yourself changes how you would evaluate a target. |
What the Evidence Actually Says
The most quoted statistic in M&A is that 70–90% of acquisitions fail. Its best-known source, a 2011 Harvard Business Review article by Clayton Christensen and colleagues, attributes the range to "study after study" without citing one or defining failure.[3]
The risks that survive scrutiny are narrower. People leave, as Kim’s numbers show. Revenue projections are the assumption most likely to be wrong: in a McKinsey study, almost 70% of mergers missed their revenue-synergy targets, while about 60% delivered their cost synergies almost in full.[4] And integrating too early costs innovation: in small technology acquisitions, structural integration reduced the target’s chance of launching new products, most sharply for teams that had not yet shipped.[5]
What AI Changed
Most of this appendix would have read the same in 2015. Six things have changed since 2023, and each alters a decision in the sections that follow.
Deal structure. An acqui-hire used to buy the company. The largest AI deals now hire the founders and license the technology, leaving the company behind: Microsoft and Inflection, Google and Character.AI, Google and Windsurf. Regulators treat them as mergers anyway. The UK’s competition authority ruled that "acquiring a team with relevant know-how – even without further assets – may fall within the CMA’s merger control jurisdiction".[6]
Price. Elad Gil’s 2018 benchmark for a team buy was $1–3 million per engineer.[7] In 2025 Sam Altman said Meta was offering some OpenAI researchers "$100 million signing bonuses".[8] Mark Zuckerberg says recruits once asked about scope; now they want "the fewest number of people reporting to me and the most GPUs".[9] A startup competes instead on remit and a stated compute budget.
Supplier neutrality. Cloud and payment providers sold to anyone, whoever owned the customer. Model vendors now decide supply by who owns, or might own, the target. When OpenAI was reported to be buying Windsurf in 2025, Anthropic limited Windsurf’s direct access to Claude; co-founder Jared Kaplan said "it would be odd for us to be selling Claude to OpenAI".[10] After SpaceX bought Cursor in August 2026, OpenAI used a "limited time window" in its contract to end supply.[11]
Code ownership. Employment contracts and an open-source scan used to settle who owned the code. The US Copyright Office now holds that "prompts alone do not provide sufficient human control to make users of an AI system the authors of the output",[12] so parts of a heavily AI-written codebase may not be protectable at all.
The cost of building. Buyers used to pay to avoid a year or two of development. PwC’s deals practice now writes: "Code is now easy to write. What is hard to replicate is the years of accumulated domain expertise, regulatory understanding, and customer relationships that make enterprise software sticky."[13]
Tools. In 2023 Samsung banned generative AI tools after an internal leak. By 2025 Shopify expected every employee to use them.[14] An acquired team now joins an AI operating model, not just a codebase.
Build, Borrow or Buy
Gil sorts acquisitions into team buys, product buys and strategic buys.[15] A team buy is a hiring decision, a product buy a technical one and a strategic buy a market one, and each needs different diligence.
Two tests come first. If you need only the technology, license it. Jeff Seibert, who sold Crashlytics to Twitter and then evaluated more than fifty startups from inside it, said of his own deal: "They didn’t just want the technology — they could have remained a paying customer for that."[16] If you need only people, hire them. Will Larson’s bar is that an acquired team must "be easier to hire or more productive once hired than investing equivalent resources into traditional hiring. Many, likely most, acquihires don’t meet that threshold."[17]
When buying still wins, make engineering produce two numbers: the cost to build the capability to parity and the cost to integrate the acquired one. At GitLab the difference "is a key input into the deal models".[18] Since 2023 the build estimate for code alone has fallen. The estimates for domain knowledge, data rights and customers have not, and those are now the better reasons to buy.
The CTO’s Seat at the Table
McKinsey found that 50–60% of initiatives to capture merger synergies are strongly related to IT, yet technology leaders "often aren’t included in the due-diligence process".[19] In a startup the omission is worse, because the CTO inherits whatever was bought.
Charity Majors, co-founder of Honeycomb, was at Parse when Facebook bought it, and no engineering leader at Facebook owned the deal: "All the VPs were shocked. They’re like, 'What? We’re acquiring who?' And as a result, we got bounced around. We were under three different VPs in the first year we were there. Nobody’s success was invested in our success."[20] The CTO either owns the acquired team’s success or argues against the deal. GitLab builds this into its process: the CTO approves the business case and term sheet, and approves again any later change to the terms.[18]
One caution: do not negotiate the price with people who will report to you; Gil warns of "bad feelings between a deal person and at least some of the entrepreneurs who get acquired".[21]
The Integration Thesis
Christensen’s team argues that "to foresee how integration will play out, we must be able to describe exactly what we are buying".[3] People, technology and customers can be lifted into the buyer’s business. A business model cannot, because its "profit formulas and processes don’t exist apart from the organization". Anouar Adlani, who has run diligence as an acquiring CTO, puts it operationally: "Before you open a single repo, you need to understand the acquisition thesis."[22]
The thesis then picks one of four integration models for each system, before signing.
Keep it standalone. The buyer adds capital and distribution and changes nothing technical. Constellation Software, which has bought hundreds of small software firms, does this by policy, arguing that "customers and BU Managers, not head office CTO’s or product strategists, should choose which products get continued investment".[23]
Integrate at the edges. Identity, single sign-on, administration and billing join the buyer’s, and the product code stays as it is.
Migrate the infrastructure. The product keeps its autonomy while its runtime moves onto the buyer’s platform (see Platform Migrations).
Rebuild and sunset. The team re-implements the product on the buyer’s stack and the original closes. GitLab’s target profile asks for teams "willing to reimplement products into GitLab in Ruby and Go" and "willing to sunset old customers within 90 days or less".[24]
Buy-Side Technical Due Diligence
Start with Appendix D’s checklist turned around. Three areas need more weight on the buy side, and one is new.
People. Diligence practitioner Kris Drouet reads commit history before the first meeting, then asks who could ship a change to a named service tomorrow if its lead were unreachable. On one deal, "Thirty-one of its last thirty-four commits carried one engineer’s name."[25] Interview the whole team. Seibert says this is where most deals fall through, when buyers "discover that there are more weak employees than strong ones."[16]
Ownership. eBay bought Skype in 2005 without owning its core peer-to-peer technology, which was licensed from a company Skype’s founders controlled. By 2009 eBay was warning investors that losing the licence meant Skype’s business "would likely not be possible".[26] Prove the chain of title for everything the thesis depends on: code, licences, data and models.
Security. Assume the target is compromised until shown otherwise. An attacker was inside Starwood’s reservation system from 2014, two years before Marriott bought the company. The UK regulator fined Marriott £18.4 million and rejected the defence that the system was due to be retired: "The fact that an IT system is due to be retired shortly does not disapply the GDPR to the data being processed through that system."[27]
AI dependencies and provenance. This is the new area. Read every model-supply contract for change-of-control and termination rights; Cursor’s chief executive had "trusted their platform to be neutral infrastructure for our business".[11] Given the Copyright Office’s position, ask which tools wrote the code and how human review was recorded. Ask counsel for a covenant that stops the target "onboarding new AI tools" between signing and close.[28]
Turn every finding into a cost. Adlani’s rule: "Not a vague 'medium risk' label, but an actual number: this will take three engineers six months to fix."[22] Most findings should change the price or the terms, not end the deal. Walk away if the target refuses code access, if the team interviews go badly, or if you face, in Drouet’s words, "a leader whose account of the system does not match the evidence".[25]
|
AUTHOR: The healthcare buyer’s questions: whether Business Associate Agreements transfer, what protected health information the target holds, and which state health-data laws apply. |
Deal Terms and the Rules Before Close
Gil’s benchmark is paid per "engineer, designer, and product manager who ends up getting an offer to join", and for product buys he advises giving acquired staff "at least a 20–50% bump in their compensation packages over what they could have gotten if they walked in off the street".[7] The headline price also splits: a $10 million offer "may mean $6 million to the cap table and $3 million in retention".[21] Turn key-person findings into protections, such as retention conditions on named engineers, escrow and specific indemnities.[25] But don’t build traps. Larson wants people never to "feel trapped to remain in circumstances that make them unhappy".[17]
Until close, the companies remain competitors. Staff at the US Federal Trade Commission put it plainly: "Right up until consummation, the merger parties are still independent businesses."[29] Plan the integration without starting it: no shared credentials, no merged systems, no direction of the target’s roadmap. Technical claims also become evidence. The European Commission fined Facebook €110 million because Facebook had said in 2014 that it could not reliably match Facebook and WhatsApp accounts, which it later did.[30]
The First Hundred Days
GitLab makes one engineering leader responsible for "the implementation of the technical integration milestones and retention of the acquired team members".[31] Pairing those two jobs matters because, as Larson observes, "the deal team who pushed to finalize the acquisition quickly disengage to move on to finding their next deal."[17]
Day 1. Speak with one voice. Put in writing what is not changing: titles, managers, product, location. Bring the acquired systems under your logging, monitoring and incident response at once, however soon you plan to retire them. Decide which AI tools the acquired team may use, and with which repositories.
Days 1–30: stabilise. Mandate little. Robert Williams, drawing on his years at Amazon, would "mandate critical functions like legal and finance - and perhaps security" and otherwise "let the acquired team pull rather than pushing services on them".[32] Keep the team’s structure and rituals for now. An engineering manager who led a team through an acquisition found that doing so "greatly helped preserve the team dynamic".[33]
Days 31–60: connect. Start with "a project that was only lightly coupled with the existing codebase".[33] Begin code review and pairing in both directions, and ship a first joint milestone by about day 60, as GitLab requires.[18]
Days 61–100: measure. GitLab surveys acquired staff at about three months and again at nine.[31] The benchmark is Kim’s: two-thirds of acquired employees remain after a year. Beat it, and track founders and top earners separately.
Keeping the People You Bought
The retention gap narrows when founders stay, when employees have longer tenure and when the target is kept structurally separate.[34] Relocating the team pushes more people to leave and found companies of their own, especially founders and top earners.[35] So give the acquired CTO a remit larger than the company they sold, keep co-founders together, leave the team in its own office, and settle each person’s level before offers go out.
Money does not fix culture. When Cognition bought the rest of Windsurf in July 2025, it promised that "100% of Windsurf employees will have vesting cliffs waived for their work to date". Three weeks later it offered about 200 of them nine months' pay to leave, and chief executive Scott Wu wrote: "We don’t believe in work-life balance."[36] Record AI-era packages have not held founders either: four of the five Adept co-founders who joined Amazon in 2024 had left by February 2026.[37] State the working culture before close, and give people work worth staying for.
The Customers You Inherited
Decide the product’s fate before close, because customers judge the buyer by the shutdown. Parse set the standard in 2016 with a year’s notice, a database migration tool and an open-source version of its server.[38] Keybase showed the alternative: its line that "Keybase’s future is in Zoom’s hands" sent users looking for replacements the same day.[39] If the roadmap is undecided, give a date by which it will be, and say what is guaranteed until then.
Platform Migrations and the Rewrite in Disguise
Instagram kept its product autonomy while moving into Facebook’s data centres, a year-long project; co-founder Mike Krieger said: "We had to completely replace the car twice in the last year."[40] TSB shows what happens when the deal model sets the date. Its new owner, Sabadell, fixed a migration timetable "without detailed knowledge of TSB’s requirements", and the 2018 cut-over left online banking "unstable and almost unusable".[41] Microsoft’s move of Wunderlist from AWS to Azure became a full rewrite, and the app was retired in 2020.[42]
AI has cut the cost of that rewrite. After Anthropic bought Bun, its creator moved 535,496 lines of Zig to Rust in 11 days with Claude Code, work he estimated would otherwise take "a small team of engineers a full year".[43] The precondition was a test suite "written in TypeScript which means it doesn’t depend on the runtime’s programming language". Google’s engineers estimated that AI cut the time spent on their internal code migrations by about half.[44] Ask in diligence whether the target’s tests would survive a change of language; the rewrite is cheap only where they would.
|
AUTHOR: Your own use of AI tools to understand an unfamiliar codebase. No published first-person account for an acquired codebase was found. |
This appendix is the buyer’s companion to Appendix D and Chapter 16. Chapter 10 provides the business case the CEO and board will expect, and Chapter 5 the language for pricing the debt you are buying. Research on acquirers finds that the second deal is the dangerous one, because buyers over-apply what they learned from the first.[45] Write your playbook down after the first._