Control over AI
Blog
Compliance and AI 8 min read

Approving an AI tool: what to ask the vendor

Six questions, with what a usable answer looks like and what an evasive one looks like. Built to be used in a call, not filed in a folder.

Assessing an AI vendor around a table
Quick answer

Six questions cover most of it. Where does processing run and which jurisdiction governs the vendor? What is retained, for how long, and can you configure it? Is your input used for training, and how does that differ by tier? Who inside the vendor can access your data and under what conditions? Who are the sub-processors and are you notified of changes? And what happens at termination? More telling than the answers is the pattern: a vendor answering concretely and verifiably is a different kind of counterparty from one pointing at a security page.

01

Six questions: location, retention, training, internal access, sub-processors, exit

02

Ask about the difference between tiers, not about the product

03

A good answer is verifiable in documentation or contract

04

A link to a trust page is not an answer

05

Record what was promised, because services change faster than assessments

An eighty-question security questionnaire often yields less than a twenty-minute conversation. Not because the questions are bad, but because they are completed by someone other than the person who knows, and because "yes" to "is data encrypted" carries almost no information.

These are six questions that do yield something, with what to listen for in each.

1. Where does processing run, and which jurisdiction governs you?

Two questions asked as one, and they need separate answers.

A vendor can run in Frankfurt and still be a US company. The data centre location then does not answer the question of which government can compel disclosure.

Usable answer: the processing region, the domicile of the contracting entity, and whether a parent company sits in a different jurisdiction. Evasion: "we host in the EU".

2. What do you retain, for how long, and can I configure it?

Ask separately about three things: conversation content, technical logs, and attachments. They frequently carry different periods.

Also ask what happens between deletion and permanent removal. At most services that gap is around thirty days.

Usable answer: a period per category, and whether it is configurable per tier. Evasion: "no longer than necessary".

3. Is my input used for training, and does that differ by tier?

The second half is the important half. At nearly every provider the answer differs between the free account, the business account and the API.

Push further: does the commitment cover only model training, or also human review and quality assurance? Those are different things, as set out in what "we don't train on your data" actually means.

Usable answer: per tier, with a pointer to where it sits contractually. Evasion: "we do not train on customer data".

4. Who inside your organisation can access my data, and why?

Almost every provider has a basis for reviewing conversations on suspicion of abuse. That is not suspicious, it is normal, and it belongs in your assessment rather than outside it.

Usable answer: under what circumstances, by which role, with what approval, and whether it is logged. Evasion: "access is strictly limited".

5. Who are your sub-processors, and am I notified of changes?

AI services frequently lean on other AI services. A tool that works on your PDFs may call a third party's model internally. That third party is then part of your chain.

Usable answer: a current list with role and location, plus a notification period and a right to object. Evasion: a list with no date on it.

Search tool, vendor or categoryโ€ฆ
700+ tools
ChatGPT๐Ÿ‡บ๐Ÿ‡ธ
HighAllowed
Claude๐Ÿ‡บ๐Ÿ‡ธ
MediumAllowed
DeepSeek๐Ÿ‡จ๐Ÿ‡ณnew
CriticalNot allowed
Perplexity๐Ÿ‡บ๐Ÿ‡ธnew
MediumNo decision yet
Mistral๐Ÿ‡ซ๐Ÿ‡ท
LowNo decision yet
Midjourney๐Ÿ‡บ๐Ÿ‡ธ
MediumNo decision yet

Every tool, scored for risk

700+ AI tools, each scored Low to Critical, with nothing pre-approved or pre-blocked until someone decides.

More about AI Tools

6. What happens when we leave?

The least-asked question, and the one that best predicts how a vendor thinks about its customers.

Usable answer: an export window, a deletion window, and confirmation on request. Evasion: "data is deleted in accordance with our policy".

What to do with the answers

Two things that separate an assessment from a filing.

Record what was promised, with a date. Not to catch anyone out, but because AI services change faster than assessment cycles. A commitment made in March is a checkable fact in November.

Decide what triggers a re-look. Not annually, but on an event: acquisition, changed terms, an incident, a new feature that widens scope, or relocated hosting. See also why an AI tool catalog ages instantly.

And keep one thing in view while reading the answers. All six questions are about the vendor. Together they say nothing about what your people put into the tool. A service can answer all six impeccably and still receive client files every day that should never have gone in. That is a second assessment, and it is not about a contract.

FAQ

Common questions

What should you ask an AI vendor?

Six things: where processing runs and which jurisdiction governs them, what is retained and for how long, whether input is used for training and how that differs by tier, who inside the vendor has access, who the sub-processors are, and what happens at termination.

Is a data processing agreement enough?

Necessary and not sufficient. A processing agreement records what is permitted. It says nothing about how the service is built, what retention actually applies, or whether your people are putting the right things into it.

What does an evasive answer look like?

A link to a general trust page, a list of certifications with no scope, or "your data is safe with us". Certifications describe a management system, not what happens to your specific input.

Do we have to assess every AI tool?

No, and you could not. Start with what is actually in use and what company data flows into it. That is a much shorter list than the catalog, and it is the list that matters.

How often should we reassess?

On an event, not on a calendar. Vendor acquisition, changed terms, an incident, a new feature that widens scope, or relocated hosting. Those are the moments an earlier judgement may have expired.