Questions to ask an AI vendor before you buy
Most AI risk comes from suppliers. Pick the areas that apply, send the questions, mark the answers — the tool shows red flags. Answers stay in your browser.
Which areas apply?
Which AI models does the product use, and from which model provider?
Good answer: A named model and provider, with information on changes.
What is your role under the AI Act (provider, distributor) and how do you classify this system’s risk? critical
Good answer: A clear role and a documented risk classification.
What documentation and instructions for use do we get as the deployer?
Good answer: Instructions, known limitations, intended purpose.
Do you help us with AI literacy (training materials for our users)?
Good answer: Training or materials included.
Who owns the outputs, and do you indemnify us against copyright claims?
Good answer: We own the outputs; an IP indemnity for business plans.
Do you sign a data processing agreement (GDPR Art. 28)? critical
Good answer: Yes, standard DPA available.
Are our inputs and outputs used to train or improve your models? critical
Good answer: No, contractually excluded.
Where is data stored and processed? Is EU data residency possible?
Good answer: EU region, or transfers under the EU–US Data Privacy Framework / SCCs.
How long do you keep prompts, files and logs, and can we delete them?
Good answer: Short, configurable retention; deletion on request.
Which sub-processors do you use (list, countries)?
Good answer: A published list with notification of changes.
Do you support our DPIA with information (data flows, risks, measures)?
Good answer: A DPIA support pack.
11 questions still unanswered.
Red flags
No red flags among the answered questions.
Which questions are most important?
Whether you get a data processing agreement, whether your data is used for training, where data is stored, and — for high-risk uses — how the vendor supports human oversight and bias testing.
What if the vendor does not answer?
Treat unclear answers to critical questions as a red flag: use the tool without personal data, choose another vendor or negotiate contract terms.
Is this enough for NIS2 or DORA?
It is a good start for supplier assessment; regulated entities need their own documented procedure and contract clauses.
General information, not legal advice — consult a lawyer for borderline cases. Regulations reviewed on 29 Sep 2026.