What should I ask an AI vendor before buying?
Ask what data the vendor collects, stores, uses for training, and shares; where it is processed; who can access it; how outputs are evaluated; what happens when the model or subprocessor changes; how costs are calculated; what support and incident commitments exist; and how you can export and delete your data if you leave. Ask for evidence and contract language, not only marketing answers.
How do you evaluate the security of an AI tool?
Start with the data and actions the tool will handle, then assess access controls, encryption, authentication, logging, incident response, subprocessors, retention, vulnerability management, and relevant independent reports or attestations. The right level of diligence depends on the use case. A tool handling public brainstorming material does not need the same approval as one processing employee, customer, health, or financial data.
Can an AI vendor use my data to train its models?
The answer depends on the vendor, product tier, account settings, contract, and jurisdiction. Do not infer the policy from a product slogan. Read the current terms, privacy documentation, data-processing terms, and enterprise agreement, and ask what happens to prompts, files, feedback, logs, and outputs. Record the checked date because these terms can change.
What is AI vendor exit risk?
Exit risk is the difficulty and cost of leaving a vendor without losing data, workflow continuity, quality, or customer commitments. It includes proprietary formats, undocumented prompts, embedded integrations, model-specific behavior, long export times, minimum commitments, price changes, and lack of a fallback. Evaluate the exit path before the tool becomes part of a critical process.
Should a small business complete an AI vendor risk assessment?
Yes, but the assessment can be proportionate. A small business can begin with a one-page record of the use case, data, permissions, vendor claims, cost, quality test, owner, contract terms, incident contact, and exit plan. More sensitive or consequential uses deserve deeper review. The goal is to make an informed decision, not to recreate a large enterprise procurement department.
How do I compare two AI vendors fairly?
Give both vendors the same representative tasks, data boundary, success rubric, volume assumptions, and support questions. Compare accepted outcomes, errors, review time, latency, total cost, contract terms, controls, and exit options. Do not compare a polished demo from one vendor with an unconfigured trial from another or treat a benchmark score as proof of fit for your workflow.