Skip to content
Is there an AI for this?

Field note · Compliance

Questions to ask before adopting an AI vendor

Eleven questions, in the order that saves the most time, with what a usable answer looks like. Written for the person who has to sign, and structured so that four of the eleven can be checked from the vendor’s own published pages before the first call.

Source
Written by us. Method and judgement — no statement on this page rests on a fetched document.
Evidence
none on this page — it links to the pages that hold it

Structured issue-spotting to support your own review — not legal advice. Verify against the cited primary sources and your counsel.

01Four you can answer before the first call

Whether a vendor *publishes* a document is a fact you can establish yourself, from the vendor’s own site, without asking anyone. It is also the fastest filter: a vendor selling to enterprises who publishes no data-processing agreement and no sub-processor list is telling you something about the stage they are at.

What the document *says* is a separate question, and a slower one. Keep the two apart — a published page is evidence that a page exists, not evidence of what is in it.

  • ASSESSMENT

    OpenAI, Google, Microsoft, AWS and Mistral AI each publish a data-processing agreement at a stable URL.

    Label withdrawnWritten as a fact resting on a fetched document, and shown as an assessment here because no stored evidence record for it could be resolved when this page was rendered.

  • ASSESSMENT

    OpenAI, Google, GitHub and Glean each publish a sub-processor list.

    Label withdrawnWritten as a fact resting on a fetched document, and shown as an assessment here because no stored evidence record for it could be resolved when this page was rendered.

  • ASSESSMENT

    OpenAI, Anthropic, Google, Microsoft and AWS each publish a supported-countries page, which is where an availability question is answered rather than in a sales call.

    Label withdrawnWritten as a fact resting on a fetched document, and shown as an assessment here because no stored evidence record for it could be resolved when this page was rendered.

  • ASSESSMENT

    A hosted provider’s home jurisdiction is itself a published fact — DeepSeek’s is recorded as China, OpenAI’s as the United States — and it decides which government can compel disclosure.

    Label withdrawnWritten as a fact resting on a fetched document, and shown as an assessment here because no stored evidence record for it could be resolved when this page was rendered.

  • ASSESSMENT

    We assess "publishes a DPA" and "offers the terms you need" as different findings, and we never present the first as the second.

    BasisRests on the evidence model used across this site: a fetched page proves the page exists at that URL on that date. A claim about its contents needs a quoted sentence from inside it, which is a separate record.


02The eleven questions

  1. 01Is our content used to train or improve your models, by default or on request?WhyThis is the question most often answered ambiguously, and the one an internal counsel will ask first.A usable answerA clause in the agreement, not a sentence on a marketing page, and a named setting we can verify.
  2. 02How long is our content retained, and can retention be set to zero?WhyRetention decides what is available to a subpoena, a breach, and a subject access request.A usable answerA stated period, a documented zero-retention option, and what changes when we enable it.
  3. 03Where is the inference performed, and where is it stored?WhyThese are two different locations and vendors often answer only the second.A usable answerBoth, per region, with the fallback behaviour when the primary region is unavailable.
  4. 04Who are your sub-processors, and how are we told when the list changes?WhyA model provider behind a product is a sub-processor. Notice of change is what makes the authorisation meaningful.A usable answerA public list, a subscription to changes, and a notice period long enough to object.
  5. 05Which model providers sit behind this product?WhyA product-shaped answer often hides a second vendor, in a second jurisdiction, with different terms.A usable answerNamed providers and the regions they serve us from.
  6. 06What logs exist, who can read them, and can we export them?WhyAudit logging is both a control you need and a second copy of the content you were protecting.A usable answerA described log schema, a retention period for the logs themselves, and an export route.
  7. 07How is tenant isolation implemented?WhySeparates a real multi-tenant architecture from a shared database with a customer column.A usable answerA description an engineer can evaluate, plus whatever independent assessment exists.
  8. 08Is the service available in our jurisdiction, contractually as well as technically?WhyAvailability and permitted use are different: a service can be reachable and still be out of scope in the terms.A usable answerThe supported-countries page, plus confirmation for our specific entity.
  9. 09What happens to our data on termination, and how long does it take?WhyExit is the part of the agreement nobody negotiates and everybody eventually uses.A usable answerAn export format, a deletion deadline, and confirmation that backups are included.
  10. 10What is your incident notification commitment?WhyOur own notification obligations start when we know, so their clock decides ours.A usable answerA stated number of hours, and what "aware" means for the purpose of starting it.
  11. 11Which of these commitments are in the contract rather than on a web page?WhyThe closing question. A commitment that only exists on a page can be edited without telling you.A usable answerA marked-up agreement, or a named clause for each answer above.

03And one thing to write before anyone signs anything

Most organisations already have staff pasting company material into consumer AI tools. That is a policy problem you can fix this month, independently of any procurement, and the Privacy Commissioner has published what such a policy should cover.

  • ASSESSMENT

    The Privacy Commissioner’s checklist recommends that an internal policy specify the permitted generative AI tools and the scope of permissible use.

    Label withdrawnWritten as a fact resting on a fetched document, and shown as an assessment here because no stored evidence record for it could be resolved when this page was rendered.

  • ASSESSMENT

    It also recommends providing clear instructions on the types and amounts of information that may be entered into those tools.

    Label withdrawnWritten as a fact resting on a fetched document, and shown as an assessment here because no stored evidence record for it could be resolved when this page was rendered.

  • RECOMMENDATION

    We recommend writing that policy before the procurement rather than after it, because the procurement takes months and the exposure is happening now.

    BasisDepends on staff already having access to consumer AI tools. Rests on the two Privacy Commissioner recommendations cited above, which describe a policy that needs no vendor relationship to implement.