Skip to main content
AI

The questions to ask before letting an AI vendor near your data

Most AI procurement conversations are about capability. The ones that matter later are about data handling, and they are rarely asked.

November 12, 2025
Published
7 min
Read time
AI
Category

Where does the data actually go

The first question is the least asked: when we send you a document, which systems does it pass through and where does it rest. Many products are a thin layer over an underlying provider, which is fine, but it means your data handling is really theirs.

Ask for the chain explicitly. Every subprocessor, every region, every point of storage. Vagueness at this stage is itself an answer.

You need this regardless of regulatory obligations, because you cannot make a sensible judgement about risk without knowing where the risk lives.

Is our data used for training

Business tiers of the major providers exclude customer data from training by contract. Consumer tiers frequently do not, and the difference is a setting or a plan rather than a technology.

Ask for it in writing rather than accepting a verbal assurance, and check whether it applies to everything or only to certain endpoints.

If a vendor cannot answer this crisply, they either do not know their own stack or would rather you did not press.

What is retained, and for how long

Retention is usually where the surprises are. Prompts and outputs are commonly kept for a period for abuse monitoring, which is reasonable and is also a copy of your data existing somewhere you did not plan for.

Ask for the retention window, whether it is configurable, and what deletion actually means. Deleted from the interface and deleted from backups are different claims.

Where the work genuinely demands it, private deployment removes most of this conversation, at a cost worth weighing rather than assuming.

What happens when it is wrong

Ask what the system does with input it is not confident about, and whether that behaviour is configurable. A product that always produces a confident answer is not more capable, it is less safe.

Ask what is logged. If you cannot see what the system was given and what it returned, you cannot diagnose a bad result and your only response will be to stop trusting the whole thing.

How do we leave

Exit terms tell you a great deal about a vendor. Can you export your data in a usable format, what happens to it after termination, and is there anything about the setup that makes moving harder than it needs to be.

Asking early is not pessimism. It is the difference between choosing a supplier and acquiring a dependency.

ReynoldsBuilt

AI, automation, and custom software

We audit an entire operation before building anything, then build what the business actually needs. Everything here comes out of real engagements.

About the studio

Find out what should actually be built.

Start with an assessment. We walk your business end to end and show you where automation and AI pay off, ranked by what they are worth.