The questions to ask before letting an AI vendor near your data
Most AI procurement conversations are about capability. The ones that matter later are about data handling, and they are rarely asked.
- November 12, 2025
- Published
- 7 min
- Read time
- AI
- Category
On This Page
Where does the data actually go
The first question is the least asked: when we send you a document, which systems does it pass through and where does it rest. Many products are a thin layer over an underlying provider, which is fine, but it means your data handling is really theirs.
Ask for the chain explicitly. Every subprocessor, every region, every point of storage. Vagueness at this stage is itself an answer.
You need this regardless of regulatory obligations, because you cannot make a sensible judgement about risk without knowing where the risk lives.
Is our data used for training
Business tiers of the major providers exclude customer data from training by contract. Consumer tiers frequently do not, and the difference is a setting or a plan rather than a technology.
Ask for it in writing rather than accepting a verbal assurance, and check whether it applies to everything or only to certain endpoints.
If a vendor cannot answer this crisply, they either do not know their own stack or would rather you did not press.
What is retained, and for how long
Retention is usually where the surprises are. Prompts and outputs are commonly kept for a period for abuse monitoring, which is reasonable and is also a copy of your data existing somewhere you did not plan for.
Ask for the retention window, whether it is configurable, and what deletion actually means. Deleted from the interface and deleted from backups are different claims.
Where the work genuinely demands it, private deployment removes most of this conversation, at a cost worth weighing rather than assuming.
What happens when it is wrong
Ask what the system does with input it is not confident about, and whether that behaviour is configurable. A product that always produces a confident answer is not more capable, it is less safe.
Ask what is logged. If you cannot see what the system was given and what it returned, you cannot diagnose a bad result and your only response will be to stop trusting the whole thing.
How do we leave
Exit terms tell you a great deal about a vendor. Can you export your data in a usable format, what happens to it after termination, and is there anything about the setup that makes moving harder than it needs to be.
Asking early is not pessimism. It is the difference between choosing a supplier and acquiring a dependency.
ReynoldsBuilt
AI, automation, and custom software
We audit an entire operation before building anything, then build what the business actually needs. Everything here comes out of real engagements.
About the studioKeep reading
More from the blog
Written for the person who has to make the call, not the person writing the spec.
Strategy · 8 min
The spreadsheet your team built is the best spec you have
Every business has a shadow spreadsheet holding the operation together. Most software projects throw it away. That is a mistake, and an expensive one.
ReadAutomation · 7 min
The worst automation failure is the one nobody notices
An automation that breaks loudly gets fixed the same day. One that fails quietly can corrupt six months of data before anyone asks a question.
ReadAI · 9 min
Hallucination is a design problem, not a model problem
Waiting for a model that never invents anything is not a plan. Building systems that assume it will is.
ReadFind out what should actually be built.
Start with an assessment. We walk your business end to end and show you where automation and AI pay off, ranked by what they are worth.