Four questions for any vendor with an AI in its product
Ask them in writing. A vendor who cannot answer in plain sentences has told you something. They work on every AI product in your stack — including ours.
- 01Where does the data live?You cannot judge who can reach your records until you know whose account holds them, and where.Listen for: a named tenant and owner. Not: “the cloud,” “enterprise-grade infrastructure.”
- 02What is retained?Some tools keep what people type into them. A vendor that keeps prompts holds a copy of everything your staff pasted.Listen for: what is kept, where, for how long, and under whose terms. Not: “we take privacy seriously.”
- 03Who sees what through it?An AI can show a person more than their own permissions allow. The answer should match the access rules your firm already runs.Listen for: enforcement in the data or the query, shown on a screen. Not: “the AI is instructed not to.”
- 04What can leave?Drafting and sending are different acts. The answer should name which acts reach someone outside the firm, and what stands between a draft and the act.Listen for: named acts, a person's approval, and a log of both. Not: “human in the loop,” unexplained.
A good answer names a mechanism — a setting, a screen, a log — rather than an intention. Ask for the page that states what the AI may touch at your firm. Either it exists or it does not.