An SME almost never builds its own AI: it buys it. Which means most of its risk — data, regulatory, operational — enters through the vendor door. The good news is that this risk filters out with a very cheap tool: questions asked at the right time. These are the ten that separate an informed purchase from an act of faith, ordered from the most basic to the most refined. Print them before your next demo.
1. Where is the data processed and stored? The mother question. A specific region, not "the cloud." If any processing happens outside the European Economic Area, under what transfer mechanism? A vendor that can't answer this in one sentence has a problem — and if you sign, the problem becomes yours.
2. Is my data used to train models? Yours, and your customers'. An acceptable answer is a contractual "no" or a clear, verifiable opt-out; an unacceptable one is ambiguity ("to improve the service"). This point belongs in the contract, not in the conversation.
3. Who can see the conversations and the prompts? The question almost nobody asks, and the one data protection authorities have started looking at closely: third-party access — human reviewers, the vendor's own vendors, affiliates — to what your people type into an assistant. Ask for the answer in writing: under what circumstances is there human access, with what controls, and whether it can be switched off.
4. What role do you take in the AI Act chain — and what does that leave for me? A serious vendor knows which obligations are theirs as a provider and which fall on you as a deployer, starting with the transparency notice that should come built in. The one who answers "don't worry about that" is, in fact, answering that they don't know.
5. What system documentation do you hand over? Instructions for use, known limitations, data on performance and accuracy, intended purpose. This is the raw material for your classification and your human oversight. "We have a whitepaper" is not documentation.
6. What model is underneath, and what happens when it changes? If the product relies on a third-party model, which one, and under what commitments? And the part almost nobody asks: do you notify model or version changes that alter the system's behaviour? A silent model change can invalidate your assessment without anyone telling you.
7. What management framework do you follow, in the absence of harmonised standards? There is no presumption of conformity with the AI Act yet, pending the harmonised standards of Article 40, so an honest answer talks about international standards, drafts in development and their own practices — with specifics. Be systematically wary of grandiose vocabulary with no article or standard behind it.
8. How do you handle incidents and vulnerabilities? Notification channel, timelines for informing the customer, track record if any. The question isn't whether they'll have an incident — it's whether you'll hear about it from them or from the press.
9. What happens to my data when the contract ends? Export in a usable format, verifiable deletion timelines, what remains in backups and for how long. The exit is negotiated at the entrance; afterwards there's no leverage left.
10. Can you put all of the above in writing? The question that turns the previous nine into something real. A data processing agreement where applicable, security annexes, notification commitments. What isn't signed, for the purposes of your file, doesn't exist.
How to use the answers
Three rules for putting this to use. First: log the answers — due diligence without a record is a chat; with a record, it's auditable evidence of diligence you'll show someone one day. Second: repeat it at every renewal — products change model, architecture and sub-processors faster than contracts do. Third, and most important: the evasive answer is information too. The vendor who dodges question 2, takes offence at question 3, or answers question 7 with inflated labels is showing you exactly how they'll behave the day you have a problem. Thank them for the unintentional honesty, and keep looking.
Ten questions, one hour of meeting, one table of answers on file. It's probably the hour with the best risk return in your entire governance programme — because it filters out the problems before they carry your logo.
This article is for informational purposes only and does not constitute legal advice.