alt Bern
|
alt Lisbon
|
alt New York
info@ai-ei.org
+351 93 832 8533
Become a Member
alt Bern
|
alt Lisbon
|
alt New York
info@ai-ei.org
+351 93 832 8533

What should you ask an AI vendor?

What should you ask an AI vendor?

Before your company relies on an AI vendor, ask how it handles your data, how it changes its models, what happens when something goes wrong, who owns the output and what role it holds under the EU AI Act. The answers show which risks stay with you and what belongs in the contract.

Hypothetical example: an online shop’s AI chatbot suddenly gives worse answers. The vendor had switched models and kept customer chats for training, and the contract required no notice of either.

Your data

Data questions come first: they decide what staff may put into the tool (see whether it is safe to share data with AI tools). Ask whether the vendor trains on your data, how long it keeps it, which other companies (sub-processors) handle it, how it is kept separate from other customers’ data, on what legal basis it leaves the EU, and how you export and delete it when you leave.

Legal requirement (GDPR, Art. 28). This applies now. A vendor that processes personal data on your behalf is a processor, and GDPR requires a contract that sets out, among other things, that the processor acts only on your documented instructions, keeps the data secure and engages sub-processors only with your authorisation (GDPR, Art. 28). This contract is usually called a data processing agreement.

Model changes and incidents

AI tools change often: the vendor may replace the model or retrain it, and behaviour can shift without any change on your side. Ask how far in advance you will be told, whether you can test a new version first, and whether you can stay on a fixed version or roll back.

Ask also what counts as an incident, how quickly you will be told, and who your contact is. A personal data breach on the vendor’s side may trigger your own notification duties, covered in how to respond to an AI incident.

Output rights

Check who holds rights in the output as between you and the vendor, whether commercial use is allowed on your plan, and whether an indemnity covers third-party claims. What to check about AI and copyright explains why this matters.

The vendor’s role under the AI Act

An AI vendor is not automatically the “provider” of the AI system under the AI Act, although it often is: the provider is whoever develops the system, or has it developed, and places it on the market or puts it into service under its own name or trademark, including for its own use (AI Act Service Desk, Art. 3). Your own role can change too: under Art. 25, a company that puts its name on a high-risk system, substantially modifies it or changes its intended purpose so that it becomes high-risk can itself become the provider. Whether you are a provider or a deployer sets out the roles.

Legal requirement (EU AI Act, Art. 13 and 26). This applies to high-risk systems: from 2 December 2027 for Annex III systems and from 2 August 2028 for Annex I Section A products; Section B products follow the sector route in Art. 2(2). The provider of a high-risk system must supply instructions for use that allow deployers to understand the output and use the system appropriately (Art. 13). The deployer must use the system in line with those instructions (Art. 26). For a tool that may be high-risk, such as in hiring, ask when those instructions will be available.

Legal requirement (EU AI Act, Art. 50). These duties apply from 2 August 2026. Some transparency duties sit with the provider, such as marking AI-generated content in a machine-readable way, and others with the deployer (AI Act Service Desk, Art. 50). Ask which apply and how the product meets them. The full timeline is in what the EU AI Act requires.

How to use the questionnaire

Recommendation. Send the core questions to every vendor, before signing or at renewal; a vendor may answer “not applicable” if it explains why. Add the extended questions for sensitive use cases: personal or confidential data, customer-facing use, integrations with company systems or possible high-risk use. Ask for written answers that reference the contract or documentation. Record any unanswered question and decide whether that risk is acceptable. The answers do not make your use compliant on their own.

Next step: send the questionnaire to the vendor of the AI tool your company depends on most, and file the answers alongside the contract.

Template

AI vendor questionnaire

Vendor: ______ · Product and plan: ______ · Completed by: ______ · Date: ______

Core questions (every vendor)

If a question does not apply to the product, answer “not applicable” and explain why.

Data

  1. Do you use our prompts, files or outputs to train or improve any model? If so, can we switch this off, and is it off by default on our plan?
  2. How long do you keep prompts, uploaded files, outputs and logs, and can we delete them on request?
  3. Where is our data stored and processed? If it is transferred outside the EU, what is the legal basis for the transfer?
  4. Which sub-processors handle our data, for what purpose, and how will you tell us about changes?
  5. If you process personal data on our behalf: will you sign a data processing agreement under GDPR Art. 28? Please attach it.
  6. When we leave, can we export our data, and will you delete it and confirm the deletion, within what period?

Model changes

  1. Which model or models does the product use, and who provides them?
  2. How far in advance will you tell us about a model change or a significant change in behaviour, and can we test it first?
  3. Can we pin a specific model version, or roll back if a new version causes problems?

Incidents

  1. What do you treat as an incident, how quickly will you inform us of one that affects our data or our users, and who is our contact?

Output rights and AI Act role

  1. Who holds rights in the output as between us and you, and is commercial use allowed on our plan?
  2. What is your role under the EU AI Act for this product (provider, distributor, importer or other), and who is the provider of the underlying model?

Transparency and documentation

  1. Which transparency duties under Art. 50 of the AI Act apply to the product, for example telling users they are interacting with AI or machine-readable marking of generated content, and how does the product meet them?
  2. What documentation can you share on the product’s intended purpose, known limitations and testing?

Extended questions (sensitive use cases)

  1. Who inside your company can access our data, and under what conditions?
  2. How is our data kept separate from other customers’ data, including in fine-tuning, retrieval or shared caches?
  3. What permissions does the integration need to our systems, such as email, files or customer records, can we limit them, and which actions can the tool take without a user’s confirmation?
  4. Do you offer an indemnity against third-party intellectual property claims relating to the output? Under what conditions?
  5. Do you consider the product, or any intended use of it, high-risk under the AI Act? If so, when will instructions for use under Art. 13 be available?

Sources and further reading

Event

AI Horizon Conference

The AI Horizon Conference returns to Lisbon, once again bringing together entrepreneurs, investors and industry leaders to discuss the future of AI.

November 11, 2026
Lisbon, Portugal
Register Now
AI Horizon
alt alt

Join Us in Shaping the Future of Ethical AI!

Join us as a member and play a vital role in shaping a future where AI is created responsibly, with integrity, transparency, and fairness at its core.

Apply Now