The questions to ask an AI supplier before you sign
AI due diligence needs evidence, change and exit questions alongside security review. Agree responsibilities, usable records and transition conditions before accepting the service dependency.
Keep development and test groups separate before comparing performance. No measured results are shown.
Security certificates, location commitments and legal review supply important procurement evidence. They should connect to the operating questions the buyer must answer once the AI service is in use. Review the complete service rather than treating a supplier’s standard pack as the acceptance decision.
Ask how behaviour can be evidenced, how local evaluation works, which changes the supplier can make and what leaving requires. These questions also matter for other software. AI’s model, data and workflow dependencies make their scope worth stating explicitly.
Agree evidence, change and exit conditions before accepting the supplier dependency. Early review gives those findings a chance to affect scope, pricing and contract terms. Later negotiation remains possible, but may carry greater cost or less choice.
The four groups
- Group 01 Role and obligations Who is the provider and who is the deployer for this system, in the supplier’s own view, and what follows.
- Group 02 Evidence What the system records, what you can retrieve, and for how long.
- Group 03 Change What can change without your agreement, and how you find out.
- Group 04 Exit What you take with you, in what format, and what stops working.
Record the relevant legal roles and obligations. Under the EU AI Act, provider and deployer duties differ according to the system and activity. The supplier’s stated view is a useful input, not the final determination. Ask legal advisers to resolve material uncertainty and preserve the agreed operational responsibilities.
The questions themselves
Ask for a sample reconstruction and the process used to obtain it. Aggregate reporting can support trend analysis without explaining one output. The buyer needs to know which case-specific records exist, who can access them and what remains unavailable.
Clarify whether model or service behaviour can change without a new identifier. Record notice, version-pinning and evaluation options, including their limits. Where changes cannot be controlled or fully observed, assess whether monitoring or a narrower use can make the remaining exposure acceptable.
The fifth question should be asked even where the terms appear to answer it, because the answer is often layered: not used for training, but retained for abuse monitoring, by a subprocessor, for a period stated elsewhere. Ask for the whole chain.
Where to find the language
The Public Buyers Community publishes updated EU AI model contractual clauses, including high-risk and customisable light versions. They are procurement aids, not complete contracts. The IAPP practical guide provides further context. Check the versions and obtain legal advice before adapting them to a particular purchase.
Use the clauses to identify relevant topics and unresolved responsibilities. Adapt their scope to the system, current law and buyer’s contract. A checklist can reveal omissions, but it cannot settle acceptance, payment, intellectual property or liability by itself.
The question behind all of them
Every question above is a version of one question: if this system is challenged, what can we show?
State the evidence question at the start of procurement. Require the supplier to identify the records available for a disputed output, the access route and the limits. Demonstrations of general capability and reconstructions of specific behaviour provide different evidence.
What this does not tell you
We do not resell platforms, take vendor commission, or bid to implement the architectures we specify, so this list has no preferred answers and no preferred suppliers. It is also not a legal template — the wording that binds anyone is a matter for your counsel, and the model clauses referenced above are a starting point rather than a document to sign unamended.
An incomplete answer does not automatically rule out the purchase. Assess its consequence for the intended use and whether restrictions or further evidence can resolve it. Record any accepted limitation so it remains visible when the service scope expands.
The procurement owner should include the four groups before shortlisting and compare the answers against the actual service needs. Bring material gaps into the investment and contract review. The outcome may be a different supplier, a narrower scope or a clearly documented dependency.