The questions to ask an AI supplier before you sign
Most AI supplier due diligence asks about security and certification and stops. The questions that decide whether a system can be operated, evidenced and left are commercial ones, and they are cheap to ask before a contract and impossible afterwards.
The security questionnaire came back complete. There is an information security certificate, the data stays in the right region, and there is a page about responsible AI with a diagram on it. Legal has reviewed the terms. The procurement process has done what procurement processes do.
None of it answers the questions that will matter in eighteen months, which are whether the system’s behaviour can be evidenced, whether it can be evaluated against your own material, whether a change to it will be visible to you, and what leaving looks like. Those questions are not in the standard pack because the standard pack was written for software that does the same thing every time.
The claim: the differentiating questions in AI procurement are about evidence, change and exit, and asking them costs nothing before signature.
The four groups
- Group 01 Role and obligations Who is the provider and who is the deployer for this system, in the supplier’s own view, and what follows.
- Group 02 Evidence What the system records, what you can retrieve, and for how long.
- Group 03 Change What can change without your agreement, and how you find out.
- Group 04 Exit What you take with you, in what format, and what stops working.
The first group is the one buyers most often skip, and it decides everything downstream. Under the EU AI Act the obligations that attach to placing a system on the market are not the ones that attach to using it, and a supplier’s view of which party is which is a fact you want in writing before you find out that both of you assumed it was the other. Ask the question plainly and record the answer.
The questions themselves
The last question is the one that produces the most informative answers. A supplier who has thought about it describes a process. A supplier who has not will offer aggregate reporting, which is not the same thing and does not answer the question that will be asked.
The second question is the sharp one. Hosted models are updated in place, and a system whose behaviour changed for reasons the customer did not cause and cannot observe is a system whose evidence is unreliable. Many suppliers cannot commit here. That is a finding, not a failure — it tells you the class of decision this system should not be supporting.
The fifth question should be asked even where the terms appear to answer it, because the answer is often layered: not used for training, but retained for abuse monitoring, by a subprocessor, for a period stated elsewhere. Ask for the whole chain.
Where to find the language
Drafting all of this from scratch is unnecessary. The European Commission’s community of practice on public procurement of AI publishes model contractual clauses for AI, in a full version aimed at high-risk systems and a lighter one for everything else, and although they were written for public buyers they have become a reasonable baseline for private contracting too — the IAPP’s practical guide to the clauses is a good way in before reading the source documents.
Using them wholesale is rarely right. Using them as a checklist of the topics a contract should not be silent on is almost always right, and it converts a negotiation about trust into a negotiation about specific obligations.
The question behind all of them
Every question above is a version of one question: if this system is challenged, what can we show?
That is worth stating explicitly at the start of a procurement, because it changes what the supplier presents. A vendor asked to demonstrate capability will demonstrate capability. A vendor asked what a customer can produce when a regulator, a customer or a court asks about one particular output will either have an answer or reveal that nobody has asked before.
What this does not tell you
We do not resell platforms, take vendor commission, or bid to implement the architectures we specify, so this list has no preferred answers and no preferred suppliers. It is also not a legal template — the wording that binds anyone is a matter for your counsel, and the model clauses referenced above are a starting point rather than a document to sign unamended.
Nor does a supplier failing several of these questions mean the system should not be bought. Plenty of useful systems cannot answer the change questions, and the right response is usually to narrow what they are used for rather than to walk away. What is not defensible is buying without knowing, and then discovering the limits at the point where somebody needs the evidence.
The person who should use this is whoever runs the next AI procurement. Put the four groups into the questionnaire before the shortlist is drawn. The answers will change the shortlist, which is precisely the point of asking early.