Contracting an AI-powered service is no longer a lab decision: it touches customer data, real processes and, increasingly, legal obligations. These ten questions require no technical background, and they separate serious vendors from those who only have a nice demo.
- What data of mine does the service use, and where is it processed? Country, infrastructure provider and whether it leaves the EU.
- Are models trained on my data? If the answer is not a clear "no" in writing, assume they are.
- Which subprocessors sit behind the service? The language model, the hosting and the analytics are usually third parties that never appear in the proposal.
- What certifications can you show me? ISO 27001 or SOC 2 guarantee nothing by themselves, but asking for them changes the conversation.
- What happens when the service fails? Availability commitment, continuity plan and who I call on a Sunday.
- How do I leave? Data export in a usable format and a verifiable deletion deadline when the contract ends.
- What record remains of what the AI does? If an agent acts on your systems, someone must be able to reconstruct what it did and when.
- Who answers when the AI gets it wrong? The contract should say so before it happens, not after.
- How is it preparing for the AI Act's transparency obligations? If the service talks to your customers or generates content, that obligation will reach you too.
- How and when do you notify me of an incident? A concrete deadline and a concrete channel. "As soon as possible" is not a deadline.
The ten answers do not need to be perfect. They need to exist, in writing, before you sign. A vendor that cannot answer these questions is not ready for your data, and a contract that does not capture them leaves you alone when something fails.
The terrain where these questions become urgent, with AI and cloud pushing into risk teams' plans, is the one we mapped in The technology risk universe in 2026.