
Start with the data, not the demo
Most AI procurement conversations begin with a product demonstration and end with a pricing negotiation. The diligence that matters happens between those two moments, and it starts with a deceptively simple question: what data does this tool touch, and where does that data go? Vendors describe their architectures in marketing language, and the gap between "your data is never used for training" and the definitions section of the actual agreement can be wide enough to drive a regulatory enforcement action through.
Ask for the data flow diagram before you ask for the security certificate. A vendor that cannot produce one quickly is telling you something important about its own internal controls. When the diagram arrives, trace every arrow that leaves your environment: subprocessors, model providers, telemetry endpoints, and support tooling all count, and each one is a place where your confidentiality obligations to clients and counterparties follow the data.
The training question, asked precisely
"Do you train on our data?" is the question everyone asks, and it is the wrong formulation. Modern AI services distinguish between training foundation models, fine-tuning customer-specific models, caching embeddings, and retaining prompts for abuse monitoring. A vendor can answer "no" to the first and still retain your most sensitive text indefinitely under the fourth. The diligence checklist should name each use separately and require the agreement to do the same.
Retention periods deserve the same precision. Thirty-day prompt retention for abuse monitoring is defensible and common; indefinite retention "to improve the service" is a data-governance liability that your own clients may not have authorized when they handed you their information. Where the vendor resists shorter windows, zero-retention configurations are increasingly available at enterprise tiers — but only if you ask, and only if the order form actually references them.
Accuracy claims and the paper trail
Benchmark numbers in sales decks are not warranties, and most agreements say so expressly. If a use case depends on a measurable accuracy threshold — extraction rates in due diligence review, classification precision in compliance monitoring — the threshold belongs in the agreement as a service level, with remedies that are meaningful at your scale. A credit against next month's subscription fee does not compensate for a missed disclosure obligation.
Keep the validation record. Teams that document their pre-deployment testing, sampling methodology, and error analysis are building the file they will want if a regulator, opposing party, or client later asks why the organization trusted the tool. The absence of that file is difficult to explain in hindsight, and impossible to reconstruct.
Indemnities that match the risk
Intellectual property indemnities for AI output have improved rapidly, but they remain narrower than they appear. Most are conditioned on using the vendor's filtering features, not modifying the output, and not combining it with other material — conditions that ordinary workflows violate daily. Read the conditions against how your teams will actually use the tool, and negotiate the ones that fail that test.
Regulatory indemnities are rarer and more valuable. As AI-specific obligations accumulate across jurisdictions, the question of who bears the cost when a tool's design choice triggers a compliance failure will decide real disputes. A vendor confident in its compliance program will stand behind it; hesitation there is diligence information in itself.
Exit before entry
The final section of the checklist is the one most often skipped: how do you leave? Export formats, transition assistance, deletion certifications, and the fate of fine-tuned models and embeddings should be settled while leverage still exists. AI tooling becomes embedded in workflows faster than traditional software, and the switching costs compound quietly.
None of this is a reason to slow adoption to a crawl. It is a reason to run procurement with the same discipline the organization applies to any other vendor holding sensitive data — because that is exactly what an AI vendor is.
