Buying AI products and services brings their security posture into your organisation. Assess vendors before adopting.
Data Handling
- Is our data used to train models? Can we opt out?
- How long are prompts, files and outputs retained?
- Where is data stored and processed?
- Who at the vendor can access it?
Security Controls
- Certifications and independent audits.
- Encryption, access control and single sign-on support.
- Logging and audit trails available to customers.
- Vulnerability management and incident notification commitments.
AI-Specific Questions
- How are prompt injection and data leakage addressed?
- How are connected tools and integrations permissioned?
- How are model changes communicated and tested?
- Is there red-teaming or third-party testing?
Compliance
- Support for privacy regulations relevant to you.
- Contractual terms on data processing and liability.
Resilience
- Uptime commitments, rate limits and fallback options.
- Exit plan: can you export data and switch vendors?
Ongoing Review
Reassess periodically and when vendors change models, terms or features.