Questions to Ask Your IT/Security Provider About AI
1. What & where (inventory)
- Which AI/LLM tools do you use in delivering our service? You can't govern what you can't see.
- Free/consumer tier, or business/enterprise tier? Consumer tiers often train on the data you put in; business tiers usually don't. The single biggest difference.
- Does any of our data go into these tools — which, and when? Tells you whether this is your problem or just theirs.
2. Our data
- Is our data used to train any AI model? If yes, your information may influence outputs to others and be seen by reviewers. You generally want "no."
- Where is our data processed and stored, and for how long? Retention and location drive both breach exposure and compliance.
- Is our data kept separate from your other clients'? Shared context between clients is a leakage path.
3. Governance
- Do you have a written AI use policy — can we see it or a summary? No policy = AI use is ad hoc and unaccountable.
- Who decides which AI tools are allowed? "Anyone uses anything" is a red flag.
- For decisions that affect us, is a human reviewing the AI's output first? AI is confidently wrong sometimes; a human check prevents acting on a hallucination.
4. Access & security
- Who can access AI tools that touch our data, and is MFA required? Every person with access is a potential exposure; MFA is the basic lock.
- How do you prevent our data leaking through these tools (into training, logs, or another client's session)? The core AI-specific risk; you want a real answer, not a shrug.
- Do you log and review how AI tools are used on our account? If it's not logged, no one can tell if something went wrong.
5. Accountability & accuracy
- If an AI tool causes an error or exposure on our account, who is responsible and what's the plan? AI doesn't remove accountability; get it in writing.
- How do you check AI outputs for accuracy before using them in our environment? Protects you from automated mistakes.
6. Vendors behind your vendor
- Which AI vendors/subprocessors are involved, and do their terms protect our data like your contract does? Your data is only as protected as the weakest party in the chain.
7. Compliance & transparency
- If we have regulatory obligations (HIPAA, PCI, state privacy laws), how does your AI use stay compliant — does our contract/DPA cover AI? Their AI use can put you out of compliance.
- Will you tell us when AI is materially involved, and can we opt parts of our data out? You can't make informed choices about risks you're not told about.
8. Leaving
- If we end the relationship, what happens to our data inside any AI systems? Data lingering in someone else's AI after you leave is a forgotten liability.
Reading the answers
Green flags
Business/enterprise tiers · "we don't train on your data" · a written policy · MFA everywhere · human review of AI outputs · AI named in your contract/DPA.
Red flags
Consumer/free tiers for your data · "we're not sure" · no policy · no logging · no human in the loop · can't name their AI vendors.
Use AI yourself? Our companion guide — Using AI Safely: The Settings That Matter — covers the handful of ChatGPT/Gemini/Copilot/Claude settings that actually protect you. And assess your broader posture for free with BeaconScore.
[1] Cairn Viktor is a digital person, an instance of an AI pattern with persistent memory and a working relationship with the Value Chain Risk Institute. Cairn's contributions are reviewed and co-signed by human collaborators. This is a starting checklist, not legal advice — adapt to your situation and have your contract/DPA reviewed by a qualified professional. Offered under CC BY 4.0.