What I'd Ask an AI Vendor Before Letting Them Near My Agency's Data
ai · August 24, 2026
Your agency holds sensitive data. Before you sign with an AI vendor, you need answers to hard questions about security, compliance, and what happens when things go wrong.
Key takeaways
- Before you adopt any AI tool, require written answers to questions about data storage, access, and retention; do not accept verbal assurances or generic security certifications.
- Ask vendors explicitly whether your agency's data will be used to train or improve the vendor's models; if they hedge or refuse to say, assume it will be.
- Demand to know what happens to your data if the vendor is acquired, goes bankrupt, or decides to sunset the product; get this commitment in writing.
- Understand your agency's own compliance obligations (FERPA, HIPAA, state data privacy laws, or local requirements) before you talk to a vendor; know what the law requires so you can hold the vendor accountable.
- Request a sample data processing agreement or terms of service in advance; if a vendor will not provide one until you are deep in the sales cycle, that is a warning sign about transparency.
- Ask who has access to your data inside the vendor's organization, how often access is audited, and what happens if someone accesses it improperly.
- Clarify the vendor's liability if there is a breach, unauthorized use, or failure to comply with your data handling requirements; vague indemnification clauses are not protection.
You receive an email from a vendor promising that their AI tool will cut your team's paperwork time in half. It sounds good. The pitch is clean. The price is reasonable. So you start thinking about signing.
Stop.
Before you let any AI tool near your agency's data, you need to ask hard questions that most vendors do not volunteer answers to. Your agency holds information about the people you serve. That data is sensitive. It is also yours to protect. If you hand it over to a vendor without understanding how they will handle it, where they will store it, and what they can do with it, you are accepting risk you should not.
This is not about being paranoid. It is about leading responsibly. If you work in public service, education, criminal justice, health, or social services, your data compliance obligations are not optional. Your vendors do not get to opt out of those obligations either. Yet many vendors will do everything they can to avoid committing to specific promises about your data in writing.
The Questions No Vendor Wants to Answer
Start with storage and access. Ask the vendor: Where is our data physically stored? In what country or region? Who has access to it inside your organization? How often is access audited? What happens if someone accesses it without permission?
Vendors often give vague answers like "we follow industry best practices" or "your data is secure in our cloud." That is not an answer. You need specifics. You need to know whether your data sits in a US data center or is replicated internationally. You need to know if customer data is mixed together or segregated. You need to know if the vendor's customer service team can see your data or if there are technical controls preventing that.
Write down the answers. If a vendor will not give you straight answers, that tells you something: either they have not thought through these questions, or they are hiding something. Neither is reassuring.
Next, ask about data use. This is the question vendors most actively avoid: Will you use our data to train or improve your AI models? Will our data be used to build features for other customers?
Some vendors say no; your data is yours alone. Others say yes but claim your data is anonymized first, so it is fine. Others refuse to give a clear answer and talk around it. Listen carefully to the non-answers. If a vendor hedges, equivocates, or changes the subject, assume they will use your data for model training. Then ask yourself: Am I okay with that? If your answer is no, cross that vendor off your list.
This matters because your data might contain information about individuals in sensitive circumstances. A teacher might use an AI writing tool in a classroom. A social worker might use an AI summarization tool on case notes. A recruiter might use an AI to screen resumes. If that data feeds into a vendor's model training, you have just shared your clients' or students' information with a system designed to learn from it and improve a product that will be sold to whoever else pays for it.
What Happens When the Vendor Fails
Ask: What happens to our data if your company is acquired, if you go bankrupt, or if you shut down this product? Get this in writing. This is not a theoretical worry. Vendors get acquired or shut down all the time. When they do, your data goes with them unless your contract says otherwise. You could lose access to it. It could be transferred to a buyer you never vetted. It could be sold off to cover the vendor's debts.
A good vendor will commit to one of these: They will return your data to you in a usable format within a specific timeframe. They will maintain your data in a secure archive for a defined period. They will destroy your data according to your instructions. Or some combination. If a vendor will not commit to any of these, you have no enforceable claim to your own data after the transaction.
Also ask: What is your liability if there is a breach, if you lose our data, or if you fail to comply with our data handling requirements?
Read the vendor's standard liability clause carefully. Many say something like "our total liability is limited to the fees you paid in the last 12 months" or "we are not liable for indirect damages." Translate that: If the vendor's failure costs you hundreds of thousands of dollars in remediation, legal fees, or regulatory fines, the vendor might only owe you back the subscription fee. That is not protection. That is the vendor shifting risk to you.
You do not have to accept these terms. You can ask the vendor to increase the liability cap or carve out exceptions for data breaches. Most will negotiate if you ask before you sign. If they refuse to discuss it, you now have data about their priorities.
Your Compliance Obligations Come First
Before you talk to any vendor, know your own compliance requirements. If you work in education, you likely have FERPA obligations. If you handle health data, HIPAA applies. If you are in criminal justice, you may have state laws about data retention and access. If you are in a state with data privacy laws, those apply. If your city or county has its own data policies, those are non-negotiable too.
Write these requirements down. Then take them to the vendor and ask: Can you comply with all of this?
Some vendors will say yes immediately. Some will say yes but need modifications to their standard contract. Some will say they cannot meet your requirements. Only the first two are acceptable. If a vendor cannot or will not commit to your compliance obligations in writing, do not sign.
This is where a data processing agreement comes in. A data processing agreement spells out how the vendor will handle your data, what they will do with it, how long they will keep it, who has access, what happens if there is a breach, and what you can require from them. If a vendor will not provide one or will not negotiate one before you sign, that is a warning. Do not let a vendor force you to accept their terms after you have already committed to buying.
Get It in Writing
The simplest rule: anything you need to be true about data handling must be in your written contract or a signed data processing agreement. Verbal assurances do not count. Email promises do not count. A vendor representative's casual statement does not count. Write it down. Have both sides sign it. Keep it.
If a vendor will not commit something to writing, assume they do not intend to honor it.
This sounds obvious, but it is where most agencies stumble. A salesperson says "oh, don't worry, we will not use your data for training." You feel reassured. You sign the contract. Eighteen months later, a new vendor executive decides to use all customer data for model training, and the original promise disappears. Now what? You have nothing in writing. The vendor's lawyer cites the contract, which says nothing about your data, and tells you it is technically allowed.
That is why everything matters. That is why you ask hard questions. That is why you require written answers.
If you are new to vendor evaluation or you are leading an agency for the first time, take this seriously. Talk to your legal counsel and your compliance or IT officer before you sign anything. Do not let anyone rush you through this process. A vendor who pushes you to sign quickly without answering your questions is not someone you should trust with your data.
None of this means you cannot adopt AI tools. Many vendors are thoughtful about data security and compliance. Many will negotiate in good faith and give you the commitments you need. But you will only find them by asking the questions that matter. Ask them before you sign. Ask them in writing. Ask them with the same seriousness you would bring to any decision that puts your agency's data and your clients' trust at risk.
Frequently asked questions
- What is the most important question to ask an AI vendor?
- Ask whether your agency's data will be used to train or improve the vendor's models. If the vendor avoids a direct answer, assume the answer is yes, and then decide if your data sensitivity makes that unacceptable.
- Why does it matter where an AI vendor stores my agency's data?
- Physical or regional storage location affects which laws apply to your data, how quickly you can retrieve it if something goes wrong, and whether a vendor's claims about compliance are even plausible.
- Should I require a data processing agreement before we sign?
- Yes. A data processing agreement specifies how the vendor will handle, protect, and return your data. If a vendor will not commit to one in advance, you have no enforceable guarantee about data treatment after you sign.
- What do I do if a vendor's standard terms do not meet my agency's compliance requirements?
- Request an amendment to the contract. If the vendor refuses, do not sign. A vendor unwilling to negotiate on compliance is telling you they prioritize other clients' needs over yours.
- How do I know if a security certification like SOC 2 is actually meaningful?
- SOC 2 certification means an independent auditor verified certain security practices at a point in time. It is a minimum baseline, not a guarantee of zero risk. Ask for details about what was audited and request references from other agencies using the same tool.
- What should I do if the vendor gets acquired or shuts down a product?
- Before you sign, require a clause stating what happens to your data, how you will access it, and how long the vendor will maintain it. Without this, you could lose access to your own data or have it transferred to a buyer you never vetted.
- Who should review the vendor contract or data processing agreement?
- At minimum, your legal counsel and your compliance or IT officer. If you handle sensitive data (health, education, criminal justice), involve your compliance team early. Do not let speed override legal review.
Related articles
All articles