Blog

4 Questions to Ask Your Vendors About AI Use

Written by Tara Swaminatha | Sep 23, 2026, 6:59:03 PM

Generative AI is a growing part of vendor fulfillment services. Some vendors use it for research or document review, others use it for customer support and behind-the-scenes process automation.

While AI can expedite these services, its use also exposes customers to additional liabilities as they remain accountable for how third parties handle information.

Privacy laws and contract terms make that clear. Let’s take a look at the four questions you should ask of vendors to protect your company from this liability.

1. What Data Are You Feeding to AI and Why?

Start with the basics. Ask the vendor which of your files, records or communications flow into an AI tool and what purpose the tool serves. The answer should be specific.

Internal files, client information and regulated categories of data require different levels of protection. You also need to know who inside the vendor’s organization can view or use this material once it enters an AI environment. If the vendor cannot explain why a dataset is needed, that is a signal to pause.

Legal insight: Data controllers must ensure that processors stay within agreed terms under many frameworks, including the GDPR and the CCPA. Repurposing data without permission can create immediate compliance issues.

Read our blog: What You Need to Know Before Uploading Internal Documents to AI Tools.

2. How Are AI Inputs Being Stored, Shared and Deleted?

Once you know what goes into the system, focus on its information lifecycle.

A vendor should know how long inputs remain in the tool, if those inputs feed model training and how deletion works in practice. Some tools retain prompts or outputs to improve their models. Others rely on subcontractors that create further data flows. It can also be important to know whether AI inputs are ever stored outside of the primary AI system, since those secondary copies may follow different retention and deletion rules. Vendors should be able to explain these relationships and show how information moves between systems.

When vendors spell out their retention rules, it becomes much easier to judge the risk. Look for:

  • Concrete deletion timelines

  • Clear deletion triggers

  • A method to confirm deletion steps actually occur

A Data Processing Agreement can serve as the backbone for these commitments because it forces both sides to put obligations in writing. If a vendor struggles to explain how information is stored or erased, probe further. Keep pressing until you understand the process and the points where your data moves or disappears.

Segmenting vendor AI work within the vendor’s environment and/or your environment

If a vendor is (or you are) using a generative AI platform to support a portion of dev work in a business operation, your dev lead or vendor team lead should ensure the code is not being used to train other customer AI or in other business operations, and that you own the IP for all steps of the process. In addition, plan for system longevity and storage for anything archived to make sure your information at project closeout is fully purged from a vendor’s environment, including the AI that produced it.

Legal Tip: Ask whether the vendor can share a Data Processing Agreement or spell out the timelines and checks they use when deleting information.

Is Your AI Chat Really Private? We take a deep dive in our blog post here.

3. Can You Trust the AI’s Output?

Accuracy becomes a central issue once AI enters the workflow. These systems can misstate facts, misinterpret documents or build answers on shaky reasoning.

Ask your vendors how they judge the quality of what the tool produces and what measures they rely on to keep outputs dependable. Human review plays an important role. Many teams use a defined review process where someone with the right expertise looks over the AI’s work before it is shared with clients.

Consider how the vendor handles uncertainty. Some systems display confidence scores or flag results for manual review. These practices reduce the chance that an error flows into a report, filing or customer communication. This approach is particularly critical in regulated industries where a single inaccurate statement can create legal or reputational harm. A vendor should be able to explain exactly how this outcome is mitigated.

Risk Note: Output errors can introduce legal liability or reputational harm, especially in regulated industries.

4. Are There Other Ways You're Using AI That We Should Know About?

Vendor AI use is not always immediately recognizable, including:

  • Drafting support

  • Summarization tools

  • Customer service responses

  • Research assistance

  • Document analysis platforms

  • Generative AI code analysis/development

All of these tasks introduce touchpoints where your data may appear. Ask for a complete inventory of AI uses connected to your engagement. This is especially important when AI tools support decisions that affect your business, customers or rights.

Even background tasks deserve attention. A vendor might use AI to prepare email responses or early-stage research notes. While the output may look routine, the underlying system could be processing your information. Transparency is the only way to understand the true scope of use.

Legal Tip: Even non-obvious use cases (e.g., AI-assisted/augmented customer service responses) should be disclosed.

Take a look at our recent blog to learn more: Choosing Compliant AI Tools: What Legal and Privacy Teams Must Know.

Engaging in strong due diligence early in the vendor relationship will protect your organization and build a foundation for responsible AI use.

Vendors who can provide clear answers to these four questions will help decide whether a vendor’s AI practices align with your expectations. Internally, your Legal, IT and procurement teams can work together to evaluate risks and document requirements.

Explore our resources on responsible AI use or connect with the Zero Day Law to learn how we can help support AI use policies.