Key Takeaways
- The first three articles in this series covered the governance gap, shadow AI, and agent identity and access risk. This final piece turns that argument into a practical tool: the ten questions to ask any vendor before you buy an enterprise AI platform.
- Gartner expects that by 2028, more than half of enterprises will use a dedicated AI security platform to govern third-party and custom AI, when incidents involving AI-driven applications will account for half of all incident-response effort.
- PwC's 2026 survey of 3,887 executives across 72 countries found that 39% reported their most damaging breach of the past three years cost more than USD 500,000; IBM's data shows 63% of organisations have no AI governance policy at all.
- The ten questions fall into four lenses — where the data goes, what controls it, what evidence remains, and whether the vendor can prove it — which is simply third party risk management applied to an AI vendor.
- Treat this checklist as a written questionnaire, sent to every shortlisted vendor before the demo: a demo is designed to show capability; a questionnaire is designed to reveal architecture.
- Score every answer on three levels — contractual, configurable, or merely aspirational — because only the first two actually protect you.
This series has argued one thing from three directions: AI transformation stalls at the point where governance runs out. Shadow AI is what happens when there is no sanctioned door. Agents that read and act on your systems are what happens when permission does not travel with the request. The final piece of the argument is practical. At some point a platform will be chosen, and the questions asked in that process will decide whether the CISO is signing off on a governed capability or inheriting an unmanaged one.
The market is moving faster than governance
The market is moving this way regardless. Gartner expects that by 2028, more than half of enterprises will use a dedicated AI security platform to govern third-party and custom AI applications, when incidents involving AI-driven applications will account for half of all cybersecurity incident-response effort. [1] PwC's 2026 survey of 3,887 executives across 72 countries found that 39% reported their most damaging breach of the past three years cost more than USD 500,000. [2] IBM's breach data still shows 63% of organisations with no AI governance policy at all. [3]

Figure 1 — The market, by the numbers.
The questions below are the ones I would want answered — in writing — before any enterprise AI platform reached procurement. This is, in substance, a third party risk management exercise, not a box-ticking formality. They are grouped into four lenses: where the data goes, what controls it, what evidence remains, and whether the vendor can prove any of it.
Ten questions

Figure 2. The ten questions map to four lenses. Most vendor decks answer the first well and the other three vaguely.
| # | The question | Why it matters | What a good answer looks like |
|---|---|---|---|
| 1 | Where are our prompts, documents and outputs processed and stored — and can we require the EU? | Data residency is a GDPR transfer question and, for many sectors, a supervisory expectation. | Named EU region; no silent routing to non-EU model endpoints; residency stated in the contract. |
| 2 | Is any of our data ever used to train or fine-tune a model — yours or a third party's? | Training on customer data is the most common hidden clause in consumer-grade AI terms. | A flat, contractual "never", covering every model the platform routes to. |
| 3 | Which models can we use, and can we switch or combine them without rebuilding? | Single-model lock-in turns a pricing or policy change by one provider into your migration project. | Multiple leading LLMs behind one interface; knowledge and context stay portable. |
| 4 | How is access controlled — by organisation, workspace and user — and can workspaces be walled from each other? | Shared licences and flat permissions are how finance data ends up in the marketing assistant. | Three-tier IAM, least-privilege roles, per-workspace assignment of knowledge, agents and connectors. |
| 5 | What does the platform detect inside prompts and responses, and what can it do about it? | Keyword DLP misses meaning; a filter that only blocks stops work and drives users to shadow tools. | Semantic detection of PII, financial, health data, credentials and injection; alert, block or mask with severity levels. |
| 6 | How are agents' permissions scoped, and what stops an agent carrying data from an internal system into an external call? | Agents cross the trust boundary in both directions; each hop can be approved while the sequence leaks. | Agent permissions bound to the invoking user and workspace; the firewall inspects every outbound call, not just the user's prompt. |
| 7 | What is logged, can we export it, and is it tamper-evident? | Without an immutable record you cannot investigate, and you cannot prove to a regulator what you did. | Separate logs for system, dialogue, automation, sharing and connectors; immutable storage; downloadable on demand. |
| 8 | Can moderation events feed our SIEM and produce a report a DPO can hand to a supervisory authority? | Evidence that lives only inside the vendor's console is evidence you do not control. | SIEM integration; moderation records naming workspace, user, policy breached, severity and action. |
| 9 | Which independent certifications do you hold, and will you share the security pack, DPA and encryption details before we sign? | Self-assessment is not assurance. If a vendor will not share documentation pre-sale, assume it does not exist. | ISO/IEC 27001:2022 from an accredited body; infrastructure certifications; a security & compliance pack on request. |
| 10 | How does the platform help us meet the EU AI Act and GDPR — literacy, logging, human oversight, purpose limitation? | Its high-risk obligations — deferred by the 2026 Omnibus package to December 2027 (standalone systems) and August 2028 (embedded systems) — are still coming; either way, the platform is where most of the evidence for this eu ai act checklist will come from. | Compliance by architecture: built-in logging, oversight controls and documentation mapped to the Act's articles. |
How to use this checklist
A fillable one-page version of this checklist — three vendor columns, a three-level score and a notes field — is available from AnyInsight: leave a few basic details on our website (URL to be added) and we'll send it straight to your inbox, so you can put the ten questions to every shortlisted vendor as a written questionnaire before the demo, not after. Demos are designed to show capability; questionnaires reveal architecture.

Figure 3 — Score every vendor answer on three levels.

Figure 4 — Demos are designed to show capability; questionnaires reveal architecture.
Weight the lenses by your exposure. A bank or insurer under DORA will care most about evidence and vendor assurance; a manufacturer wiring agents into its ERP should press hardest on question 6. And involve the DPO from the first round — the answers to questions 1, 2, 7 and 8 are theirs to accept or reject.
How AnyInsight answers
We wrote this checklist because it is the one we designed AnyInsight to pass. Data is hosted in the EU and never used for training. More than twenty leading LLMs sit behind one governed portal, with a three-tier IAM, walled workspaces and per-workspace assignment of knowledge, agents and the 500-plus MCP connectors. A zero-trust GenAI firewall inspects every prompt, response and agent call semantically, and can alert, block or mask by severity. Five log types and an immutable Data Vault feed your SIEM and give the DPO a downloadable record naming workspace, user, policy, severity and action.
The platform is ISO/IEC 27001:2022 certified by TÜV NORD — the kind of third-party issued, not self-declared, iso 27001 ai certification question 9 asks about — and built for GDPR and the EU AI Act by architecture rather than by add-on.

Figure 5 — How AnyInsight answers the four lenses.
Conclusion
These ten questions turn "where does the data go, what controls it, what evidence remains, and can the vendor prove it" into a third party risk management exercise you can check off rather than take on faith. Send it out as a written questionnaire, score every answer as contractual, configurable or roadmap, and bring the DPO in from round one.
It is also what this series has argued throughout: governance is not the brake on AI transformation — it is what lets AI transformation scale safely. From the governance gap in Part 1, to shadow AI, to agent identity and access, to today's procurement checklist — the same argument, four different scenes.
If you're about to buy an enterprise AI platform, request our security & compliance pack, or take these ten questions straight to any vendor on your shortlist — including us.

Figure 6. This series ran four parts; this is Part 4, the final instalment. Part 1 covered the governance gap; Part 2 covered shadow AI; Part 3 covered agent identity and access.
If you would like to put the questionnaire to us, request the security & compliance pack — certifications, DPA and encryption details — or start a free trial at www.anyinsight.ai. Either way, ask every vendor the same ten questions. The ones who answer all of them in writing are the ones who have thought about your CISO before they thought about your budget.
![[Governed AI Transformation 03]If AI Can Read It, AI Can Leak It](http://www.anyinsight.fr/cdn/shop/articles/Governed_AI_Transformation_03_If_AI_Can_Read_It_AI_Can_Leak_It_36e2b4b3-3d64-4e02-9cad-1d9b6687daf5.png?v=1789973238&width=900)
![[Governed AI Transformation 02]Shadow AI Is Already Inside Your Company. Banning It Won't Work.](http://www.anyinsight.fr/cdn/shop/articles/Governed_AI_Transformation_02_Shadow_AI_Is_Already_Inside_Your_Company_Banning_It_Won_t_Work.png?v=1789973232&width=900)
![[Governed AI Transformation 01]The Bottleneck Isn't Ambition. It's AI Governance.](http://www.anyinsight.fr/cdn/shop/articles/Governed_AI_Transformation_01_The_Bottleneck_Isn_t_Ambition_It_s_AI_Governance_30b77d6a-6b2f-49e4-8f73-703f00562879.png?v=1789973220&width=900)