[Governed AI Transformation 04] Ten Questions to Ask Before You Buy an Enterprise AI Platform

A CISO's third party risk management checklist for the EU AI Act era.

Key Takeaways

  • The first three articles in this series covered the governance gap, shadow AI, and agent identity and access risk. This final piece turns that argument into a practical tool: the ten questions to ask any vendor before you buy an enterprise AI platform.
  • Gartner expects that by 2028, more than half of enterprises will use a dedicated AI security platform to govern third-party and custom AI, when incidents involving AI-driven applications will account for half of all incident-response effort.
  • PwC's 2026 survey of 3,887 executives across 72 countries found that 39% reported their most damaging breach of the past three years cost more than USD 500,000; IBM's data shows 63% of organisations have no AI governance policy at all.
  • The ten questions fall into four lenses — where the data goes, what controls it, what evidence remains, and whether the vendor can prove it — which is simply third party risk management applied to an AI vendor.
  • Treat this checklist as a written questionnaire, sent to every shortlisted vendor before the demo: a demo is designed to show capability; a questionnaire is designed to reveal architecture.
  • Score every answer on three levels — contractual, configurable, or merely aspirational — because only the first two actually protect you.

This series has argued one thing from three directions: AI transformation stalls at the point where governance runs out. Shadow AI is what happens when there is no sanctioned door. Agents that read and act on your systems are what happens when permission does not travel with the request. The final piece of the argument is practical. At some point a platform will be chosen, and the questions asked in that process will decide whether the CISO is signing off on a governed capability or inheriting an unmanaged one.

The market is moving faster than governance

The market is moving this way regardless. Gartner expects that by 2028, more than half of enterprises will use a dedicated AI security platform to govern third-party and custom AI applications, when incidents involving AI-driven applications will account for half of all cybersecurity incident-response effort. [1] PwC's 2026 survey of 3,887 executives across 72 countries found that 39% reported their most damaging breach of the past three years cost more than USD 500,000. [2] IBM's breach data still shows 63% of organisations with no AI governance policy at all. [3]

Chart of market statistics — 50% of enterprises using a dedicated AI security platform by 2028, 50% of incident response involving AI-driven applications, 39% of breaches over USD 500,000, 63% with no AI governance policy

Figure 1 — The market, by the numbers.

The questions below are the ones I would want answered — in writing — before any enterprise AI platform reached procurement. This is, in substance, a third party risk management exercise, not a box-ticking formality. They are grouped into four lenses: where the data goes, what controls it, what evidence remains, and whether the vendor can prove any of it.

Ten questions

Diagram mapping ten vendor questions to four lenses — data, control, evidence, vendor

Figure 2. The ten questions map to four lenses. Most vendor decks answer the first well and the other three vaguely.

Table 2. Ten questions for any enterprise AI platform, with the reason each matters and what an acceptable answer contains.
# The question Why it matters What a good answer looks like
1 Where are our prompts, documents and outputs processed and stored — and can we require the EU? Data residency is a GDPR transfer question and, for many sectors, a supervisory expectation. Named EU region; no silent routing to non-EU model endpoints; residency stated in the contract.
2 Is any of our data ever used to train or fine-tune a model — yours or a third party's? Training on customer data is the most common hidden clause in consumer-grade AI terms. A flat, contractual "never", covering every model the platform routes to.
3 Which models can we use, and can we switch or combine them without rebuilding? Single-model lock-in turns a pricing or policy change by one provider into your migration project. Multiple leading LLMs behind one interface; knowledge and context stay portable.
4 How is access controlled — by organisation, workspace and user — and can workspaces be walled from each other? Shared licences and flat permissions are how finance data ends up in the marketing assistant. Three-tier IAM, least-privilege roles, per-workspace assignment of knowledge, agents and connectors.
5 What does the platform detect inside prompts and responses, and what can it do about it? Keyword DLP misses meaning; a filter that only blocks stops work and drives users to shadow tools. Semantic detection of PII, financial, health data, credentials and injection; alert, block or mask with severity levels.
6 How are agents' permissions scoped, and what stops an agent carrying data from an internal system into an external call? Agents cross the trust boundary in both directions; each hop can be approved while the sequence leaks. Agent permissions bound to the invoking user and workspace; the firewall inspects every outbound call, not just the user's prompt.
7 What is logged, can we export it, and is it tamper-evident? Without an immutable record you cannot investigate, and you cannot prove to a regulator what you did. Separate logs for system, dialogue, automation, sharing and connectors; immutable storage; downloadable on demand.
8 Can moderation events feed our SIEM and produce a report a DPO can hand to a supervisory authority? Evidence that lives only inside the vendor's console is evidence you do not control. SIEM integration; moderation records naming workspace, user, policy breached, severity and action.
9 Which independent certifications do you hold, and will you share the security pack, DPA and encryption details before we sign? Self-assessment is not assurance. If a vendor will not share documentation pre-sale, assume it does not exist. ISO/IEC 27001:2022 from an accredited body; infrastructure certifications; a security & compliance pack on request.
10 How does the platform help us meet the EU AI Act and GDPR — literacy, logging, human oversight, purpose limitation? Its high-risk obligations — deferred by the 2026 Omnibus package to December 2027 (standalone systems) and August 2028 (embedded systems) — are still coming; either way, the platform is where most of the evidence for this eu ai act checklist will come from. Compliance by architecture: built-in logging, oversight controls and documentation mapped to the Act's articles.

How to use this checklist

A fillable one-page version of this checklist — three vendor columns, a three-level score and a notes field — is available from AnyInsight: leave a few basic details on our website (URL to be added) and we'll send it straight to your inbox, so you can put the ten questions to every shortlisted vendor as a written questionnaire before the demo, not after. Demos are designed to show capability; questionnaires reveal architecture.

Three-level scoring model for vendor answers — contractual, configurable, aspirational

Figure 3 — Score every vendor answer on three levels.

Diagram comparing a vendor demo (shows capability) with a written questionnaire (reveals architecture)

Figure 4 — Demos are designed to show capability; questionnaires reveal architecture.

Weight the lenses by your exposure. A bank or insurer under DORA will care most about evidence and vendor assurance; a manufacturer wiring agents into its ERP should press hardest on question 6. And involve the DPO from the first round — the answers to questions 1, 2, 7 and 8 are theirs to accept or reject.

How AnyInsight answers

We wrote this checklist because it is the one we designed AnyInsight to pass. Data is hosted in the EU and never used for training. More than twenty leading LLMs sit behind one governed portal, with a three-tier IAM, walled workspaces and per-workspace assignment of knowledge, agents and the 500-plus MCP connectors. A zero-trust GenAI firewall inspects every prompt, response and agent call semantically, and can alert, block or mask by severity. Five log types and an immutable Data Vault feed your SIEM and give the DPO a downloadable record naming workspace, user, policy, severity and action.

The platform is ISO/IEC 27001:2022 certified by TÜV NORD — the kind of third-party issued, not self-declared, iso 27001 ai certification question 9 asks about — and built for GDPR and the EU AI Act by architecture rather than by add-on.

Checklist-style diagram of how AnyInsight answers the four lenses

Figure 5 — How AnyInsight answers the four lenses.

Conclusion

These ten questions turn "where does the data go, what controls it, what evidence remains, and can the vendor prove it" into a third party risk management exercise you can check off rather than take on faith. Send it out as a written questionnaire, score every answer as contractual, configurable or roadmap, and bring the DPO in from round one.

It is also what this series has argued throughout: governance is not the brake on AI transformation — it is what lets AI transformation scale safely. From the governance gap in Part 1, to shadow AI, to agent identity and access, to today's procurement checklist — the same argument, four different scenes.

If you're about to buy an enterprise AI platform, request our security & compliance pack, or take these ten questions straight to any vendor on your shortlist — including us.

Series progress graphic — Governed AI Transformation, Part 4 of 4 (final)

Figure 6. This series ran four parts; this is Part 4, the final instalment. Part 1 covered the governance gap; Part 2 covered shadow AI; Part 3 covered agent identity and access.

If you would like to put the questionnaire to us, request the security & compliance pack — certifications, DPA and encryption details — or start a free trial at www.anyinsight.ai. Either way, ask every vendor the same ten questions. The ones who answer all of them in writing are the ones who have thought about your CISO before they thought about your budget.

Risorsa in evidenza

10 Questions Before You Buy an Enterprise AI Platform

Use this checklist to evaluate whether a platform has the governance, security, identity, and access controls needed to scale AI safely.

Inizia oggi a costruire con Trusted AI

Crea il tuo account AnyInsight.ai e usufruisci di una prova gratuita di 14 giorni con accesso completo a tutte le funzionalità.
Avvia prova gratuita

Informazioni su AnyInsight.ai

AnyInsight.ai è una piattaforma sicura di AI workforce, powered by HEARTBOT AI Inc. , che aiuta le aziende a creare, distribuire e gestire AI agents senza coding. Basata su un’architettura zero-trust, offre controllo degli accessi integrato, prompt injection protection, governance e compliance, così le aziende possono scalare l’AI con fiducia.

Frequently asked questions

Q1: How is this checklist different from a typical vendor security questionnaire?
A1: Most generic vendor questionnaires are built for software procurement in general, and rarely ask about model training data, agents crossing system boundaries, or AI-specific record-keeping duties. These ten questions are a third party risk management checklist built specifically for enterprise AI platforms, with four lenses — data, control, evidence, vendor — mapped to the risks that are unique to AI.
Q2: What if a vendor won't answer a question in writing?
A2: Treat that as the answer. A vendor unwilling to put something in a contract or document usually means the capability sits at the "roadmap slide" level rather than "contractual" or "configurable". You can ask them to add it to the contract, or simply score that question as a fail when comparing vendors.
Q3: Do smaller companies really need a vendor risk assessment this thorough?
A3: Yes, though you can weight it by risk. A smaller company may not face sector rules like DORA, but data residency, training clauses, access control and record-keeping are risks any organisation takes on the moment it hands data to a third-party AI platform — these questions shouldn't be skipped just because the company is small.
Q4: Does an ISO 27001 certification really guarantee a vendor's AI security is good?
A4: An independent certification like ISO/IEC 27001:2022 proves the vendor's security management system has passed third-party audit, rather than self-declaration — which carries more weight than "we take security seriously" marketing language. But certification alone won't tell you how agent permissions are designed, which is why question 9 has to be asked alongside the other nine, not treated as a single deciding factor.
Q5: Which EU AI Act obligations are actually in force right now, and which aren't?
A5: Article 4's AI literacy duty has been in force since 2 February 2025. The high-risk system obligations, originally due in August 2026, have under the 2026 Omnibus simplification package been deferred separately to December 2027 (standalone systems) and August 2028 (embedded systems). In other words, the obligations haven't disappeared — only the timeline has moved — so asking vendors for evidence against this eu ai act checklist now, rather than waiting until the deadline is close, carries far less risk.
Disclaimer

The insights and information shared in this article regarding the EU AI Act are for informational purposes only and do not constitute professional legal advice. We do not provide legal consulting services and assume no legal liability for any decisions made based on the content of this publication. As the interpretation and application of laws can vary depending on specific circumstances, we strongly recommend consulting a qualified legal advisor or attorney before making any compliance assessments or business decisions.

Reference

[1] Gartner, "Gartner Predicts AI Applications Will Drive 50% of Cybersecurity Incident Response Efforts by 2028" (March 2026). https://www.gartner.com/en/newsroom/press-releases/2026-03-17-gartner-predicts-ai-applications-will-drive-50-percent-of-cybersecurity-incident-response-efforts-by-2028

[2] PwC, "2026 Global Digital Trust Insights" (October 2025). https://www.pwc.com/gx/en/issues/cybersecurity/global-digital-trust-insights-sectors.html

[3] IBM & Ponemon Institute, "Cost of a Data Breach Report 2025". https://www.ibm.com/reports/data-breach

Continua a esplorare

Articoli correlati

Visualizza tutti gli articoli