# Ten questions to ask an AI development vendor

Written for the person whose job is to say no. Every question asks for something that either already exists or does not.

Use them in RFPs and vendor security reviews. No attribution needed.

1. What existed before the build started? Show me the threat model and the DPIA, with their dates.
2. Pick one change from last quarter, at random: who made it, who approved it, when, and why?
3. Run the same input twice. Show me the diff.
4. Which run is in production for me, and what evidence attaches to that run, not to the tool that made it?
5. When you regenerate the system, what is guaranteed to stay the same, in writing?
6. What must every delivery pass before it reaches me, and can I read it before I sign?
7. Show me one delivery that failed a check, and what happened next.
8. Where does my data live during the build, and what enforces that: a policy or a control?
9. If you disappeared tomorrow, could my team rebuild and run this from the handover alone?
10. Which model providers sit underneath you, and what of mine reaches them?

---

Our answers, with receipts: https://tai.ga/en/resources/ten-questions-ai-development-vendor/

Score your own last AI project against the same bar: https://tai.ga/gate
