Move Beyond Feature Demos
AI vendor reviews should examine data handling, model routing, retention, access control, prompt protection, audit logs, red teaming, and incident response.
Data Questions
Ask what data is processed, where it is stored, whether it trains models, how long it is retained, and whether sensitive inputs can be masked or blocked.
Runtime Questions
For agents and copilots, ask how tool calls are controlled, how prompt injection is detected, and whether high-risk actions support approval workflows.
Evidence Questions
Vendors should provide logs, attestations, control descriptions, test results, and integration paths that fit your security operations.