AI vendor due diligence
AI Vendor Due Diligence: The 2026 Checklist
Sixteen checks across eight areas, in the order they cause the most expensive regret if skipped, built for the buyer who has one call to get this right before the contract is signed.
An AI vendor is not a fixed thing you buy once. The model version moves, the contract terms rarely keep pace, and by the time something goes wrong (a training-data dispute, a subprocessor you never approved, a provider that raises prices 40% at renewal) the upper hand has already shifted to them. This checklist is the order to work through before any signature, built around the eight areas that cause the most expensive regret.
What data processing terms do you need before you sign?
Data terms decide who is liable when something leaks, and they are the clause vendors most often try to handle with a link to a policy page instead of contract language.
- A signed Data Processing Agreement with Standard Contractual Clauses in place wherever the vendor processes EU personal data outside the EEA.
- A written prohibition on using your prompts, documents or outputs to train or fine-tune any model, including in aggregated or anonymised form, with no policy-page carve-out.
How do you avoid getting locked into one model or provider?
Switching cost is usually invisible at signing and expensive at renewal. Ask what happens the day you want to leave, not just what happens while things are working.
- An abstraction layer or documented interface so the underlying model can be swapped without a full rebuild of your integration.
- The contractual right to run your own evaluation set against a candidate replacement before you are asked to migrate anything.
What does the EU AI Act require from your vendor?
The Act is no longer theoretical. General-purpose AI model obligations took effect August 2, 2025, and the rules for high-risk systems under Annex III became applicable August 2, 2026, so any vendor still waving this off as "future regulation" is behind, not ahead.
- The vendor's own risk classification for the system (minimal, limited, or high-risk), stated in writing, not answered verbally on a call.
- Technical documentation and a risk management file if the use case sits in a high-risk category, plus written confirmation the system tells users they are interacting with AI where that is legally required.
What security posture should you verify before signing?
A vendor with strong security posture can produce evidence in a day. One without it will ask for a week and hand you a summary page instead of a document.
- A current penetration test summary and a named security contact you can actually reach.
- SOC 2 Type II or ISO 27001 certification, or a credible roadmap with dates if certification is still in progress.
What exit and portability rights do you need?
Exit terms are worth negotiating hardest, because they are the ones you will never think to check again once the system is live and the contract is signed.
- Export rights over your prompts, evaluation sets, retrieval indexes and any fine-tuned weights, in a usable, non-proprietary format.
- A transition assistance clause covering a defined number of weeks after termination, plus evidenced deletion of your data once you leave.
What SLA terms actually matter?
An SLA that lists an uptime percentage on a marketing slide is not a service level agreement. A real one ties every number to a remedy.
- An uptime commitment tied to a service credit, with the credit amount specified, not left to goodwill.
- Latency and response-time thresholds sized to your actual workload, plus a support escalation path with named response times by severity.
Who owns the IP in your prompts and outputs?
This is the clause most buyers assume rather than read, and the assumption is wrong more often than not.
- Explicit assignment of output ownership to you in the contract, not an implied license that leaves ambiguity if the relationship ends badly.
- Confirmation that your prompts and fine-tuning data remain your property, even where you have separately consented to their use in improving a shared model.
What should the subprocessor list disclose?
Every AI vendor has subprocessors, whether that is a cloud host, a model provider, or an evaluation tool. The question is whether you got to see the list before you signed or found out about it later.
- A full list of subprocessors, the countries they operate in, and what each one actually touches in your data pipeline.
- An advance notice period before that list changes, with a genuine right to object rather than a passive notification.
The two questions that settle most of it
Ask who is accountable for accuracy in month four, after the honeymoon period and the original sales engineer have moved on. Then ask to speak to a reference running the same use case in production, not a pilot. A vendor with a real answer to both is worth the rest of this checklist. A vendor with neither is selling a demonstration dressed up as a product.
If you are weighing whether to run this evaluation yourself or bring in outside eyes, an AI consulting company that has sat on both sides of these contracts will catch what a first read misses, and the same discipline applies before you even pick who builds the system: see how to choose an AI agency for the vetting questions that come before the vendor questions above.
Frequently asked questions
What is the single most important item in AI vendor due diligence?
The written prohibition on using your data to train or improve any model. Everything else (security, SLA, IP) is negotiable after the fact. A vendor that trained on your inputs without consent cannot be undone by a later contract amendment.
Does the EU AI Act apply if my vendor is based outside the EU?
Yes, if the system is used or its output affects people in the EU. The Act applies by market, not by vendor headquarters. Ask any non-EU vendor for their EU representative and their risk classification in writing.
How long should a vendor due diligence review take?
A focused review against a checklist like this one takes two to five business days once the vendor responds. The bottleneck is almost never your side, it is waiting on the vendor to produce documentation that should already exist.
What is a reasonable subprocessor notice period?
Thirty days before a new subprocessor is added is standard. Anything shorter than fourteen days is worth pushing back on, since it does not leave enough time to assess a new party touching your data.
Should due diligence differ for a pilot versus a full production contract?
The data processing, EU AI Act and IP terms apply from day one of a pilot, because a pilot still touches real data. Exit and SLA terms can be lighter for a short pilot, then tighten before the production contract is signed.
Related
Ready to put AI to work?
Book a discovery audit and we will map the highest-ROI AI agents and automations for your business.
Book a discovery audit →