AI Vendor Due Diligence: What to Check Before You Sign

AI vendor due diligence is the same exercise you already run on any processor, plus four questions that did not exist five years ago and that most security questionnaires still do not ask.

The general parts are well covered elsewhere. This is the delta.

The four AI-specific questions

Any AI vendor processing personal data on your behalf is a processor under GDPR Article 28, so a valid DPA is a legal requirement rather than a nice-to-have. Assume that part is table stakes and go looking for these.

1. Training defaults, per tier

The one that catches people. Commercial tiers at the major vendors contractually prohibit training on customer data. Consumer tiers frequently permit it, at the same brand, under the same logo.

Your diligence covers the enterprise agreement you signed. It says nothing about the free account an employee opened with a work email, which runs under consumer terms and a different default. Two people at your company can paste the same document into what looks like the same product and get opposite outcomes.

These defaults also move. OpenAI and Anthropic have both changed consumer defaults within roughly the last eighteen months. A policy you verified last year is not a policy you have verified.

2. Retention

Ask how long inputs and outputs are held, and separate the API answer from the product answer, because they are usually different.

API retention commonly runs somewhere between 7 and 30 days. Anthropic has been at 7 days, described in vendor comparisons as the strongest default in the market; OpenAI has been at 30. Zero data retention exists at several vendors but generally requires approval rather than a checkbox, which means it needs to be asked for during procurement rather than discovered afterwards.

3. Subprocessor depth

AI vendors stack subprocessors faster than legacy SaaS did, and the chain is longer than most buyers expect. A single AI feature routinely involves the model provider, the cloud it runs on, a content moderation service, an analytics provider and security tooling.

Each is a place your data goes. This deserves its own treatment, in Subprocessors: The Vendors Behind Your Vendor.

4. Transfer mechanism, read properly

Standard Contractual Clauses in the 2021 form, the UK Addendum where relevant, and a transfer impact assessment. None of that is new.

What is worth your attention is the carve-outs. Vendors advertise EU-only processing and then except support access, abuse monitoring, or a subprocessor that is not regional. An EU-only claim needs reading line by line, because the exceptions are where the transfers actually happen.

Why the paperwork alone is not enough

A DPA describes an intended arrangement at a moment in time. It does not tell you what is running today.

Three things change after signature and none of them require your consent. Subprocessors get added, and the notice window at most AI vendors has compressed to somewhere between 14 and 30 days, which is not long enough for a real assessment. Defaults get revised, as the consumer flips demonstrate. And the vendor ships a new AI feature into a product you already licensed, which changes what the software does with your data without changing a word of your contract.

That last one is the gap between due diligence as practised and due diligence as needed. Your review was accurate. The product moved.

A workable process

  1. Ask the tier question explicitly. Not “do you train on customer data” but “which of your tiers permit training, and what governs an employee using a free account with a work email”. The second question gets a much more interesting answer.
  2. Get zero data retention decided during procurement. It is an approval, not a setting, and asking later means asking without leverage.
  3. Require the published subprocessor list and an objection mechanism, and negotiate the notice window upward if you can. Fourteen days is not a diligence period.
  4. Diff the DPA annually. Vendors update these pages quietly. Keep a dated copy of what you agreed to so you can see what moved.
  5. Watch the product, not just the contract. Vendor changelogs are where new data processing shows up first.

That last step is the one nobody staffs, and it is what CopperFeed records: dated entries for the releases and repricings that change what your software does.

The training question in detail is in Does Your AI Vendor Train on Your Data. And none of this reaches tools nobody told you about, which is shadow AI.

Vendor-specific retention and training defaults cited here reflect published comparisons at the time of writing and change without notice. General guidance, not legal advice. Verify current terms and take advice on your own obligations.