The questions you should be asking your suppliers about AI
4 minute read
Mitchell Lane
June 18th, 2026
You deserve to work with technology partners that prioritise your safety in every aspect of service. Our specialists, alongside experts at Bitsight, have put together the main questions you should be asking your suppliers about their AI use.
AI is woven into almost every piece of software your organisation uses. It’s in your security tools, your procurement platforms, your HR systems, your finance software. But here’s the thing: most organisations are so focused on how they use AI that they forget to ask how their vendors do. And that gap is where some of the most serious cyber and compliance risks now live.
According to Verizon’s 2026 Data Breach Investigations Report, breaches with third-party involvement have increased by 60% from last year’s dataset, reaching 48% of total breaches.
Think about the technology partnerships that work best for your organisation. Chances are, they’re built on transparency. The suppliers who have invested seriously in responsible AI governance are often the ones most eager to talk about it.
The AI model risk management market was valued at over $7.5 billion in 2024 and is projected to reach nearly $16 billion by 2030. That growth reflects the scale of investment going into AI governance across the industry. Ask your suppliers the below questions to ensure they’re ahead of the curve.
1. How do you control which data trains your AI models, and can our data be excluded?
Data governance is one of the most important conversations you can have with any AI-enabled vendor, and confident suppliers will have clear, well-rehearsed answers. What you want to understand is whether your data is used in model training, how it’s protected throughout that process, and whether you have the option to opt out.
It’s also worth asking how suppliers protect against model inference attacks (where a bad actor attempts to extract training data by interrogating the model) and how they guard against data poisoning, where corrupted inputs are introduced to manipulate model behaviour. A supplier with a mature AI programme will have robust controls in place for both and will be able to explain them clearly.
2. Which features use AI, and how does it influence decisions?
AI is transforming the way software makes decisions, from dynamic pricing and predictive maintenance to security alerts and workflow automation. Understanding where AI is involved in the products you use helps you manage your own governance and compliance obligations more effectively.
Ask your supplier to walk you through which features are AI-driven, how those models influence outputs, and what human oversight exists. The more business-critical the process, the more useful this transparency becomes, not just for risk management, but for helping your own teams understand and trust the tools they’re using day to day.
3. What AI models do you use, and where do they come from?
Not all AI models are built the same way, and understanding a supplier’s model provenance helps you build a more complete picture of your overall technology risk landscape. Is the supplier using a commercially developed model, something built in-house, or components drawn from open-source repositories?
You’ll also want to understand whether model training feeds into a shared, centralised system or runs as an isolated private model.
4. Do you have a formal AI governance framework and acceptable use policy?
By 2026, a written AI governance framework should be a standard part of any serious technology vendor’s documentation, and most leading vendors will already have one. Look for evidence of structure: a cross-functional AI council or governance board, regular policy reviews, and clear accountability for AI-related decisions.
Investment in this area is a sign that AI is being taken seriously at a leadership level, not just treated as a product feature. If your vendor has this in place, it also makes your own compliance and procurement processes significantly easier.
5. How do you protect the integrity of your AI models and infrastructure?
AI systems require their own layer of security controls, beyond traditional IT protections. This includes access management around who can interact with or modify models, monitoring and logging of model activity, and processes for scanning models for vulnerabilities or unexpected changes.
IBM’s 2025 Cost of a Data Breach Report found that 13% of organisations reported breaches involving AI models or applications, highlighting why this area deserves specific attention.
6. What safeguards exist against AI bias?
As AI takes on a larger role in business decision-making, ensuring those decisions are fair and consistent becomes increasingly important. Responsible vendors actively test their models for bias, document the results, and have processes in place to identify and address issues as they arise.
7. Can we turn off AI features if we need to?
Flexibility matters. In some regulatory environments, or for specific use cases, you may need the option to limit or disable certain AI-powered features. It’s a straightforward question, and the answer helps you understand how the product is architected and what your options are.
Some vendors offer AI as a configurable layer; others have it deeply integrated into core functionality. Neither is inherently right or wrong but knowing the answer before you commit means you can make an informed decision and plan accordingly.
Better questions lead to better partnerships
Our specialists at Phoenix and Bitsight believe the best technology partnerships are built on openness. Whether it’s how we use AI within our own products and services, how we help you govern AI across your organisation, or how we support you in assessing risk across your wider supplier base, we’re always happy to have the conversation.
Want to explore how Phoenix and Bitsight can help you build a more confident, more resilient approach to AI and cyber security?

