AI security questionnaire questions: what buyers ask and how to answer truthfully
This area changes quickly. Check your providers' current terms before you answer, and have counsel review commitments that will sit in a contract.
Over the past couple of years, many enterprise questionnaires have added a block on artificial intelligence. Even if you do not sell an "AI product", a buyer may ask whether AI features, AI-assisted support tools or AI coding assistants touch their data. The questions are usually simple. The risk is answering them from marketing language rather than from what your systems actually do.
First, build a factual inventory
Before answering any AI question, write down, in plain facts:
- Where AI is used in your product. Features that send customer content to a model, features that use only metadata, and features that use none.
- Where AI is used around your product. Support chat, internal summarisation, code assistants, transcription tools, analytics. Customer data can reach these through tickets, logs and screenshots even if the product itself has no AI.
- Which providers and which models are involved, under which account type (consumer, business, API, enterprise).
- What the contract with each provider says about retention, training and human review. Read the terms for the specific plan you use, not the provider's general homepage.
This inventory is the evidence behind every answer below. If you cannot produce it, the honest answer to most of these questions is "we are still documenting this", and you should say that rather than reassure.
The questions buyers ask, and how to answer
1. "Do you use AI or machine learning in the service?"
Answer yes or no first, then scope. A common problem is answering "No" because the core product is not AI, while an AI chatbot is processing support tickets that include customer data. Describe each use separately and say whether customer content is involved.
2. "Which third-party model providers do you use?"
Name them, and what each is used for. Treat them like any other subprocessor: they belong on your subprocessor list if they process customer data. If you use a provider only for internal, non-customer data, say that.
3. "Is customer data used to train models?"
This is the question buyers care about most. There are two separate parts: whether you train or fine-tune on customer data, and whether your providers may train on it. For each, the answer must come from a document: your own policy, and the provider's terms for your account type. If you do not train on customer data, say so and say how you enforce it. If you are not certain what a provider's terms allow for your plan, do not answer "No" until you have checked.
4. "How long do providers retain prompts and outputs?"
Retention by providers is often different from retention in your own systems, and can differ by plan (for example, some API plans have limited retention for abuse monitoring, with options to reduce it for eligible customers). State the period from the provider's current terms, name the plan, and say whether you have any zero-retention arrangement. If you do not know, say you are verifying it. Do not estimate.
5. "Can humans review prompts or outputs?"
Two places to check: your own staff (who can see logs and conversations, and under what access control) and provider staff (whether the terms permit human review for abuse monitoring or quality). Answer both.
6. "How do you defend against prompt injection and misuse?"
Be careful here. Prompt injection is an unsolved problem in the industry, and nobody can honestly claim to eliminate it. Describe the measures you actually have: limiting what a model can do (no write access to sensitive systems without confirmation), separating untrusted content from instructions where feasible, output handling, logging, and testing. Avoid "fully protected" or "immune".
7. "Where is data processed when AI features are used?"
Residency for AI can differ from residency for your main database. A model endpoint may be in a different region, and some providers route traffic across regions by default. State the region(s) used for AI processing and whether you can pin it.
8. "Can customers opt out of AI features?"
Say what exists today: a workspace setting, a contract term, or nothing. If opt-out requires a support request, say that.
9. "Do you have an AI governance policy?"
If you have a short acceptable-use or AI policy for staff and for features, name it and its version. If not, a one-page statement is a reasonable first step. Do not describe a "framework" you have not written.
10. "How do you validate model output accuracy and bias?"
Answer in terms of what you test and how often. If outputs are suggestions that a user reviews before acting, say so. Do not claim accuracy figures you have not measured.
Example answers (examples only)
These are illustrations of the pattern. Replace every fact with your own.
Question: Is customer data used to train third-party or in-house models?
Answer: We do not train or fine-tune any model on customer data. Our AI summarisation feature sends customer content to [Provider], under its business API terms, which state that API inputs are not used to train its models [cite document and date checked]. We have not negotiated additional terms beyond the provider's standard agreement.
Question: What is the retention period for prompts and outputs at your AI provider?
Answer: We do not yet have a confirmed retention figure from our provider for our current plan, and we do not want to state one we cannot support. We are verifying this with the provider and will update this answer. In our own systems, prompts and outputs are not stored beyond [period], per SEC-POL-009.
Question: Do you test for prompt injection?
Answer: Partly. The AI feature cannot take actions in the product; it only returns text for the user to review. We have tested it manually with adversarial inputs but have not had an independent assessment. We treat prompt injection as a continuing risk, not a solved one.
Common mistakes
- Answering for the product only. Forgetting internal tools such as support assistants and meeting transcription that touch customer data.
- Quoting a provider's marketing page. Terms differ by plan. Quote the contract or documentation for your plan, with the date checked.
- Treating "we don't train on your data" as complete. Buyers want to know about provider retention, human review and location too.
- Overpromising on security. "Fully secure against prompt injection" is not a claim anyone can defend.
- Letting answers go stale. Providers change terms, models and regions. Add AI answers to your regular review calendar.
A related point: how you answer questionnaires with AI
Buyers may also ask whether you use AI to fill in their questionnaire. It is a fair question. If you use a general chatbot, your documents may leave your environment, and generated answers may contain unsupported claims. If you use a tool, ask how it generates answers and where your data goes. The automation comparison sets out the differences between generative and extractive approaches.
Where to put the answers
Once verified, add each AI answer to your approved library, with the provider, plan, source document and date checked. Many of these questions sit beside the traditional ones on subprocessors and data retention. See the 20 common topics for how they connect.
Want answers that cite their sources? Use the free analyser to see which of your buyer's questions are AI-related, open a free workspace for a 10-answer preview, or look at the demo first.