Four Questions to Ask Every AI Vendor

← back to home

Pillar 01 // Ownership
questions.md

$ ask --before-you-sign

Four questions to ask every AI vendor

Whose name are the accounts under where the building happens. What can you export tomorrow, and in what format. What happens to your data if you cancel, and is that on paper. What keeps working without them, and what doesn't. Four questions, ten minutes, and they work with every vendor in this market. Including us, and the answer to the last one isn't fully comfortable in our case either.

DD DataDrift Digital • July 10, 2026 • 8 min

This post is useful even if you're buying from someone else. That's the point: the questions below aren't designed to make us look good, they're designed to make the difference visible between vendors who've thought about this and vendors who avoid the topic.

There's a reason this matters. When we literally asked the question will I own my AI system to two AI search engines in July 2026, we mostly got back law firms writing about copyright on AI-generated text. That's a different topic. Of the parties that actually build systems, exactly one answered the question from the build side. So if you want a clear answer here, you have to go get it yourself.

01 / the definitionWhich questions do you ask an AI vendor before signing?

Four, and all four are about the day you want to leave. Whose name the accounts are under, what you can export, what happens to your data on cancellation, and what keeps working without the vendor. Together they say more about a supplier than any demo, because they measure something a demo doesn't show.

What you're measuring isn't technology but construction. Two vendors can build exactly the same thing and still end up with an opposite outcome on the day something goes wrong. That difference lies in who owns what, and it's almost never visible in what you get to see.

02 / question oneWhose name are the accounts under where the building happens?

This is the most important of the four, and it comes first because all the other answers depend on it. Building happens inside systems: a CRM, mailboxes, a calendar, telephony. The question is simple: are those under your name and do you pay for them, or are they under the vendor's name with you given a login.

GOODAn answer that includes an account name. "It runs in your CRM, on your subscription, we get access as a user." If in doubt: ask who receives the invoice for that subscription.
BAD"You get your own environment from us." That sounds like ownership and means the opposite. Also bad: "technically it doesn't matter" — technically it indeed doesn't matter, and legally it matters entirely.

Why it matters: this single choice determines whether cancelling is an action or a move. If everything is under your name, you revoke the vendor's access and keep everything. If it's under theirs, you depend on their cooperation at exactly the moment you no longer agree.

03 / question twoWhat can I export tomorrow, and in what format?

Note the word tomorrow. Not "can I get my data" — everyone says yes to that. The question is whether you can pull it out yourself today, without a request, without waiting, and without anyone's approval.

GOODA format and a button. "Contacts and notes as CSV, documents as PDF, and you can do that yourself at any moment." Even better if someone just shows it to you.
BAD"Of course you get your data." An answer without a format isn't an answer. Also bad: "we'll create an export for you" — then your access depends on their schedule.

Why it matters: exportability is the only form of ownership you can verify without a lawyer. Everything on paper has to be enforced. An export button only has to be pressed.

While you're at it, explicitly ask about the part people forget: the documented way of working. You usually do get your customer data. The description of how you work, the one that came out of the conversations, is at least as valuable and gets stuck more often than you'd think.

Don't ask whether you own it. Ask what you can take with you tomorrow.

04 / question threeWhat happens to my data if I cancel, and is that on paper?

Two questions in one, and the second part is the real one. Everyone gives a reassuring verbal answer. The question is whether it's written down somewhere you can still read back in two years, when the people you're talking to now may no longer work there.

GOODA reference to a clause in the agreement, plus a retention period. "Your data stays yours, we delete our copies within thirty days, it's in clause so-and-so." Plus a data processing agreement without you having to ask for it.
BAD"We're always careful about that." That's a character description, not an agreement. Also bad: a vendor who doesn't know what a data processing agreement is, while about to work with your customer data.

Why it matters: this is the point where a pleasant working relationship and a solid agreement part ways. You don't need the agreement while things go well. You need it on the one day things go badly, and by then it's too late to make it.

05 / question fourWhat keeps working without you, and what doesn't?

This question is a character test. Because there's no vendor for whom everything keeps working. Someone who only names benefits in response to this question either hasn't understood it or hopes you won't.

GOODA split you can repeat back. "This keeps standing, this stops." A vendor who can name their own essential part knows what they deliver.
BAD"Everything just keeps working for you." Then either nothing was built, or the answer is wrong. Also bad: a long explanation that dodges the question.

Why it matters: the answer tells you exactly what you're paying for. What stops when the vendor leaves is what the vendor does. If nothing stops, you're buying maintenance on something you already had yourself.

06 / honestlyAnd if we get asked those four questions ourselves?

Then the first three are comfortable and the fourth not entirely. That's exactly why we dare to write the questions this sharply: they'd be worthless if we only asked them where it suited us.

  • Accounts. Under your name. We build inside your existing systems, not in an environment of ours that you get a login for.
  • Export. Your data lives in systems you manage yourself, so you export without asking us anything. The documented way of working is included and can be requested as text.
  • Cancelling. You keep your accounts, your data and your documented way of working. What stops is the maintenance on the layer in between.
  • Without us. This is where the discomfort sits. The integrations and instructions that do the work are our build layer, and we don't transfer those. Cancel, and the automated work stops and you're back to manual work. Back to manual work isn't back to zero, but it's a real loss and we'd rather name it ourselves.

If you're looking for a vendor who hands you the complete engine so you'll never need anyone again, that's not us. That's explained further in who owns it once it works, together with the question of where the dependency actually sits.

There's a fifth question that isn't about the vendor but about you: is this the right moment. The most common reason such a project fails isn't the vendor but the timing. How to test that for yourself is in how do you know you're ready for an AI system, and what a system doesn't do for you regardless in what an AI system won't do for you.

Frequently asked questions
Which questions do I ask an AI agency before signing?+
Four, and all four are about the day you want to leave. Whose name are the accounts under where the building happens. What can I export tomorrow, and in what format. What happens to my data if I cancel, and is that on paper. What keeps working without you, and what doesn't. A vendor who gives a concrete answer to all four has thought it through.
Do I own the prompts and the workflows?+
Usually not, and that's not necessarily a problem as long as it's clear beforehand. The instructions and integrations are the builder's way of working and most parties don't transfer those. What you do need to secure is that your customer data and your own documented way of working are and remain exportable. Keep asking until you know which side of the line each part falls on.
What if my vendor stops in two years?+
That depends entirely on question one. If the accounts are under your name, your systems and your data simply keep existing and only the maintenance falls away. If it's under the vendor's name, their bankruptcy becomes your problem too. This is why the account question comes first: it determines how bad every other scenario is.
Can I switch to another party later?+
Yes, provided your data and your documented way of working are exportable. What you don't take with you is the previous party's build layer, so a new builder starts fresh with the integrations. With a good description of your way of working in hand, that's a matter of rebuilding, not reinventing. Without that description, you do start from zero.
Do I need a data processing agreement?+
If a vendor works with your customer data, that's regulated territory, and the precise interpretation is work for a lawyer, not a blog. Practically: ask about it and pay attention to how it's answered. A vendor who brings it up themselves is further along than one who has to be asked.
30 minutes, free, no sales pitch

Feel free to ask us these first.

Schedule a call

We look at where your time is leaking away and tell you honestly whether we can do anything about it. Often the answer is: you can do this yourself. Then we say so, and you've spent thirty minutes on a clear answer.

→ Schedule a call (30 min)

This text was produced with AI assistance and checked and approved by a human before publication.