10 Questions to Ask Any AI Vendor Before You Sign
The demos were impressive. Pricing came in inside the budget. The procurement team got the security review back without a single red flag. Six months later, the token bill is three times higher than the pilot estimate, the integration broke when the vendor pushed an update, customer data is sitting in a system that has no documented export path, and the renewal contract just landed with a 32% price increase.
This is one of the most common AI procurement stories of 2026, and it is rarely a failure of due diligence. It is a failure of asking the right questions in the right phase. Most AI vendor evaluations focus on capability ("can it do the task?") and price ("is it in budget?"). Both are necessary. Neither is sufficient.
According to Gartner research published in 2026, more than 30% of generative AI initiatives launched in 2024 and 2025 are projected to be abandoned by end of year, with cost overruns and unclear business value as the leading drivers. [1] The contracts those projects were built on are a major reason why.
The 10 questions below are organized into five evaluation categories: cost, lock-in, data, performance, and roadmap. Each question is designed to surface a specific risk that does not show up in a demo or a feature comparison spreadsheet. Use them in your next vendor call.
Category 1: Cost and Pricing
What does the full pricing model look like at 5x my current usage?
AI pricing tiers often look reasonable at low volume and become prohibitive at scale. Ask the vendor to model out cost at the volume you would actually run if the project succeeds, including overage charges, premium model surcharges, and any fees for higher concurrency or longer context windows. The answer should be a written number, not a verbal range. If the vendor cannot give you a defensible model, you will be the one absorbing the variance.
Can you cap my monthly spend, and what happens at the cap?
Usage-based AI pricing creates real exposure: a single buggy automation can spike costs overnight. Ask whether the vendor offers a hard spend cap, a soft alert with optional throttling, or no cap at all. The right answer depends on your risk tolerance, but the wrong answer is "we'll work with you" because that is a sentence, not a control.
Category 2: Vendor Lock-In
Can I export all my data, prompts, and configurations? In what format?
This is the single most important question on the list. Vendor lock-in is the largest hidden cost in AI procurement, and it almost always lives in data portability. Ask specifically for prompts, fine-tune training data, conversation histories, configuration files, and any custom workflows. The answer should be a documented export process, not a support ticket. "Yes, just contact our team" is not the answer you want when you are trying to leave.
Who owns the model fine-tunes built on my data?
If you provide the training data, you should own the resulting fine-tune. Many vendor agreements quietly assign ownership to the vendor, which means even if you can export your raw data, you cannot take the trained model with you. Read the IP clause carefully. If the vendor owns the fine-tune, you are paying to train an asset that walks away with them.
Category 3: Data and Privacy
Where is my data stored, who has access, and is it used to train your models?
Three sub-questions that need three explicit answers. Data residency matters for compliance (GDPR, HIPAA, sector-specific rules). Access matters for security audits. The training question is the one that surprises buyers most often: many AI vendors retain the right to use customer inputs for model improvement unless the customer explicitly opts out. Ask for the opt-out in writing.
What is your data deletion policy when I cancel, and how do I verify it?
"All data is deleted upon termination" is a marketing line. The procurement question is how. Within what timeframe? Across primary storage and backups? Will the vendor provide a deletion certificate? If your industry has compliance requirements around data destruction, this is non-negotiable. If it does not, this is still the question that separates serious vendors from the rest.
Category 4: Performance and Reliability
What is your published uptime SLA, and what is the credit if you miss it?
Many AI vendors publish aspirational uptime numbers without committing to financial credits when they fall short. The credit structure is what makes the SLA real. A 99.9% uptime claim with no credit clause is marketing. A 99.5% commitment with a defined credit when missed is an actual contract. Ask for the latter.
How do you handle model deprecation when an upstream provider sunsets a model?
Most AI vendors are built on top of foundation models from a small number of providers. When those providers retire a model, your vendor has to migrate, and that migration can change behavior, latency, and cost. Ask what notification window the vendor commits to, whether they offer a transition period on the old model, and whether they re-test prompts before forcing a migration. Vendors who have answered this question before will have a documented process. Vendors who have not are still figuring it out on your time.
Category 5: Support and Roadmap
What is your real support response time, and what is actually included at my tier?
Vendor websites advertise "24/7 support" without specifying that it applies only to the enterprise tier or only to platform-down incidents. Ask for the response time guarantee in writing for your specific tier, the channels included (chat, email, phone, named technical contact), and the escalation path when an issue is not resolved on first response. Time spent on this question pays off the first time something breaks.
Will the integration I am buying today still exist in 18 months?
AI vendors are consolidating fast. Acquisitions, pivots, and product sunsets are common. Ask the vendor directly: what is the roadmap for the specific integration, model, or feature you are evaluating? Is it a strategic priority or a legacy product? If a feature was added in the last six months and has not been mentioned in any roadmap update since, it may not be there in 18 months. Buyers who ignore this end up rebuilding workflows on a different platform within two years.
How to Use the 10 Questions: A 30-Day Evaluation
Asking 10 hard questions across multiple vendors is its own project. The 30-day evaluation framework keeps it focused and produces a defensible decision document at the end.
Sending the questions in writing matters more than asking them on a call. Written answers are reviewable, comparable across vendors, and contractually useful in a way that "yes, our team mentioned that on the demo" is not. Vendors who refuse to answer in writing are telling you something important.
Green Flags in Vendor Responses
- Written, specific answers to all 10 questions
- Documented data export process with format details
- Hard spend cap or alert-and-throttle option
- Named technical contact and escalation path
- Explicit opt-out of training data use
- Public roadmap with shipped features tracked
Red Flags to Watch For
- "Contact support to discuss" instead of a process
- Verbal-only pricing commitments
- Auto-renewal with under 30-day cancellation window
- Unilateral mid-term price escalator clauses
- Vendor IP ownership of customer fine-tunes
- SLA percentage with no credit structure
Key Takeaways
- Capability and price are necessary but not sufficient in AI vendor evaluation. The risk lives in cost at scale, vendor lock-in, data terms, reliability commitments, and roadmap stability.
- Data portability is the single highest-leverage question. If you cannot export your data, prompts, fine-tunes, and configurations, every other risk gets worse over time.
- Get answers in writing. Verbal commitments are not contracts. Written answers are reviewable, comparable, and enforceable in a way that "we discussed it" is not.
- Use the 30-day evaluation framework to apply the questions consistently across 3 to 4 vendors. Decisions made on calendar pressure rather than evidence are the ones that get rebuilt 18 months later.
- Annual contracts make sense after validation, not before. Stay month-to-month while the use case is being proven, then negotiate annual pricing once you have 90 days of production data.
Frequently Asked Questions
What is the most important question to ask an AI vendor before signing?
The most important question is what your data costs to get out. Vendor lock-in is the single largest hidden cost in AI procurement. If you cannot export your prompts, fine-tune data, conversation history, and configuration in a portable format, you are buying a system you cannot leave without rebuilding from scratch. Every other question on the list matters, but data portability is the one that determines whether the relationship is a partnership or a trap.
How much do AI vendor costs typically increase from pilot to production?
AI vendor costs commonly run two to four times higher in production than in pilot, primarily because pilots use smaller volumes, simpler queries, and shorter context windows. Production workloads tend to involve longer conversation histories, more complex prompts, and higher concurrent usage. Most pilot pricing estimates are accurate for the pilot itself, but they substantially underestimate the cost of running the same workflow at the volume the business actually needs.
Should I sign annual contracts with AI vendors or stay month-to-month?
For new AI capabilities you are still validating, month-to-month is almost always the better choice. The AI vendor landscape is changing fast, model capabilities are shifting quarterly, and pricing is still being recalibrated. Annual commitments make sense only when you have completed at least 90 days of production-level use, you have measured the actual cost and value, and the discount on the annual contract meaningfully exceeds the optionality cost of being able to switch.
What red flags should buyers look for in AI vendor contracts in 2026?
Five contract red flags consistently appear in AI vendor agreements: auto-renewal clauses with short cancellation windows, restrictive data export terms that block migration, vendor rights to use customer data for model training without explicit opt-out, vague uptime and incident response commitments, and price escalator clauses that allow unilateral mid-term increases. Any one of these is negotiable. Multiple of them in a single contract is a sign the vendor expects to recover acquisition costs through customer friction rather than ongoing value.
Sources & References
- Gartner. "Predicts 2026: Generative AI Initiatives, Cost, and Abandonment." Gartner Research, 2026. Figure cited: more than 30% of GenAI initiatives projected to be abandoned by end of year due to poor data quality, escalating costs, and unclear business value.
- Andreessen Horowitz. "The Economics of Generative AI: Pilot to Production Cost Patterns." a16z Research, 2026. Figures cited: 2 to 4x typical cost increase from pilot to production workloads.
- Forrester. "The State of AI Procurement: Buyer Maturity and Contract Terms in 2026." Forrester Research, 2026. Findings cited: contract terms around data portability, training opt-out, and SLA credits as leading buyer pain points.
- IDC. "Worldwide AI Software Tracker, 2026 Edition." IDC, 2026. Figures cited: AI software market consolidation patterns and vendor stability metrics.
- BetterCloud. "State of SaaSOps 2026: Spend Visibility and Renewal Practices." BetterCloud Annual Report, 2026. Figures cited: SaaS contract auto-renewal exposure and cost recovery patterns.