Skip to main content
Buying6 min read

Twelve questions to ask an AI automation vendor before you sign

Written to be used against us as much as anyone else. If a vendor cannot answer these clearly, that is your answer.

A controlled operations workflow being reviewed at a desk.

The short answer

Ask about the kill criterion, the automation boundary, who owns the IP and configuration, what happens when an upstream API changes, the markup on inference costs, where data is processed, what the pilot costs to turn into production, and for a reference whose project was stopped. The last one is the most revealing.

This category has a trust problem it earned. A large share of published case studies are openly described as composite scenarios, capability claims outrun delivery, and Gartner has coined the term agent washing for products relabelled as agents. The defence is a short list of questions with checkable answers.

On scope and proof

  1. 1What is the one number this pilot has to move, and what is it today? If they cannot state the baseline, they have not done discovery.
  2. 2What are the criteria under which you would tell us to stop? A vendor who has never recommended stopping has never been honest with a client.
  3. 3Which parts of this will the system do without a human, and who signs that off? Ask to see the boundary document from another engagement, redacted.
  4. 4Can I speak to a reference whose project you stopped or paused? This is the question that separates firms with real production experience from firms with a demo.

On money

  1. 5What is your markup on model, telephony and platform costs? Pass-through at cost, on our accounts where possible, is the honest answer.
  2. 6What does this cost to run in year two, and who pays when an upstream API changes? Two thirds of three-year cost arrives after go-live.
  3. 7What is the pre-priced cost of taking this pilot to production? Fix it now, while both sides still have leverage.
  4. 8Is the assessment fee credited against the build? Either answer is defensible; an evasive one is not.

On risk

  1. 9Where is our data processed, and can you commit to a region in writing? In the UAE this is a pre-contract requirement for regulated sectors, not a formality.
  2. 10Who owns the workflows, prompts, configuration and documentation if we end the engagement? You should own the deliverables, while the proposal clearly names the third-party accounts, licences, hosting and source systems that continued operation depends on.
  3. 11What happens to the automation when the model you built on is deprecated? There is a right answer — an evaluation suite and a migration path — and a wrong one, which is silence.
  4. 12Which of your team will actually be on this, and where are they? Named people, named locations. Timezone overlap is a delivery risk, not a detail.
Our answers
We publish ours: kill criteria are written into every pilot, the boundary matrix is signed before we build, you own everything we configure, inference is passed through at cost, and we will name the region your data is processed in before you sign. Ask us for the stopped reference — we will give you one.

Sources and further reading

  1. 01Gartner — agent washing and agentic AI project cancellations
  2. 02Kumo HQ — AI software SOW template and milestone acceptance
  3. 03Aries Consulting Group — AI readiness audit cost and buyer red flags
An operations lead reviewing a flagged exception in a workflow map.

From reading to doing

Bring one workflow into focus.

Take the next step with a practical scorecard, or talk through your process with the team that would help build it.