Subscribe free
Tools and shortcuts3 min readAdvanced

Vet an AI tool before your organisation uses it

An impressive demo isn’t due diligence. Before your organisation adopts an AI tool, check what happens to your data, the contract, the controls and whether it does the job.

3 min read 1:17 video with captions
Video transcript

Your organisation wants to roll out a new AI tool, and the demo looked great. Before anyone uploads real data, here’s what to check.

Start with the data. Does the provider train its models on what you put in? How long does it keep it? And where is it stored and processed?

Get those answers for the plan you would actually buy. The consumer and business versions of the same tool often handle data quite differently.

Then ask for the paperwork: a data processing agreement, the list of sub-processors, independent security evidence such as an ISO 27001 certificate or a SOC 2 report, and admin controls like single sign-on and audit logs.

Next, trial it with a small group on real tasks with nothing sensitive in them, and compare it fairly with how you work now.

Watch for red flags: vague promises about your data, consumer terms only, or a security page full of logos but no reports you can read.

If it will handle personal data, check whether UK data protection law requires an impact assessment before you start. Involve your data protection lead early.

Read the full guide below for the complete checklist, and a prompt that drafts your supplier questions.

In 30 seconds

  • Start with data: does it train on your inputs, how long does it keep them, and where?
  • Ask for a , the list and current, independent security evidence.
  • Trial it on real tasks, check admin controls and exit terms, and do a if needed.

A team has found an AI tool that could save hours a week, and the demo was impressive. Before anyone uploads a customer list, someone has to ask the unglamorous questions: where the data goes, what the contract says, who controls access, and whether it really does the job. This checklist is for that person.

Your data: training, retention and location

Start with three questions. Does the provider use what you put in to its models? How long does it keep your data, including deleted chats and backups? And where is it stored and processed?

Get the answers for the plan you’d actually buy, because terms often differ between the consumer and business versions of one tool. When Anthropic updated its consumer Claude terms in 2025, it said it would keep data for five years from users who let it train on their chats, rather than the usual 30 days. Its business plans run on separate commercial terms and aren’t used for training by default.

If data will leave the UK, the international transfer rules in apply. Ask which countries are involved, and which legal safeguards the provider relies on.

The paperwork and the controls

Ask the supplier for

  • A data processing agreementThe contract UK GDPR requires when a supplier handles personal data for you. It limits what they can do with it.
  • The sub-processor listEvery other company that handles your data on the provider’s behalf, such as cloud hosts, and how you’ll hear about changes.
  • Security evidenceIndependent proof, such as ISO 27001 certification or a SOC 2 report. Check its scope, its date and what it leaves out.
  • Admin controlsCentral user management, audit logs and retention settings, so IT can control access and see what happens.

Controls often depend on the tier. On Claude’s business plans, for example, comes with Team, but audit logs and custom data retention need Enterprise. Ask for the security reports themselves, not a page of logos, and have whoever handles contracts read the data processing agreement.

Trial it on real work

A demo shows the best case. Run a time-limited trial with a small group, on real tasks that contain nothing sensitive, and compare the results with how you work now. Our guide to testing AI models yourself shows how to keep that comparison fair.

Check what it can connect to, such as email, files or your customer database, and what permissions each connection asks for. Prefer read-only access, and connections your admins can switch off centrally. Then cost the whole thing: per-seat prices, usage limits, charges for heavy use and the minimum contract term. Finally, ask how you get your data out, and how it’s deleted when you leave.

Good signs and red flags
Good signRed flag
Written terms: no training on your business data by defaultVague promises, or “we may use your data to improve our services”
A data processing agreement and a published sub-processor listOnly consumer terms, or no answer about sub-processors
Current ISO 27001 or SOC 2 evidence you can readLogos on a security page, but no reports
Single sign-on, user management and audit logsShared logins and no admin view
A clear way to export and delete your dataNo route out, or deletion nobody will confirm

Do you need a DPIA?

If the tool will process personal data, check whether you need a data protection impact assessment, or . UK GDPR requires one before processing that’s likely to result in a high risk to people, particularly when it uses new technology. That can include AI tools handling customer, staff or patient data, so involve your data protection lead early and see the guidance from the ICO, the UK’s data protection regulator.

Draft your supplier questions

I’m assessing [tool] for [what we’d use it for] at a [type and size of organisation] in the UK. It would handle [types of data, such as customer emails]. Write a due diligence questionnaire covering: training on our data; retention and deletion; where data is processed; the data processing agreement and sub-processors; security certifications; admin controls; integrations and permissions; data export; pricing and limits. Put the questions most likely to rule it out first.

Check every answer against the contract and the supplier’s own documents, not its marketing pages.

Once you’ve chosen, set the ground rules for using it: see how to write an AI policy. If it will link to email or files, read connect AI to your apps, safely.

Check yourself

3 quick questions nothing is saved
1Why read the business terms rather than the consumer ones?

2What does a sub-processor list tell you?

3When does UK GDPR require a data protection impact assessment?

Tools in this guide

Sources (3)

Spotted a mistake? Tell us and an editor will check it.

Up next in Tools and shortcuts

Advanced3 min read

Connect AI to your email, calendar and files, safely

Connectors let an AI assistant search your email, calendar and files, and sometimes act for you. Here’s how they work, the risks, and the settings that keep you in charge.

More guides

Get AI explained at your level, every weekday

The five stories that matter, in plain English, plus a new guide each week. Free.