If you sell software, your security questionnaires have grown an AI section - and it is the part most vendors answer worst. Buyers are not trying to catch you out. They are trying to work out whether using your product creates an AI risk they now have to govern, and whether you have thought about it at all.
What buyers are actually asking
Do you use AI, and where?
Sounds trivial; frequently answered wrongly. Vendors say "no" while running AI-powered search, or an AI feature in a subprocessor's platform. Buyers verify against your documentation and marketing - a contradiction damages trust across the whole response.
Does our data train your models?
The single most important question. The answer must be unambiguous, and it must match your contract and privacy policy. "We may use aggregated data to improve our services" reads as a yes to a careful reviewer and will generate follow-ups.
Which models and providers do you use?
Buyers want the model providers named, because those are subprocessors in their chain. Refusing to name them is increasingly a blocker rather than a defensible commercial position.
Can AI features be disabled?
Many regulated buyers need this - either for specific data classifications or entirely. A clear yes with instructions is a strong answer; "not currently" is acceptable if honest; silence is not.
How do you handle inaccurate output?
They are probing whether AI output is presented as authoritative. Explain where human review sits, whether output is traceable to source data, and what the product does and does not claim.
Answer AI questions from an evidenced position
GRC Copilot maintains your AI inventory, maps it to ISO 42001 and EU AI Act expectations, and stores approved answers with the evidence behind them - so the AI section stops being the slow part.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
The rest of the section
- Data location for inference - increasingly asked by buyers with residency obligations.
- Retention of prompts and outputs, and whether zero retention is available.
- Human review of inputs - whether any of your staff or contractors read customer prompts.
- Governance - ISO 42001 status, AI policy, whether AI systems appear in your risk register.
- Automated decisions about individuals, which trigger specific obligations for the buyer.
- Model change notification - will they be told before the underlying model changes?
- AI incident handling - is it covered by your incident process?
Preparing answers you can defend
- Build your AI inventory first. You cannot answer accurately without knowing every AI feature in your product, including those inside vendors you use.
- Align the artefacts. Questionnaire answers, contract, privacy policy and public documentation must agree. Reviewers cross-check.
- Name your model providers and list them as subprocessors.
- Write the answers once, approved by whoever owns the product decision, and reuse them.
- State roadmap items as roadmap, with dates - not as current capability.
The pattern that loses deals is not having gaps. It is answering the AI section vaguely, which tells a reviewer you have not inventoried your own AI - and that raises questions about everything else you claimed.
Turn it into an advantage
Most vendors answer this section poorly. Publishing your AI posture on your trust page - what AI you use, which providers, training and retention position, how to disable it - lets buyers self-serve and signals maturity before the questionnaire arrives. It is currently a cheap differentiator.
Frequently asked questions
What if we use AI only internally, not in the product?
Say so precisely, and be accurate: if internal AI touches customer data - in support, for example - that is in scope for the buyer's question.
Do we need ISO 42001 to answer well?
No. A clear AI inventory, a policy and honest answers are sufficient for most buyers today. Certification helps in regulated sectors and is becoming a differentiator.
Should we name our model providers?
Generally yes. Buyers need them for their own subprocessor records, and refusal increasingly reads as evasion.
How often should these answers be reviewed?
Whenever you add an AI feature or change model provider - and at least quarterly. This area moves faster than the rest of your questionnaire content.
Key takeaways
- Answer "do you use AI" accurately - including features inside your vendors.
- Be unambiguous about training use, and align it with your contract.
- Name model providers; they are subprocessors in the buyer's chain.
- Publishing your AI posture on a trust page is currently a cheap differentiator.