The proposals do not arrive in an orderly line. Marketing wants a chatbot on the website. Finance wants a copilot in the spreadsheet. Someone in operations saw a demo of an agent that files its own tickets. Each one lands with a different vendor, a different deck, and a different set of promises, and the security review starts from scratch every time.

Here’s the thing. You do not need a different review for each one. Under the hood, a chatbot, a copilot, and an agent are the same shape of thing: software that reads from somewhere, produces something, and maybe acts on it. So the questions that matter are the same too, and there are only a few of them.

Three AI project security review questions

What can it reach? Not what it is designed to use, what it can actually get to. Which file shares, which mailboxes, which databases, which SaaS accounts. Whose permissions does it inherit when it runs? An AI review can go wrong here, with a tool that was pointed at one folder and quietly handed the keys to the whole drive.

What is it allowed to do? Reading is one category. Writing is another, and it is the one that costs money when it goes wrong. Can it update a record, send an email, change a setting, approve a payment? Make the vendor say the list out loud. “It only reads” is a fine answer. “It can take actions” is a fine answer too, as long as the actions are listed.

Where did that answer come from? Any AI that answers questions about your business should be able to point at the document it used. Think of it like a new analyst who hands you a number. The first thing you ask is “where did you get that?” If the analyst cannot show you, the number does not go in the board deck. The same standard applies here, and source inspection belongs in the review before the answer informs a decision. A citation helps you check a claim; it does not prove the claim is correct.

Two more questions round it out. Where does it run, and who owns the data? Get the answer in plain language and write it down. If the vendor cannot explain it in a paragraph a non-technical person can follow, that is your answer. And who approves the actions that matter? Name a person. A committee is where accountability goes to hide.

The key thing is that a short frame beats a long one because people will actually use it. A long intake form gets skipped or filled in by the vendor’s sales engineer. Five questions on one page get asked in the first meeting, by the project sponsor, before anyone has fallen in love with the demo.

So basically you are giving every department the same short test and letting the proposals sort themselves. The ones that pass are easy to say yes to. The ones that stall on the first question were never ready, and now everyone can see why.

Practical next step: put these five questions on a single page and send it to whoever runs project intake. Ask that every AI proposal arrives with the answers filled in before it reaches you. Then watch which question stalls most often. That is where your first real project is.


Where Ovatio fits

Ovatio Protect helps make information exposure visible within supported sources. Ovatio Comply applies configured policies to supported requests routed through it, and OvatioIQ Knowledge helps teams inspect the sources behind enterprise answers.