The vendor call is going well until you ask the one question that matters. “Where does the model actually run, and what happens to our data when it gets there?” The answer comes back as a paragraph about enterprise-grade security and a promise to send the whitepaper. You are being asked to sign off on a picture nobody has drawn.
Here’s the thing. This is not a hard question. It is just one that vendors are not used to answering precisely, because most buyers do not ask precisely. Ask better and you get better answers.
Review AI data residency training and retention
Draw the boundary on one page. Literally one page. Where does your data live? Where does the model run? What crosses the line between those two places, and in which direction? A box for your environment, a box for theirs, and arrows. If you cannot draw the arrows, nobody on the call can either, and that is the finding.
Ask the training and retention questions with specific words. “Do you use our data to train?” is too soft; the answer will be a reassuring noise. Ask instead: is training on our data disabled, in writing? What is retained after a request finishes? For how long? Who inside your company can see it? Each of those has a short factual answer or it does not, and a vendor who has to check is telling you something.
Match the inference location to the data class, not to the vendor pitch. This is the decision that makes the rest easy. Set the approved boundary for each data class using your obligations, contracts, and security policy. That may mean an on-premises or approved cloud environment for restricted information. Less sensitive information may be suitable for an external API after its training, retention, and access controls are reviewed. Decide per data class. Then every vendor conversation is a matching exercise instead of a negotiation.
Think of it like a hospital. Patient information follows an approved handling path. The cafeteria menu can go on the public website. Nobody agonizes over that split, because someone decided it once and wrote it down.
Redact before it leaves, restore when it returns. A model does not need the account number to summarize the dispute. It does not need the patient’s name to draft the letter. Where the workflow supports it, swap sensitive fields for placeholders on the way out and restore them through a controlled process on return. Validate the redaction: missed fields and surrounding context can still expose information. Redaction is one control in the handling plan.
Put the answers in the contract, not the slide deck. Put the commitment in the terms you sign. Training disabled, retention period, data location, and the right to delete all belong in the terms you sign, and if the vendor resists moving them there, that resistance is the most honest thing you learned on the call.
The key thing is that the one page you drew is now your standard story. It answers the board, the auditor, and the department head who wants to know why one project got a fast yes and another did not.
None of this slows adoption down. So basically it front-loads the one conversation that otherwise happens after the pilot has real data in it, when it is expensive.
Practical next step: pick the AI tool your company is most likely to buy next, and before the next vendor call, draw the two boxes and the arrows for it yourself. Bring the drawing. Ask the vendor to correct it. The corrections are your due diligence, done before the call ends.
Where Ovatio fits
An AI Readiness Assessment helps your team clarify data boundaries and deployment choices within an agreed scope.