Switch language한국어
Back to the list

AI vendor selection is not software procurement

TL;DR AI

Key summary

2 min read
  1. AI procurement needs its own review because model access, training use, and sub-processing create risks that ordinary SaaS checklists do not cover.

  2. The article says prompts and customer data may be used for training, embedded in model weights, or routed through undisclosed sub-processors.

  3. It argues ISO 42001 is a more relevant governance standard for AI vendors than SOC 2 or ISO 27001 alone.

  4. Examples like AWS Bedrock, Anthropic Claude, Azure OpenAI, and Salesforce show that similar products can have very different data-access and compliance terms.

  5. Procurement teams should do AI-specific due diligence to avoid contractual, regulatory, operational, and lock-in risk.

Read the original