Field NotesDue diligence · July 1, 2026

Due diligence for AI you did not build

The AI your organization is most exposed to is probably AI you did not build. It came in through the copilot inside your office suite, the scoring feature your CRM vendor switched on, or the model your vendor calls behind an API. Standard third-party questionnaires have not caught up with this. The question families below have, and each one traces back to a failure in the Atlas.

Where does our data go, and what happens to it? Get the mechanical answer, not the marketing one. Which prompts, files, and records leave your environment, to which model provider, retained how long, used for training or not, under which contract clause. The Samsung engineers who pasted source code into ChatGPT were using a permitted tool exactly as designed, and the design kept what it was given. When the AI is a vendor feature, that same flow runs automatically and at scale.

What can the integration reach, and what can it send out? EchoLeak is the reference case. Microsoft 365 Copilot could read a user’s mail and files because that was the product, and that same reach let one hostile email walk data out with no click. For any AI feature wired into your systems, ask what it can read, where it can send, and what happens when the content it reads contains instructions. A vendor who cannot describe the boundary between data and commands does not have one.

Who stands behind the output? Air Canada argued its chatbot was responsible for its own answers, and a tribunal rejected that in a paragraph. When a vendor’s model tells your customer something wrong, the liability lands on you. So ask what the vendor warrants about output, what recourse exists, and what controls let you bind the system to your actual policies.

How does change arrive? CrowdStrike pushed one file to millions of machines at once, and the update category with the lightest checks was the one that took down hospitals. AI vendors push model updates, prompt changes, and new features continuously, and any of them can shift behavior your processes depend on. Ask whether updates are staged or global, whether you get notice before behavior changes, whether you can pin or delay a version, and what a rollback looks like.

Who is behind the vendor? Your vendor’s answers are only as good as their model provider’s answers, and that relationship sits in a contract you have never read. Map the chain at least one level down. The surprises have been living there.

One habit ties this together, carried over from years of operational due diligence on funds: never accept the documented answer as the control. A policy is paperwork. Ask when the control last fired, what it caught, and who reviewed the result. Vendors with real controls answer that in a sentence.

The full checklist, with scoring and follow-through questions, is part of my working practice rather than the site. If you are running a diligence and want it, start at the contact page.


Back to Field Notes