Skip to content

AI Governance & Ethics

Make AI Workplace Vendors Show Their Models and Data Paths

Start with one sensitive workflow, then require evidence for every model, storage system, evaluation, incident path, and opt-out behind it.

Irene VaskoGovernance & Ethics Writer

August 9, 2026 · 8 min read

Laptop showing an AI meeting summary beside a procurement checklist and vendor architecture diagram.
Laptop showing an AI meeting summary beside a procurement checklist and vendor architecture diagram.

Start with a Thursday one-on-one. An employee joins a video call, the workplace assistant records it, a model produces a transcript and summary, and the software sends both participants a list of action items. That narrow workflow is a better procurement test than a general claim about “enterprise AI,” because it exposes what the product collects, which companies process it, and what happens when the summary is wrong.

Two products can present nearly identical meeting-summary screens while relying on different model providers, retention periods, hosting arrangements, and review controls. A familiar interface does not reveal whether audio reaches a third-party model, whether prompts remain in diagnostic logs, or whether turning off AI also removes previously generated content.

The procurement task is to turn each hidden dependency into a named answer, supporting evidence, and a contractual commitment. Roadmap promises do not count.

Draw the workflow before reading the policy

Write the one-on-one workflow as a sequence: capture audio, create a transcript, generate a summary, extract action items, store the output, and send notifications. Ask the vendor to place every service that receives data beneath the relevant step.

The result should identify the contracting vendor, cloud host, model provider, transcription provider, analytics services, and support systems. A subprocessor is another company that processes customer data for the vendor; the vendor should state which listed companies meet that role rather than leaving the buyer to infer it from a generic privacy page.

Also mark where a human can intervene. Can either participant stop recording before transcription starts? Can an administrator prevent summaries for selected teams? Can a user correct an attributed statement before an action item enters another system?

For the Thursday meeting, the fallback might be an unrecorded call with manual notes. That costs convenience and searchability, but it keeps the workflow available when consent, confidentiality, or system reliability rules out AI processing.

A useful first requirement is direct:

For the meeting-summary workflow, Supplier shall identify every model, service, storage location, and subprocessor that can receive customer audio, transcripts, prompts, outputs, metadata, or diagnostic logs.

Require a model and dependency register

“Powered by a leading model” is not a model list. Request the provider, model name or family, deployed version where available, hosting arrangement, processing region, and purpose within the workflow. If the vendor routes requests among several models, the register should name the permitted pool and explain what determines routing.

Ask whether the model runs in the vendor’s cloud account, a model provider’s application programming interface, or a customer-controlled environment. These arrangements can expose the same summary button while producing different access paths, deletion mechanics, and costs. A dedicated or customer-controlled deployment may reduce shared infrastructure risk, but it usually adds administration and may restrict which features arrive first.

Version changes matter because a new model can alter speaker attribution, refusal behavior, formatting, or action-item extraction without changing the product name. Use this requirement: “Supplier shall provide advance notice of material model or hosting changes and identify which evaluations were repeated before deployment.” Define “material” in the procurement record, covering at least a provider change, new data destination, altered training use, or a change that affects an agreed evaluation threshold.

Put retention and training terms next to each data type

Do not accept one retention period for “customer data.” The Thursday meeting creates audio, transcript text, a summary, action items, user feedback, access logs, support records, and possibly embeddings, which are numerical representations used to retrieve related content. Each can have a different deletion path.

For every data type, record where it is stored, why it is kept, the default retention period, configurable limits, backup treatment, and deletion timing after contract termination. Then ask the same questions about the model provider and other subprocessors. Deleting a summary from the workplace application is incomplete if the prompt remains in a provider log or a copied transcript sits in a support ticket.

Training language needs a binary answer followed by exceptions. Does the vendor or any subprocessor use customer inputs, outputs, feedback, or metadata to train or improve models? If the answer is no by default, identify the contract term that says so. If an optional improvement program exists, require affirmative administrator enrollment, a list of included data, and a way to withdraw without losing the core product.

A workable clause reads: “Supplier shall not use Customer Content to train or improve general-purpose or cross-customer models unless Customer has opted in through a documented administrator control.” Security documentation may support this promise, but a policy page that the vendor can revise unilaterally is not equivalent to a contract term.

Test the claim the workflow makes

The relevant evaluation is not whether the underlying model performs well on a broad benchmark. The product claims it can summarize a workplace conversation and assign statements to the correct person, so ask for evidence about those tasks under conditions resembling actual use.

The evaluation record should describe the test data, languages, audio conditions, number of speakers, scoring method, human review process, known exclusions, and results by important subgroup or scenario. For the one-on-one workflow, inspect missed decisions, invented action items, incorrect speaker attribution, and sensitive text that appears in the summary despite an instruction to omit it. An average score can hide the failure that creates the most workplace harm.

Buyers should also run an approved pilot with synthetic or authorized content. Include overlapping speech, an ambiguous deadline, a correction late in the conversation, and a statement that must not become an action item. Record the input, output, model identifier, configuration, reviewer decision, and whether the user-facing correction control worked. The time spent building this test is part of the product’s adoption cost, but it produces reusable acceptance evidence instead of another feature demonstration.

Set a retesting trigger. A model change, revised system prompt, new transcription service, or altered routing rule should cause the vendor to repeat the affected evaluation before the change reaches the covered workflow.

Define incidents and the receipts they produce

A security incident definition may not cover an AI system that invents a disciplinary statement, exposes one customer’s summary to another, or silently sends content to an unapproved model. Add an AI incident category tied to the workflow and specify who receives notice.

Require the incident record to contain the affected workflow, data types, users or tenants, model and configuration, detection source, containment action, customer impact, and remediation status. Set contractual placeholders for notice and update intervals rather than accepting “promptly,” then align them with the buyer’s internal escalation process.

The audit trail should show who enabled recording, which model processed the meeting, when the output was generated, who viewed or edited it, and when deletion occurred. Logs cannot prove that a summary was accurate, but they can establish which system produced it and whether the approved route was followed.

Verify that opting out changes the data path

An opt-out is useful only if its effect is observable. Test controls at the organization, team, user, and individual-meeting levels where the product claims to support them. Disable AI for the Thursday one-on-one, repeat the workflow, and confirm that no recording, transcription request, model call, summary, or downstream action item appears.

Then inspect existing material. The vendor should state whether disabling the feature deletes prior summaries, leaves them under the original retention schedule, or only stops new processing. Ask how administrators export and delete those records, including copies held by subprocessors.

Document the fallback in the deployment plan. If opting out removes automated notes, employees need a manual note field or another approved workflow; otherwise, teams may route sensitive meetings through personal recording tools that procurement cannot inspect.

Score evidence before features

Use pass-or-fail gates for model disclosure, prohibited training use, required retention controls, incident notice, audit fields, and a tested opt-out. Score product quality only after both vendors clear those gates. A polished summary is not worth buying when the buyer cannot identify where the underlying transcript went.

Attach the accepted workflow diagram, dependency register, evaluation report, retention schedule, and change-notice terms to the procurement record. When the vendor replaces the model behind the same summary button, those documents show what must be reviewed again.

Questions people ask

Is a vendor’s security certification enough for AI procurement?

No. A security certification may cover access controls and operational processes, but it may not identify the models receiving prompts, evaluate summary accuracy, or prohibit training on customer content. Use it as supporting evidence while requesting workflow-specific data maps, model records, and contract terms.

Should a buyer reject any product that uses third-party models?

Not automatically. Third-party models can offer better capability or lower operating costs, but they add another processing relationship to inspect. The vendor should disclose the provider, hosting arrangement, retention terms, permitted uses, change process, and deletion path so the buyer can compare that dependency with a self-hosted alternative.

What should happen when the vendor changes models?

The vendor should notify the buyer when the change affects an agreed material category, update the dependency register, and repeat evaluations linked to the changed component. The buyer can then check whether speaker attribution, action-item extraction, retention, routing, or other accepted behavior has moved outside the procurement requirements.

Does switching off an AI feature delete earlier content?

Not necessarily. A control may stop future model calls while leaving transcripts, summaries, logs, backups, and subprocessor copies under existing retention schedules. Test the setting, inspect the audit trail, and require the vendor to document separate procedures for disabling processing, exporting records, and deleting previously created content.

ShareFacebook
ai governanceprivacy and data rightsai at workai procurementworkplace softwaremodel governancevendor riskdata retention

One story a day

The story of the day, in your inbox

One real story about AI each morning — no hype, no alarm, just company for the road.

Read next

Laptop displaying a cropped airport image beside metadata fields and a Content Credentials verification panel.

AI Governance & Ethics

What an AI-Generated Image Label Can Actually Prove

A visible badge, file metadata, generation log, and signed Content Credential answer different questions. Cropping and reposting expose the gaps between them.

Irene Vasko · 8 min read

A support chat labeled Automated assistant beside a phone displaying an incoming customer-service callback.

AI Governance & Ethics

When a Customer-Service Bot Has to Say It Is a Bot

There is no blanket U.S. disclosure rule. A practical answer depends on where the customer is, what the bot is doing, and whether chat becomes an AI-generated call.

Irene Vasko · 8 min read

A laptop displaying a hiring bias-audit table beside a printed job notice and handwritten calculation notes.

AI Governance & Ethics

How to Read NYC’s Hiring-AI Bias Audit Before You Apply

A public audit can reveal which hiring system was tested, whose outcomes were counted, and where selection rates diverged. It can also conceal job-level differences and omit demographic groups.

Irene Vasko · 8 min read