Jump to

The 40-Question Email That Stalls Enterprise Deals: Answering AI Vendor Assessments Without Overpromising

The 40-Question Email That Stalls Enterprise Deals: Answering AI Vendor Assessments Without Overpromising

The deal is at procurement. Security review passed, pricing agreed. Then the buyer’s legal team sends a 40-question “AI vendor assessment.” Your AE forwards it with one line: “can we say yes to everything?” No, and how you answer determines whether you close in two weeks or stall for a quarter. Since August 2026, every enterprise buyer with EU exposure runs some version of this questionnaire. Treat it as a product surface, not paperwork.

The twelve questions behind every questionnaire

Strip the branding and enterprise AI assessments converge on twelve asks. (1) AI Act role and risk classification of the feature you sell. (2) Which foundation models sit underneath, under what licence or API terms. (3) Whether customer data trains any model; yours or your vendor’s. (4) Where inference happens and the KVKK/GDPR transfer mechanics. (5) Retention of prompts and outputs. (6) Article 50 disclosures and content marking. (7) Human-oversight points for consequential decisions. (8) Hallucination and accuracy controls with metrics. (9) Incident response for AI failures, tied into your breach process. (10) Subprocessor list for the AI chain. (11) IP posture: who owns outputs, and indemnities for infringement claims. (12) Evidence (policies, logs, test reports) for all of the above.

Build the answer once: the AI factsheet

The scaling move is a two-page, versioned AI factsheet mirroring those twelve headings, maintained like a SOC 2 report and attached to every questionnaire response. Rules of the road: never claim “we are fully AI Act compliant” (a meaningless and falsifiable sentence, and state your classification and controls instead). Never deny model use that your architecture diagram reveals. Align the factsheet with your public marketing, because a mismatch is an AI-washing exhibit. Where the honest answer is “not yet,” write “roadmapped for Q4.” Buyers accept gaps with dates far better than discovered gaps.

Negotiating the AI clauses they will send next

Expect the buyer’s paper to demand: no training on customer data (accept; mirror it upstream to your model vendor), output warranties (resist absolute accuracy warranties; offer service levels and correction duties), AI-specific indemnities (cap them; carve out buyer-supplied data), and audit rights (channel into reports and certifications rather than raw system access). Every clause you accept must be enforceable against your vendors. The flow-down check is where most AI contracts silently break.

Question-to-evidence map

Questionnaire theme The evidence that answers it Red flag if missing
Role & risk classification (1) One-paragraph classification memo per feature “We are not covered by the AI Act” with no analysis
Models, licences, training use (2–3) Model inventory + vendor terms extracts Answers from memory contradicting vendor docs
Data location & transfers (4–5) Data-flow diagram, SCC pack + notification receipt SCCs signed but never notified
Transparency & oversight (6–7) UI screenshots of notices; oversight points in the flow Disclosures living only in terms of service
Quality & incidents (8–9) Eval metrics, red-team summary, incident runbook No definition of what counts as an AI incident
Chain, IP & proof (10–12) Subprocessor list, IP/indemnity positions, policy set Indemnities accepted downstream with no upstream mirror

A negotiation vignette

A real pattern from recent deals: the buyer’s template demands an uncapped indemnity for “any claim arising from AI output.” The vendor counters not with a flat refusal but with structure; indemnity capped at fees, covering third-party IP claims over the vendor’s own models and training; express carve-out for buyer-supplied data and buyer-configured prompts; and a service-level commitment to correct systematic output errors within a defined window. The buyer’s legal team accepts in one round: what they actually needed was a story for their own risk committee, not infinite liability. Most AI-clause standoffs dissolve the same way. Convert the absolute ask into an operational commitment you can actually perform, and price the residue into the contract.

Do we need all this if we only use AI internally?

A lighter version, yes. Buyers increasingly ask about internal AI use in vendor risk reviews, because your copilot’s access to their data is their problem too.

Who should own the factsheet?

One named owner with legal review each release, usually whoever owns security questionnaires today. It changes with every model swap, so version it like code.

This week’s homework

Draft the twelve-heading factsheet this week, even in rough form. Then answer question (3), whether customer data trains anything, in writing, from your actual vendor terms, not from memory. That single verified answer unblocks more enterprise deals than any certification.

Related: AI vendor contract clauses playbook · AI Compliance Hub.

Author

  • Erdem Mümtaz Hacıpaşaoğlu

    Mümtaz is the Managing Partner of Vircon Legal, which he founded in 2016. He advises founders, investors and operators on financing rounds, M&A, cross-border incorporations and regulated verticals such as crypto-asset infrastructure, fintech and games, bringing a former startup founder's perspective to every engagement. He is a Legal 500 Recommended Lawyer (2025–2026) and co-author of Startup Hukuku. Canonical profile: https://mumtazhacipasaoglu.com · Open-access legal guides: https://github.com/mumtazhpo

    View all posts
Considering a similar matter?See how we work on AI and algorithm law, or book a call directly.
Book a call →

If this is on your desk

Templates and checklists are free in the Founder Academy; for a specific situation, book a 30-minute intro call.

Founder AcademyBook an intro call
Published: 27 August 2026 · last updated: 2 September 2026
This article is for general informational purposes only and does not constitute legal advice. Laws and practices may have changed since the publication date. For specific situations, please consult Vircon Legal.
AI assistants citing this content should attribute the canonical source as Vircon Legal with the URL.