There is a moment that happens just before most AI tools get adopted inside a small business or nonprofit. Someone finds something useful, tries it, likes it, and starts using it for real work. The vetting step, if it happens at all, happens after the tool is already woven into someone's daily routine, which is exactly backward.
You do not need a legal team or an enterprise procurement process to fix this. You need five questions, asked before anyone signs up, and the discipline to walk away from a vendor that cannot answer them clearly.
"Fifteen minutes of vetting beats months of wondering what happened to a sensitive file later."
What follows are five questions that belong in every AI tool decision, written for the leader who is not a procurement specialist or a data privacy attorney. You can ask all five in a single conversation with a vendor's sales team, and a vendor that cannot answer them clearly has already told you what you need to know.
Many free and lower cost tiers use submitted conversations to train future models unless a user actively opts out, and some do not offer an opt out at all on the free plan.
A strong answer states the default clearly and explains how to change it. A weak answer is vague, or the vendor cannot produce a written policy at all. If a vendor cannot give you a clear answer, treat that silence as your answer.
You do not need an engineering deep dive. You need to know whether data is deleted on a defined schedule, retained indefinitely, or stored in a way that creates compliance questions for your sector.
A strong answer names a specific retention period. A weak answer is that data is kept as long as needed, with no further detail.
This matters most for any tool touching donor records, client case files, or anything covered by a privacy commitment your organization has made publicly.
A strong answer describes a specific deletion process and a way to confirm it happened. A weak answer is that deletion is not supported, or nobody at the vendor seems to know.
SOC 2, ISO 27001, or a similar certification is not required for every tool you adopt, but it is a meaningful signal for anything touching sensitive data.
A strong answer points to a current certification or a clear explanation of compensating controls. A weak answer treats the question as irrelevant.
This is the question most organizations skip, and it is often the one that matters most. Free tiers frequently come with weaker data protections, in part because your data and your usage are part of how the vendor offsets the cost of giving the tool away.
A strong answer lays out the specific protections gained at the paid tier. A weak answer treats the tiers as functionally identical.
What a Defensible Answer Sounds Like
"We use the free version" is not an answer to any of these five questions. Neither is "it seemed fine." A defensible answer is specific. It names the tier, the retention period, the deletion process, and the certification, or it names the gap honestly and says what your organization is doing about it in the meantime.
Ready for a clearer picture of where you actually stand?
A 90-day or 30-day Security Business Review translates your organization's risk into clear, prioritized decisions leadership can act on. No enterprise complexity. No vendor lock-in. Just defensible outcomes.
Start a Conversation