AI Tool Security: What to Check Before Approval

Photo: Dan Nelson / Pexels
Key takeaways
- Check training, retention, certifications, contracts and access controls before approving any AI tool.
- Business and enterprise tiers usually exclude your data from training; consumer tiers usually don't.
- A signed DPA covers personal data; a signed BAA is required before any health data goes near an AI tool.
- SOC 2 Type II is the baseline certification; ISO 27001 is a stronger signal.
- A vendor that won't answer these questions has effectively already answered them.
Someone on your team wants to start using a new AI tool. Approving it takes five minutes if you just click 'OK', but AI tool security means checking a handful of things first, or you're trusting a vendor you know almost nothing about with your company's data. That takes closer to thirty minutes, and it's the difference between a decision you can defend in a customer security review and one that turns up as a finding in an audit. It matters more as the company grows: the tool you wave through today is the one a customer, an auditor or an investor asks about a year from now, and 'we didn't check' is a far worse answer than 'we checked, and here's the record.' Here's the checklist worth running through before any AI tool touches real company data, whether it's a chatbot, a note-taker or an AI feature bundled into software you already use.
Start with training and data use
The first question is whether the tool trains its models on what you feed it. Check the terms for the specific tier you're evaluating, not the marketing page for the product generally. Enterprise and business tiers from OpenAI, Anthropic, Google and Microsoft all state they don't train on your data by default; consumer tiers often do, or only stop if a user manually opts out, which almost nobody does. Even where an opt-out exists, it's usually buried in account settings nobody revisits after sign-up, so a default-on training setting should be treated as a training tool, not an optional one. Our AI Tool Risk Directory has already checked this for 60-plus common tools, so you don't have to read every privacy policy yourself.
How long does the vendor keep your data?
Retention is the second question, and people skip it because training gets all the attention. A tool that doesn't train on your inputs can still hold onto them for months, which matters if the vendor is ever breached. Ranges vary a lot: Anthropic cut its API log retention from 30 days down to 7 days as of 14 September 2025 (API only, not the consumer Claude.ai product), while other vendors sit anywhere from zero to 90 days on their business tiers. Ask for the number in days, not a vague answer like 'as long as needed,' and check whether that window covers backups and logs, not just the primary chat history, since a 30-day retention promise means little if backups sit around for a year.
Does it have SOC 2, ISO 27001, or neither?
SOC 2 Type II is the baseline expectation for B2B SaaS handling company data, and the AICPA's Trust Services Criteria is what the audit is actually measured against. ISO 27001 is a stronger, broader signal because it covers the vendor's whole information security management system, not just one product. A SOC 2 Type II report covers a period of months rather than a single point in time, so check the report's date range and ask for the most recent one, not one from two renewal cycles ago. Neither certification proves a tool is safe for sensitive data, but a vendor that can't produce either report is telling you something.
Do you need a DPA, a BAA, or both?
If personal data of anyone in the EU or UK will pass through the tool, you need a signed Data Processing Agreement before you use it, full stop. Under GDPR Article 28, that agreement has to cover specific things: what the processor may do with the data, their sub-processors, and their deletion obligations once the contract ends, so a one-line 'we take privacy seriously' clause on a vendor's website doesn't count. If it's health data, you need a signed Business Associate Agreement before any protected health information goes near it, no exceptions for a quick trial. Most vendors only offer these on paid business or enterprise tiers, which is one more reason a free consumer account is rarely the right home for a work AI tool.
Who can actually log into it?
Check whether the business tier supports single sign-on, role-based permissions and an admin console showing who's using what. Without that, individuals can still spin up personal accounts outside the approved workspace, and you're back to shadow AI even after you 'approved' the tool at company level. Checking this alongside the data questions above catches most of what a formal risk review would flag anyway, and it's the step most likely to get skipped because it feels like an IT problem rather than a security one.
What if a vendor won't answer these questions?
Treat silence as an answer. A vendor that can't tell you their retention period, their breach notification timeline, or whether they'll sign a DPA hasn't necessarily done anything wrong, but they've made your decision for you: don't put sensitive data through their product yet. Under GDPR you have 72 hours to notify a breach; a vendor who can't state their own SLA for that is a genuine red flag, not just an inconvenience.
Document what you found, even if the answer is 'no'
Whatever you decide, write it down. A short note against the tool in your register - training: no; retention: 30 days; SOC 2: yes, dated March 2026; DPA: signed - turns a five-minute decision into something you can produce on request months later. If the answer to any question is 'no' or 'unknown,' record that too, along with what you decided to do about it: approved with restrictions, rejected, or revisit in six months. Auditors and customer security teams generally care less about a perfect answer to every question than about evidence that someone asked the questions in the first place.
Why the extra twenty-five minutes is worth it
An ops manager at a 40-person logistics company once approved an AI scheduling assistant the same day a driver asked for it, because it looked useful and the free trial was one click away. Three weeks later a customer's security questionnaire asked which AI tools touched shipment data and whether each had a DPA on file. Nobody could answer for the scheduling tool, because nobody had checked. It's the kind of gap that stays invisible until exactly the moment someone asks about it. The fix took an afternoon: cancel the free account, sign up on the vendor's business tier, get the DPA signed, and note both in the tool register. Running the checklist before approval would have taken less time than the clean-up did.
Make it a habit, not a one-off
None of this needs a compliance team. Run new tools through ModelCharter's free vendor risk assessment before you approve them, check the AI Tool Risk Directory for ones we've already profiled, and add the result to your AI usage policy so the decision is written down, not just remembered. For a longer walkthrough of the whole process, see how to vet an AI tool before rollout. The next audit or customer questionnaire will thank you.
| Check | Good sign | Red flag |
|---|---|---|
| Training on your data | Business/enterprise tier states no training by default | Only a consumer tier with training on by default |
| Data retention | Fixed retention window, typically 0-90 days on paid tiers | Vendor can't state a retention period |
| Certifications | SOC 2 Type II report or ISO 27001 certificate available | No report offered, or only a self-assessment |
| Contracts | Signs a DPA for personal data, a BAA for health data | Refuses to sign a DPA or BAA before rollout |
| Access controls | SSO, role-based permissions, admin console | Anyone can sign up outside the approved workspace |
| Breach notification | Stated SLA, e.g. within 72 hours | No answer, or 'we'll let you know eventually' |
“The tools that refuse to answer basic data questions are usually telling you everything you need to know.”