ModelCharter
ModelCharter Team

AI Tool Security: What to Check Before Approval

Digital security shield protecting technology for the AI tool security checklist

Photo: Dan Nelson / Pexels

Key takeaways

  • Check training, retention, certifications, contracts and access controls before approving any AI tool.
  • Business and enterprise tiers usually exclude your data from training; consumer tiers usually don't.
  • A signed DPA covers personal data; a signed BAA is required before any health data goes near an AI tool.
  • SOC 2 Type II is the baseline certification; ISO 27001 is a stronger signal.
  • A vendor that won't answer these questions has effectively already answered them.

Someone on your team wants to start using a new AI tool. Approving it takes five minutes if you just click 'OK', but AI tool security means checking a handful of things first, or you're trusting a vendor you know almost nothing about with your company's data. That takes closer to thirty minutes, and it's the difference between a decision you can defend in a customer security review and one that turns up as a finding in an audit. It matters more as the company grows: the tool you wave through today is the one a customer, an auditor or an investor asks about a year from now, and 'we didn't check' is a far worse answer than 'we checked, and here's the record.' Here's the checklist worth running through before any AI tool touches real company data, whether it's a chatbot, a note-taker or an AI feature bundled into software you already use.

Start with training and data use

The first question is whether the tool trains its models on what you feed it. Check the terms for the specific tier you're evaluating, not the marketing page for the product generally. Enterprise and business tiers from OpenAI, Anthropic, Google and Microsoft all state they don't train on your data by default; consumer tiers often do, or only stop if a user manually opts out, which almost nobody does. Even where an opt-out exists, it's usually buried in account settings nobody revisits after sign-up, so a default-on training setting should be treated as a training tool, not an optional one. Our AI Tool Risk Directory has already checked this for 60-plus common tools, so you don't have to read every privacy policy yourself.

How long does the vendor keep your data?

Retention is the second question, and people skip it because training gets all the attention. A tool that doesn't train on your inputs can still hold onto them for months, which matters if the vendor is ever breached. Ranges vary a lot: Anthropic cut its API log retention from 30 days down to 7 days as of 14 September 2025 (API only, not the consumer Claude.ai product), while other vendors sit anywhere from zero to 90 days on their business tiers. Ask for the number in days, not a vague answer like 'as long as needed,' and check whether that window covers backups and logs, not just the primary chat history, since a 30-day retention promise means little if backups sit around for a year.

Does it have SOC 2, ISO 27001, or neither?

SOC 2 Type II is the baseline expectation for B2B SaaS handling company data, and the AICPA's Trust Services Criteria is what the audit is actually measured against. ISO 27001 is a stronger, broader signal because it covers the vendor's whole information security management system, not just one product. A SOC 2 Type II report covers a period of months rather than a single point in time, so check the report's date range and ask for the most recent one, not one from two renewal cycles ago. Neither certification proves a tool is safe for sensitive data, but a vendor that can't produce either report is telling you something.

Do you need a DPA, a BAA, or both?

If personal data of anyone in the EU or UK will pass through the tool, you need a signed Data Processing Agreement before you use it, full stop. Under GDPR Article 28, that agreement has to cover specific things: what the processor may do with the data, their sub-processors, and their deletion obligations once the contract ends, so a one-line 'we take privacy seriously' clause on a vendor's website doesn't count. If it's health data, you need a signed Business Associate Agreement before any protected health information goes near it, no exceptions for a quick trial. Most vendors only offer these on paid business or enterprise tiers, which is one more reason a free consumer account is rarely the right home for a work AI tool.

Who can actually log into it?

Check whether the business tier supports single sign-on, role-based permissions and an admin console showing who's using what. Without that, individuals can still spin up personal accounts outside the approved workspace, and you're back to shadow AI even after you 'approved' the tool at company level. Checking this alongside the data questions above catches most of what a formal risk review would flag anyway, and it's the step most likely to get skipped because it feels like an IT problem rather than a security one.

What if a vendor won't answer these questions?

Treat silence as an answer. A vendor that can't tell you their retention period, their breach notification timeline, or whether they'll sign a DPA hasn't necessarily done anything wrong, but they've made your decision for you: don't put sensitive data through their product yet. Under GDPR you have 72 hours to notify a breach; a vendor who can't state their own SLA for that is a genuine red flag, not just an inconvenience.

Document what you found, even if the answer is 'no'

Whatever you decide, write it down. A short note against the tool in your register - training: no; retention: 30 days; SOC 2: yes, dated March 2026; DPA: signed - turns a five-minute decision into something you can produce on request months later. If the answer to any question is 'no' or 'unknown,' record that too, along with what you decided to do about it: approved with restrictions, rejected, or revisit in six months. Auditors and customer security teams generally care less about a perfect answer to every question than about evidence that someone asked the questions in the first place.

Why the extra twenty-five minutes is worth it

An ops manager at a 40-person logistics company once approved an AI scheduling assistant the same day a driver asked for it, because it looked useful and the free trial was one click away. Three weeks later a customer's security questionnaire asked which AI tools touched shipment data and whether each had a DPA on file. Nobody could answer for the scheduling tool, because nobody had checked. It's the kind of gap that stays invisible until exactly the moment someone asks about it. The fix took an afternoon: cancel the free account, sign up on the vendor's business tier, get the DPA signed, and note both in the tool register. Running the checklist before approval would have taken less time than the clean-up did.

Make it a habit, not a one-off

None of this needs a compliance team. Run new tools through ModelCharter's free vendor risk assessment before you approve them, check the AI Tool Risk Directory for ones we've already profiled, and add the result to your AI usage policy so the decision is written down, not just remembered. For a longer walkthrough of the whole process, see how to vet an AI tool before rollout. The next audit or customer questionnaire will thank you.

CheckGood signRed flag
Training on your dataBusiness/enterprise tier states no training by defaultOnly a consumer tier with training on by default
Data retentionFixed retention window, typically 0-90 days on paid tiersVendor can't state a retention period
CertificationsSOC 2 Type II report or ISO 27001 certificate availableNo report offered, or only a self-assessment
ContractsSigns a DPA for personal data, a BAA for health dataRefuses to sign a DPA or BAA before rollout
Access controlsSSO, role-based permissions, admin consoleAnyone can sign up outside the approved workspace
Breach notificationStated SLA, e.g. within 72 hoursNo answer, or 'we'll let you know eventually'
AI tool security checklist: good signs vs red flags
The tools that refuse to answer basic data questions are usually telling you everything you need to know.
ModelCharter's compliance team

Frequently asked questions

Does a free AI tool need the same security checks as a paid one?
Yes, and often more. Free and consumer tiers are the ones most likely to train on your inputs and skip contracts like DPAs, so they need closer scrutiny, not less, before anyone uses them with company data. Treat 'it's free' as a reason to look harder, not a reason to skip the checklist.
What's the difference between a DPA and a BAA?
A Data Processing Agreement (DPA) covers personal data generally under GDPR. A Business Associate Agreement (BAA) is the HIPAA-specific contract required before protected health information can touch a vendor's system. You may need one, both or neither, depending on what data the tool will actually see.
Do I need to redo this checklist for every AI feature bundled into software I already use?
Yes, at least briefly. An AI summary feature inside your CRM or a new AI add-on in existing software can have completely different training and retention terms from the base product, so it deserves its own quick check rather than inheriting the approval of the software around it.
How often should approved AI tools be re-checked?
Once a year at minimum, and whenever the vendor changes its terms or you renew the contract. Vendors do change training defaults and retention windows, so a tool approved in good faith last year can drift out of policy without anyone noticing until an audit flags it.

Put this into practice

Generate a free AI usage policy for your team, then see which of your tools are safe to use.

Open the generator