Before adopting AI, ask where data is processed, whether it is sent to third parties, who can access it, whether tokens are encrypted and whether tenants are isolated.

Then ask about retention, deletion, audit logs, backups, admin access and incident handling. For cloud connectors, understand which permissions are requested and whether least privilege is used.

Finally, define who reviews AI output and how errors are escalated. Document-AI security covers both data protection and control over how outputs are used.