Then ask about retention, deletion, audit logs, backups, admin access and incident handling. For cloud connectors, understand which permissions are requested and whether least privilege is used.
Finally, define who reviews AI output and how errors are escalated. Document-AI security covers both data protection and control over how outputs are used.