“We use AI” is a claim, not a credential. It should prompt a question, not a nod.
Count how many suppliers have added AI to their pitch this year. AI-assisted quoting. AI nesting. AI scheduling. AI inspection. Some of it is real and useful. We use several of these tools ourselves. But one question keeps getting skipped, and it’s the one every purchasing manager should ask before placing work:
Where does my data go when your AI touches it?
When you send a supplier a drawing, you’re sending your design intent, your tolerances and your material choices. It is one of the most valuable things you own. In a lot of supplier businesses right now, a file like that is being pasted into a chat window by someone with good intentions and no policy behind them.
The Risk Isn’t AI. It’s Unmanaged AI.
Unmanaged use looks like this: drawings uploaded to public tools whose terms permit the provider to retain or train on them. Quoting data run through platforms nobody assessed. No access control, so anyone can use any tool with any customer’s data. No record, so six months later the supplier genuinely can’t tell you where your part file went.
None of that requires bad intent. It just requires nobody having thought about it.
And that exposure doesn’t stay with your supplier. It flows back to you. Your customer contract, your confidentiality obligations, your insurance position. If they leak your data, you’re the one explaining it.
What To Actually Ask
Five questions will tell you most of what you need to know:
- Do you use AI tools anywhere in handling my data? Quoting, drafting, programming, inspection, correspondence.
- Which tools, and are they enterprise instances or public versions? Enterprise agreements typically prohibit training on your data. Free consumer tools frequently don’t.
- Who’s permitted to use them, and how is that controlled? “Everyone, informally” is an answer.
- What’s your policy on uploading customer drawings? If it isn’t written down, it doesn’t exist.
- What independent cyber security certification do you hold? It covers their security controls, not their AI use, so ask both.
What Counts As Proof
Smaller suppliers will often tell you ISO 27001 is out of reach, and that’s fair. It’s built for enterprise. But it’s no longer the only option. Standards like SMB1001 are scaled for businesses of 5 to 200 staff and map against the Australian Essential Eight, UK Cyber Essentials and the US CMMC framework. We hold CyberCert Gold under SMB1001, alongside ISO 9001:2015. The standard your supplier holds matters less than the fact that somebody independent has assessed them. One caveat, and it cuts against our own argument: certification is not AI governance. It examines security controls, not how a business uses AI, and any supplier claiming otherwise is overselling, ourselves included. What certification does tell you is that someone with no stake in the answer has been through the fundamentals. That beats never having been looked at.
The Short Version
Don’t be impressed by AI on a capability statement. Be impressed by a supplier who can tell you exactly which tools they use, who’s allowed to use them, what data is permitted anywhere near them, and who has had an independent third party check the fundamentals.
