Is your vendor's AI safe?
Load the vendor's answers to the AI vendor questionnaire, or answer the questions here. You'll get a risk tier, the red flags about their AI and AI agents, and the contract terms to ask for.
Nothing leaves your browser. The spreadsheet is read on your computer.
Or answer the questions here
What it looks for
- Whether your data trains anyone's AI model, and whether you can opt out.
- For AI agents that touch your data: human approval before actions, a kill switch, logs you can get, least privilege, testing and notice before changes.
- Which models, providers and sub-processors see your data, and for how long.
- A written AI policy, an inventory, a named owner and staff training.
The rules and weights are on How the scoring works.
Questions
Is the vendor's spreadsheet uploaded anywhere?
No. It's read on your computer and the page blocks every outgoing request. Nothing is stored after you close the tab.
Which spreadsheet does it read?
The one downloaded from the AI Vendor Questionnaire, returned with the Supplier answer column filled in. Any CSV with a Ref column and an answer column using the same references works.
How are answers scored?
Yes/No questions score full points for the safe answer, half for Partly and nothing for the risky answer or no answer. Written answers score when they're given and are listed for you to read. Any critical red flag makes the vendor at least High risk.
What if the vendor doesn't use AI agents?
If the vendor answers that it doesn't use agents, the agent questions are marked not applicable instead of counting against it. The same applies to every AI question if it doesn't use AI at all.
Sources
- EU AI Act (Regulation (EU) 2024/1689), EUR-Lex
- NIST AI Risk Management Framework
- Checked 28 September 2026.