Your vendor questionnaire was built for a different era.
Traditional third-party controls (data handling, access controls, encryption in transit) still matter, but they don’t cover what AI vendors are actually introducing into your environment: model training on your data, opaque decision-making, hallucinated outputs with real consequences, and attack surfaces that didn’t exist five years ago. Most Enterprise vendor questionnaires haven’t caught up, and with AI now embedded in everything from HR to legal ops to your GRC software, the gap is growing. These are the ten questions every CISO should be asking AI vendors right now.