In Practice: AI in the Enterprise | Day 25: How to Talk to Your Foundation Model Vendor About Risk (When They’re Not Used to Being Asked)

“We haven’t really thought about that,” the vendor says. It’s the third question in a row where that’s their answer.

You’re asking about their model’s training data composition. They give you a vague answer about “internet-scale data.” You ask how they audit for biases in specific demographic segments. They mention some internal metrics but can’t share details. You ask what happens if their model’s outputs degrade over time—how do you know, and what’s their accountability for supporting you through that?

Blank stare.

This is what happens when enterprise risk management meets the foundation model industry. These are questions every organization should ask any model provider—including their own internal platforms. No provider is exempt from this scrutiny.

I watched this unfold at an organization that was evaluating foundation models for a mission-critical use case. They were comparing three vendors. All three had impressive benchmark scores. Two had larger market share. All three struggled when asked basic governance questions.

Vendor A couldn’t explain how they’d support model evaluation in a regulated industry. Vendor B had no framework for understanding when their model was performing poorly for a specific type of decision. Vendor C didn’t have clear terms around what happens if the model causes harm in production—insurance? Liability caps? Shared responsibility?

None of them were bad actors. Many vendor relationships haven’t yet matured to include these conversations.

Here’s what makes this problem acute: You don’t have a choice of who builds the foundation model. But you have full responsibility for how it’s used. Your organization is accountable. Your model’s outputs are driving decisions. Your brand is attached to the outcomes. If the model fails, you’re the one explaining it to regulators, customers, and your board.

But you can’t control whether the vendor invests in understanding failure modes, bias auditing, degradation monitoring, or liability frameworks. You can only choose whether to use their model or not.

So how do you make that choice?

Start by understanding that the vendor’s relationship to risk management is different from yours. They’re thinking about model performance on benchmarks and market adoption. You’re thinking about liability and business continuity. These aren’t opposed—but they’re not aligned either. A model that performs well on benchmarks might have gaps in exactly the areas that matter to your use case.

When you’re evaluating vendors, the technical benchmarks are table stakes. But they should be the end of your technical evaluation, not the beginning. The real questions are about robustness and transparency.

Ask about transparency first. Can the vendor explain what data the model was trained on? In detail, not vaguely. What’s the composition? What’s included and what’s excluded? When was it trained? What happened since? Have there been updates? If so, what changed? This is fundamental. You can’t assess model risk if you don’t know what it was trained on.

Ask about bias auditing. How do they audit for performance gaps across demographic segments? How do they know if the model performs differently for different populations? Do they have data on this? Can they share it? What’s their protocol for identifying and addressing bias? Not “do they think bias is important”—everyone thinks bias is important. “What’s their operational framework for detecting and managing it?” Many won’t have a clear answer. That tells you something.

Ask about degradation. How does the vendor monitor for model drift or degradation? What’s their detection methodology? How quickly would they notice if the model’s outputs started getting worse? What’s their support model if that happens? Some will say they monitor internally but can’t share details for competitive reasons. Others will say they don’t monitor customer deployments at all—that’s the customer’s responsibility. Understand where the boundary is.

Ask about accountability. If the model causes harm in production, what’s the vendor’s responsibility? Is there insurance? Liability caps? Shared accountability? This is uncomfortable to ask because it feels adversarial. But it’s essential. If the vendor hasn’t thought about it, that’s important information. If they have clear answers, that tells you they’ve dealt with enterprises who needed it.

Ask about customization and fine-tuning. If you need to fine-tune the model on your own data, what’s their support? What’s the process? What happens to your data? How do they ensure fine-tuned models maintain their governance properties? Many vendors have weak answers here because they’re optimized for off-the-shelf use, not enterprise customization.

Ask about failure modes specific to your use case. You know better than anyone where this model could fail in your business. Describe it. Ask the vendor if they’ve seen similar issues. What would they recommend? How would they support you if that failure occurred? Some vendors will have thought through this. Others will give you generic reassurance.

Here’s the hard part: The vendor’s answers to these questions are often uncertain or incomplete. They might not have great answers. That’s not a disqualifier. But it’s data. If a vendor has thought deeply about these problems and has frameworks for managing them, that’s worth something. If a vendor hasn’t thought about them at all, that’s also worth knowing. You’re not looking for perfect answers. You’re looking for evidence that they’ve dealt with enterprise risk management.

After you’ve asked these questions, the real conversation starts. Most vendors, when pressed, want to get better at this. They’ve built good models but haven’t had to integrate them into enterprise governance structures. They’ll often work with you on transparency, monitoring, and accountability if you ask clearly what you need.

The organizations doing this well have made a deliberate choice: We’re going to use someone else’s model, but we’re not going to give them our governance responsibility. We’ll understand what we’re inheriting. We’ll set clear expectations. We’ll require transparency and accountability. We’ll integrate their model into our risk management framework, not theirs.

That conversation looks different from a typical vendor evaluation. It’s not about price or feature parity. It’s about understanding whether this vendor can be a partner in managing the risks their model introduces.

Many vendor relationships are maturing into these conversations. And the ones who engage deeply tend to stay. Because when you’re selecting a foundation model, you’re not just selecting a model. You’re selecting a risk partner. And that’s a different conversation entirely.

Leave a comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.