BusinessChecklist6 min readPublished September 20, 2026

10 questions · 2 regulators · 6 dated events · what "AI-powered" has to mean on paper

How to Check a Vendor's AI Claim Before You Buy It

Ten questions to send any AI-powered vendor, the answers that should end the conversation, and what the FTC and the EU AI Act actually say, quoted and dated.

DA
Digital Applied Team
Research and practical guidance
Editorial dateSeptember 20, 2026
Regulator pages readSeptember 22, 2026

Every agency, software vendor and consultancy now says AI-powered, and from the outside a buyer cannot tell an automated pipeline from a person with a chatbot tab open. The difference matters for price, for where your data goes, and for who is accountable when the output is wrong. Regulators on both sides of the Atlantic have started saying so in enforceable terms, which gives a buyer something better than instinct to point at.

This post is a checklist a founder or operations lead can send to any vendor as it stands. It gives ten questions, maps each to the risk it retires, lists the answers that should end the conversation, and quotes what the US Federal Trade Commission and the EU AI Act have actually said, with dates. It is not legal advice. And it applies to us: Digital Applied sells AI services, and every question below is one we expect to be asked.

Key takeaways
  1. 01
    The FTC has held that there is no AI exemption from existing law, and has acted on it since September 2024.Operation AI Comply, announced September 25, 2024, and later orders against Workado (April 2025) and Cox Media Group with two other firms (finalised August 27, 2026) all turned on AI claims the companies could not back.
  2. 02
    The EU AI Act's transparency rules have applied since August 2, 2026.Chatbots must say they are AI and AI-generated or altered content must be labelled and machine-readably marked. The high-risk obligations were pushed to December 2, 2027 and August 2, 2028 by the AI Omnibus, in force since July 27, 2026.
  3. 03
    Ten questions cover automation, data, evidence, guarantees, audit rights and exit.Each one retires a named risk. The tenth asks the vendor to put the other nine in the contract, which is the question that turns answers into obligations.
  4. 04
    A percentage with no denominator ends the conversation.So does a guarantee with no remedy, a refusal to name model providers, and a claim that nothing is ever human-run. The regulator cases below show what those answers looked like when they were tested.

01The US recordWhat the US regulator has said

On September 25, 2024 the Federal Trade Commission announced Operation AI Comply, a sweep against companies it said were using AI claims to deceive. Its then chair, Lina Khan, is quoted in the release: "there is no AI exemption from the laws on the books." The first cases included a company that sold an AI service it called the world's first robot lawyer; the FTC's complaint said the company had not tested whether the product matched a human lawyer and had hired none. Its proposed order required a $193,000 payment and barred claims that the service could substitute for a professional without evidence.

The pattern continued under the next administration, with a narrower stated focus. On April 28, 2025 the FTC announced an order against Workado, which had advertised an AI content detector as 98 percent accurate; the FTC said independent testing found about 53 percent on general-purpose content. On December 22, 2025 the same agency set aside an earlier order against an AI writing tool, saying its focus is fraud and tangible consumer harm. On July 1, 2026 it opened comment on a policy statement about AI accuracy. And on August 27, 2026 it finalised orders against Cox Media Group and two other firms over an "Active Listening" marketing service they had claimed used AI on voice data from smart devices; the FTC said the service was not based on voice data and consumers had not opted in. The three firms pay $930,000 in total.

Consumers trusted Workado's AI Content Detector to help them decipher whether AI was behind a piece of writing, but the product did no better than a coin toss.Chris Mufarrige, Director of the FTC's Bureau of Consumer Protection, April 28, 2025

02The EU recordWhat the EU AI Act requires, and since when

The dates have moved, so they are quoted from the European Commission's own AI Act page as read on September 22, 2026. The Act entered into force on August 1, 2024 and became applicable on August 2, 2026, with exceptions. The rules for general-purpose AI models applied from August 2, 2025. The transparency rules came into effect in August 2026; the Commission's enforcement notice for August 2, 2026 says chatbots and other interactive systems must tell users they are dealing with AI, deepfakes must be labelled, and AI-generated or altered content must carry machine-readable marks. The high-risk obligations were delayed by the AI Omnibus, which entered into force on July 27, 2026: the sensitive-area use cases in Annex III now apply from December 2, 2027, and systems embedded in regulated products from August 2, 2028.

For a buyer of an AI-labelled service, the practical consequence is the transparency layer. If a vendor puts a chatbot in front of your customers in the EU, or generates content your business publishes there, the disclosure and marking obligations exist now and someone has to own them in the contract. The Commission's guidelines on transparency obligations and its code of practice on marking AI-generated content, both linked from the pages above, are the documents to ask the vendor about.

What the checklist does with these

Question 1 is the FTC's question: is the thing you are selling as AI actually AI, and can you show it. Question 4 is the Workado question: what was the test behind the number. Questions 2, 3 and 8 are the EU questions: who processes what, where, and who tells the end user. Question 9 asks the vendor to volunteer its own regulatory history before you find it.

03The checklistThe ten questions

Send the left column. Keep the right column for yourself; it is why each question is there, and the order in which to weigh the answers.

Digital Applied's checklist, September 20, 2026. The questions are ours; the regulatory context is in sections 01 and 02.
#Question to sendRisk it retires
1Which steps of the service are automated, which are done by a person, and which are a person using an AI tool?Paying automation prices for manual work, or manual prices for a script
2Which model providers and subprocessors touch our data, and will you name them in the contract?An unknown third party holding your customer data
3What data is the system trained, fine-tuned or prompted on, and is any of it ours or a competitor's?Your data improving a rival's service; confidentiality breaches
4For any quoted improvement, what was the before, the after, the sample size, the period and the method?A percentage with no denominator
5Is any outcome guaranteed, and if so what is the remedy in writing?A guarantee that is a marketing line, not a contract term
6What audit rights do we have: logs, samples of AI output, and the right to inspect on notice?No way to check the answer to question 1 after signing
7When the AI is wrong, who catches it, how often is it checked, and who pays for the rework?Errors reaching your customers under your name
8Where is our data stored, for how long, who can read it, and what happens to it when we leave?Retention and access you did not agree to
9Which of your public claims about AI have you had to withdraw, correct or settle?Buying from a vendor already known to a regulator
10Will you put the answers to questions 1 to 9 in the contract as representations?A verbal answer that evaporates at renewal

04The stop signsAnswers that should end the conversation

Most vendors will answer most of the questions well. These are the answers that mean you stop, because each one is the shape of a claim a regulator has already tested.

A percentage with no denominator"Our clients see 40% more leads" with no before, after, sample or period. The FTC alleged Workado had no competent and reliable evidence for its 98%.
Q4
A guarantee with no remedy"Results guaranteed" that is not a contract term with a refund, credit or exit attached
Q5
A refusal to name model providers or subprocessors"Proprietary" is not an answer to where your customer data goes
Q2
"Nothing is ever done by a person"Either untrue or unchecked. The FTC's Cox Media Group orders turned on a service that did not work the way it was sold.
Q1, Q7
No audit rights of any kindIf you cannot sample the output or read a log, question 1's answer is unverifiable for the life of the contract
Q6
A refusal to put the answers in writingAn answer the vendor will not represent is an answer the vendor does not stand behind
Q10

05The readingReading the answers

Good answers have a recognisable shape. They name things: a model provider, a region, a retention period, a person's role. They attach a method to every number and a remedy to every promise. And they distinguish, without being pushed, between what the system does alone, what a person does with it, and what a person does without it. Three answer patterns cover most vendors.

Pattern 1
Automated with human review
Most agencies and many tools

The system drafts or classifies; a person checks a stated share. Ask for the share, who the person is, and what the review found last month. This is a legitimate and common design; the risk is a review rate that is asserted rather than measured.

Verify the rate
Pattern 2
Fully automated
Pipelines, classifiers, monitoring

No person in the loop by design. Then questions 6 and 7 carry the weight: what is logged, how you can sample it, and who pays when it is wrong. The EU transparency obligations attach here if end users interact with it.

Verify the logs
Pattern 3
A person using AI tools
Consultancies, content, research

Perfectly fine, and often what "AI-powered" means. The honest vendor prices it as human work made faster. The risk is question 3: what tools, on what data, under what terms.

Verify the data

Two of our earlier posts help with the data questions in particular. Who can read your conversations with an AI product, by vendor, is in our human-review census; what people are actually willing to let an agent do on their behalf, by survey, is in our access-permissions statistics post. And how the frontier labs themselves are evaluated, which is question 4 one level up, is the subject of our census of independent evaluation arrangements. If you would rather have the ten questions answered about our own services before you ask them, our AI transformation service page is where to start.

06Next stepThe claim is only as good as the sentence the vendor will sign

Put it into practice

Send the ten questions before the demo, and make question 10 a condition of the deal

Paste the left column of the table into your next vendor email. Score the replies against the six stop signs. For the vendors that pass, ask for the answers as contract representations, with the audit right from question 6 and the remedy from question 5 attached. A vendor that agrees has told you what AI-powered means in its case; a vendor that declines has told you too.

Digital Applied

Buy AI services on written terms.

We answer these ten questions about our own work up front, and we help clients run the same checklist across every AI vendor they are considering.

Vendor checklistContract representationsAudit design
Your next project

Start with the ten questions

  • What is automated and what is not
  • Where your data goes and who sees it
  • What the vendor will sign
Questions and answers

Applying this post

No. It is a procurement checklist with the regulatory context quoted from the regulators' own pages and dated. For a contract in your jurisdiction, ask a lawyer; for the regulatory documents themselves, the links in sections 01 and 02 go to the primary pages.
Digital Applied newsletter

Deep dives on AI, marketing and development.

Practical guides and fresh insights by email. No recycled takes.

Related dispatches

Continue reading

Business

Hassabis Proposes a FINRA for AI: What Buyers Should Know

DeepMind's Demis Hassabis proposes a FINRA-style body where frontier labs submit models 30 days pre-release. Why buyers should treat it as a procurement signal.

July 14, 2026 · 11 minRead
AI Development

Who Checks a Frontier AI Lab's Work? 12 Arrangements

A census of 12 external evaluation arrangements at Anthropic, OpenAI and Google DeepMind: who evaluates, who pays, what access they get, what gets published.

September 20, 2026 · 6 minRead
Business

How Much of Their Own Work AI Does at Tech Companies

28 on-record figures from 13 companies on how much of their own code or work AI does, each with its exact definition, date and source. Why none are comparable.

September 18, 2026 · 9 minRead
Business

The AI Tool You Use Does Not Own the Model It Runs On

Most AI products resell a model under a contract between two other companies, and contracts end. Four durable places to check what your tool actually runs.

August 28, 2026 · 17 minRead
Business

Use Customer Questions for AI Content Without Exposure

Turn customer questions into AI-assisted content briefs while reducing identifying details, preserving meaning and checking the finished text for exposure.

September 14, 2026 · 5 minRead
Business

PixVerse's $439M Bet: From Video Models to Game Engines

PixVerse closed a $439M Series C at a $2B-plus valuation and is betting it on an AI-native game engine, not video. Alibaba led the round as backer and buyer.

July 24, 2026 · 10 minRead