Every agency, software vendor and consultancy now says AI-powered, and from the outside a buyer cannot tell an automated pipeline from a person with a chatbot tab open. The difference matters for price, for where your data goes, and for who is accountable when the output is wrong. Regulators on both sides of the Atlantic have started saying so in enforceable terms, which gives a buyer something better than instinct to point at.
This post is a checklist a founder or operations lead can send to any vendor as it stands. It gives ten questions, maps each to the risk it retires, lists the answers that should end the conversation, and quotes what the US Federal Trade Commission and the EU AI Act have actually said, with dates. It is not legal advice. And it applies to us: Digital Applied sells AI services, and every question below is one we expect to be asked.
- 01The FTC has held that there is no AI exemption from existing law, and has acted on it since September 2024.Operation AI Comply, announced September 25, 2024, and later orders against Workado (April 2025) and Cox Media Group with two other firms (finalised August 27, 2026) all turned on AI claims the companies could not back.
- 02The EU AI Act's transparency rules have applied since August 2, 2026.Chatbots must say they are AI and AI-generated or altered content must be labelled and machine-readably marked. The high-risk obligations were pushed to December 2, 2027 and August 2, 2028 by the AI Omnibus, in force since July 27, 2026.
- 03Ten questions cover automation, data, evidence, guarantees, audit rights and exit.Each one retires a named risk. The tenth asks the vendor to put the other nine in the contract, which is the question that turns answers into obligations.
- 04A percentage with no denominator ends the conversation.So does a guarantee with no remedy, a refusal to name model providers, and a claim that nothing is ever human-run. The regulator cases below show what those answers looked like when they were tested.
01 — The US recordWhat the US regulator has said
On September 25, 2024 the Federal Trade Commission announced Operation AI Comply, a sweep against companies it said were using AI claims to deceive. Its then chair, Lina Khan, is quoted in the release: "there is no AI exemption from the laws on the books." The first cases included a company that sold an AI service it called the world's first robot lawyer; the FTC's complaint said the company had not tested whether the product matched a human lawyer and had hired none. Its proposed order required a $193,000 payment and barred claims that the service could substitute for a professional without evidence.
The pattern continued under the next administration, with a narrower stated focus. On April 28, 2025 the FTC announced an order against Workado, which had advertised an AI content detector as 98 percent accurate; the FTC said independent testing found about 53 percent on general-purpose content. On December 22, 2025 the same agency set aside an earlier order against an AI writing tool, saying its focus is fraud and tangible consumer harm. On July 1, 2026 it opened comment on a policy statement about AI accuracy. And on August 27, 2026 it finalised orders against Cox Media Group and two other firms over an "Active Listening" marketing service they had claimed used AI on voice data from smart devices; the FTC said the service was not based on voice data and consumers had not opted in. The three firms pay $930,000 in total.
Consumers trusted Workado's AI Content Detector to help them decipher whether AI was behind a piece of writing, but the product did no better than a coin toss.Chris Mufarrige, Director of the FTC's Bureau of Consumer Protection, April 28, 2025
02 — The EU recordWhat the EU AI Act requires, and since when
The dates have moved, so they are quoted from the European Commission's own AI Act page as read on September 22, 2026. The Act entered into force on August 1, 2024 and became applicable on August 2, 2026, with exceptions. The rules for general-purpose AI models applied from August 2, 2025. The transparency rules came into effect in August 2026; the Commission's enforcement notice for August 2, 2026 says chatbots and other interactive systems must tell users they are dealing with AI, deepfakes must be labelled, and AI-generated or altered content must carry machine-readable marks. The high-risk obligations were delayed by the AI Omnibus, which entered into force on July 27, 2026: the sensitive-area use cases in Annex III now apply from December 2, 2027, and systems embedded in regulated products from August 2, 2028.
For a buyer of an AI-labelled service, the practical consequence is the transparency layer. If a vendor puts a chatbot in front of your customers in the EU, or generates content your business publishes there, the disclosure and marking obligations exist now and someone has to own them in the contract. The Commission's guidelines on transparency obligations and its code of practice on marking AI-generated content, both linked from the pages above, are the documents to ask the vendor about.
Question 1 is the FTC's question: is the thing you are selling as AI actually AI, and can you show it. Question 4 is the Workado question: what was the test behind the number. Questions 2, 3 and 8 are the EU questions: who processes what, where, and who tells the end user. Question 9 asks the vendor to volunteer its own regulatory history before you find it.
03 — The checklistThe ten questions
Send the left column. Keep the right column for yourself; it is why each question is there, and the order in which to weigh the answers.
| # | Question to send | Risk it retires |
|---|---|---|
| 1 | Which steps of the service are automated, which are done by a person, and which are a person using an AI tool? | Paying automation prices for manual work, or manual prices for a script |
| 2 | Which model providers and subprocessors touch our data, and will you name them in the contract? | An unknown third party holding your customer data |
| 3 | What data is the system trained, fine-tuned or prompted on, and is any of it ours or a competitor's? | Your data improving a rival's service; confidentiality breaches |
| 4 | For any quoted improvement, what was the before, the after, the sample size, the period and the method? | A percentage with no denominator |
| 5 | Is any outcome guaranteed, and if so what is the remedy in writing? | A guarantee that is a marketing line, not a contract term |
| 6 | What audit rights do we have: logs, samples of AI output, and the right to inspect on notice? | No way to check the answer to question 1 after signing |
| 7 | When the AI is wrong, who catches it, how often is it checked, and who pays for the rework? | Errors reaching your customers under your name |
| 8 | Where is our data stored, for how long, who can read it, and what happens to it when we leave? | Retention and access you did not agree to |
| 9 | Which of your public claims about AI have you had to withdraw, correct or settle? | Buying from a vendor already known to a regulator |
| 10 | Will you put the answers to questions 1 to 9 in the contract as representations? | A verbal answer that evaporates at renewal |
04 — The stop signsAnswers that should end the conversation
Most vendors will answer most of the questions well. These are the answers that mean you stop, because each one is the shape of a claim a regulator has already tested.
- A percentage with no denominator"Our clients see 40% more leads" with no before, after, sample or period. The FTC alleged Workado had no competent and reliable evidence for its 98%.
- Q4
- A guarantee with no remedy"Results guaranteed" that is not a contract term with a refund, credit or exit attached
- Q5
- A refusal to name model providers or subprocessors"Proprietary" is not an answer to where your customer data goes
- Q2
- "Nothing is ever done by a person"Either untrue or unchecked. The FTC's Cox Media Group orders turned on a service that did not work the way it was sold.
- Q1, Q7
- No audit rights of any kindIf you cannot sample the output or read a log, question 1's answer is unverifiable for the life of the contract
- Q6
- A refusal to put the answers in writingAn answer the vendor will not represent is an answer the vendor does not stand behind
- Q10
05 — The readingReading the answers
Good answers have a recognisable shape. They name things: a model provider, a region, a retention period, a person's role. They attach a method to every number and a remedy to every promise. And they distinguish, without being pushed, between what the system does alone, what a person does with it, and what a person does without it. Three answer patterns cover most vendors.
Automated with human review
The system drafts or classifies; a person checks a stated share. Ask for the share, who the person is, and what the review found last month. This is a legitimate and common design; the risk is a review rate that is asserted rather than measured.
Fully automated
No person in the loop by design. Then questions 6 and 7 carry the weight: what is logged, how you can sample it, and who pays when it is wrong. The EU transparency obligations attach here if end users interact with it.
A person using AI tools
Perfectly fine, and often what "AI-powered" means. The honest vendor prices it as human work made faster. The risk is question 3: what tools, on what data, under what terms.
Two of our earlier posts help with the data questions in particular. Who can read your conversations with an AI product, by vendor, is in our human-review census; what people are actually willing to let an agent do on their behalf, by survey, is in our access-permissions statistics post. And how the frontier labs themselves are evaluated, which is question 4 one level up, is the subject of our census of independent evaluation arrangements. If you would rather have the ten questions answered about our own services before you ask them, our AI transformation service page is where to start.
06 — Next stepThe claim is only as good as the sentence the vendor will sign
Send the ten questions before the demo, and make question 10 a condition of the deal
Paste the left column of the table into your next vendor email. Score the replies against the six stop signs. For the vendors that pass, ask for the answers as contract representations, with the audit right from question 6 and the remedy from question 5 attached. A vendor that agrees has told you what AI-powered means in its case; a vendor that declines has told you too.