ELL ADVISORY

What to Ask an AI Vendor Before You Sign: A UK Buyer's List

Fawad Bhatti, Founder of Ell Advisory
Founder, Ell Advisory · Ex-Hilti Principal PM · HEC Paris MBA
18 min read

TL;DR

The UK's only official AI procurement guidance was published 8 June 2020 and is written for public sector buyers. Private mid-market buyers have nothing. Three things worth knowing before you sign: ISO/IEC 42001 certifies the organisation, not the product — it is not assurance that the thing you are buying works; UK GDPR Article 28(3) makes nine contract terms mandatory where the vendor touches personal data, and the sub-processor clause is the one that reveals which model provider is actually behind the product; and anything that allocates work to people or scores their performance is caught by Annex III(4)(b) of the EU AI Act from 2 December 2027 — inside the life of a three-year contract signed now. Start with where your admin time actually goes.

A quote for an AI system landed on my desk last month. Six figures. Four pages. One line of pricing: "Discovery, build and integration — fixed price."

I wrote about what the components actually cost a few weeks ago, so I will not repeat the arithmetic. The point here is different, and it is not really about price. A finance director handed that quote has nothing to push against. There is no unit, no rate, no split — and so no question they can ask that does not sound like haggling.

That is a due diligence problem, not a pricing problem. And when I went looking for the guidance a UK mid-market buyer is supposed to use, I found that it does not exist.

8 Jun 2020

Date of the UK's only official AI procurement guidance

Office for AI — written for the public sector

38

Controls in ISO/IEC 42001 Annex A

Across nine areas — organisation, not product

9

Contract terms the ICO says are mandatory

UK GDPR Article 28(3)

2 Dec 2027

Worker-management AI becomes high-risk

EU AI Act Annex III(4)(b)

There is no guidance written for you

The UK does have official guidance on procuring AI. Guidelines for AI Procurement was published on 8 June 2020 by the Office for Artificial Intelligence, with the Government Digital Service, Crown Commercial Service and the World Economic Forum. It is still live on gov.uk, with no withdrawal notice, so it remains current.

It is also, in its own words, for "public sector procurement professionals."

I am not going to call it outdated, because much of it holds up. The problem is narrower and more awkward: it is six years old, and it was written for a buyer with a procurement function, a legal team, and a statutory duty to run a fair competition. A 180-person manufacturer buying its first AI system has none of those things, and it is buying under commercial pressure from a salesperson who does this every week.

So the list below is the one I use. It is not legal advice — see the note at the end — and where an item rests on published rules I have sourced it, so you can check the rule rather than take my word.

ISO 42001 certifies the company, not the product

This is the single most common category error I see, and it is expensive.

ISO/IEC 42001 is the first international standard for an AI management system, published in December 2023. Its Annex A sets out 38 controls across nine areas, covering AI policy, impact assessment, the AI lifecycle and data governance. It is a real standard and getting certified is not trivial.

But read what it certifies. From BSI, the UK national standards body and one of the bodies that certifies against it: certification applies to organisations, not products. It says the company has a governance system for how it develops and uses AI.

It does not say the product you are being sold is accurate. It does not say it works on your documents, in your industry, at your volumes. A certified vendor can sell you a system that performs badly on your data and remain entirely compliant with the standard, because the standard is about how they run themselves.

The question that separates the two

"You're ISO 42001 certified — what does your management system say about accuracy testing on a new customer's data before go-live?" A vendor with a real system will have an answer, because impact assessment and lifecycle management are in Annex A. A vendor treating it as a badge will change the subject.

Treat the certificate as a signal about the company's maturity, which is genuinely useful. Do not treat it as product assurance, which it is not, and do not let it substitute for a pilot on your own data.

The nine terms the ICO says must be in the contract

If the vendor processes personal data on your behalf — and almost any system touching employees, engineers, drivers or customers does — then they are a processor and you are the controller. A written contract is mandatory, and UK GDPR Article 28(3) sets out what it has to contain.

This is not a negotiating position. It is the minimum content of a lawful contract, and the ICO publishes the list.

Exhibit 1 — UK GDPR Article 28(3)

What the contract must contain, and the question it becomes

Required termAsk the vendor
1Subject matter and duration of processingWhat personal data does the system touch, and for how long is it held?
2Nature and purpose, and duty to assistWhat exactly is the system doing with it — storing, inferring, training?
3Acts only on documented instructionsCan you use our data for anything we have not written down — including improving your model?
4Sub-processors need authorisation, notice and back-to-back termsName every sub-processor, including the model provider and its country. Notify us before you change one.
5Appropriate technical and organisational measuresHow do you help us answer a subject access request about data inside your system?
6Assistance with security, breaches and DPIAsWhat is your breach notification window to us, in hours?
7Deletion or return at end of contractOn termination, do we get the data back or is it deleted — our choice, and in what format?
8Submit to audits and inspectionsWill you accept an audit clause, or only a certificate in place of one?
9Provide information to demonstrate complianceWho is your DPO or data protection contact, and will they take a call from ours?

Required terms as published by the Information Commissioner's Office, "What needs to be included in the contract?", UK GDPR Article 28(3), fetched 29 July 2026. The right-hand column is the author's rendering of each requirement as a buying question, not ICO wording.

Item 4 is the one to lead with. An AI vendor that calls a third-party model API is engaging a sub-processor. Most buyers I speak to have no idea which model provider sits behind the product they are buying, or which country it runs in — and quite often the vendor would rather they did not ask, because the answer reveals how thin the product is.

Article 28(3) gives you the right to know, the right to be told before it changes, and the right to object. Use it. "Name every sub-processor including the model provider and the hosting region" is a lawful, ordinary request, and the quality of the answer tells you more about the vendor than the demo did.

The ICO also notes it may issue standard clauses for controller–processor contracts, which is worth watching if you are doing this repeatedly.

Do you need a DPIA?

Probably, but not automatically — and the honest answer matters, because "every AI project needs a DPIA" is both wrong and the kind of thing that gets ignored once someone discovers it is wrong.

Article 35(3) of the UK GDPR makes a DPIA mandatory for:

  • systematic and extensive evaluation of personal aspects based on automated processing, including profiling, where decisions produce legal or similarly significant effects;
  • large-scale processing of special category data;
  • systematic monitoring of a publicly accessible area on a large scale.

Separately, the ICO treats innovative technology as a high-risk factor, and explicitly names artificial intelligence, machine learning and deep learning as examples. The ICO's position is that a combination of two high-risk factors normally means a DPIA is required, though a controller may decide innovative technology alone is enough. The controller — you, not the vendor — is responsible for that assessment.

In practice: AI gives you one factor for free. Most systems that touch workers pick up a second one without trying. If your AI allocates jobs, scores performance, or reads anything about an identifiable person at scale, assume a DPIA and be pleased if you are wrong.

The clause that outlives the contract

I covered this in detail when the Digital Omnibus came into force, so briefly.

Annex III(4)(b) of the EU AI Act classifies as high-risk any AI used to allocate tasks on the basis of individual behaviour or personal traits, or to monitor and evaluate performance and behaviour. Dispatch software that assigns jobs to engineers based on how they performed on previous jobs is inside that description. So is a productivity dashboard that ranks them.

Those obligations apply from 2 December 2027. A three-year platform contract signed this autumn runs straight through it.

Ask this before signature, not at renewal

Not "are you compliant" — nobody is, because the harmonised standards are unfinished, which is precisely why the deadline moved. Ask: what is your plan for December 2027, is it in the roadmap or is it a paid module, and who carries the conformity assessment burden — you or me? Then get the answer written into the contract rather than the sales deck.

If you sell only into the UK and no output of the system reaches the EU, this may not apply to you at all — the scoping walkthrough is in that post.

Price: demand the split

One line of pricing is not a price. From the cost benchmark: on a typical build the model itself is around 1.4% of year-one spend, published unit prices for document extraction span 135x between the cheapest and dearest meters, and the median UK contract day rate for machine learning work is £575.

Those three facts mean a quote should break into at least four lines, because each moves on a completely different driver — and only one of them is genuinely negotiable.

Exhibit 2 — Anatomy of a quote you can challenge

The four lines, what drives each, and where the negotiation actually is

LineWhat drives itNegotiable?
Model / inferencePublished per-token or per-page list prices. Roughly 1.4% of year-one spend on a typical build.Barely — it is a list price
Hosting and runCloud region, uptime commitment, data residency. Recurring, and it outlives the build.Some — via architecture
Build daysDay rate × days. UK contract median for machine learning work is £575/day.Yes — this is the negotiation
Support and changeWhat happens after go-live, and what a change request costs once you are committed.Yes — and check it now

Model share of year-one spend and the £575 median contract day rate from the Ell Advisory 2026 AI cost benchmark (ITJobsWatch machine learning contract median, n=1,026, six months to 27 July 2026). The negotiability column is the author's judgement, not a sourced figure.

A vendor who will not split them is either hiding the margin or does not know their own cost base. Both are worth finding out before you sign.

Ownership and exit

The last section has no source behind it, so I will label it plainly: this is my opinion, formed from watching these contracts, not a rule I can point you at.

Get explicit written answers on who owns what when it ends. The code and configuration. The prompts, which in a lot of these systems are the actual intellectual property. Any fine-tuned weights or trained artefacts derived from your data. The extracted, structured data itself, which is usually the most valuable thing produced and the thing most likely to be locked in a proprietary schema.

And ask the exit question in the least comfortable form: if we terminate in eighteen months, what do we walk away with, in what format, and what does it cost to get it? Vendors who have thought about this answer immediately. The pause before the answer is the information.

Where to start

None of this needs a lawyer to begin. It needs you to know which processes the system will touch and what data moves through them — the same inventory that tells you where your admin time is going, which is what the hidden waste audit is for. If you would rather work through a live quote with someone who has read a few hundred of them, book a call.

This is not legal advice

Ell Advisory is an operations and AI consultancy, not a law firm. The Article 28(3) terms and the DPIA triggers above are reproduced from published ICO guidance and UK GDPR, and are accurate as fetched on 29 July 2026 — but whether and how they apply to a specific contract is a question for a qualified adviser. The ownership and exit section is explicitly opinion. Take proper advice before signing anything material.

Frequently Asked Questions

What should I ask an AI vendor before buying?

Ask for a priced breakdown rather than a single fixed-price line, covering model and inference, hosting and run, build days and support. Ask them to name every sub-processor including the model provider and its hosting region, which UK GDPR Article 28(3) entitles you to. Ask what their ISO 42001 management system says about accuracy testing on your data before go-live. Ask what happens to your code, prompts, trained artefacts and extracted data on termination, in what format and at what cost. And for anything that allocates work or scores people, ask what their plan is for the EU AI Act's December 2027 high-risk obligations.

Does ISO/IEC 42001 mean an AI product is safe?

No. ISO/IEC 42001, published in December 2023, certifies an organisation's AI management system, not an individual product. Its Annex A contains 38 controls across nine areas covering AI policy, impact assessment, lifecycle and data governance. A certified vendor can still sell a product that performs poorly on your data. Treat it as evidence of company maturity, not as product assurance, and still run a pilot on your own data.

What must an AI supplier contract include under UK GDPR?

Where the supplier processes personal data on your behalf, Article 28(3) requires the contract to set out the subject matter and duration of processing; its nature and purpose; that the processor acts only on your documented instructions; that sub-processors require your authorisation, with notice of changes and back-to-back obligations; appropriate technical and organisational measures; assistance with security, breach notification and DPIAs; deletion or return of data at the end of the contract at your choice; submission to audits and inspections; and provision of the information needed to demonstrate compliance.

Do I need a DPIA for an AI project?

Often, but not automatically. UK GDPR Article 35(3) mandates a DPIA for systematic and extensive automated evaluation producing legal or similarly significant effects, large-scale special category data processing, or large-scale systematic monitoring of a publicly accessible area. Separately the ICO treats innovative technology — naming AI, machine learning and deep learning — as a high-risk factor, and generally expects a DPIA where two high-risk factors combine. As controller, the assessment is your responsibility, not the vendor's.

Who owns the code and data in an AI project?

There is no default answer in law, which is why it must be written down. Establish separately who owns the source code and configuration, the prompts, any fine-tuned weights or trained artefacts derived from your data, and the structured data the system produces. The extracted data is usually the most valuable output and the most likely to be locked in a proprietary schema, so agree the export format and any exit cost before signature rather than at termination.


Sources. Guidelines for AI Procurement, Office for Artificial Intelligence, 8 June 2020, via gov.uk (checked for withdrawal notice 29 July 2026). ISO/IEC 42001 scope and certification basis via BSI; standard identity via the ISO catalogue. Article 28(3) required terms via the ICO. DPIA triggers via the ICO on when a DPIA is needed and examples of high-risk processing. EU AI Act positions carried from the 30 July analysis, verified 28 July 2026. All URLs fetched and verified 29 July 2026.