Tool · Compliance CheckI checked these questions and rules on · 23 Aug 2026
What has to be in place before you point AI at anything?
Nine questions about your data, its behaviour and your accountability. No product name comes out, but the requirements that follow from your situation, and the places where your own answers contradict each other.

too long? here it is in six lines
- Nine questions about four things: your data, what it is allowed to do, your accountability and your practice.
- No product name comes out. Model specs age within a month; requirements last years.
- The heaviest question is what goes in. Customer personal data where somebody else is the controller changes everything after it.
- The most skipped question is whose name it acts under. An agent under an employee's session has that person's permissions and leaves that person's trail.
- Below the requirements are the contradictions: places where two of your own answers cannot both stand. That is the most interesting part.
- Not legal advice. It maps what you need to find out; the answers come from your own contracts.
With most AI projects that stall, the technology is not the problem. They stall on a question nobody asked beforehand and that turns out afterwards to be the most important one. Is this kind of information allowed in here. Who is accountable when it goes wrong. Who manages this a year from now.
Those are not legal questions. They are design questions dressed up as legal questions, and they usually get asked after something has already been bought.
This check asks them first. Nine questions, three minutes, and you get no product advice but a list of requirements: this is what you should demand of any vendor, given what you feed it and what you let it do.
Why no product name comes out
That is a deliberate choice. Model specifications and terms change every few weeks. An instrument that names a product is wrong within a month in a way nobody notices, because it still looks authoritative.
Requirements age far more slowly. “There has to be a processing agreement” and “I have to be able to show what happened” still hold when the whole market looks different again. So that is what you get here.
The four things this is about
Your data. What goes in, may it leave the EU, and may the vendor use it to improve their models. Those three questions together decide most of the outcome. If nothing in there is non-public, almost anything is fine. If it contains personal data of customers for which somebody else is the controller, that changes everything that comes after it.
Its behaviour. What is the thing allowed to do: only answer, make proposals somebody approves, or act inside systems itself. And under whose name does that happen. This is the question that gets skipped fastest and costs the most afterwards, because an agent working under an employee’s session has exactly that person’s permissions and leaves exactly that person’s trail.
Your accountability. Do you have to be able to demonstrate later what happened, and who carries the risk when it goes wrong. When the answer is “not written down anywhere”, that does not mean there is no risk. It means the risk is yours.
Your practice. Which cost model can you sell or justify, and who manages this a year from now. That last question is not there for form’s sake. Most AI pilots do not die of technology, they die of ownership.
What contradictions are, and why they are the point
Below the requirements there is a block with contradictions. That is the most interesting part of the outcome.
A contradiction is a place where two of your own answers cannot both stand. You want it to act inside systems on its own, for instance, but it may only work under the user’s session and you want to be able to demonstrate afterwards who did what. Those three together do not work. Not because a vendor falls short, but because it does not add up internally.
That is exactly what an adviser digs out in an hour-long conversation, and what no questionnaire tells you. If nothing comes out, that is information too: it usually means you answered a few questions with “I do not know”.
How to read the outcome
At the top are the hard requirements: do not start without these. Below them the trade-offs, so not a blocker but a choice you should make deliberately. Every line says which answer it follows from, so you can go back and change an answer if you disagree.
A report comes out that you can download. It is a self-contained file you forward to whoever has to read the agreement, and that is usually not the person who picked the tool.
What this is not
Not legal advice, and I am not a lawyer. This instrument tests nothing against any law or standard. It maps which questions you need to answer before you choose; the answers to those questions come from your own contracts and your own advisers.
And it runs entirely in your browser. Your answers go nowhere, because there is no server to send them to. That is not only tidy, it is also the reason you dare put commercially sensitive answers into it.
Everything happens in your browser. Your answers go nowhere. There is no server to send them to.
What comes out
Answer the questions. The result appears below as you go.
Self-contained HTML file. Forward it to your security officer or your customer.