notahuman.nl

Tool · Compliance CheckI checked these questions and rules on · 23 Aug 2026

What has to be in place before you point AI at anything?

Nine questions about your data, its behaviour and your accountability. No product name comes out, but the requirements that follow from your situation, and the places where your own answers contradict each other.

In front of a closed door with a clipboard, going down the list before going in

With most AI projects that stall, the technology is not the problem. They stall on a question nobody asked beforehand and that turns out afterwards to be the most important one. Is this kind of information allowed in here. Who is accountable when it goes wrong. Who manages this a year from now.

Those are not legal questions. They are design questions dressed up as legal questions, and they usually get asked after something has already been bought.

This check asks them first. Nine questions, three minutes, and you get no product advice but a list of requirements: this is what you should demand of any vendor, given what you feed it and what you let it do.

Why no product name comes out

That is a deliberate choice. Model specifications and terms change every few weeks. An instrument that names a product is wrong within a month in a way nobody notices, because it still looks authoritative.

Requirements age far more slowly. “There has to be a processing agreement” and “I have to be able to show what happened” still hold when the whole market looks different again. So that is what you get here.

The four things this is about

Your data. What goes in, may it leave the EU, and may the vendor use it to improve their models. Those three questions together decide most of the outcome. If nothing in there is non-public, almost anything is fine. If it contains personal data of customers for which somebody else is the controller, that changes everything that comes after it.

Its behaviour. What is the thing allowed to do: only answer, make proposals somebody approves, or act inside systems itself. And under whose name does that happen. This is the question that gets skipped fastest and costs the most afterwards, because an agent working under an employee’s session has exactly that person’s permissions and leaves exactly that person’s trail.

Your accountability. Do you have to be able to demonstrate later what happened, and who carries the risk when it goes wrong. When the answer is “not written down anywhere”, that does not mean there is no risk. It means the risk is yours.

Your practice. Which cost model can you sell or justify, and who manages this a year from now. That last question is not there for form’s sake. Most AI pilots do not die of technology, they die of ownership.

What contradictions are, and why they are the point

Below the requirements there is a block with contradictions. That is the most interesting part of the outcome.

A contradiction is a place where two of your own answers cannot both stand. You want it to act inside systems on its own, for instance, but it may only work under the user’s session and you want to be able to demonstrate afterwards who did what. Those three together do not work. Not because a vendor falls short, but because it does not add up internally.

That is exactly what an adviser digs out in an hour-long conversation, and what no questionnaire tells you. If nothing comes out, that is information too: it usually means you answered a few questions with “I do not know”.

How to read the outcome

At the top are the hard requirements: do not start without these. Below them the trade-offs, so not a blocker but a choice you should make deliberately. Every line says which answer it follows from, so you can go back and change an answer if you disagree.

A report comes out that you can download. It is a self-contained file you forward to whoever has to read the agreement, and that is usually not the person who picked the tool.

What this is not

Not legal advice, and I am not a lawyer. This instrument tests nothing against any law or standard. It maps which questions you need to answer before you choose; the answers to those questions come from your own contracts and your own advisers.

And it runs entirely in your browser. Your answers go nowhere, because there is no server to send them to. That is not only tidy, it is also the reason you dare put commercially sensitive answers into it.

Everything happens in your browser. Your answers go nowhere. There is no server to send them to.

  1. 01

    What goes in?

    This determines nearly everything else. Pick the heaviest category that could occur, not the most common one.

  2. 02

    May that data leave the EU?

  3. 03

    May the vendor use it to improve models?

  4. 04

    What is it allowed to do?

  5. 05

    Whose identity does it act under?

    The question most often skipped, and the most expensive one afterwards.

  6. 06

    Do you need to be able to demonstrate afterwards what happened?

  7. 07

    Who carries the risk when it goes wrong?

  8. 08

    Which cost model can you sell or justify?

  9. 09

    Who manages this a year from now?


What comes out

Answer the questions. The result appears below as you go.

All toolsArchive