Practical AI Readiness

Vendor Claims vs. Reality: How to Evaluate AI Features

"AI-powered" is on every vendor slide right now. Here is what it actually means, what it usually does not mean, and the questions worth asking before you sign anything.

Magnifying glass highlighting AI features in a vendor agreement

Every vendor has AI features now. It says so on the website, in the demo, in the renewal email, and in the proposal that landed in your inbox this week.

What it rarely says is what those features can actually access, what they do with your data, whether you can turn them off, and what happens to the information that flows through them.

That gap, between what a vendor claims and what you are actually agreeing to, is where most nonprofit technology risk quietly lives. And it is almost never surfaced in a demo.

This is not because vendors are dishonest. It is because demos are designed to show you what works. Your job, before you sign or renew anything, is to ask about what does not.

"Demos are designed to show you what works. Your job, before you sign or renew anything, is to ask about what does not."

What Vendor AI Claims Actually Mean

Here are the phrases you will hear most often, and what they usually mean in practice.

"AI-powered". This means the product uses some form of machine learning or automation in its workflow. It does not tell you where, how, or what data it uses to do it. Ask what specifically is AI-driven and what is not.

"Built-in AI assistant". This usually means a chat or drafting feature layered on top of the core product. What it does not tell you is whether that assistant can access your organizational data, your client records, your communication history, or your connected integrations. Ask exactly what the assistant can see.

"We use your data to improve the product". This is the sentence that deserves the most follow-up. It can mean anything from basic usage analytics to training AI models on your content. Ask whether your data is used to train models, whether you can opt out, and what the default setting is on your current plan.

"Enterprise-grade security". This describes how the data is stored and transmitted. It says nothing about what the vendor does with the data once they have it. Security and privacy are different questions. Ask both.

"Compliant with HIPAA / SOC 2 / GDPR". Compliance certifications confirm the vendor has met certain standards. They do not confirm that your specific use of the product is compliant, or that the AI features you are evaluating fall under the same certification scope. Ask whether the AI features specifically are covered.

The Questions That Actually Surface the Problems

You do not need to become a technical expert to evaluate a vendor's AI claims. You need six questions. Ask them before the demo ends, before the contract is signed, and before any renewal that includes new AI features.

1What data does this feature access?

Get specific. Does it access client records? Communication history? Connected integrations? Files stored in the platform? Do not accept "it only uses what you give it" as a complete answer. Ask what it can access even if you do not actively give it anything.

2Is my data used to train AI models?

This is the most important question and the one most people forget to ask. The answer varies significantly between free and paid tiers, and often between product versions. Get it in writing if you can.

3Can I opt out, and what is the default?

Many platforms default to opt-in for data training, meaning you are contributing unless you actively change a setting. Ask where that setting is, whether it applies to your whole organization, and whether it covers all AI features or just some of them.

4How long is my data retained, and what happens to it when I leave?

Data retention policies vary widely. Ask specifically about AI feature data, not just general platform data. They are sometimes governed by different terms.

5Who do I call when something goes wrong?

Not when the software crashes. When the AI feature does something unexpected with client data, sends something it should not have, or surfaces information in a context it should not appear in. If the vendor cannot give you a clear answer, that is a governance gap, not a support question.

6What does this feature do that I cannot turn off?

Some AI features are optional. Others are embedded in the core workflow and cannot be disabled without affecting core functionality. Know which one you are dealing with before you commit.

A Note on Free Tiers and Built-In Features

Two situations deserve extra attention because they are where most nonprofit AI risk actually shows up.

Free tiers almost always operate under different terms than paid or enterprise plans. If your organization is using a free version of any AI tool, check the privacy policy and terms of service specifically for the free tier. The answers to the six questions above are often very different from what applies to the paid version.

Built-in features inside platforms you already pay for deserve the same scrutiny as standalone tools. An AI summarization feature added to your meeting platform, a drafting assistant built into your CRM, or an automation layer added to your project management tool: none of these are covered by the security review you did when you first signed the contract. They need a fresh look.

What You Are Actually Responsible For After the Contract is Signed

Vendors are responsible for building products that do what they say. You are responsible for understanding what you agreed to and making sure it fits how your organization handles information.

That is not a small responsibility. Your clients, donors, and community members did not consent to having their information processed by tools your organization never reviewed. The fact that a vendor offers a feature does not mean your organization has evaluated whether using it is appropriate.

The demo will not tell you that. The questions above will get you closer.

Next Step

Ready to Formalize Your Vendor Review Process?

The Nonprofit AI Readiness Toolkit includes a structured vendor and platform risk review. It walks you through exactly what to capture for each tool, how to assess the risk level, and what follow-up looks like when the answers are unclear.

If you have a vendor conversation coming up, or a renewal on the calendar, the toolkit gives you the framework to evaluate it properly.

SERIES: Practical AI Readiness

Lisa Montague is Partner and CEO at Coat Rack, a nonprofit technology consulting firm based in Cedar City, Utah.