Most businesses walk into an AI vendor meeting with the wrong question in mind. They ask “what can this do?” when the better question is “what should we actually be doing, and with what?”

I spend a lot of my discovery calls talking regulated businesses out of bad AI decisions — as often as I talk them into good ones. Here’s what should be on your list before you sign anything.

1. Ask About Their Worst Project (Not Their Best One)

Any vendor can tell you a success story. Ask what went wrong on someone else’s watch, and you’ll learn a lot faster.

I’ve got two stories that sit at opposite ends of the spectrum. On the good end: a large communications provider that couldn’t afford to roll AI out to 100,000 employees at frontier-model pricing. Their fix was to use frontier models for reasoning and task breakdown, then route the actual work down to local, self-controlled instances — cutting costs by roughly 90%.

On the bad end, it’s a story I’ve seen play out over and over: a company decides to “roll out AI” simply because it came free with a tool they already own, like Microsoft Copilot. Nobody stopped to ask what the business was actually trying to accomplish, which models made sense, or what the security implications were. That approach means handing over sensitive information just because it’s there and it’s free or cheap — with no discussion of policies, procedures, data governance, sovereignty, or compliance before rollout.

The takeaway for your meeting: ask the vendor to walk you through a project that went sideways, and how they caught it. If they can’t name one, that’s information too.

2. Ask What Questions They Ask You First

A good consultant should be interviewing you before they start scoping anything. If they’re not, that’s a red flag in itself.

Before I scope any Renevar engagement, I want to understand what the business is actually trying to accomplish — sales enablement, financial workflows, something else entirely — and whether the team has a realistic grasp of what AI can and can’t do. I’m also probing for experience with automation: has this business done it before, or is this their first attempt? A lot of what people expect from AI is shaped by consumer tools like ChatGPT, but enterprise environments assume controls — access management, security, audit trails — that don’t come standard the way they do with traditional enterprise software.

There’s a question I know is controversial but necessary: is AI even the right tool for this? Some problems are better, cheaper, or more securely solved without it. A consultant who never asks that question is a consultant trying to sell you AI, not solve your problem.

The takeaway for your meeting: if the vendor jumps straight to a proposal without asking what you’re trying to accomplish and what you’ve tried before, pump the brakes.

3. Ask Enough to Spot the Red Flags Yourself

There’s one phrase that should send you running: “AI can do everything.”

It sounds confident. It’s actually a sign the vendor hasn’t thought the project through — or that they’re really just selling automation and process work dressed up as AI. And there’s a real downstream risk: when a vendor claims a single tool handles everything, they usually end up quietly pulling in third-party services and connectors to cover the gaps AI can’t fill on its own. Each of those integrations is a new place your data can go, often without a clear answer to where.

The takeaway for your meeting: ask directly what the tool can’t do, and who else your data touches once it’s connected. A vendor with a real answer has done the work. A vendor who deflects hasn’t.

4. Ask How Compliance Has Actually Changed a Project — Not Just Whether They “Support” It

Plenty of vendors will say they support SOC 2 or HIPAA. Fewer can tell you a specific moment where that requirement changed their technical approach.

Here’s an example: under SOC 2 Type II, auditors don’t just take your word for it — they require evidence, including a full accounting of third-party processors and exactly what data each one touches. Every AI auxiliary tool you connect — MCP servers, integrations, anything tied into a frontier model — becomes another third-party vendor in that audit trail. With HIPAA and other frameworks covering personal or medical information, the stakes are even higher: you generally can’t pass an audit unless identifiable data is stripped out or handled with real controls. The compliance requirement doesn’t just add paperwork — it dictates what data can touch the cloud at all, and shapes the entire technical architecture from there.

The takeaway for your meeting: ask for a specific example of a compliance requirement that forced a redesign, not a checklist of frameworks they claim to support.

5. Ask Them to Correct Your Biggest Misconception

If a vendor tells you the price is fixed, ask them to explain why — in detail.

This is one of the most common and costly misunderstandings I’m seeing right now. Low flat rates for AI tools are largely possible because they’re being subsidized by the frontier model providers — not because the real cost of usage is actually that low. Pricing is fundamentally about tokens, the unit that measures how much you’re using a model, and token consumption has changed dramatically with the rise of agentic AI. Where a chat-based interaction used to be the norm, agents now run tasks autonomously for extended periods, and I’ve seen token usage run 10 to 50 times higher for “power users” and developers than for someone doing occasional chat-based work. Even Microsoft is shifting Copilot toward token-based pricing to capture that real cost — and the fallout has already made headlines, with some developers reporting their monthly bills jumped from around $29 to nearly $750 after the change took effect.[^1] Assuming a flat number of seats covers you indefinitely simply isn’t realistic. If you haven’t already worked through what platform and pricing model actually fits your business, our breakdown on choosing a secure AI platform is a good next read.

The takeaway for your meeting: ask how usage is measured, what happens when consumption spikes, and get a real answer on tokens — not just a monthly number.

The Real Question Behind All Five

Every one of these questions comes back to the same thing: does this consultant understand your business well enough to tell you no when AI isn’t the answer, and to build the right controls in when it is? If a vendor can’t engage with these five questions specifically, that’s the clearest signal of all.

Curious what a real discovery call looks like? See how Renevar approaches AI implementation, read our breakdown of what AI implementation actually costs, or check what to look for in a managed IT services provider before your next vendor meeting.

[^1]: GitHub Copilot’s new token-based billing spurs consternation among devs, TechCrunch, May 30, 2026.

Brooks Snow is a co-founder of Renevar, a cybersecurity, compliance, and secure AI platform company serving small and mid-size enterprises. With backgrounds spanning software development, network infrastructure, data center operations, and security clearance-level compliance work, the Renevar team has been building secure, always-on systems since 2000.

This article was developed from a recorded interview with Brooks Snow, Chief Executive Officer at Renevar, and drafted with AI assistance. All expertise, opinions, and examples are Brook’s own.