FISTA Solutions does not load Google Analytics until you accept. Rejecting keeps optional analytics off. Read the Cookie Policy.

All field notes

Leadership · 4 minute read

How to Answer Customer Questions About AI

Customers ask four things: whether AI touches their data, whether a human reviews decisions affecting them, what happens when the AI is wrong, and whether their data trains models. Answer with specific, consistent facts from the inventory and contracts, and never promise controls you do not have.

By FISTA Solutions· AI-Native Engineering Team·
How to Answer Customer Questions About AI article cover

Customer questions about AI have moved from curiosity to procurement. Security questionnaires now include AI sections, contracts include AI clauses, and account teams are asked in meetings whether a human reviews the decisions. Companies that answer inconsistently create problems that surface later in audits and renewals. This guide gives the four recurring questions, how to answer them, and how to maintain the answers.

What do customers actually ask?

QuestionWhat they need to knowWhere the answer comes from
Does AI process our data, and which data?Their own compliance positionThe inventory and data flow mapping
Is a human involved in decisions affecting us?Whether they can contest outcomesThe autonomy and oversight design
What happens when the AI is wrong?Error handling and remedyIncident and correction processes
Is our data used to train models?Confidentiality and competitive concernProvider contracts and internal policy
Where is processing performed?Residency obligationsDeployment configuration
What is your AI governance?Whether you are in controlInventory, framework, evidence

Each has a factual answer that exists somewhere in the company. The failure is not usually that the answer is bad; it is that nobody can produce it consistently.

Why does the answer set need an owner?

Because inconsistent answers cause the damage. One account team says no AI touches customer data; another describes an agent that does; a questionnaire response says something different again. The customer notices, the trust cost is immediate, and in a contract negotiation the inconsistency becomes leverage.

The remedy is a single maintained answer set, grounded in the inventory and the actual contracts, reviewed by security and legal, with one named owner who updates it as deployments change. Sales, support, and account teams use it verbatim rather than improvising. The executive guide to AI agent governance describes the inventory the answers draw on.

How should the data question be answered?

Specifically. "We use AI in the following processes; in those processes the following categories of your data are processed; it is processed by these providers under contracts that prohibit training on your data and specify these retention periods; processing occurs in these regions." That level of detail satisfies most enterprise customers and can be verified.

Vague answers ("we take data security seriously") invite escalation to their security team, which then asks harder questions of a less prepared audience. The data residency explained for executives piece covers the processing-location component.

How should the human review question be answered?

By reference to the actual design: which decisions are made by people, which are prepared by AI and decided by people, and which are automated with monitoring. If a decision affecting the customer is automated, say so and explain how they can contest it, which in several jurisdictions is also a legal requirement.

This is the question where over-promising is most tempting and most dangerous. A commitment that a human reviews every decision, made in a sales meeting and written into a contract, is expensive if the process actually samples. The how much autonomy should AI agents have guide covers the design the answer must reflect.

What if the customer asks for a control you do not have?

Say so, plainly, then state what you do have and what you could commit to and by when. Three reasons this is the right answer: promising an absent control is a contractual exposure; customers with mature procurement will audit; and a clear boundary is received better than a vague assurance that later unravels. If the control is genuinely needed by several customers, that is a product decision to take deliberately, not a commitment to make in a meeting.

Should customers be told proactively?

Where AI affects them, yes: when they interact with an agent, when AI informs a decision about them, and when their data is processed by AI. Some of this is legally required in several jurisdictions, and all of it is better delivered by you than discovered by them. Customers told plainly generally accept it; customers who discover undisclosed AI use react to the concealment more than to the AI. The AI transparency with employees and customers guide covers the design.

What should executives ask?

  • Do we have one maintained answer set, and who owns it?
  • Could we answer, for any customer, which of their data AI processes?
  • Have we promised any control in a contract that we do not actually have?
  • When did the answer set last get updated against the inventory?
  • What do we tell customers proactively, and is it enough?

How can FISTA Solutions help?

FISTA Solutions maintains the inventory, data flow mapping, and oversight documentation that customer answers depend on, through its AI enablement practice, and builds AI agents whose data handling, human review points, and error correction paths are documented and verifiable. Since 2017, FISTA has delivered 150+ projects for 50+ companies across 12+ countries.

To build an answer set your account teams can use without improvising, talk to FISTA on WhatsApp, or read how to build customer trust in AI agents.

Share-ready article cover

Download the generated social format.

Download cover

Clear answers

Questions raised by this field note.

Straightforward guidance for evaluating scope, fit, and the next step.

01What do customers ask about a vendor's AI use?

Whether AI processes their data and which data; whether a human reviews decisions that affect them; what happens when the AI is wrong and how errors are corrected; whether their data is used to train models; where processing occurs; and what the vendor's governance and incident processes are.

02How should a company answer AI security questionnaires?

From a maintained answer set grounded in the inventory and the actual contracts, reviewed by security and legal, with a named owner who keeps it current. Ad hoc answers from whoever receives the questionnaire produce inconsistencies that surface later in audits and contract negotiations.

03Should you tell customers when AI is used in their service?

Yes, where it affects them: when they interact with an agent, when AI informs a decision about them, and when their data is processed by AI. Several jurisdictions require some of this, and customers who discover undisclosed AI use react far worse than those told plainly.

04What if a customer asks for a control you do not have?

Say so, and say what you do have and what you could commit to and by when. Promising a control that does not exist creates a contractual exposure and an incident waiting to be discovered during an audit. Customers respect a clear boundary more than a vague assurance.

05Who should own customer AI answers?

A named owner, usually in security, legal, or the AI program, maintaining a single answer set that sales, support, and account teams use. The answers must be updated as deployments and contracts change, because stale assurances become false statements.

Start with the hard problem

Need the outcome owned, not merely analyzed?

Tell us where delivery is constrained. We’ll map the fastest credible path from intent to verified production.

Start a project