When a new AI tool comes up for approval, a familiar process kicks in. Someone sends the vendor a security questionnaire. They check for the right certifications, confirm there's an enterprise tier, read the data-handling page. The tool passes. It gets approved, and everyone feels the box is checked.
It's a reasonable process aimed at the wrong question. "Is this tool safe?" treats safety as something the vendor ships, a property baked into the software. It isn't. Safety lives in how the tool gets used, and no questionnaire reaches that far.
A secure tool used wrong is still a leak
Picture the most locked-down, enterprise-grade, certification-laden AI tool you can. Now picture an employee pasting a confidential client contract into it on a personal account, to summarize before a call. The tool's security didn't fail. It worked exactly as designed. The data still left your control, because the risk was never in the vendor's infrastructure. It was in the decision about what data goes in, and who's using which account.
That's the piece vendor vetting skips entirely. It can tell you the tool won't be the weak link. It tells you nothing about whether your people know what they're allowed to put into it, which is where the actual exposure lives. LayerX's 2025 research found 71% of connections to AI tools run through personal accounts, and that even on corporate accounts, more than half skip single sign-on (the company-managed login IT can actually see and shut off). The carefully approved enterprise tool and the personal-login workaround often sit side by side on the same desk.
Why the vendor question is so tempting
Vetting a tool feels like governance because it's concrete and finite. There's a vendor to email, a checklist to complete, a clear yes or no at the end. The harder questions, what data is fine to use, who decides, how people are expected to work, have no tidy questionnaire and no vendor to hand them to. So the easy task stands in for the hard one, and the hard one quietly never happens.
The result is a company that has approved its tools and still has no idea what's flowing into them. The procurement box is green. The governance box was never really opened.
The question that actually matters
The better question isn't about the tool at all. It's about the use: what data are we comfortable putting into AI tools, which uses are fine and which aren't, and who owns that call? Answer that, and tool selection becomes simple, because you're choosing tools to fit decisions you've already made. Skip it, and the most secure tool on the market just becomes a well-built container for a problem you never addressed.
This is also why choosing tools and governing AI are different jobs, and why we deliberately do only one of them. We never pick or resell tools; that call stays yours, and our contract keeps it that way. What we build is the layer underneath: the traffic-light data classification and approved-tool process your own team applies to this tool, and every tool after it, without another vendor review each time.
Knowing where you stand on that is a better starting point than another vendor review. The AI Readiness Assessment maps it across the five dimensions that decide whether your AI use holds together, in about two minutes.
The tool can be perfectly safe and your data still walks out the door. Safety was always a question about how you use the thing, not about the thing itself.
Keep reading
Part of a series on AI governance, the structure underneath the tools.
- What's Safe to Paste Into ChatGPT?. The use-side question vendor vetting never reaches.
- The 4 Stages of AI Governance Maturity. The structure that makes tool questions answerable.