Enterprise AI vendor evaluations increasingly require more than security questionnaires and marketing claims. Buyers need to understand how AI systems use data, how governance decisions are made, and what operational controls exist when AI interacts with sensitive information.
Most AI vendors claim to have governance programs. Few can answer specific questions about what data their AI features access, which subprocessors receive that data, and what controls exist around automated actions. This guide gives enterprise buyers ten questions that cut through vendor marketing language—and documents exactly how Nylas answers each one. A downloadable Enterprise AI Vendor Evaluation Checklist is also available for teams conducting procurement or security reviews.
Nothing on this page constitutes legal advice. Organizations should consult legal counsel regarding their specific regulatory obligations.
Why vendor claims aren’t enough
Enterprise software purchases now routinely include AI capabilities that weren’t present in the product two years ago. That creates a gap: procurement and security review processes built around traditional SaaS evaluations were not designed to assess AI-specific risks.
Vendors claiming to have “responsible AI principles” or “enterprise-grade AI governance” rarely face follow-up questions that test whether those claims are operational or merely aspirational. The questions below are designed to close that gap. They apply to any AI-enabled software vendor — and for each one, Nylas has documented its position.
The ten questions
1. Is customer data used to train AI models?
This is the first question to ask and the one most buyers forget to pin down specifically. Vague answers — “we take data privacy seriously” or “your data is protected” — do not answer the question.
A complete answer should cover:
Whether customer data is used for general-purpose model training
Whether data is used for customer-specific model tuning
Whether data is used for product improvement, analytics, or benchmarking
Whether data is used for internal testing or evaluation
Whether any of the above requires explicit customer authorization or opt-in
What types of data are involved and under what conditions
How Nylas answers this: Nylas does not use customer data to train general-purpose machine learning models. Nylas does not develop or operate proprietary foundation models. Customer email, calendar, contacts, and scheduling data processed through Nylas features is not used to improve or train underlying AI models.
2. Which AI providers or subprocessors are involved?
AI-enabled features often involve a chain of providers: the platform vendor, the underlying model provider, a data processing service, and potentially additional subprocessors. The vendor a buyer contracts with may not be the entity operating the AI that processes their data.
A complete answer should cover:
Which third-party AI providers supply the underlying models or inference services
Whether those providers receive customer data and under what terms
What role each provider plays in the workflow
Whether subprocessors are disclosed in vendor documentation or data processing agreements
How customers are notified when subprocessors change
What contractual safeguards govern those relationships
How Nylas answers this: Nylas relies on third-party providers for AI-enabled functionality where applicable and reviews those providers to evaluate security, privacy, operational, and contractual risks. Customers requiring specific information about which AI providers or subprocessors are involved in a given feature should contact Nylas directly. Nylas maintains documentation of its subprocessor relationships.
3. What data does the AI system actually process?
Not all AI workflows process the same data, and vendors often frame this question in terms of what they do not process rather than what they do. Buyers need specifics.
A complete answer should cover:
What categories of data the AI system can access (message content, metadata, calendar events, contact records, authentication tokens)
Whether sensitive or regulated data may be processed
How data minimization is applied — whether AI systems access only what is required for a specific function
Whether customers can limit what data is shared with AI features
How long AI-related data is retained
Whether metadata alone (recipients, timestamps, subject lines, calendar details) is treated with the same care as message content
The metadata point matters more than buyers often realize. Recipient patterns, meeting frequency, scheduling context, and email volume can reveal organizational structure, business relationships, and operational priorities without touching message content.
How Nylas answers this: Where AI-enabled functionality is present in Nylas products, it may process customer-provided content for purposes such as summarizing information, structuring data, or assisting workflow automation. Nylas applies data minimization principles to AI-related processing. Not every customer uses AI-enabled functionality, and not every workflow requires the same data processing. Customers evaluating specific AI features should ask Nylas what data each feature accesses and how retention is applied.
4. How does AI fit into the vendor’s existing security program?
AI-enabled features should be evaluated as part of a vendor’s overall security posture, not as a standalone capability. AI governance should extend existing security programs rather than operate as a parallel discipline. An AI feature with sophisticated model architecture but weak surrounding security controls is not a safe choice for enterprise deployment.
A complete answer should cover:
Encryption in transit and at rest for AI-processed data
Access restrictions on who within the vendor organization can access AI-processed data
Authentication safeguards for AI system access to customer data
Monitoring and logging of AI-assisted actions
Retention controls for AI-processed data
Vulnerability management processes for AI features
Incident response procedures specific to AI-related events
Vendor security reviews for third-party AI providers
How Nylas answers this: Nylas’s approach to AI governance is integrated with its broader security program, not maintained separately. AI-enabled features are subject to the same access controls, encryption standards, monitoring, and vendor review processes as other platform functionality. Nylas maintains incident response processes covering AI-related misuse and unexpected outputs. Customers with questions about specific security controls should contact Nylas directly or review Nylas’s security documentation.
5. Are AI features optional or configurable?
Organizations have different risk tolerances, internal AI governance policies, and regulatory obligations. A vendor whose AI features cannot be disabled or scoped creates compliance and operational problems for enterprise customers regardless of how good the underlying governance is.
A complete answer should cover:
Whether AI features can be enabled or disabled at the account or tenant level
Whether there are role-based controls on which users can access AI functionality
Whether customers can limit which workflows use AI
Whether there are configuration options for data sharing or retention specific to AI features
Whether AI features can be separated from non-AI platform functionality
How Nylas answers this: Nylas designs AI-enabled features to be configurable. Not every customer uses AI-enabled functionality, and organizations can evaluate which features apply to their use case before enabling them. AI features are not universally applied across all accounts. Customers should contact Nylas directly to understand configuration options for specific features relevant to their deployment.
6. How does the vendor make AI governance decisions?
Governance is ultimately a process question, not a features question. “We have an AI ethics board” is different from “here is how we evaluate a new AI use case before launch, what approval it requires, and what ongoing monitoring we apply.” Buyers should push for the latter.
A complete answer should describe whether the vendor has documented processes for:
Reviewing AI use cases before they are built or enabled
Evaluating AI vendors and subprocessors before they are onboarded
Testing security and privacy risks associated with AI features before launch
Documenting data flows involving AI systems
Monitoring AI features for misuse or unexpected behavior in production
Handling incidents involving AI-enabled workflows
Updating policies as regulations, risks, and operational standards evolve
The absence of documented process is itself an answer.
How Nylas answers this: Nylas continues to evaluate and refine its AI governance practices as technologies, customer expectations, and regulatory obligations evolve. AI governance at Nylas is treated as an ongoing operational process, not a one-time certification. Customers can ask Nylas directly about its process for evaluating new AI use cases, reviewing subprocessors, and handling AI-related incidents.
7. How are AI outputs reviewed or controlled?
There is a meaningful governance difference between an AI feature that summarizes information and one that can act on behalf of users. Buyers need to understand not only what an AI feature produces, but what it can do.
A complete answer should cover:
Whether AI outputs are acted on automatically or require human review
Whether the AI system can send messages, change records, or trigger workflows without human approval
What safeguards exist to prevent unintended actions
How errors in AI outputs are surfaced and escalated
Whether AI-generated actions are distinguishable from user-generated actions in logs and audit trails
How Nylas answers this: Nylas designs AI-enabled features to support customer-controlled configuration, including the ability to insert review, approval, or escalation steps in automated workflows. The appropriate level of oversight depends on the specific workflow and the customer’s configuration choices. Customers building agentic workflows on Nylas should define human oversight checkpoints appropriate for their use case.
8. Can customers audit AI activity?
Auditability is increasingly a baseline expectation in enterprise software, and AI-enabled actions require the same audit trail as any other system change. Without it, security teams cannot investigate incidents, compliance teams cannot demonstrate controls, and operations teams cannot troubleshoot unexpected behavior.
A complete answer should cover:
Whether AI activity is logged separately from standard user actions
Whether administrators can see when and how AI features were used
Whether AI-generated actions are distinguishable from user-generated actions in audit logs
What retention period applies to AI activity logs
Whether audit logs are exportable for external review
How Nylas answers this: Customers with specific auditability requirements should contact Nylas directly to understand what logging and audit capabilities apply to the AI features relevant to their deployment. Nylas supports customers through the Professional Services Program in evaluating architecture, workflow design, and operational configuration, which includes how AI features interact with access controls and audit processes.
9. How does the vendor address abuse and misuse risks?
AI systems operating in communications environments introduce specific misuse vectors that traditional security programs were not designed to address. Buyers should ask whether vendors have specifically evaluated these risks and what mitigations are in place.
Key risk areas for communications platforms:
Prompt injection: Malicious content embedded in email or calendar data may attempt to manipulate AI systems into taking unintended actions. Ask whether the vendor has tested for prompt injection in its AI features and what mitigations are deployed.
Phishing and impersonation: AI features that compose or route communications can be exploited to generate convincing phishing content at scale. Ask how the vendor limits this risk and what detection capabilities exist.
Workflow automation misuse: AI-assisted automation that executes actions across connected accounts can propagate errors or misuse at high speed without appropriate scope controls and review checkpoints. Ask what permission scoping applies to automated actions.
Excessive permissions: AI systems may request or accumulate access beyond what specific tasks require. Ask whether AI features operate under the same least-privilege access principles that govern human access.
Sensitive data exposure: Communications data varies significantly in sensitivity. Ask whether AI features that process communications broadly have controls to limit exposure to highly sensitive data types.
Interconnected vendor ecosystems: AI functionality in a communications platform may involve multiple providers. Ask whether the full subprocessor chain has been evaluated for these risks, not just the primary vendor.
How Nylas answers this: Nylas evaluates these risks as part of its security and AI governance programs. Nylas applies least-privilege principles to AI-enabled feature design, reviews third-party AI providers for security and operational risks, and maintains incident response processes for AI-related misuse and unexpected outputs. Customers building agentic or automated workflows should also apply their own controls at the application layer.
10. Who is responsible when something goes wrong?
AI-enabled workflows often span multiple systems, providers, and organizations. A single workflow may involve an AI model provider, a communications platform, cloud infrastructure, application developers, and the enterprise deploying the solution. When something goes wrong, responsibility rarely rests with a single party.
Enterprise buyers should understand how responsibilities are divided before adopting AI-enabled features. Clear accountability is an important part of effective governance and incident response.
Nylas views AI governance as a shared responsibility. Nylas is responsible for the security, reliability, and governance of the platform services it provides, including evaluating third-party AI providers, applying security and privacy controls, and maintaining incident response processes for platform-related events. Customers are responsible for how AI-enabled features are configured within their own applications, what data those features are permitted to access, what workflows they automate, and where human oversight is appropriate. Effective AI governance depends on both platform controls and customer governance practices working together.
Evaluation scorecard
Use this template when documenting vendor responses during security or procurement review.
Question
What a strong answer looks like
Red flags
Data used for training?
Clear “no” with documented policy
Vague, hedged, or unanswered
Subprocessors disclosed?
Named providers, contractual commitments
“We use industry-standard partners”
Data processed by AI?
Specific data types and minimization approach
“We protect all data” without specifics
AI and security program integration?
AI controls described as part of broader program
AI described as isolated from security review
AI features configurable?
Opt-in or disableable at account/tenant level
All-or-nothing; no customer control
Governance process documented?
Described pre-launch review and ongoing monitoring
“We have an ethics policy” without process detail
Output review controls?
Configurable human review; AI actions logged separately
Fully automated with no oversight option
Audit capability?
AI activity logged, exportable, distinguishable from user actions
No AI-specific audit trail
Misuse mitigations?
Specific controls for prompt injection, phishing, excessive permissions
Generic security posture claims only
Customer data for model training
Clear documented policy
“Subject to change” or unclear contractual language
Want a version you can use during procurement reviews, security assessments, or vendor evaluations?
Download the Enterprise AI Vendor Evaluation Checklist — a printable worksheet that includes all 10 evaluation questions, red flags to watch for, and space to document vendor responses during due diligence.
Frequently asked questions
Why do these questions matter specifically for communications platforms?
Email, calendar, contacts, and scheduling systems sit at the center of most business operations. They contain business correspondence, customer interaction records, authentication credentials, and internal decision-making context. When AI features interact with those systems, they can affect access permissions, automate outbound communications, and process sensitive data in ways that carry governance implications. That makes the stakes for weak AI governance higher in communications platforms than in many other software categories.
What is the difference between a vendor having an AI policy and having AI governance?
An AI policy is a written document. AI governance is the operational process by which decisions about AI systems are made, reviewed, and enforced. A vendor with a policy but no governance process cannot answer questions about how a specific feature was evaluated before launch, what ongoing monitoring applies to it, or how they would respond if the feature began behaving unexpectedly. Buyers should ask for process evidence, not policy documents.
Is customer data being used to train AI models a dealbreaker?
Not automatically, but it should be a fully informed decision. If a vendor uses customer data for model training, buyers need to understand: what types of data are involved, whether there is an opt-out, what contractual language governs the use, and whether the use is disclosed in the vendor’s data processing agreement. Undisclosed training use that surfaces after a contract is signed creates both regulatory and trust exposure.
What is prompt injection and why does it matter for email and calendar AI?
Prompt injection is a type of attack in which malicious content embedded in external input — in this case, an email or calendar event — attempts to manipulate an AI system into taking unintended actions. For example, an email could contain hidden instructions that cause an AI assistant to forward sensitive messages, modify calendar events, or generate phishing content on behalf of the user. Buyers should ask vendors whether they have tested for prompt injection and what mitigations are deployed in production AI features.
Is there a checklist I can use during vendor evaluations?
Yes. Nylas provides an Enterprise AI Vendor Evaluation Checklist that summarizes the questions covered in this guide and includes space to document vendor responses during procurement, security, and compliance reviews. Organizations can use it alongside their existing vendor risk assessment processes to help ensure AI governance considerations are evaluated consistently.
How should AI vendor evaluation be documented for compliance purposes?
Keep a record of the questions asked and the answers received during vendor evaluation. If a vendor’s position on data training, subprocessor disclosure, or configuration options changes after contract signing, documented pre-contract representations may be relevant. For regulated industries, this documentation may also be required to demonstrate due diligence in vendor selection.
Does Nylas have documentation on its AI governance practices?
What should buyers do if a vendor refuses to answer these questions?
The answers—or, in some cases, the inability or unwillingness to provide them—can reveal as much about a vendor’s governance maturity as the answers themselves. Buyers should factor that into their evaluation. For enterprise deployments involving sensitive communications data, undocumented governance practices are an operational risk, not just a procurement concern.
Why should procurement teams ask these questions before signing a contract?
Because answers often become contractual expectations.
It’s easier to negotiate before procurement than after deployment.
Closing
Enterprise AI governance is increasingly determined not by whether a vendor uses AI, but by how that AI is governed in practice. Understanding what data AI systems can access, what actions they can take, how those actions are monitored, and how vendors manage risk provides a far clearer picture of operational maturity than broad statements about “responsible AI.”
As AI becomes a standard component of enterprise software, these questions should become a routine part of vendor due diligence alongside traditional security, privacy, and compliance reviews. Organizations that ask them consistently will be better positioned to evaluate not only individual AI features, but the governance practices that support them over time.
Nylas welcomes these conversations and has made a great deal of information available in the Nylas Trust Center. Organizations looking for a structured way to document vendor responses can also use the accompanying Enterprise AI Vendor Evaluation Checklist during procurement, security, and compliance reviews. The Nylas team is available to answer questions as part of their evaluation process.