Module 2: Know the Service and Its Reach

Who Is Behind This AI Service?

Replace popularity rankings with an evidence-led investigation of the exact product you plan to use.

In this lesson, you will learn to:

  • Identify the legal provider and exact service scope.
  • Collect product-specific evidence for training, retention, access, deletion, and security.

Who Is Behind This AI Service?

A practical provider-research method covering legal identity, exact product and plan, primary documents, security evidence, subprocessors, and dated claims.

Start with identity and exact scope

A familiar model name may appear in products operated by different companies. A consumer chatbot, enterprise workspace, application programming interface, school account, and third-party wrapper can have different terms and data paths even when they use a related model. Begin with the legal entity, exact product, plan, account type, region, and feature you intend to use.

Find the official privacy notice, terms, product data-controls page, security documentation, and—where relevant—data-processing agreement and subprocessor list. Record the page title, date accessed, and scope. Marketing phrases such as “private,” “secure,” or “enterprise-grade” are questions, not answers. Which data is covered? Is human review possible? Are prompts used for training by default? Can an administrator change the setting?

Read for decisions, not for reassurance

Search primary documents for prompts, uploads, outputs, training, improvement, retention, deletion, human review, subprocessors, location, security, account controls, and changes to terms. Note whether a statement applies to your plan. “API data is not used for training” does not answer what happens in a free consumer chat. “You can delete chats” does not necessarily describe deletion from every backup or safety log.

Look for contradictions and gaps. Product documentation may explain a control that the contract does not guarantee. A certification covers a defined system and period; it does not prove that your intended use is lawful, accurate, or appropriate. When the evidence does not answer a material question, record “unknown” and choose a lower-risk use rather than filling the gap with an assumption.

Research the company and ecosystem

Check the provider’s official company information, ownership, leadership, contact routes, support history, security advisories, and reputation for disclosing incidents. Identify major subprocessors and whether the feature sends data to another service. Distinguish independent reporting from affiliate marketing and AI-generated comparison pages that cite one another.

Freshness matters. Terms, defaults, model suppliers, and account controls can change. Recheck before a new sensitive use and after major product changes. Capture the evidence that justified your choice rather than relying on memory. The objective is not to find a universally “best AI.” It is to decide whether this exact service, configuration, and account is appropriate for this exact task and information.

Resources

  • NIST AI RMF Playbook — Use NIST’s suggested actions and documentation prompts when evaluating AI risk and evidence.