Skip to content

Buying an AI agent platform? Twelve due-diligence questions on data, logs, pricing and exit

Twelve questions to get answered in writing before you sign an AI agent platform: data residency, log export, cost reporting, high-risk controls and exit.

By Published Updated 8 min read
Costs and buying, 8 min read — A row of translucent glass boxes on a dark table, each glowing blue-violet, one opened with its lid set beside it.

The short answer

Before you sign, get twelve answers in writing: where your data is stored and processed, whether it trains models, which logs you can export and for how long, how each task is priced and reported, which actions the agent may never take alone, how disclosure works, and what you take with you when you leave.

Key takeaways

  • A demo shows what an agent can do; due diligence shows what you can prove, control and take with you afterwards.
  • In KPMG's survey of 314 US leaders at $1bn+ firms (July–August 2026), 74% included cost reviews in AI approvals.
  • In the same survey, 49% had defined high-risk uses that agents may not decide on alone, so ask how a platform enforces that list.
  • Ask for complete log export in a standard format, on demand and on a schedule; a dashboard you can only look at is not an export.
  • Exit terms belong in the first contract: your prompts, configurations, logs and evaluation sets should leave with you.

Why a demo is not due diligence

A demo shows what an agent can do on a good day. Due diligence shows what you can prove, control and take with you on a bad one. The twelve questions below cover data, logs, pricing, controls and exit, and each needs an answer in writing, ideally in the contract or its annexes.

Buyers are moving fast enough that these questions now come up in real purchases. In KPMG's AI Quarterly Pulse, a survey of 314 US leaders at companies with $1 billion or more in revenue (24 July–25 August 2026), 62% said they were building or deploying agents, up from 53% in the second quarter.1 The same survey found 74% included cost reviews in AI approvals.1

Scale is harder than adoption. In a Gartner survey of 1,303 leaders at organisations with $50 million or more in revenue (January–April 2026; geography not stated), 22% had successfully scaled AI across multiple business units or adopted an AI-first approach.2 Our view: much of the gap between a pilot and a second business unit is decided by contract terms nobody read during the demo.

Agent buying in 2026

Buyers already ask about cost and control

74%include cost reviews in AI approvalsKPMG, US, Jul–Aug 2026 1
49%define high-risk uses barred from autonomous decisionsKPMG, US, Jul–Aug 2026 1
22%have scaled AI across business units or gone AI-firstGartner, Jan–Apr 2026 2
Sources: KPMG, AI Quarterly Pulse Q3 2026; Gartner, survey of 1,303 leaders.

Data: where it lives and what it trains

Start with data, because it is the hardest thing to change after go-live. An agent reads your records, writes drafts and stores conversations, so every one of those copies needs a home you can name.

1. Where is our data stored and processed, including by model providers? Ask for the regions for storage, for inference and for backups. Many platforms store data in one region and send prompts to a model hosted in another. If your customers or regulators care about residency, the answer has to cover the model call, not only the database.

2. Is our data used to train or tune any model, yours or a provider's? The answer you want is "no, by default, in the contract". A setting in an admin panel can change; a clause cannot change without your signature.

3. Which subprocessors touch our data, and how are we told about changes? Get the list, the notice period for additions and your right to object. Model providers, vector stores and observability tools all count.

Logs: what you can see and take away

Logs are the area where vague answers cost the most later. Without them you cannot investigate a complaint, measure an exception rate or show an auditor what the agent did. We set out the fields we record in our guide to agent audit logs; this section turns that list into buying questions.

4. Can we export complete logs in a standard format, on demand and on a schedule? Complete means the input, the retrieved context, each tool call, the output, the model and version, and the person who approved or overrode it. A dashboard you can only look at is not an export.

5. How long are logs kept, and can we set that period? You want a retention period you choose, plus deletion on request. Too short and you cannot investigate; too long and you hold personal data you no longer need.

6. Can we tie every action to a named agent identity and a human owner? If the agent writes to your ERP or CRM as a shared admin user, your own audit trail will not tell you who did what. Ask for a dedicated service account per agent, with permissions you set.

Pricing: what a task costs and how you will know

Pricing questions decide whether finance can sign off a second workflow. Agent platforms now charge per seat, per conversation, per action, per credit or per outcome, and several mix them.

Outcome pricing is spreading. HubSpot moved two of its agents to per-outcome prices from April 2026, charging per resolved customer conversation and per qualified lead.3 That can align incentives, but only if you agree what counts as "resolved". Our comparison of outcome-based agent pricing walks through the definitions to pin down.

7. What is the billable unit, and who decides when one has occurred? Get the definition in the contract, with examples of edge cases: a conversation reopened the next day, a lead later rejected by sales.

8. Can we see cost per task, per workflow, per month, in a report we can export? Our view: if the platform cannot report its own cost per task, you will end up building that report yourself, usually after the first surprising invoice. Our breakdown of monthly running costs lists the lines to expect.

9. What caps, alerts and price-change notice do we get? Ask for a hard monthly cap per workflow, an alert well before it, and a written notice period for any change to unit prices.

Controls and disclosure: what the agent may never do alone

Controls are where a platform shows whether it was built for production or for demos. In KPMG's Q3 survey (US, July–August 2026), 49% of leaders said they define high-risk uses barred from autonomous decisions.1 A list in a policy document only helps if the platform can enforce it.

10. How do we block actions or require human approval for named uses? You should be able to say, in configuration, that refunds above a limit, contract changes or anything touching credit decisions always stop for a person. Ask to see it working, then ask what happens if the approver is away.

11. How does the platform support disclosure that users are talking to AI? As of October 2026, Article 50 of the EU AI Act has applied since 2 August 2026. A Cloud Security Alliance research note reads it as requiring providers of conversational systems to make sure users know they are dealing with AI, unless that is obvious from the context.4 This is not legal advice, so check your own obligations with counsel. Even if you sell nowhere in the EU, a configurable disclosure line and a logged record that it was shown cost little to ask for now.

Twelve questions, five areas

  1. Data (1–3)

    Storage and inference regions, training use, subprocessors.

  2. Logs (4–6)

    Complete export, retention you set, a named identity per agent.

  3. Pricing (7–9)

    The billable unit, cost per task reporting, caps and notice.

  4. Controls (10–11)

    Enforced approval for high-risk uses, disclosure support.

  5. Exit (12)

    Your prompts, configurations, logs and test sets leave with you.

Illustrative. Our checklist; ask for every answer in writing.

Exit: what leaves with you when you switch platforms

Exit terms belong in the first contract, because you have the most bargaining power before you sign. The question is simple to ask and revealing to hear answered.

12. If we leave, what do we take, in what format, and how long do we have? The list should include prompts and instructions, workflow configurations, tool definitions, knowledge sources, evaluation sets with their expected answers, and the full log history. Ask for a transition period after notice, during which the agent keeps running while you move.

Our view: the evaluation set is the most valuable thing on that list. It encodes what "correct" means for your business, and it is what lets you test a replacement platform in weeks rather than months. If a vendor treats it as their property, treat that as a reason to walk away.

Answer you hearWhat it usually means
"Logs are available in the dashboard"No export; ask for a format and a schedule
"We don't train on customer data"Ask whether that is in the contract or a setting
"Pricing is usage-based"Ask for the unit, a cap and a cost-per-task report
"You can add approvals with custom code"Controls are not built in; budget for building them
"Migration support is available"No exit terms; ask what is exported and when

Illustrative. Phrases we treat as prompts for a follow-up question, not as disqualifiers.

How do you run the due-diligence review in a week?

Send the twelve questions to every shortlisted vendor at once, with a deadline and a request for answers that reference contract clauses. Then score the replies on whether each answer is written, specific and enforceable.

Run the scored replies past three people: whoever owns the process, someone from finance and someone responsible for security or data protection. Each reads different questions closely. A vendor that answers ten of twelve in writing usually beats one with a better demo and vague terms.

If you have not yet picked the workflow, start there instead. The platform choice matters less than the process you hand it, and our AI automation page describes how we scope one workflow, with acceptance criteria agreed before any build.

Sources

  1. KPMG, AI Quarterly Pulse Q3 2026: 314 US leaders at $1bn+ firms, 24 Jul–25 Aug 2026 (Sep 2026)
  2. Gartner, survey of 1,303 leaders at organisations with $50M+ revenue, Jan–Apr 2026; geography not stated (Sep 2026)
  3. No Jitter, HubSpot brings outcome-based AI pricing to customer engagement (Apr 2026)
  4. Cloud Security Alliance, research note on EU AI Act Article 50 transparency (Jul 2026)

Questions readers ask

  • Log export and exit terms, in that order. Without complete, exportable logs you cannot investigate a complaint, measure exceptions or show an auditor what happened. Without exit terms your prompts, configurations and evaluation sets stay with the vendor. Both are cheap to agree before signing and expensive to negotiate afterwards.

Keep reading

Free, in two minutes. Enter your domain and we'll score it against three competitors across six engines.

No account needed. The report is emailed within 24 hours.