# AI Buyer FAQ / Trust-Center FAQ
Executive Summary
This FAQ turns AI security posture into buyer-safe answers for sales, procurement, and trust-center use. It does not replace the full questionnaire answer bank. It is the short-form public or semi-public layer that points back to evidence.
The FAQ should be accurate, constrained, reviewed, and tied to source artifacts. It should never drift into unsupported claims about provider training use, retrieval authorization, human oversight, prompt retention, or incident response.
Public sample notice
FAQ publishing decision
Publish only approved or approved-with-caveat answers. Keep legal-review, partial, and planned answers internal until evidence and owner approval are complete.
FAQ Snapshot
The FAQ is not marketing copy. It is controlled evidence language.
FAQ answer set
AI Buyer FAQ
The FAQ maps buyer questions to short answers, buyer-safe answers, evidence, answer status, and public publishing rules.
Buyer FAQ
Buyer FAQ summary
| Question | Status | Evidence |
|---|---|---|
| What AI features are included in the product? | Approved | AI System Inventory, Architecture Review |
| Is customer data used to train foundation models? | Legal review | Provider Boundary Statement |
| Are prompts, outputs, or retrieved snippets retained? | Partial | AI Trace Schema, Incident Playbook |
| Can users receive information through AI that they cannot access directly? | Partial | RAG Authorization Review, RAG Test Plan |
| Do you test against prompt injection? | Approved | RAG Test Plan, Red-Team Findings |
| Can the AI system take actions on behalf of users? | Approved | Tool Inventory, Permission Matrix |
| What human oversight exists for AI actions? | Partial | Permission Matrix, Release Gate |
| Can AI behavior be audited after an incident? | Approved with caveat | Trace Schema, Evidence Appendix |
| Do AI changes go through security review before release? | Partial | Release Gate, Operating Model |
| How are AI-specific incidents handled? | Planned | Incident Response Playbook |
Public FAQ rules
Public FAQ rules
Findings
FAQ Readiness Findings
Provider training-use language needs legal approval
The provider training-use answer is procurement-sensitive and should not be published without route-specific legal approval.
RAG authorization answer must remain partial
The FAQ should not say retrieval authorization is complete until negative tests prove restricted content cannot enter retrieval, reranking, prompt assembly, or generated answers.
AI incident response answer is not ready for strong trust-center claims
The incident response answer should remain planned or internal until the playbook is approved and tabletop-tested.
Update triggers
FAQ update triggers
Related artifact: Enterprise AI Security Questionnaire Answer Bank
The answer bank is the controlled source for longer questionnaire responses.
Related artifact: Model Provider Boundary Statement
The provider boundary statement supplies approved model-provider language.