"Do you use AI in your product?" — the inventory question
It is usually the first question of the AI section, and it looks like the easy one — a checkbox before the hard part starts. It is not a checkbox. It is an inventory question, and everything after it will be checked against how you answer it.
Why buyers ask this
Enterprise buyers run AI due diligence inventory-first: before assessing any control, they want the list — which AI capabilities exist in the product, which models power them, who the providers are, and what data flows to them. The standard instruments — the AI-CAIQ (Cloud Security Alliance, October 2025) and the SIG 2026 AI domain — serve exactly that review, and what buyers typically request through them starts with the inventory: AI systems in scope, model provenance, AI subprocessors, data flows. Your "yes" or "no" here decides which follow-up sections open — and, since the EU AI Act's Article 50 transparency obligations apply from 2 August 2026 (not postponed by the Digital Omnibus), this question is also where a buyer starts working out which of those obligations sit with you.
The question is also a credibility test. Your marketing site, changelog and product UI are public. If any of them say "AI-powered" and your questionnaire says "no", the reviewer notices — and then re-reads every other answer in the document with that contradiction in mind.
The honest answer structure
Answer with a short inventory, not a bare yes. One entry per AI capability shipped in the product — including features powered by third-party models (OpenAI, Anthropic, Google, or an embedded AI feature from another vendor). For each: what it does, which model and provider, whether you fine-tune, and where it is processed. Close the list explicitly, so the buyer knows it is complete.
Template — adapt and verify every bracket before use:
"Yes. [Your product] includes the following AI capabilities: (1) [feature name] — [what it does, e.g. drafts summaries from customer documents]; powered by [provider]'s [model] via API; no fine-tuning on customer data; processed in [region]. (2) [feature name] — [same structure]. [Provider(s)] appear on our public subprocessor list, and we maintain an internal AI-systems inventory covering model, provider, purpose, data flows and user-facing disclosure for each capability. No other AI capabilities are shipped in the product."
That inventory is the same artifact Step 1 of our method for the whole AI section is built on: write it once, answer every downstream question from it, and the document stays consistent.
The mistake that costs deals
Answering "no" because "we don't build AI — we just use the OpenAI API." This fails twice.
It fails factually. The buyer is asking about capabilities in your product, not about who trained the weights. A drafting feature that calls a third-party LLM is an AI feature in your product, full stop — and it is discoverable in minutes from your own website.
It fails legally. For the purposes of Article 50(1) of Regulation (EU) 2024/1689, a company that ships a third-party model under its own brand is the provider of the resulting AI system — the rebranding rule. So the transparency duty (informing users they are interacting with AI, unless that is obvious to a person who is "reasonably well-informed, observant and circumspect") can sit with you, not with the model vendor. A "no" on the inventory question, followed by a buyer's lawyer finding provider duties on your side, is how an AI section turns into a legal escalation. Map your own case in six questions with the free Article 50 checker, or read who owes what under Article 50.
Mini-FAQ
Our AI features just call the OpenAI or Anthropic API — can we answer "no"?
No. The question covers AI capabilities in your product regardless of who built the underlying model — and for the purposes of Article 50(1), shipping that model under your own brand makes you the provider of the resulting system.
We only use AI internally, not in the product — do we still answer "yes"?
Read the question's scope. If it asks about the product and nothing in the product uses AI, the precise answer is "no AI capabilities in the product", plus a short factual note on internal use if the buyer's wording is broader. Precision is the point.
Does answering "yes" create extra legal obligations?
The answer itself doesn't change your legal position — if you ship AI features under your own brand, the Article 50 duties that match those features apply from 2 August 2026 whether or not a questionnaire ever asks. What "yes" opens is follow-up: models, providers, subprocessors, and the training-data question. Answering from a prepared inventory keeps all of it consistent.
Just received the questionnaire this question sits in? Start with the first-24-hours playbook.