17 July 2026

12 Questions to Ask an AI Agent Vendor Before You Sign

Twelve questions to put to an AI agent vendor before signing, each with the regulator evidence that makes it non-negotiable and what a good answer sounds like.

Sixty-nine per cent of enterprises have credential sharing somewhere in their AI agent fleet, and the organisations doing it report incidents or near-misses at 63.5% against 40.9% for those giving every agent its own scoped identity, according to VentureBeat Pulse Research (June 2026 wave, 107 respondents at firms of 100+ employees). That single comparison is the reason an AI agent security questionnaire now belongs at the front of vendor due diligence rather than in the appendix of an MSA. The questions below are the ones a UK regulated buyer should put in writing before signing — each with the evidence behind it, and what a credible answer sounds like.

Why an AI agent security questionnaire now decides vendor due diligence outcomes

Okta's AI Agents at Work 2026 (Apprize360, March 2026; 292 executives and 492 knowledge workers across seven countries including the UK) found 58% of executives reporting an AI-related security issue or close call in the past 12 months, and only 34% applying the same security controls to their agentic labour force as to their human one. Gravitee's State of AI Agent Security 2026 (900+ executives and practitioners, 4 February 2026) puts confirmed or suspected incidents at 88%, with only 21.9% treating agents as independent identity-bearing entities and 45.6% still relying on shared API keys.

The bar itself is already published. The NCSC states it in one line: "If you cannot understand, monitor or contain an agent's actions, it is not ready for deployment". And the commercial cost of a vendor who cannot answer is documented — the Bank of England's February 2026 AI roundtables with banks, G-SIBs and insurers recorded that "Procurement and contract negotiations with third-party AI providers were slowed by inconsistent familiarity with regulated firms' compliance requirements", and noted that "the Bank could explore convening financial and technology firms to agree minimum standards for third party AI providers to the regulated financial sector".

Questions 1–4: identity, delegated permissions, credential lifetime and tool access

  • 1. Does each agent get its own non-human identity, or do agents share an API key? Microsoft's June 2026 guidance is explicit: "Assign each agent a non-human identity in Microsoft Entra Agent ID and apply Conditional Access to its workload identity." A good answer names the identity per agent instance, enrols it in your directory, and lets you revoke it without a vendor redeploy. "We use a service account" is a fail.
  • 2. What is the exact scope of delegated permission, and how is least privilege enforced? The NCSC's test is to "give agents only the minimum access they need, for the shortest time required" and to "constrain what an agent can access, what actions it can take and when it can take them". Ask for a written permission manifest per agent, read and write separated, deny by default. The ICO describes a poorly implemented agentic system as one "connected to databases not needed for their tasks".
  • 3. How long do the agent's credentials live? NCSC: "use temporary credentials where possible and revoke elevated access when tasks are complete". A good answer is a maximum token TTL you can state in seconds, minted per session, with no static secret sitting in a config file.
  • 4. Which tools and connectors can the agent reach, and who approves an addition? Microsoft's pattern is to "Disable Allow all on MCP connections and enable only the specific tools an agent needs", to "Maintain a tenant-level allowlist of approved MCP publishers and servers", and to "require a documented owner for any third-party server before production use". OWASP's State of Agentic AI Security and Governance v2.01 flags MCP vulnerability CVE-2025-6514, a remote code execution flaw rated 9.6 on the CVSS scale.

Questions 5–8: approval gates, kill switch, audit trail retention and monitoring coverage

  • 5. Which actions require a human to approve, and can we set the threshold ourselves? Microsoft recommends human-in-the-loop approval "For high-impact actions such as financial data access, external sharing, or account changes". The threshold must be yours, by action class and value — not a vendor default. Note the caveat from the Bank of England's February 2026 roundtables: "The concept of having a 'human-in-the-loop' was also challenged by the rise of agentic AI." Approval gates only count if a human can actually keep up with them.
  • 6. What is the kill switch, who can pull it, and what happens to in-flight actions? The Bank of England's AI Consortium (3 June 2026) named "mechanisms to intervene or halt activity through kill switches" and "ensuring agent actions remain within clearly defined limits" as practical controls. A good answer is customer-side, per-agent and fleet-wide, with a stated time to containment tested during the pilot.
  • 7. What is in the audit trail, how long is it kept, and can we export it without asking you? This is the question that sets AI agent audit trail requirements in a regulated industry: input, tool call, decision, output, acting identity and approver on every action, retained to match your own regulatory retention period, exportable in bulk in a machine-readable format by your team. The ICO singles out systems that "have no measures in place to secure access, monitor or stop activity".
  • 8. What percentage of your deployed agents are actively monitored today? Ask for the number, not the capability. Gravitee found that on average "only 47.1% of an organization's AI agents are actively monitored or secured", and that 14.4% of organisations have all agents going live with full security or IT approval. Anything below 100% coverage is a gap you inherit; require detections to feed your SIEM.

Questions 9–12: prompt-injection testing, controller versus processor, sub-processors and exit

  • 9. How do you test for prompt injection, and what did the last test find? The NCSC confirms agentic systems "inherit known LLM risks like susceptibility to jailbreaking and prompt injection", and OWASP maps prompt injection to six of the ten categories in its Top 10 for Agentic Applications. A good answer is adversarial testing per release with results shared under NDA, plus tool-layer design where untrusted content cannot escalate privilege. "The model is trained to refuse" is not a control.
  • 10. Who is controller and who is processor, for each processing operation? The ICO names "issues around determining controller and processor responsibilities through the agentic AI supply chain" as a novel risk, and states that "organisations remain responsible for data protection compliance of the agentic AI they develop, deploy or integrate in their systems and processes". Expect an allocation per operation in the DPA, not a blanket processor claim.
  • 11. Which sub-processors and model providers touch our data, where, and what notice do we get? The NCSC tells buyers to "manage supply chain risk for third-party components, models, tools and integrations", and the Bank of England's Consortium noted that "concentration arises from underlying characteristics of AI provision, particularly at the model and compute levels, with limited alternatives". Ask for the list, the inference locations, a notice period on change and a right to object.
  • 12. What exactly happens on exit? The voluntary DSIT Code of Practice for the Cyber Security of AI (31 January 2025), which builds on the NCSC's Guidelines for Secure AI Development, closes with a secure end-of-life phase and Principle 13, "Ensure proper data and model disposal". Your exit clause needs four things standard SaaS clauses do not cover: bulk audit-log export, connector de-provisioning with credential revocation, preservation of regulatory evidence beyond the contract term, and certified deletion.

The UK procurement artefacts an agent vendor should have ready before contract

For NHS work the artefacts are specified. NHS England's DSPT Guide 10 states that "Every supplier, data processor and joint controller linked to your organisation who processes personal or confidential information must have completed a data security and protection toolkit", that it is your responsibility to check they have done so, and that if not "they should be able to demonstrate an equal or higher standard". It also tells buyers to check the supplier's DSPT status for the latest year's submission and, for digital health and care technology, says you "are encouraged to request and review their Digital Technology Assessment Criteria (DTAC) submission". For suppliers of critical IT systems, certification "might include" ISO/IEC 27001 from a UKAS-accredited certifying body, Cyber Essentials or Cyber Essentials Plus, depending on the nature and criticality of the service — and Article 28 of UK GDPR sets the requirements when appointing a processor.

For the security review itself, a mature team will send the Cloud Security Alliance's AI Controls Matrix v1.1 (14 July 2026) — 247 control objectives across 18 domains, including a 13-control Model Security domain, with a 320-question AI-CAIQ for self-assessment and third-party evaluation and mappings to ISO/IEC 42001, the NIST AI RMF and the EU AI Act. CSA's Capabilities-Based Risk Assessment scores agentic risk across System Criticality, AI Autonomy, Access Permissions and Impact Radius, and maps the resulting Low, Medium and High tiers to those controls. If a vendor cannot work in that language, they will stall the buying committee — Forrester's State of Business Buying, 2026 (21 January 2026) reports that "The typical buying decision now includes 13 internal stakeholders and nine external influencers", with procurement a decision-maker in 53% of business buying cycles.

How Braivex answers these twelve questions

Braivex deploys agents into your existing systems rather than asking you to move data into ours, so per-agent identity, scoped permissions and customer-held kill switches sit on your side of the boundary. We answer all twelve in writing before contract — against your questionnaire, your DPA and your retention schedule, not our template — and we scope the first deployment the way the NCSC advises: "deploy agentic AI incrementally, starting with tightly bounded pilots using clearly defined tasks". You can see the deployment patterns under solutions and the pre-built agents on the marketplace.

If you are assembling the security pack for an agent deployment this quarter, send us your questionnaire and we will return it completed with evidence attached. Get in touch.