Topic cluster

AI vendor evaluation: security, lock-in, and TCO

3 notes · last update July 20, 2026
Quick answer

Choosing an AI vendor is a security and compliance decision, not just a feature one. Before you sign an MSA you need a framework: security questions, a lock-in risk map (data, model, integration), and real TCO, because the quoted price is rarely the total cost.

This cluster gives you tools to evaluate an AI vendor for NIS2, security, and cost. We lay out 12 questions worth asking before signing an MSA (data retention, sub-processors, right to audit, incident notification, exit), plus three layers of vendor lock-in and two contractual traps that most often cost you later. We show how to build a transparent, unbiased vendor comparison matrix (air-gap, PL model, RAG, NIS2/AI Act support, TCO, SLA), with methodology, because in a regulated niche a biased ranking destroys trust. We honestly flag where the author is a party (building CortexMine) and give the criteria by which you assess him. Start with the pre-MSA questions, then close the conversation with specifics.

// notes in this topic

TCO is not decided by the GPU price tag, but by utilization and horizon. How to model on-prem AI vs cloud over three years: three different cost models, a full CAPEX and OPEX line-item list, the break-even point and an honest look at when cloud wins.

AI vendor lock-in is rarely one bad decision — it's the sum of reasonable steps across three layers (data, model, integrations). The worst traps sit not in the architecture but in the contract. How to spot them before you sign an MSA.

Frequently asked questions
What's the most important vendor question?

“Where is my data physically processed and who is the sub-processor?”, it ties directly to NIS2 Article 21.

How do I avoid lock-in?

Ensure data portability, open formats, and exit clauses; avoid being locked in at the model and integration levels at the same time.

Are the comparisons on this portal objective?

We state explicit criteria and disclose that the author builds his own product, judge by the methodology, not the verdict.

Want to apply this to your case: architecture, compliance, and cost?

→ Book 30 min