Choosing an AI vendor is a security and compliance decision, not just a feature one. Before you sign an MSA you need a framework: security questions, a lock-in risk map (data, model, integration), and real TCO, because the quoted price is rarely the total cost.
This cluster gives you tools to evaluate an AI vendor for NIS2, security, and cost. We lay out 12 questions worth asking before signing an MSA (data retention, sub-processors, right to audit, incident notification, exit), plus three layers of vendor lock-in and two contractual traps that most often cost you later. We show how to build a transparent, unbiased vendor comparison matrix (air-gap, PL model, RAG, NIS2/AI Act support, TCO, SLA), with methodology, because in a regulated niche a biased ranking destroys trust. We honestly flag where the author is a party (building CortexMine) and give the criteria by which you assess him. Start with the pre-MSA questions, then close the conversation with specifics.
TCO is not decided by the GPU price tag, but by utilization and horizon. How to model on-prem AI vs cloud over three years: three different cost models, a full CAPEX and OPEX line-item list, the break-even point and an honest look at when cloud wins.
AI vendor lock-in is rarely one bad decision — it's the sum of reasonable steps across three layers (data, model, integrations). The worst traps sit not in the architecture but in the contract. How to spot them before you sign an MSA.