What questions should be in an enterprise AI agent RFP?
An enterprise AI agent RFP should cover deployment model, data residency, air-gapped support, private RAG, identity and RBAC, audit logging, model governance, BYOM support, compliance evidence, subprocessors, operating model, and pricing predictability.
How do we evaluate an on-prem AI agent platform?
Evaluate whether orchestration, retrieval, embeddings, model inference, logs, and governance can run inside your environment. Then ask for diagrams, evidence samples, SIEM integration details, offline update process, model lifecycle controls, and production support commitments.
What is a red flag in AI agent vendor evaluation?
A major red flag is any architecture where sensitive prompts, source documents, embeddings, or audit logs must leave your perimeter without a clear technical reason, customer approval path, and compensating control.
Should an RFP require air-gapped AI deployment?
Require air-gapped deployment if your environment has no outbound internet, supports defense or government workloads, touches OT or critical infrastructure, or has policy restrictions that prohibit external model APIs.
How should procurement compare token pricing with platform pricing?
Model the cost at production volume: prompts, tool calls, private RAG retrieval, batch jobs, retries, agent loops, users, environments, connectors, support, and infrastructure. Token-only pricing often looks simple in pilots but can be hard to forecast at enterprise scale.
What evidence supports EU AI Act and DORA readiness?
Useful evidence includes AI inventory, risk classification, human-oversight controls, model and dependency registers, audit logs, incident-review data, operational resilience test support, technical documentation, and controlled change history.