White Paper

Bring Your Own Model: A Buyer's Guide to AI Architecture in Enterprise Software

Every vendor now ships AI inside their product. This guide gives you the questions, tests and contract terms to find out whose model it runs on, where your data goes, and what sovereignty really requires in the GCC.

PDF · 426 KB

The AI inside the software you already own arrived in a release note, not a procurement decision. Nobody asked where the prompts go, whose key pays for them, whether the AI can see data the user cannot, or what happens when the vendor swaps the model underneath you.

This eight-page guide is written for the people who have to answer for that: the CIO who signs the contract, the CISO who owns the data, the Chief AI Officer who owns the inventory, and the CFO who receives the bill.

Inside:

- The seven architecture patterns vendors use, and how to tell in one question which one you are being sold
- Six dimensions that decide the answer: data flow, identity and permissions, model portability, auditability, cost and sovereignty
- Twenty questions to paste into your next RFP
- A ten-test proof-of-concept battery you can run in a fortnight, including the twenty-minute permission test most buyers never run
- Six contract clauses worth insisting on, from no-training commitments to model-change notice
- What sovereignty actually requires in the GCC: four levels, the verified regional position of the major cloud and model providers, and the regulations that already bite
- A weighted scoring model, and a translation table for what vendor answers usually mean

Every regional and regulatory statement was verified against primary sources in September 2026 and is dated accordingly.

Please use your company email address, not a personal one.

We use these details to send you the document and to follow up about our work. See our Privacy Notice.