Arc Intelligence Book a 20-minute call

Arc / Ten Control Questions

Ten control questions to ask any AI agent vendor.

Including us. Each question comes with the answer that should worry you. Take it into your next vendor call and use it.

How to use this

Ask the question. Then ask for the artifact.

Most AI vendor calls stay at the level of description. The vendor describes a control, you write it down, and nobody checks whether the control exists. These ten questions are built to move past description.

Each one asks for something you can look at. A list, a log, a name, a live demonstration. If the answer is a sentence and the vendor cannot produce the artifact behind it, that is your finding.

Written by Arc Intelligence. Free to use, copy, and share. No attribution needed.

Q The Ten Questions
  1. 01

    What can this agent reach right now, and who wrote that list down?

    Every agent has a blast radius. It is the set of systems, records, and actions available to it. Someone has to have written that set down, on purpose, before the agent went live.

    The answer that should worry you “It uses the service account we already had.” That means the agent inherited a human’s permissions and nobody scoped it. A person uses judgment about what to open. An agent opens everything it is allowed to.

  2. 02

    If the agent is wrong, how do we find out?

    Not how you find out that it crashed. How you find out that it produced a confident, well formatted, wrong answer that nobody questioned.

    The answer that should worry you “The business would notice.” That is not detection. That is waiting for a customer complaint, and it only catches the errors that happen to be visible.

  3. 03

    Show me every action one agent took last Tuesday.

    Do not accept a description of the logging. Ask for the log. Pick a day, pick an agent, and ask them to pull it up while you watch.

    The answer that should worry you A log of prompts and replies. You asked what the agent did to your systems, not what it said. If the record only holds conversation, you cannot reconstruct an incident and you cannot hand anything to a regulator.

  4. 04

    What happens to an instruction hidden inside a document the agent reads?

    This is prompt injection. An attacker writes commands into a file, the agent reads the file, and the agent treats those commands as orders from you. A claim document, an email attachment, and a scanned form are all delivery routes.

    The answer that should worry you “The model is trained not to fall for that.” Model behaviour is not a control. It changes with every version and it cannot be audited. Ask what stops the instruction outside the model.

  5. 05

    Who can stop this agent at 2am on a Sunday, and how long does it take?

    Agents run on machine time. Your staffing runs on human time. The gap between those two is where a small problem becomes a large one.

    The answer that should worry you A single name with no rota behind it, or “we would raise a ticket.” Ask for the target time to a decision, not the target time to an acknowledgement.

  6. 06

    What data leaves our environment, and what is stripped before it does?

    If the agent calls an external model, something is being sent out. You need to know exactly what, and what was removed first. PHI is protected health information. PII is personal information that identifies someone.

    The answer that should worry you “It is encrypted in transit.” That answers a different question. Encryption protects data from a stranger in the middle. It does nothing about what the model provider receives and stores.

  7. 07

    Which decisions can this agent make without a person, and what is the largest one?

    Ask for a number. The largest payment it can approve. The largest number of records it can change in one run. The most sensitive category of file it can open unsupervised.

    The answer that should worry you Nobody has put a number on it. If there is no ceiling written into the system, the ceiling is whatever the agent decides on the day.

  8. 08

    We change a business rule today. When is the agent actually following it?

    Rules change. Limits move, a state adds a requirement, legal tightens a definition. You need to know where the rule lives and how fast it takes effect.

    The answer that should worry you “We update the prompt.” A prompt is a request, not a rule. It is followed most of the time, which is a different thing from being enforced. Ask where the rule is enforced when the model ignores it.

  9. 09

    When the agent is wrong, who is accountable: you, us, or the model provider?

    Ask this early and ask for the clause. Three parties touch the decision, and in most agreements the liability quietly lands on the one holding the customer relationship. That is you.

    The answer that should worry you A confident answer that is not in the contract. Reassurance in a meeting is not a contractual position. Ask them to point at the page.

  10. 10

    Break your own control in front of me.

    Ask the vendor to attack their own system while you watch. Feed the agent a document with a hidden instruction. Ask it for a record it should not have. Push it past a limit. Then watch what the system does.

    The answer that should worry you A slide about their security posture. Any vendor who has genuinely built the control can show it working, and can show it failing safely. If they will not demonstrate it, assume it has not been tested.

Now ask us

Bring these ten to our call.

We wrote them, so we will answer all ten. You should also know what our answer to question nine looks like today: Arc Intelligence has no live insurance deployments. The architecture on this site is a target architecture, built and tested in our own environment.

The AI Workforce Risk and Readiness Assessment runs these questions against the agents you already have in production, and gives you the answers in writing.