
None of these mean a vendor is dishonest. They mean the demonstration has been engineered to avoid a weakness, and your job in the room is to find out which one.
The nine
- Cherry-picked data. Ask: can we run this on a sample we bring, unseen, right now?
- No failure cases. Ask: show us the last three things it got wrong and what happens next in the workflow.
- Refusal to run on your input. A soft refusal — "we'd need a scoping call first" — is still a refusal. Note it.
- Vague model provenance. Ask: which models, hosted where, and what changes if that provider deprecates them?
- No named delivery team. Ask: who from this call is on our engagement, and what else are they on?
- Seat-based pricing on an outcome product. Ask: if this works, our headcount on this task falls. How does your pricing survive that?
- No governance answer. Ask: walk us through the last legal review you failed and what you changed.
- References that are all pilots. Ask: which of your references is running unassisted today?
- Unwillingness to be watched in public. The strongest signal in the list.
The single strongest test
Ask them to run it in front of an audience they do not control. Everything above is a proxy for that one question, and a vendor's answer to it tells you more than a completed security questionnaire.
Keep reading
Reading helps. Seeing the capability tested is better.
When you're ready to move from ideas to evidence, bring us the problem and we'll build the right session around it. The first one is free.