
Where Does Your AI Actually Run? 10 Questions to Ask Your Provider
Where a provider stores your data and where it actually processes it are two different questions—and the second one determines latency, auditability and compliance for your customer operations. This checklist is built for the meeting itself: ten questions to put to your provider before you move customer operations onto AI. Each comes with a pointer on what a strong answer looks like, so you can separate specifics from assurances on the spot.
1 · Where the processing happens — not just the storage
In which data centre—city and jurisdiction—does the AI inference itself run, as opposed to where our data is stored?
A good answer names specific facilities and puts the processing location in the contract, not just in the sales deck.Does any part of a request—prompts, transcripts, embeddings, logs—leave the region at any point, even transiently?
A good answer comes with a complete data-flow map that covers every subprocessor, including transient routing.Which AI model providers do you rely on, and do they offer regional inference endpoints for our deployment?
A good answer names the providers and shows regional endpoints or an on-premise option—not a promise to check later.
2 · Latency and operations
What latency do live customers experience today, measured per interaction—and can we see it on a dashboard?
A good answer shows operational metrics from real traffic, not laboratory benchmarks or averages from another market.What happens if the regional endpoint degrades or fails—does traffic fail over to infrastructure outside the region, and who decides?
A good answer is a documented failover policy you can veto, with the trade-off between availability and residency stated explicitly.
3 · Audit and evidence
Can you prove, per interaction, where it was processed—with logs an auditor can review independently?
A good answer offers per-interaction records with timestamps and location attribution, exportable in standard formats.What exactly is logged at the application layer—data fields touched, workflow steps, outcomes—beyond simple authentication events?
A good answer describes per-action logging; login records alone mean the audit trail has gaps.How are retention and anonymisation configured—can we set retention per use case, down to zero?
A good answer treats retention as a setting you control, not a policy you inherit from the provider.
4 · Exit and control
If we leave, how do we take our data, configurations and logs with us—in what format and on what timeline?
A good answer is a defined export path plus deletion evidence, committed in the contract.Can we move to a hybrid or on-premise deployment later without rebuilding—and which parts of the stack would we then control ourselves?
A good answer is a concrete migration path with named components, not a roadmap promise.
Where Amira stands on this
Amira is an AI-native Customer Operations platform built to answer these ten questions in specifics: in-region hosting (EU, UAE, KSA), BYOK, separation of workflow and AI servers, and per-interaction records of latency, cost and processing location, with retention configurable down to zero. If you want to put the ten questions to us directly, book a 60-minute demo.
Get Amira Weekly
AI in customer service, from the Gulf – one email every Friday. No spam, unsubscribe anytime.
By subscribing you agree to our privacy policy.



