Basics / 10 August 2026 / 7 min

AI agent selection checklist: seven questions before buying

Seven questions that separate a working agent from a polished presentation: data, control, sources, boundaries and the artifact.

Short answer: Before buying an AI agent, ask seven questions: what is its task and result criterion; what data does it receive and under what permissions; where does it stop and ask a human; how is every conclusion linked to a source; what does the agent not allow itself to claim; in which perimeter does the data run; in what form is the artifact returned. If there is no answer to any question — it is not an agent but a demo.

Why seven questions

All seven questions are not an invented framework but the eight fields of the agent passport that the site fixes for every launch: task, input, process, output, limits, permissions, perimeter and verification (more on the pricing page). An agent with a filled passport answers every question; an agent without a passport is a beautiful presentation with unpredictable behavior.

Questions 1–3: task, data, stopping

1. What is the task and the result criterion? The site's principle: before launch the task, the input data, the expected artifact, the acceptance criteria, the limits and the decision-maker are fixed. Without this the price is not even discussed.

2. What data does the agent receive? The trust model requires least privilege: every source and tool is connected separately, access to other data must not be implied by the interface.

3. Where does the agent stop and ask a human? Human control is mandatory: disputed decisions stop and wait for confirmation, sensitive actions are explained before consent. An agent without stopping points is an unmanaged process.

Questions 4–5: sources and the boundaries of claims

4. How is the conclusion linked to the source? In a verifiable agent every conclusion is traceable: the work journal records inputs, decisions and sources; the result can be followed back to the source data. Examples: the RAG navigator answers with exact quotes and references, the database consultant — with a link to the source table, the requirements analyst ties every requirement to a source.

5. What does the agent not allow itself to claim? The limits must be named in the passport: a sample is not market statistics, minutes require human verification, a RAG answer does not constitute legal advice, an audit is not a certification. If the limits are not in the passport — they exist only in the advertising.

Questions 6–7: perimeter and artifact

6. In which perimeter does the data run? Cloud, team or local — the perimeter is fixed before launch together with the retention period and the list of processors. For sensitive data this is the decisive question: local processing architecturally excludes passing to third parties.

7. In what form is the result returned? The right answer is a verifiable artifact: a document, a draft, a table, a report with quotes. The artifact can be opened, edited and passed on. If the result exists only in the chat with the agent and nowhere else — it can neither be checked nor used.

How to use the checklist

Run both the purchase candidates and your own implementation project through these questions. Then the route is short: a demo launch to check the claims, the method to fix the criteria, the security principles for the perimeter and access. If questions remain after the demo — it is more honest to go back to the assessment than to paying the invoice.

Read also: How much does it cost to implement an AI agent: three engagement models · Cloud, team or local perimeter: how to choose the execution environment

Questions and answers

Why do you need a checklist when choosing an AI agent?

A seven-question checklist helps you check the agent before launch: the goal, the data, the human control points, the link between conclusion and source, the limits, the perimeter and the acceptance criteria. Without a checklist it is easy to miss a critical limit that makes the result useless.

Is a local perimeter mandatory?

No: the perimeter is chosen by data sensitivity. For tasks without trade secrets or personal data, a cloud or team environment may be appropriate; sensitive records may require a local environment. The client chooses the deployment environment.

Is one demo enough for a decision?

The demo checks the claims on synthetic data; the launch decision should be made after fixing the acceptance criteria on your own materials.

How many questions are in the checklist?

Seven: the goal, the data, the control points and questions for a human, the link between conclusion and source, what cannot be claimed, the perimeter, the form of the artifact.

Why is it important to ask, “What does the result not support?”

It reveals the limitations in advance: every agent passport defines what the result does not support.

What does 'the link between conclusion and source' mean?

Every conclusion is traceable back to the source data: the journal and the quotes confirm the result.

How do I verify the deployment environment?

Ask where the data is processed, whether it is shared with third parties, and request the disclosure list before production deployment.

Does the checklist apply to other vendors' agents?

Yes. The questions are universal and can be applied to any agent product.

What to do with the vendor's answers?

Compare them with the passport, the journal and the demo: claims without mechanisms are a red flag.

Who should go through the checklist?

The implementation owner and the team should review it before pricing is discussed.

First step

Choose a ready-made solution or describe your process.

Pick one of the twelve agents and subagents, or fill in the questionnaire for custom development.

Search agentseffect.com

Quick links