Don't ask whether your vendor uses AI. Ask how they supervise it.
Every software partner now says they use AI. That single fact tells you almost nothing about whether you can trust the result. The question that actually protects you is a different one, and it is easy to ask.
"Do you use AI?" tells you nothing anymore
Almost every vendor now answers yes. Used by an experienced team for the repetitive parts, AI is a real productivity lever. Sent straight to production by someone who does not read the output, it is a time bomb. The label is the same; the risk is completely different. So the question that protects you is not whether a partner uses AI, but how they supervise it.
Six questions to ask any vendor. Including us.
If a partner cannot answer these clearly, that is your answer.
Who reviews the code?
Every line, human-reviewed before it ships, or generated and trusted blindly? Ask who actually reads it and signs off.
What actually gets tested?
Real automated tests and a pipeline, or just 'it ran once in a demo'? Ask what proves the next change is safe too.
How is security audited?
Is security checked continuously, before and after launch, or simply assumed? Ask how vulnerabilities get found and fixed over time.
Where does your data live?
On EU infrastructure you can name, or on someone else's servers abroad? For regulated data, that answer is a compliance decision.
Who owns the result?
Do you get readable code you fully own, with no lock-in, or an app trapped on a platform? Ask what you can take with you.
Who is accountable when it breaks?
A named team that stands behind the work, or a tool with a disclaimer? When something fails, you want a person, not a platform.
In Belgium, supervision is not optional
If you work with customer, health, financial or government data, an insecure AI-built app is not a technical detail, it is a legal exposure. Under GDPR, you are liable, not the platform that generated the code. That is why we keep data on EU infrastructure, stay compliance-aware by default, and treat every line as something we have to stand behind. Local, accountable, and built for the rules you actually operate under.
Our answer to all six is yes
Every line reviewed by an engineer. Tests and a pipeline as standard. Security audited continuously. Data on hosting that fits your compliance. Code that is yours, with no lock-in. And a named team that stands behind it. That is what supervising AI properly looks like, and it is the whole point of how we work.
See how we audit AI-built codeWant a partner who can answer all six?
Bring us your project, or your questions. We will answer them straight, and show you exactly how we supervise the AI behind your software.