Blog · AI

How to choose an AI agency: what to ask before you sign

You can spot a good AI agency by its answers to a few simple questions, not by its demo. Ask where the models run and where your data goes, who approves what the agent does, how it connects to the software you already use, what stays yours at the end and what a pilot with written criteria looks like. If the answers are vague, the contract will be too.

8minute read
2026-10-05published
AIcategory
Consultant at a table with a laptop and papers, talking to a client
AI
01

What an AI agency actually does

The label "AI agency" covers very different companies today. Some run training sessions. Others build chatbots for websites. Others connect a language model to your accounting, your ERP or your internal documents so it can take over part of the office work. They can all have the same polished website and the same convincing demo. The difference only shows after you sign, when the agent has to work on your real data.

We are an AI agency based in Bucharest, so this article is not neutral. We still tried to write it as the list we would want any business owner to have before talking to anyone, us included. The questions below need no technical knowledge. They only need clear answers, put in writing. If an agency can't answer them in a first conversation, it won't be able to answer them three months into the project either.

It's worth saying where we start from. According to Eurostat, in 2025 20.0% of EU companies with at least 10 employees used AI technologies, and Romania had the lowest share in the Union, 5.2%. For many companies here, the first AI project is also the first experience with this kind of supplier. That is exactly why it matters to know what to ask.

02

First question: where the models run and where the data goes

Before any talk about what the agent can do, ask what happens to one of your company's documents once it reaches the agent. Which server reads it? In which country? Is a copy kept anywhere? Can it be used to train a model? A serious supplier answers by drawing the path your data takes, not with a line about "enterprise-grade security".

The question has a legal side too. If the agency processes personal data on your behalf, Article 28 of the GDPR requires a written contract in which the supplier commits to process data only on your documented instructions, including when it comes to transfers outside the EU. The same article says that when the work ends, the data is deleted or returned to you, whichever you choose. If the agency has no such contract ready, you have learned something important about it.

At RSM Romania, an audit and tax advisory firm, this question was the starting point. The requirements written down from day one were open-source models, no training on client data, hosting in EU data centres and controlled outbound connections. The architecture we delivered keeps the agent and the knowledge base on the firm's own server, while the models are called in a European cloud. The inference provider can be swapped without changing the rest of the system.

30 minutes, free. We'll tell you honestly if it makes sense.

03

Who approves what the agent does

An assistant that only answers questions is one thing. An agent that sends emails, edits documents or prepares tax returns is something else. Ask directly: which actions does the agent take on its own, and which go through a person's approval? Where can you see what it did? Who can stop it, and how? The answer should differ by type of action. Reading a document doesn't need the same approval as sending an email to a client.

The European AI regulation (the AI Act) sets human oversight requirements for high-risk systems in Article 14. Among them, a person must be able to decide not to use the system's output, to disregard it or to reverse it, and to stop the system with a stop button or a similar procedure. Most projects in an ordinary company don't fall into the high-risk category. The rule is still a good standard to ask of any agency, because it describes exactly what you want to be able to do when the agent gets something wrong.

We tested everything first on our own accounting. The agent reads the journal and the trial balance, flags the accounts that would block the SAF-T return, generates the file and runs the official validation. The accountant decides the corrections, and the digital certificate signature and the approval to file stay with a person. Every step is logged. That is what an answer to "who approves" should look like: concrete, step by step, naming the role that presses the button.

04

How it connects to the software you already have

An agent that can't see the company's data is just a more expensive chat. Ask how the agent will reach your ERP, your accounting software or your internal documents. Also ask what happens to those systems: do they stay untouched or do they need changes? An answer like "we'll change the system so the AI works" is a sign to keep looking. The software you've used for years has already been checked by your accountant, your auditor and your team.

There is now an open standard for this part. The official documentation describes the Model Context Protocol (MCP) as an open-source standard for connecting AI applications to external systems, such as databases, files and tools. An agency that works with public standards leaves you more freedom than one that wires everything through its own solution that only it can maintain. So ask which standards the agency uses and whether another supplier could carry on the work without starting from scratch.

At FOX, a cured meats producer that runs on SAP, the discovery for digitising production started from one fixed rule: SAP is not modified. The extensions sit separately, on the SAP BTP platform, and talk to the core system only through the official interfaces. With software that has no API, such as SAGA, we read the data directly without writing to the database. It's worth asking the agency to tell you in writing which of these options applies to your system.

05

What stays yours at the end

The question few clients ask at the start is the one that matters most two years later. If you part ways with the agency, what do you take with you? The code? The agent configurations? The instructions written for them? The knowledge base built from your documents? Is the cloud account in your name or the agency's? These questions feel premature at a first meeting, but they are much easier to negotiate before signing than after.

A healthy answer sounds roughly like this: the code and the infrastructure belong to the client, the accounts are in the client's name, and the model in use can be replaced without rebuilding everything. An answer to avoid is a monthly subscription to a closed platform with no export, where everything you built disappears with the contract. Paying monthly for maintenance isn't necessarily bad. Not being able to leave is.

The questionA good answerA red flag
Unde rulează modelele?Server and country stated in writing, with an EU option available."In the cloud, it's safe." No details.
Who approves the agent's actions?A list of actions that go through a person and the log where they show up."The agent is autonomous, you don't need to do anything."
How does it connect to the ERP?Through the official interfaces or read-only access; the ERP stays untouched.The ERP core has to be modified.
What stays mine?Code, configurations and accounts in the company's name.Proprietary platform, no export.
What does the first step look like?A pilot on one process, with acceptance criteria written beforehand.A big 12-month contract from the first conversation.
06

What a pilot with written criteria looks like

The safest way to choose an AI agency is not to choose it on paper but on a small project. A good pilot has a single process, a description of how things work now and acceptance criteria written before the work begins. At the end, it either meets them or it doesn't. There is no room for readings like "it went fairly well".

At RSM, implementation runs in stages, and the acceptance criteria are written before each stage. At FOX, the relationship grew in three separate steps: first AI training for 28 employees, then a redemption platform for a campaign with 250 winners, then the discovery for production. The client saw the result of each stage before deciding on the next one. That is the shape we recommend to you, whoever you work with.

  • 01Pick one process, with high volume and low risk, and describe how it is done today.
  • 02Ask the agency for a written proposal: what the agent does, what stays with people, what data it uses and where it runs.
  • 03Write the acceptance criteria together, before the first line of code.
  • 04Run the pilot with a person checking every result in the first weeks.
  • 05Decide the next step only after comparing the result with the written criteria.
07

Don't forget your people

An AI project doesn't end at delivery. Your colleagues need to know what the agent does, where it usually gets things wrong and when not to trust it. The AI Act actually requires, in Article 4, applicable since 2 February 2025, that companies using AI systems take measures to ensure AI literacy among the staff who work with them. Ask the agency whether team training is included or has to be bought separately.

The last question is the simplest: can you stop working together after the first report? An agency that is confident in its work isn't afraid of it. With us, discovery ends with a written report, the offer comes at a fixed price on a written scope, and the client can stop there. Whichever agency you choose, ask for the same freedom. And if a supplier insists that you sign long term before you've seen a single result, take that as an answer.

08

Sources and further reading.

30 minutes, free. We'll tell you honestly if it makes sense.

FAQ

Frequently asked questions

What does an AI agency do?

It builds and runs AI systems for a company: assistants on internal documents, agents that work inside the ERP or the accounting software, process automation and team training. Agencies differ a lot, which is why the questions you ask before signing matter.

How do you choose an AI agency for your company?

Ask five questions and get the answers in writing: where the models and data run, who approves the agent's actions, how it connects to your existing software, what stays yours at the end and what a pilot with acceptance criteria looks like. Then start with a small project.

Does my company's data end up in a public model if I work with an AI agency?

It depends on the architecture. Models can run on EU servers or on the company's own server, with no training on your data. Ask for a drawing of the data path and a processing agreement under Article 28 of the GDPR.

Do I have to change my ERP to use AI?

Usually not. The agent connects through the ERP's official interfaces or reads the data without writing to the database. If an agency asks you to modify the core of the system, it's worth asking for other options.

What should a contract with an AI agency include?

Besides scope and price, the contract should state where the models and data run, who owns the code, configurations and accounts, what happens to the data at the end and, if personal data is processed, the clauses required by Article 28 of the GDPR.

The Niche Society
The Niche Society TeamAI and software engineers from Bucharest · LinkedIn
published 2026-10-05

Let's see what can be automated in your business.

A free 30-minute session: we'll tell you what can be automated, how long it takes and what it costs, with a fixed price after discovery.

+40 733 045 833
Call: +40 733 045 833Free session