What should an AI model vendor due diligence checklist cover?
An AI model vendor due diligence checklist should cover six decisions: model identity, provider boundary, credential scope, subprocessor chain, lifecycle control, and operating risk. NIST AI 600-1 treats generative-AI risk as something that can appear at model, application, ecosystem, and lifecycle levels, so a vendor questionnaire that asks only for a security PDF is incomplete.
Source: NIST AI 600-1, Generative AI Profile · published July 2024; rechecked 2026-08-11
Which model identity facts should procurement record?
Procurement should record the exact model ID, release state, licence, context limit, modalities, provider route, and capture date. Moonshot’s model list, for example, names kimi-k2.7-code as a dedicated coding model with a 256K context, while kimi-k2.6 is listed as a general multimodal model; the family label alone would lose that distinction.
Source: Moonshot AI Kimi API model list · rechecked 2026-08-11