Risky, the character from Everybody Hates Chris, sold everything: a watch that stopped after two days, sneakers that fell apart in the first rain, a cell phone with a screen that went blank the following week. The product had packaging, had a convincing story, had a price. What it didn't have was real delivery. Today the same scene plays out in AI sales meetings: a polished slide deck, an impressive demo, a high monthly contract, and a tool the company pays for every month without being able to say what it actually changed in the operation.
This post is about two problems that appear when companies buy AI the wrong way. The first is paying and getting no results at all. The second is paying, getting something back, and at the same time sending the company's internal data to a server you don't control and don't know where it's located. Both have a solution. But only if you know what you're hiring before you sign.
Are you paying for AI, or paying to say you have AI?
There is a big difference between having AI in the company and having an AI subscription in the company. Anyone can get a subscription. You go to the website, enter your card, and in five minutes you have access to a platform that promises to transform your business. The problem starts when the transformation never shows up.
Most companies that contract AI today use the tool in two or three isolated cases: drafting an email, summarizing a meeting, handling a basic support reply. That's not bad, but it's a tiny fraction of what was promised and what was paid for. The monthly bill keeps coming, the vendor keeps sending "active users" reports, and inside the company nobody can point to a single process that became different, faster, or cheaper because of the tool.
That's buying from a con man. The product exists, works at some level, but the result that would justify the investment never appears. And unlike worn-out sneakers, an AI subscription doesn't leave an obvious mark that something went wrong. The money walks out quietly, month after month, buried in a technology budget that already has other line items nobody questions.
The warning sign is simple: if nobody at the company can say how much time or money AI saved last quarter, with a number, the problem is already there. AI that doesn't change results isn't worth what it costs. And AI that nobody knows how to measure probably isn't changing any results at all.
Where exactly is your company's data?
The second problem is quieter and more dangerous. When you use a cloud AI, whatever the platform, you are sending information to another company's server. Information that can include a commercial proposal you asked the AI to review, a customer service conversation with client data, a financial spreadsheet a manager pasted into the chat for analysis, a contract the legal team asked the tool to summarize.
The privacy policy of most of these platforms says it doesn't store data or uses encryption. And it's probably true, within what the terms cover. The problem isn't just what the company does with the data today. The problem is that the data left your network. It passed through a server you don't control. It was exposed to a risk surface you didn't audit and that isn't inside your security perimeter.
For a company that handles customer data, financial information, or sensitive internal processes, this risk isn't hypothetical. It's the kind of exposure that shows up in client contract terms, in audit requirements, in legal questions before closing a bigger deal. "Where do you process data?" is an increasingly common question. And "we use a third-party cloud AI" is rarely the answer the other side of the table wants to hear.
Here the con man isn't selling a defective product. He's selling a product that appears to work while creating a problem you'll discover later, at a worse moment, with bigger consequences.
How to recognize AI that won't deliver
There are three questions that separate a tool that will change results from a tool that will just occupy a budget line:
Is there a measurable goal? Any AI implemented without a defined goal will deliver exactly what wasn't asked for: nothing trackable. The goal doesn't have to be sophisticated. It can be "reduce customer response time by 30%" or "cut the time spent on weekly reports in half." If the vendor can't help define that before selling, that's where the problem starts.
Does the tool know your business or is it generic? Generic AI answers general questions well. AI that transforms operations knows who your customers are, how your process works, and what the exceptions in your area look like. That difference doesn't come out of the box. It comes from configuration and adjustment work that most AI vendors don't include in the contract because it takes effort and reduces margin.
Do you control where the data lives? If the answer is no, or if you don't know how to answer, the second problem is already installed. Not needing to know where data lives was acceptable five years ago. Today it's operational risk with a name and address.
AI that works has a clear home: inside your operation
On-premise AI means the tool runs on your company's servers, or in infrastructure you control, without any data leaving your perimeter. What you type stays inside the house. What the AI processes doesn't pass through any third-party server. The result appears on your screen without having passed through any place you didn't approve.
This fully resolves the second problem. But it also resolves the first, because AI installed inside the operation must be configured for the specific business. You can't put a tool inside the company's structure and leave it responding generically. The adjustment work that most cloud vendors skip because it's inconvenient becomes a mandatory part of the process when AI lives inside your house.
It's not a solution for every company, at every moment. It requires a minimum infrastructure, an honest diagnosis of where the processes that will receive the tool are, and someone who knows how to configure the AI for the way the business works. What it delivers in return is trackable results and data that stays where you decided it stays.
What separates those who pay and receive from those who pay and wait
The difference is not in the tool. It's in the implementation process. Companies that pay for AI and get results start with a diagnosis: where are the bottlenecks, which process will receive the tool first, how will we measure whether it worked. This step is usually skipped because it seems bureaucratic and because the vendor is in a hurry to close the contract.
When the diagnosis doesn't happen, the tool enters the company with no address. It sits there available to whoever wants to use it, however each person sees fit, without a goal and without control. In three months, the company has usage data and no results data. In six months, the question nobody wants to ask starts appearing in meetings: "but is this tool actually worth it?"
At Steply, the work starts with a diagnosis before any tool is installed. We map where AI will actually change results, define how to measure that, and only then configure the solution to work inside the company's real process. When the business involves sensitive data, the solution goes on-premise. When the client needs speed before the infrastructure is ready, we define the boundaries of what can go outside and what can't.
If you are paying for AI and can't say what it changed, or if you are using cloud AI with data that shouldn't leave the company, the moment to review that is before the next contract comes up for renewal. It starts with a free diagnosis: we map where the problem is and what can be done.