The moment after the AI demo

The room is buzzing. A vendor just typed one sentence and out came a 12-line configuration, pricing, and a cover letter that would pass for your best seller's work. Someone whispers, "If this is real, we can skip half our steps." The CFO looks at you like you just found money.

I’ve been in that room many times. I remember a pilot where the AI stitched together a clever bundle, complete with a neat discount ladder. It looked perfect. Then legal flagged it for violating a pricing policy that exists for a reason. That’s when excitement turns into sweat.

The pressure kicks in. Competitors are moving. Your CEO is asking if you can roll this out by quarter end. This is exactly when teams make the wrong call.

Evaluate the brakes, not the engine

The default mindset is simple: the best AI CPQ is the one that automates the most. The most fluent text. The most clicks removed. The fewest fields touched.

That's how you buy trouble. You’re asking about the engine’s speed, but you haven’t looked at the brakes. Your most sensitive commercial data is about to flow through this system - customer identities, configurations and engineering rules, pricing and discount structures, contract terms. A glamorous demo can hide unacceptable risk.

CPQ is not about automation - it’s about correctness.

The safest and most effective AI-enabled CPQ is not a pure generative black box. It’s a hybrid. Generative AI makes the system easier to talk to. Symbolic logic guarantees the result is correct. The AI helps you talk to the rules engine, but it never gets to break the rules.

AI does not replace logic - it depends on it.

When I say this, someone always counters: "But the AI looked right in the demo." Of course it did. Demos are curated. Real quoting is messy - exceptions, regional pricing, special terms, legacy edge cases. If the system can’t explain itself, your team won’t trust it, and adoption will stall.

If the system cannot explain itself, it will never be trusted.

Here are the rules I use when I sit on your side of the table:

  • Rule 1 - Treat data sovereignty as a showstopper, not a checkbox. Know exactly where customer and pricing data flows, who can see it, and whether it is used for training. If the vendor can’t draw the data flow and name the processors, you don’t have control.
  • Rule 2 - The AI is the interface. The rules engine is the law. Generative suggestions must be validated against symbolic logic before they hit a quote, a BOM, or an ERP transfer. No exceptions, no "probably fine".
  • Rule 3 - Explainability is part of the UI. Every AI-assisted output should come with a why: which rules fired, which constraints applied, which policies narrowed the options. If a rep can’t see it, they won’t trust it.
  • Rule 4 - Security is a living practice. Encryption in transit, at rest, and during processing. Role-based access. Audit logs that a real auditor can use. Regular patching with customer notification. Compliance that maps to GDPR, ISO 27001, and SOC 2, not just logos on a slide.
  • Rule 5 - Avoid the Black Box Hero. This anti-pattern promises magic output with no trace. It feels fast and smart, until it creates a discount, config, or term nobody can justify. That’s how you lose a deal and a customer.

The three conversations to have with your vendor

Skip the shopping list of features. Have three strategic conversations and listen for clarity, not charisma.

1) The Data Sovereignty Conversation

Where does our commercial data live, who can access it, and is it used for training? Ask the vendor to walk you through the full data flow. What enters the AI features, where it is stored, and which sub-processors are involved. If you need EU-only processing, can they prove it? If their AI component sends snippets to external providers, what controls stop leakage of customer names, pricing, or product rules?

Your red lines should be plain: customer and pricing data do not train public systems. Ever. Contracts should say it. Data Processing Agreements should name the boundaries. If you can’t enforce it, it’s a risk disguised as innovation.

2) The Trust and Correctness Conversation

How do we prove the AI’s output is correct? Can the system explain itself? What stops it from hallucinating a price or a configuration? The right answer is simple: generative AI sits on top of symbolic logic, and every suggestion is validated before it becomes part of a quote. The vendor should show you a rules-first path where AI drafts, the rules engine validates, and only then can a human accept.

I’ve seen teams try the reverse - let the AI decide, then hope the rules catch it. That’s building a house on sand. Put the logic first and the text second. Treat the AI as autopilot for quoting. You still fly the plane, but the flight laws are encoded and cannot be broken.

Ask to see explanations inline: which compatibility rules were applied, which discount policies were enforced, which approvals were triggered. No explanations, no trust. No trust, no adoption.

3) The Governance and Control Conversation

How is the AI secured, updated, and kept compliant? Is it a native, auditable part of the platform or a clever add-on strapped to the side? You want encryption at every stage, role-based access, field-level permissions, anomaly monitoring, and audit logs you can actually use in an investigation.

Ask about the lifecycle: how updates are tested, how customers are notified, and how you can pin versions during peak seasons. If the vendor doesn’t use their own AI in their quoting or services workflows, press pause. If they don’t trust it internally, why should your sales team?

Compliance is not a sticker. It’s a practice. Map their claims to GDPR and the EU AI Act. If you sell in regulated markets like healthcare or public sector, require proof of data residency and processing controls that hold up under scrutiny.

Adoption is the only metric that matters.

Practical moves you can apply this week:

  • Run a 60-minute data flow audit with the vendor. On one slide, draw every hop of customer, pricing, and product data through the AI features. Mark storage, region, retention, and access. Highlight where training could occur. If the picture is fuzzy, you’re not ready.
  • Write three non-negotiables into the contract. 1) No use of your data for training. 2) Processing-region guarantees aligned to your markets. 3) Auditability and explainability as acceptance criteria - outputs must cite rules and validations.
  • Pilot with guardrails on. Configure the system so AI suggestions cannot bypass the rules engine. Turn on full audit logs. Set up a weekly review of rejected suggestions and false positives. Aim to improve constraints, not to loosen them.

A quick story from my own work: in one multinational rollout, we treated the AI as a drafting assistant for solution descriptions while the configuration and pricing stayed locked to symbolic rules. Quotes got faster. Errors went down. The reps trusted the system because it could show its work. That’s the win.

One last counterpoint I hear: "But our competitors are going full AI." Maybe. Or they’re shipping confident-looking errors at scale. Progress without control is theater, not business.

Calm truth:

A fast quote is nice. A correct, explainable, and secure quote is revenue.