Every agency site promises agents and transformation. These twelve questions — and what a good answer sounds like for each — are how you tell them apart before you sign.
The short answer: vet a Canadian AI automation agency on twelve things — where your data lives, PIPEDA and PHIPA handling, a signed DPA, production references, fixed fee against written scope, who owns the code and prompts, security practice, monitoring, and your exit plan. Any agency worth hiring answers all twelve without hedging.
Because the category is two years old and the marketing is uniform. Every agency site promises agents, automation and transformation, and almost none of them publish a price, a delivery method or a compliance posture you could check. Meanwhile the failure rate is documented: MIT's 2025 NANDA report, "The GenAI Divide: State of AI in Business 2025", found that roughly 95% of enterprise generative-AI pilots delivered no measurable business impact, and that buying from specialist vendors and forming deployment partnerships succeeded far more often than internal do-it-yourself builds. Choosing the partner well is most of the outcome.
The questions below are ordered so the disqualifying ones come first. Ask them in a first call, before anyone opens a slide deck. If you want to see who is operating in this market before you start, we maintain sourced roundups of AI automation agencies in Toronto and AI agents companies across Canada, and we include our own entry with the same criteria applied.
Every automation you buy becomes a place your customers' personal information lives. If processing, storage and model inference happen on United States infrastructure, you have imported a cross-border privacy question into a workflow you may not have thought of as sensitive.
Good answer: named Canadian regions for processing, storage and inference, stated without hedging, plus a straight answer about any sub-processor that sees the data. "We take privacy seriously" is not an answer.
PIPEDA governs commercial handling of personal information across Canada. A data processing agreement is what turns a vendor's verbal assurances into obligations you could enforce.
Good answer: compliance explained in specifics — encryption in transit and at rest, access controls, audit logging, a stated retention window — and a signed DPA offered as standard rather than as an upsell. Our PIPEDA and PHIPA guide sets out the baseline.
Ontario health information custodians carry obligations that go well beyond PIPEDA, and they flow to the agents you deploy. An agency that has never delivered into a clinic will often not know what it does not know.
Good answer: a specific description of role, retention, logging and breach notification under PHIPA, plus at least one clinic deployment they can describe. In Quebec, the equivalent conversation is about Law 25.
The gap between a pilot and production is where most AI projects die. A demo proves the agency can build a demo. A reference call proves someone's staff use the thing every day.
Good answer: a named reference in a comparable industry, running the work in production, who will take a call. If everything is under NDA and nothing can be described even in outline, treat that as a data point.
Time and materials transfers all discovery risk to you, and AI projects are mostly discovery. Fixed fee against a defined scope forces the agency to understand the problem before quoting it.
Good answer: a fixed price tied to a written description of the workflow, the integrations and the exclusions, with change requests priced separately. Published tiers are a good sign; ours are on the deployment page, and typical Canadian ranges are broken down in our AI agent cost guide.
Prompts, tool definitions and workflow configuration are the real asset in an agent build. If the agency keeps them, you are renting your own process back from them for as long as you use it.
Good answer: you own the deliverables outright, including prompts and configuration, delivered into a repository you control. Licensing a shared platform is legitimate — but it should be stated plainly, not discovered at renewal.
"It works" is not a test. Without written criteria, the final invoice arrives at the moment the agency thinks the project is finished, which is rarely the moment you do.
Good answer: a list of specific cases the agent must handle correctly — including the awkward ones and the ones where it must refuse or escalate — agreed before work starts and tied to the final payment.
Sales-led agencies are frequently selling a senior engineer and staffing a junior one, or subcontracting offshore without saying so. That matters for quality and it matters for where your data goes.
Good answer: named people, their role on your project, and a clear statement about subcontractors and their location. Ask who you call when the agent misbehaves at 4pm on a Friday.
An agent that fails silently is worse than no agent, because you keep believing the work is being done. Monitoring is the difference between a system and a science project.
Good answer: logging of every action the agent takes, alerting on failures and anomalies, a named owner for the alerts, and a way for you to inspect what happened on any given interaction without filing a ticket.
You are granting a third party credentials to your calendar, your CRM and possibly your practice-management system. The blast radius of a compromised integration is your entire customer list.
Good answer: least-privilege credentials scoped per integration, secrets held in a managed vault rather than in code or configuration files, rotation on staff changes, and a described incident-response process. Note that a serious firm says "aligned with SOC 2" only if that is true, and never claims to be "certified" in a framework that does not certify.
The build is the smaller number. Usage, hosting, monitoring and the inevitable adjustments are what you pay every month for years, and vendors who avoid the question are usually avoiding a bad answer.
Good answer: an itemized estimate of ongoing costs — model and telephony usage, hosting, monitoring — plus a stated rate or included allowance for changes. Ask what a typical month looks like for an existing client.
The best time to negotiate leaving is before you arrive. Agencies that expect you to want out write long lock-ins; agencies that expect to earn renewal do not need them.
Good answer: no multi-year lock-in for standard work, your data exported or deleted on request, documentation good enough for another team to take over, and a stated notice period. If they cannot describe an orderly handover, you are the one carrying that risk.
A few answers should end the conversation early. "We're certified compliant" — PIPEDA and PHIPA are laws, not certifications, and a firm that misuses the word is telling you how carefully it reads legislation. "We can't discuss where the data is processed" — that is always a decision someone made, and you are entitled to know it. "We'll scope it as we go" on a project quoted in tens of thousands of dollars. "Our platform, our prompts" without saying so up front. And any pitch that leads with a percentage improvement it cannot source: a real firm cites Statistics Canada or a named study, not a number from a competitor's landing page.
Be equally suspicious of the opposite failure — an agency that agrees to everything. Good partners tell you when your problem does not need them, which is often. If the task has a fixed trigger and a fixed outcome, you may only need workflow automation; our comparison of AI agents, chatbots and Zapier-style automation walks through how to tell.
Send the twelve questions to your shortlist in writing before the first meeting and compare the written answers side by side. Written answers are harder to improvise and easier to hold someone to later. Then use the meeting for the two things writing cannot do: meet the person who will actually build the thing, and watch how they respond when you push on a detail they got wrong.
Score each vendor on all twelve rather than on the demo. Demos are the part every agency has rehearsed; data residency, ownership, monitoring and exit are the parts that determine whether you still have working automation in eighteen months. And put the same questions to us — the checklist is not a trick that only Mihron AI passes, and if another firm answers them better, hire that firm.
Mihron AI is a Toronto-based AI agents and workflow-automation company building and operating agents for Canadian businesses on fixed fees, with processing and storage in Canadian regions. See our services, our approach as an AI agents company in Toronto, our workflow automation guide, and what projects cost in our AI agent cost guide.
We will answer all of them in writing, including the ones about data residency, ownership and leaving.