The clearest warning signs in this category are things a vendor says, not things a product does — which is useful, because it means you can spot most of them on a first call before you've committed a minute of trial time. The eight below came from clinicians describing what they wish they'd noticed sooner.
I build one of these tools, so I'm describing a field I'm standing in. Several of these are tests we'd pass and at least one is a place we'd have to give you an awkward answer. That's the point of writing them down.

Most of these show up in the first conversation, long before a trial does.
1. Everything is a strength
The most reliable signal, and the easiest to test: ask what the tool does badly and where they'd tell you not to use it.
A vendor who knows their product answers crisply and specifically. A vendor who deflects into a benefit is reading you a brochure. Clinicians told me this question changed their shortlist more than any feature comparison did.
2. "Compliant" used as a finished state
No software is compliant on its own. Compliance describes how information is handled in your practice — the obligation stays with you, and a vendor can supply safeguards but not carry the duty.
So "we're compliant, so you're covered" is either a misunderstanding or a convenient one. The better answer sounds like: here are the specific safeguards you can point to when you do your own assessment.
3. The demo runs on their document, not yours
A sample case is chosen to flatter the sample. If you can't run your own structure, your own section order and your own length before paying, you're evaluating a performance rather than a product.
This is the one clinicians said cost them the most: a tool that looked excellent on a tidy two-page example and fell apart on a real twenty-page report with an uneven profile.
4. Time savings quoted as a single number
A saving depends on your document length, your structure, how much you edit and how fast you already write. A figure without those anchors is describing somebody else's practice.
Ask what the baseline was and how it was measured. If there isn't an answer, the number is decoration. There's a method for producing your own in how I'd measure whether an AI tool actually saves you time.
5. Vagueness about where content is processed
Storage location and processing location are different questions, and a page can answer the second while implying the first. Ask for the path step by step, and notice whether the vendor names an exception.
Almost every real architecture has one. A vendor who volunteers theirs has thought about it; a vendor whose diagram is entirely tidy either hasn't looked or isn't telling you. The full question set is in what to ask about where your data is processed.

Ask for the path. Notice whether they name the awkward step or produce a tidy diagram.
6. De-identification described as a guarantee
It's a control that lowers risk, not a mathematical promise that content can never be reconnected to a person. A vendor presenting it as absolute has told you how carefully they read their own field.
Related: if "we don't train on your data" is offered as the complete answer to privacy, ask separately about retention, sub-processors, and what happens on your device before transmission. Those are four claims, not one.
7. Output you can't trace back to your input
The one I'd weight most heavily, because it decides whether reviewing the document is a genuine check or a formality.
If you can take a sentence in the draft and find what it came from, review is real. If the draft is fluent and unverifiable without redoing the work, you've been handed liability with a time saving attached. Test this deliberately: leave a gap in your trial material and see whether the tool flags the absence or confidently fills it.
8. No clean way out
Ask on day one how you'd leave: what you can export, in what format, whether you get underlying content or only rendered files, and what's deleted when you cancel.
A vendor with a straightforward answer expects to be kept for good reasons. A vague one is relying on it being hard to go.
Where would we set off one of these?
Number five, if you push far enough — and I'd rather say it here than have you find it.
Our documentation processing runs on edge infrastructure in Montreal, and there is one step in report drafting where content transits a large-model provider outside Canada. That's the awkward exception in our own path. I write it down every time because a clinician doing a privacy assessment needs the real answer, not a flag on a homepage.
Run all eight at us alongside everyone else. The full evaluation framework is in how to choose documentation AI for a clinical practice, and if you want to see the drafting first, it's here.
— Ian
