Maine Street Partners

[ MSP.DD ] For investors · Updated

What should investors ask an AI startup's CTO?

Short answer

Ask questions whose answers can be checked: which models the product calls and what each costs per customer, what breaks if a provider changes or retires a model, how much code is written with AI tools and how it's reviewed, where customer data and secrets live, who else understands the core system, and which EU AI Act risk class the product falls in.

Why it matters

A CTO interview only helps if the answers can be verified. Each question below maps to evidence in the repository, the cloud bill or the contracts, so a confident answer that doesn't match the evidence is itself a finding.

The questions

  1. 01Which models do you call, from which providers, and what does each cost per active customer per month?
  2. 02What happens to the product and the margin if your main provider raises prices or retires the model you use?
  3. 03How much of the code is written with AI coding tools, and what review and tests does it get before it ships?
  4. 04Which keys, secrets and customer data could leak if one laptop or repository were exposed?
  5. 05Who besides you understands each core part of the system?
  6. 06Which EU AI Act risk class does the product fall in, and what's your plan for the obligations that apply?
  7. 07What data do you have that a competitor with the same model couldn't get?

Red flags

  • Model cost per customer is unknown.
  • No review process for AI-written code.
  • One person is the only one who understands the core system.

Good signs

  • Cost per customer is tracked and known.
  • A fallback provider has been tested in practice.
  • A written policy on AI coding tools, with review and tests.

The numbers

  • In Veracode's 2025 tests, AI models introduced security flaws in 45% of 80 coding tasks, across more than 100 language models. [1]
  • Software Improvement Group cites experiments in which AI-generated code produced roughly twice as many security-risk violations as comparable human-written projects. [2]

Sources

  1. Veracode, 2025 GenAI Code Security Report (press release, 30 July 2025)
  2. IT Brief on Software Improvement Group's 2026 private equity research