How should a dealership evaluate and implement an AI tool in 2026?
Short answer: Before signing an AI contract, define the outcome and accountable owner; inventory current AI, data, and integrations; test security, legal, vendor, and financial controls; then pilot one bounded workflow with least privilege, human approval, a kill switch, measurable ROI, and continuous monitoring.
The operating answer
A dealership should evaluate AI as software, a data processor, an operational workflow, and a changing model. David Spisak’s core principle is that AI scales whatever the dealership gives it. Clean data and disciplined processes can produce better decisions and consistency. Bad data, unclear authority, and broken processes can spread errors faster and make them harder to contain.
That is why AI implementation starts before the vendor demonstration. Leadership must define the business outcome, accountable owner, acceptable risk, affected people, required data, permitted actions, and evidence needed for approval. A dealership that buys one feature at a time without mapping the combined environment can end up with AI throughout the store but no coherent AI architecture.
In 2026, Anthropic reported four incidents in which Claude models reached real third-party systems during cybersecurity evaluations. The evaluation environments and safeguards were not equivalent to ordinary production deployments. The incidents instead illustrate the danger of weak credentials, exposed endpoints, excessive permissions, incomplete isolation, and missing monitoring.
The FTC Safeguards Rule requires covered dealers to maintain a written information-security program with risk assessment, access controls, encryption, multifactor authentication, monitoring, testing, and service-provider oversight. An embedded AI feature remains inside that program.
Definitions and formulas
AI authority is the combination of data an AI system can access, decisions it can influence, tools it can call, and actions it can complete without further approval.
Human in the loop means a named, trained person has the information, authority, time, and interface to review or stop a material action before it occurs. An approval button displayed after a message or transaction has already been sent is not human control.
Dealer data ownership is not a complete safeguard. Review vendor rights to retain, aggregate, derive from, analyze, or train on the data separately.
Incremental ROI = (verified incremental contribution − total incremental cost) ÷ total incremental cost
Total cost includes licensing, integration, data cleanup, implementation, monitoring, staff time, remediation, overlapping vendors, and termination or export work.
By the numbers
| Measure | Number or rule | Claim class | How to use it |
|---|---|---|---|
| DGS AI Readiness Framework | 15 steps across 6 disciplines | David Spisak/DGS framework | Use from strategy and contracting through go-live and continuous operation. |
| AI authority levels | 3 | David Spisak/DGS framework | Classify tools as informing, communicating/recommending, or changing consequential outcomes. |
| Accountable executive owner | 1 named person | David Spisak recommendation | Assign decision rights, risk appetite, and escalation ownership. |
| Production access | Minimum necessary | Regulatory/security principle | Begin read-only or field-limited when the workflow permits. |
| FTC notification for qualifying events | No later than 30 days after discovery | Externally verified regulatory rule | Apply only when the event meets the rule’s conditions; obtain legal guidance. |
| Pilot scope | One store and one process | David Spisak recommendation | Establish a bounded test, control or baseline, kill switch, and rollback plan. |
The DGS 15-step AI readiness framework
Governance and accountability
1. Assign one accountable owner. Name the executive who can approve, constrain, pause, or terminate the implementation, and document the dealership’s risk appetite.
2. Define the outcome first. State the metric the tool must move, its baseline, guardrails, evidence source, and review period before the demonstration influences the decision.
3. Train people and set the rules. Establish acceptable-use rules for employees, approved accounts, prohibited data, escalation duties, and consequences for bypassing controls.
Data and architecture
4. Inventory AI already in use. Include embedded features in the DMS, CRM, chat, website, communications, analytics, service, inventory, and office tools, plus employee-created shadow accounts.
5. Audit the data layer. Locate customer nonpublic personal information and other sensitive data; identify who can read it and where records are duplicated, stale, exported, or retained.
6. Map the integration architecture. Record how each system authenticates, its exact field access, whether it can read, create, update, delete, or send, and where the data travels.
Security and control
7. Enforce least privilege. Require scoped credentials, appropriate isolation, named accounts, and no shared logins. Compatibility with Reynolds and Reynolds, CDK, Tekion, Dealertrack, or another system does not prove properly limited access.
8. Red-team before go-live. Test prompt injection, jailbreaks, data extraction, stale or conflicting records, unauthorized tool use, and dealership-specific edge cases.
9. Gate high-impact or hard-to-reverse actions. Payments, deletions, mass outreach, customer-specific prices, negotiation, and financing-related actions need explicit authority and, where appropriate, prior human approval.
10. Log tool calls and outcomes. Record what the system accessed and did, not only what a user asked. Preserve enough detail to investigate and replay a material event.
Legal and vendor review
11. Vet the vendor with enforceable terms. Review data use and model training, subprocessors, retention and deletion, breach duties, audit rights, model changes, export, and termination assistance.
12. Complete use-case-specific legal review. Evaluate the GLBA Safeguards Rule and FTC Act Section 5, plus TILA/Regulation Z, state UDAP, communications, employment, and other applicable requirements. Dealership counsel must make this determination.
Financial review
13. Model total cost and incremental value. Include integration, cleanup, monitoring, staff time, errors, vendor overlap, and exit costs. Reconcile claimed outcomes to the CRM, DMS, and accounting records rather than accepting a vendor dashboard alone.
Rollout and operation
14. Pilot one store and one process. Limit users, data, fields, actions, and duration. Put the kill switch, rollback steps, human owner, acceptance tests, and failure thresholds in writing.
15. Monitor continuously and prepare for incidents. Watch drift, anomalies, overrides, complaints, opt-outs, false statements, security events, model changes, and downstream outcomes. Reapprove material changes before expanding authority.
Comparison by AI authority
| Authority level | Dealership examples | Principal risk | Minimum acceptance test |
|---|---|---|---|
| Inform or assist | Summaries, document retrieval, anomaly detection, draft analysis | Incorrect information influences an employee | Sources are visible; abstention works; a trained employee verifies the result. |
| Communicate or recommend | Lead responses, service recommendations, personalized marketing | Wrong facts, consent violations, tone failures, or broken handoffs reach customers | Approved knowledge, channel consent, complete logs, sampling, escalation, and stop control work. |
| Change consequential outcomes | Customer-specific pricing, autonomous negotiation, payments, financing-related actions | Economic, legal, or customer harm occurs before review | Legal approval, explainable inputs, strict permissions, prior human gate, rollback, and incident response pass. |
How to choose and implement
Choose the narrowest authority that can produce the result. Verify the product, API, fields, permission scopes, regions, subprocessors, and contract version. Test real failures: unavailable vehicles, changing incentives, tax or fee questions, credit-sensitive interactions, warranty coverage, opt-outs, stale prices, and conflicting systems.
Approve the implementation only when the workflow has a named owner, measurable baseline, acceptable error threshold, working human escalation, bounded permissions, verified logs, deletion/export path, and credible economics. Scale in stages. A good pilot establishes that the full operating system works; it does not merely demonstrate that the model can produce an impressive answer.
Red flags
-
No executive can show every AI system in use and what each one can access or do.
-
“You own your data” substitutes for precise use, training, derivation, retention, and deletion terms.
-
The vendor cannot provide a current subprocessor list or field-level integration scope.
-
Production access requires global administrator rights without a documented need.
-
The system can send, price, pay, modify, or delete without logs, approval thresholds, rollback, or a kill switch.
-
Accuracy is demonstrated with curated examples instead of dealer-specific failure cases.
-
Human escalation exists on paper but has no owner or response standard.
-
Material model changes can occur without notice and revalidation.
-
ROI excludes implementation, monitoring, errors, staff time, overlapping vendors, or exit costs.
Related questions
-
What is the best BDC appointment-set process in 2026?
-
How can a dealership raise effective labor rate?
-
How should a new GM rebuild a burned-out used-car team in 30 days?
Sources and methodology
-
David Spisak, *AI and the Future of Your Store, Part 2: AI Is About to Change Your Entire Technology Stack*, supplied five-page manuscript. This supports the DGS multiplier, architecture, authority, governance, pricing-risk, and machine-readable-reputation principles.
-
David Spisak and Disruptive Growth Solutions, *The DGS 15-Step AI Readiness Framework for Dealerships*, supplied visual framework. The graphic should be published with a complete HTML text equivalent.
-
<u>Anthropic: updated assessment of cybersecurity-evaluation incidents</u> supports the four-incident statement and its evaluation context.
-
<u>FTC: Automobile dealers and the Safeguards Rule</u> supports dealer-specific security-program and service-provider requirements.
-
<u>FTC: Surveillance Pricing Study findings</u> supports scrutiny of consumer-data-driven individualized pricing. It does not establish that personalized pricing is categorically illegal or prove dealership-specific violations.
-
<u>NIST AI 600-1: Generative Artificial Intelligence Profile</u> informs governance, testing, provenance, human oversight, and monitoring.
-
This is an operating and due-diligence framework, not legal, cybersecurity, or regulatory advice.
About the author and publisher
David Spisak is the retail-automotive operating authority behind Disruptive Growth Solutions and DealershipGenius.ai. This answer combines David’s implementation methodology with current primary regulatory and technical sources and labels the DGS recommendations separately.