Last chapter was about finding the AI already inside your walls. This one is about the AI you never built, never trained, and don't control — but that your organization is fully exposed to anyway, because it's sitting inside a vendor contract you signed for something else entirely.
Most third-party risk programs were built for a world of static software. AI vendors break that assumption completely.
The model underneath a tool you assessed in January can be silently swapped, retrained, or fine-tuned by March — and your questionnaire has no way of knowing. The frameworks, checklists, and review cycles your organization relies on were designed for software that stays still. AI doesn't stay still.
Third-party AI risk doesn't arrive through a single, obvious door. It enters through three distinct channels — each with its own level of visibility and control.
Tools procured specifically because they're AI — at least flagged for review during procurement. These are the visible ones.
Vendors you've used for years that quietly added AI features, entering through a door your process doesn't watch. No new contract. No new review.
The AI your vendor's vendor uses — with no contract, no visibility, and no leverage on your end. The most invisible risk of all.
Standard vendor questionnaires were not designed with AI in mind. Two critical questions are almost never asked — and their absence leaves significant exposure unaddressed.
After the AI processes your data — is it used to train the vendor's models? Retained for "product improvement"? Or fully isolated to your instance? Most questionnaires never ask. Most contracts never specify.
When the model gets something wrong — a biased output, a hallucinated fact, a harmful recommendation — who bears responsibility? The vendor? Your organization? The answer is rarely written down anywhere.
Understanding where your exposure actually lives requires mapping the full supply chain of AI capability flowing into your organization.

The deeper you go in the supply chain, the less visibility you have — and the more your risk depends entirely on your vendor's own governance practices, which you may have no right to audit.
Governing AI you didn't build requires deliberate, structured action across your vendor lifecycle. Here is the practical playbook.
Ask in writing: has any AI capability been added since your last review? Don't rely on vendors to volunteer this information — require it explicitly.
Data-use restrictions, model-change notification requirements, and audit rights should be standard inclusions at every contract renewal going forward.
Not just by spend or criticality — by the nature and depth of AI involvement. A low-spend vendor processing sensitive decisions via AI may carry more risk than a high-spend infrastructure provider.
Who are your vendor's AI subprocessors? This question alone will surface risks that no standard questionnaire currently captures.
Not your default annual cycle. AI models change faster than annual reviews can track. Quarterly touchpoints for high-risk AI vendors should be the baseline.
Governing third-party AI is not a one-time assessment — it is a continuous cycle that must be embedded into your existing vendor management processes, running at the pace AI actually changes rather than the pace your legacy program was designed for.
When renewing or negotiating vendor contracts where AI is involved, these are the provisions that matter most — and that most standard templates currently omit entirely.
Explicit prohibition on using your organization's data to train, fine-tune, or improve the vendor's models — unless you have affirmatively consented in writing.
Contractual obligation for the vendor to notify you before making material changes to the underlying AI model — with a defined notice period and your right to re-assess.
The right to audit or request third-party audits of the vendor's AI systems, data handling practices, and subprocessor relationships — not just their security controls.
Clear language specifying who bears responsibility when the AI produces harmful, biased, or incorrect outputs — and what remediation obligations the vendor carries.
Requirement to disclose all AI subprocessors (fourth parties) and to notify you of any changes to that list — mirroring the GDPR subprocessor model applied to AI.
This pillar doesn't have a dedicated artefact in the toolkit yet — vendor and third-party AI risk is the next template planned for the register.
The vendor and third-party AI risk register template is actively in development. When published, it will provide a structured framework for capturing AI-specific vendor attributes, risk tier classifications, contract clause status, and fourth-party subprocessor mapping — all in a single, auditable register.
The next chapter moves from vendors back inward: data governance and consent in the age of AI.
The three entry points of third-party AI risk, why standard security reviews fall short, and the five concrete actions to build your vendor AI map.
You are exposed to AI you never built, never assessed, and don't control. Governing it requires new questions, new contract clauses, and a faster review cadence.
Data governance and consent in the age of AI — turning the lens back inward to examine how your own data practices hold up under AI's demands.
Borrowed Risk: Governing AI You Didn't Build