Third-party AI risk
The AI in your environment that will cause a problem is usually AI you did not buy. It arrived as a feature in a product you already had, or as a sub-processor of a supplier you already assessed, and your existing third-party risk process does not see either.
Four ways AI enters without being procured
- Feature activation. A SaaS product you already use ships an AI assistant. No new contract, no new review, new processing.
- Sub-processor change. Your supplier adds a foundation model provider to its stack. Whether you hear about it depends on a notification clause you may not have.
- Embedded models. A component inside a product you bought, which the vendor may not itself enumerate.
- Shadow adoption. Individuals connecting tools via OAuth to systems that already hold your data.
Only the first is visible to a normal procurement process, and only if someone is watching release notes.
Where this usually goes next
Three situations account for most people reading this page. Each has a different answer.
A deal is blocked on an AI questionnaire
Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.
You need ISO/IEC 42001 documentation
23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.
You are not sure what reaches you
Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.
This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →
The model supply chain is not a normal supply chain
Expert analysis. Three properties that break conventional third-party risk assumptions:
- The component changes without a version bump. A model behind an API can be updated, quantised or replaced with behaviour you never tested. Your contract may not require notice.
- Provenance is often unavailable. Training data lineage for a foundation model is usually not disclosable, which limits how far Art. 10 data governance can reach through the chain.
- Attack surface is model-specific. Art. 15 names data poisoning, model poisoning, model evasion, confidentiality attacks and model flaws. A supplier’s ISO 27001 certificate covers roughly one of them. CISO view →
Where the Regulation puts responsibility
| Situation | Who owes what |
|---|---|
| You buy and use | Vendor is provider; you are deployer with Art. 26 duties. |
| You rebrand it | Art. 25: you become the provider. |
| You repurpose it into an Annex III use | Art. 25: you become the provider, including where the underlying system is a general-purpose AI system. |
| You resell it | Distributor duties under Art. 24, verify CE marking, declaration and instructions. |
| You import it from outside the EU | Importer duties under Art. 23, verify the conformity assessment was carried out. |
None of these move by contract. Roles →
Status labels on this page
Verified fact: Article references and dates cited above, checked against the consolidated Regulation.
Expert analysis: The tables, tiering and assessments on this page are our practice, not a standard.
Unsettled: Procurement practice is not codified and varies by buyer. Verify specific programme requirements against the buyer's own published materials.
Visibility first
You cannot assess a supply chain you cannot enumerate. Inventory, then tier, then contract — in that order, because each step makes the next one cheaper.
Not sure where you sit?
The classifier maps your system against Articles 5, 6, 50 and Annex III. Twelve questions, no email.
Frequently asked
How does AI enter an organisation without being procured?
Four common routes: an existing SaaS product activating an AI feature without a new contract; a supplier adding a foundation model provider as a sub-processor; models embedded inside a purchased component that the vendor may not itself enumerate; and individuals connecting third-party AI tools by OAuth to systems that already hold company data. Only the first is normally visible to a procurement process.
Who is responsible for AI supplied by a third party?
Under the EU AI Act, the vendor is normally the provider and the buyer the deployer, each with different obligations. Article 25 shifts the buyer into the provider role where they put their name or trade mark on the system, make a substantial modification, or modify the intended purpose so that it becomes high-risk, including where the underlying system is a general-purpose AI system. Resellers may have distributor duties under Article 24 and importers under Article 23.