The Hidden Supplier Risks in Enterprise AI

Diagram showing AI supplier risk across data retention, training terms, and embedded AI features

Table of Contents

Most AI supplier risk does not sit in the AI systems organisations build. It sits in the AI systems they use.

This represents a structural shift in how technology risk gets managed. Organisations have spent years building governance around the systems they control – their infrastructure, their applications, their data stores. Third-party risk management exists as a discipline, but it was built for a world where suppliers provided defined services under stable commercial arrangements.

The AI supplier landscape looks nothing like that. Suppliers add AI features to existing platforms with little announcement, and terms of service change with limited notice. A tool that was safe for one category of data may not be safe once the supplier updates its data handling practices, and the sheer number of AI tools now in use across most organisations makes comprehensive supplier governance genuinely hard.

The AI supplier risk hiding in terms your staff never read

The most immediate AI supplier risk for most organisations sits in the terms of service for the tools staff already use – terms almost certainly never reviewed by anyone in legal, compliance, or risk.

Data retention and usage matter most here. Does the supplier keep prompts submitted to the tool, for how long, and for what purpose? Is submitted data used to train or fine-tune models, and if so, under what conditions, with or without an opt-out? These answers differ a lot between tools, and they matter far more when the data involved is personal, commercially sensitive, or regulated.

Jurisdictional processing matters second. Where is data processed and stored? Are there sub-processors, and where are they based? For organisations subject to UK GDPR, these are not optional questions – data processing agreements are required for suppliers handling personal data, and many AI providers, especially smaller ones, either lack adequate DPAs or have not updated them to cover AI-specific handling, an area the ICO continues to focus on.

Training data terms deserve close attention too. Some consumer-facing AI tools, particularly free or low-cost ones, permit submitted content to be used for model training by default, often buried in terms nobody reads. For organisational use involving anything beyond genuinely public information, that is a real governance concern.

The embedded AI problem

A particularly hard category of AI supplier risk involves features added to platforms an organisation already uses and trusts. A project management tool adds AI summarisation. A CRM adds AI-powered contact analysis. A communication tool adds AI note-taking and transcripts, while an email client adds AI drafting.

In each case, the organisation already has a commercial relationship with the supplier and already trusts the platform with its data. It may not have noticed the AI features arrive, or may have noticed and assumed existing data agreements cover them.

Often, they do not. AI features frequently involve different sub-processors, different data handling, and different retention terms than the core platform, so the DPA covering the underlying platform may not cover the AI layer. The data flows reviewed when the platform was first adopted may have expanded significantly without anyone noticing.

This is one of the biggest gaps in most organisations’ current third-party governance: existing supplier relationships are being relied on to cover AI features that were never part of the original review. It is the same blind spot covered in why most organisations have no real visibility of AI usage.

What proportionate AI supplier risk management looks like

For new tools, supplier review should be built into the onboarding process rather than treated separately. Before a tool joins the approved list, its key terms get reviewed, the data processing position gets understood, and a decision gets made about what categories of organisational data are appropriate for it.

For existing suppliers that have added AI features, the priority is finding which platforms are now processing organisational data through AI, and whether existing governance covers that adequately. Usually, this is a bigger task than assessing new tools, because the number of platforms involved is often large and the changes happened without prompting any review.

Not every supplier needs the same scrutiny. A risk-tiered approach – focusing detailed review on suppliers handling significant volumes of personal data, sensitive information, or regulated content – is proportionate and practical. Organisations that apply the same rigour to every AI tool tend to build a governance overhead they cannot sustain.

Keeping AI supplier risk under review

AI supplier terms are not stable. They change as business models evolve, as regulation tightens, and as the competitive landscape shifts, so an assessment that was accurate when conducted can be materially out of date within months.

Building a review cadence is the baseline – at minimum an annual review of significant AI suppliers, with a way to catch material term changes between reviews. Subscribing to supplier term change notifications, and treating significant changes as triggers for reassessment rather than routine notices to file, turns supplier governance from a one-off exercise into an ongoing programme. Our AI Supplier Review Checklist covers the 29 criteria worth checking, whether for a new supplier or a periodic review.

The organisations most exposed are those treating supplier governance as a one-time due diligence exercise. By contrast, the best-positioned organisations have built ongoing review into their governance programme from the start.

Black Chili’s AI Governance and Guardrails Design service includes AI supplier review criteria and an ongoing governance framework that keeps third-party risk visible.

If you are not sure what AI tools are in use inside your organisation, an AI Exposure Review gives you a clear, independent picture - what is being used, what data it touches, and where the real risks are.

Related Posts