Vendor & Supply-Chain AI Risk

The riskiest AI in your business is the AI you didn't buy.

AI is arriving through the SaaS you already trust — not the AI you procured. Discover it, trace where your data goes, and score every vendor against the frameworks your regulator and board ask about.

Start from a pre-assessed vendor baseline — not a blank 40-question cycle.

Built in Norway & the UK · EMEA-sovereign by default

The problem

Your vendors turned on AI. Nobody told security.

Nearly every organisation was hit by a SaaS- or AI-ecosystem security incident last year. The common thread: AI features that shipped inside trusted tools, touching real data, with no review and no entry on any inventory.

AI arrived through procurement, not security

Vendors ship AI features in a product update. No review, no sign-off, no entry on any list.

Questionnaires can't keep up

A 40-question SIG cycle takes a quarter and is stale on arrival. Vendors ship AI faster than you can survey them.

Your data is the supply chain

Vendor AI routes your customer data, contracts and code through models and sub-processors you never contracted with.

The obligation lands on you

Under the EU AI Act you are the deployer. “The vendor handles it” is not a defensible answer to a regulator.

What CISOs need to see

Nine questions every CISO must be able to answer

Vendor AI risk isn't a single yes/no. It's a set of answers you should be able to produce on demand — for any tool, in front of an auditor, in the next board meeting.

Discovery

Which of our vendors quietly shipped AI?

The AI you didn't procure is already live inside the SaaS you trust — bolted onto your CRM, your helpdesk, your IDE. You can't assess what you can't see.

Data & training

Where does our data go — and is it training a model?

What does the feature ingest, is your data used to train or fine-tune, can you opt out, and does any of it leave the EU?

Sub-processors

Which models and fourth parties sit behind it?

One AI feature can call a foundation model, which calls another API — a nesting doll of sub-processors most discovery tools never see.

Vendor governance

Does the vendor govern its own AI?

Frameworks (ISO 42001, NIST AI RMF), human oversight, red-teaming, audit trail — or are they shipping AI with no controls of their own?

Reliability

What happens when the model drifts or goes dark?

Retraining cadence, change notification, and failover. If the vendor's AI degrades — or is pulled — what breaks in your workflow?

Regulation

Can one assessment satisfy every obligation?

EU AI Act deployer duties, DORA third-party ICT, NIS2, ISO 27001 and SOC 2 — mapped once, evidenced everywhere.

Contracts

Do our contracts give us audit and exit rights?

Right to audit, right to exit, and notification of material AI or sub-processor changes — the protections regulators now expect.

Continuous monitoring

Is this a one-time questionnaire or a live signal?

Vendor posture changes the day after you assess it. Point-in-time due diligence has to become continuous monitoring.

Evidence

Can we show the board the register on demand?

A live inventory of every vendor's AI — risk-scored, owned, and audit-ready — not a spreadsheet rebuilt the night before the meeting.

The supply chain

Follow the data, not the contract

You signed with one vendor. Your data may travel through three more. Every hop is a place it can be retained, trained on, or exposed — and a place your contract probably never reached.

Your data

Customers · contracts · code

SaaS vendor

The tool you bought

Foundation model

OpenAI · Anthropic · Google

Sub-processors

Fourth parties you never signed

“Your third party's sub-processor is your fourth party — and the regulator still calls it your data.”

Why it's board-level now

Four regulations now point at your vendors' AI

Third-party AI moved from a procurement footnote to a named obligation. The accountability sits with you — the deployer — not the vendor who shipped the feature.

EU AI Act

As a deployer (Art. 26) you must use third-party AI within the provider's instructions, ensure human oversight, and keep records. High-risk obligations phase in from 2 August 2026.

DORA

Financial entities must register every ICT third party — AI providers included — with pre-engagement due diligence and contractual audit and exit rights.

NIS2

Supply-chain security is a board-level duty. You're accountable for the security posture of the vendors embedded in your essential services.

ISO 42001 & NIST AI RMF

Vendor AI is in scope of your AI management system. Map each vendor to the controls so one assessment serves your certification and your auditors.

How to mitigate it

The vendor-AI mitigation playbook

Eight controls that take SaaS vendor AI from an unmanaged exposure to a governed, auditable part of your supply chain — whatever tools your teams adopt next.

Keep a live vendor-AI inventory

Discover AI continuously, not once a year. An inventory that updates itself is the only one that's still true when the regulator calls.

Minimise and mask the data

Apply DLP and on-device redaction before data reaches a vendor's AI, and switch off training on your data wherever the vendor allows it.

Map and gate sub-processors

Require vendors to disclose their model providers and downstream processors — and approve the chain before sensitive data flows through it.

Tier vendors by risk

Classify each vendor by data sensitivity and business criticality, and scale the depth of due diligence to the tier instead of assessing everything equally.

Harden access and egress

Enforce SSO and least privilege, scope API keys narrowly, restrict egress, and keep a kill-switch to cut a vendor off fast.

Put AI clauses in the contract

Negotiate audit rights, exit rights, a training opt-out, and notice of material AI or sub-processor changes — before signing, not after an incident.

Monitor and re-trigger

Watch for new AI features, model updates and posture drift, and re-open the assessment automatically when a vendor's risk profile changes.

Plan the exit and the outage

Define data deletion on exit, failover, and a contingency for the day a model is restricted or pulled — so no single vendor is a single point of failure.

How Prompt Shields answers it

From a blank questionnaire to a living vendor register

Atlas AI discovers the vendor AI in your stack, scores it from a baseline Prompt Shields already maintains, and keeps it current — so vendor due diligence stops being a quarterly fire drill.

Step 1

Discover the vendor AI in your stack

On-device and integration-based discovery surfaces the AI embedded in the SaaS you already use — including the tools no SSO log or API connector reveals.

Step 2

Start from a pre-assessed baseline

Prompt Shields has already assessed the common AI vendors — their underlying models, the data those models touch, and the use cases — and keeps it current. You inherit the work instead of mailing out questionnaires.

Step 3

Score risk against every framework

Each vendor is mapped to the EU AI Act, DORA, ISO 42001, NIST AI RMF and the OWASP LLM Top 10, with gaps ranked by criticality and deadline.

Step 4

Monitor continuously

Posture changes, new sub-processors and model updates raise a signal — so your register stays true between assessments, not just on the day you ran one.

The vendor assessment is already done

You don't start from a blank questionnaire. Build on the vendor AI assessment Prompt Shields has already done and keeps current — and put your effort into your own context, not months of third-party due diligence.

Leverage work already done

Inherit a maintained map of each vendor's AI instead of re-running due diligence from scratch.

Save the assessment effort

Skip the 40-questionnaire cycle and the quarter-long wait. Start from a pre-assessed baseline on day one.

Understand models, data and use cases

See the underlying AI models, the data they touch, and the use cases — the substance your board and auditors actually ask about.

Discover vendor AIInherit baselineScore and mapMonitor continuously

Know your vendors' AI before your auditor asks.

A 30-minute walkthrough: how Atlas AI discovers the AI inside your SaaS, maps the supply chain, and scores every vendor against the EU AI Act, DORA, ISO 42001 and NIST AI RMF.