Third-Party AI Risk

Overview

Most enterprises consume AI through third-party APIs (OpenAI, Anthropic, Google) or embed open-source models. Each introduces risk that your existing vendor risk management may not cover.

Risk Categories

RiskDescriptionImpact
Data exposureYour data sent to third-party for processingPrivacy violation, IP leakage
Vendor lock-inDeep integration with one provider's APIBusiness continuity risk
Model changesProvider updates model, behavior changesApplication breakage, safety regression
AvailabilityProvider outage takes down your AI featuresService disruption
Compliance gapProvider's data handling doesn't meet your requirementsRegulatory violation
Supply chainProvider's model is compromised or poisonedInherited compromise

Subsections