Essential Questions: Uncovering Hidden Risks When Engaging AI Vendors

4

Four Critical Questions to Ask Any AI Vendor Before You Sign

A 2026 breach traced through an unsanctioned AI tool exposed credentials across multiple companies — and none of the affected customers ever had a contract with the tool responsible.

The incident is a warning that traditional vendor risk management is no longer enough. As artificial intelligence layers multiply inside software products, the hidden supply chain beneath a single vendor relationship has quietly grown into one of cybersecurity's most pressing blind spots. Understanding the key risks and challenges AI presents to businesses is no longer optional — it is a prerequisite for responsible procurement.


When the Breach Starts Somewhere You Never Audited

In April 2026, Vercel disclosed that attackers had accessed its internal systems and extracted environment variables containing API keys, access tokens, and database credentials. For any business running its website on Vercel, those credentials may have been compromised.

The investigation revealed that the breach did not originate at Vercel itself. A Vercel employee had signed up for a tool from Context.ai, a small AI company, using a Vercel Google Workspace account. That signup granted the tool broad OAuth access to the account.

In February 2026, a Context.ai employee downloaded game cheat scripts from an untrusted site. The machine picked up credential-stealing malware. Attackers used the OAuth access to enter the Vercel employee's Workspace account and then moved into Vercel's systems from there.

Context.ai appeared on no Vercel customer's vendor list. Those customers had no contract with Context.ai and no mechanism to audit how it operated. Their credentials were exposed regardless.

Kip Boyle, Founder and CISO of Cyber Risk Opportunities, described the problem plainly in a September 2026 analysis published by SecureWorld. "The AI tools a vendor runs inside its own shop never show up on it," he wrote, referring to standard third-party risk inventories. "We record the company we pay and stop there. That habit costs more than it used to."

Why Unsanctioned Tools Are the Entry Point Nobody Watches

The Vercel breach illustrates a pattern that security professionals are seeing with increasing frequency: the weakest link is rarely the vendor you vetted. It is the tool that vendor's employee signed up for independently, using corporate credentials, without any formal approval process.

This dynamic — sometimes called shadow IT at the AI layer — means that even a thoroughly audited primary vendor relationship can carry unreviewed risk inside it. Every employee who connects a third-party AI tool to a corporate account is, in effect, adding a supplier that no procurement team has evaluated.

The practical implication is that vendor risk management programs built for a pre-AI software landscape are structurally insufficient. They were designed to evaluate the companies organisations pay directly. They were not designed to surface the ecosystem of AI tools operating inside those companies.


The Hidden Surface Area Inside Every AI Product

A conventional software vendor runs on infrastructure that security teams can identify and evaluate — cloud providers like AWS or Azure with known compliance certifications and established audit trails. An AI vendor introduces a different kind of complexity.

The model powering the product may have been built by a separate company, hosted on infrastructure the vendor does not control, and updated on a schedule the vendor itself may not set. That expanded attack surface rarely appears in a contract or a standard security questionnaire. For teams working through the right questions to ask any IT service provider, AI-specific supply chain risk deserves its own dedicated line of enquiry.

Boyle, who has spent more than 30 years in cybersecurity and recently published Gears Don't Guess: The Executive's Practical Guide to Thriving in the Face of AI Hype and Risk, argues that procurement conversations need to go deeper. He recommends four specific questions for any vendor carrying AI inside its product.

The Four Questions That Expose Hidden Risk

1. Where does your data go?

The question is not whether data is encrypted in transit. The question is whether customer data feeds model training and whose model is involved. Teams should ask whether deletion requests reach whatever the model may have absorbed. Boyle notes that a privacy policy carries no binding weight because vendors can revise it at any time. The commitment needs to live in the contract.

2. Who validates the output?

AI products make different architectural choices about where human review sits in the workflow. Some require a person to approve every result. Others act autonomously — sending communications, writing to databases, and calling other systems without human sign-off. Understanding the boundaries of autonomous action and where oversight gaps exist is essential before granting a tool access to sensitive systems.

3. Where is the audit trail?

If a tool handles data for an extended period and a compliance auditor later asks what it did during a specific month, someone needs to be able to answer. Teams should establish what gets logged, who can access those logs, how long records are retained, and whether they can be exported on demand.

4. What happens when the model changes?

AI vendors push model updates far more frequently than traditional software vendors release new versions. A model change can alter how the system handles data and produce different outputs to identical queries. Contracts should include advance notice requirements for material changes and a testing window before updated models interact with live data.

What These Questions Are Actually Testing

These four questions do more than gather information — they test a vendor's operational maturity. A vendor with strong AI governance will answer these questions without hesitation, because the answers are already documented internally. A vendor that struggles to respond is signalling that the governance infrastructure does not yet exist.

The quality of the answer matters as much as the answer itself. Vague commitments to "data security best practices" without specifics about model ownership, training data policies, and change management processes are a meaningful indicator of risk — one that a standard security questionnaire will not capture.

Understanding what artificial intelligence actually is and how it works at a foundational level helps procurement and security teams ask sharper follow-up questions when vendor answers are incomplete or evasive.


Reading the Answers — and the Silences

Boyle points to Talairis Law Group, an AI-native law firm that launched in May 2026, as an example of transparent architecture. The firm's public-facing materials describe how each piece of work is maintained on a per-customer record, how an attorney reviews every deliverable, and how the firm does not train AI models on customer data. That level of disclosure is what visible plumbing looks like.

Not every vendor will have immediate answers to all four questions. Boyle acknowledges that missing answers are not automatic disqualifying factors. They identify where additional due diligence is required. A vendor that cannot name the companies behind its own product, however, is not managing that supply chain on the customer's behalf.

Legal teams often raise a practical objection: companies cannot enforce contractual terms against vendors they have no direct agreement with. Boyle's response is that awareness remains the goal and that flow-down contract language handles enforcement. A primary vendor can be required to impose the same standards on its own AI suppliers. Failure to do so puts that vendor in breach of the primary agreement.

This approach — sometimes called contractual flow-down — shifts the enforcement burden to the primary vendor relationship, where direct agreements exist. It does not eliminate supply chain risk, but it creates accountability at the layer where accountability is legally enforceable.

For organisations managing complex vendor ecosystems, the NIST Cybersecurity Framework provides a structured methodology for identifying, assessing, and responding to supply chain risks — including those introduced by AI subprocessors and unsanctioned tools.

Where to Start This Week

The practical starting point is immediate. Security and procurement teams can identify the AI vendor handling their most sensitive data this week and run the four questions on the next available call. The second priority is the tools employees have already adopted without formal approval. An unsanctioned tool is a supplier that no one has reviewed — and as the Vercel breach demonstrated, an unreviewed supplier can become the entry point for a breach affecting customers who never knew it existed.

Building This Into Standard Onboarding

For professionals managing vendor relationships or procurement decisions, these four questions provide a reusable framework applicable across industries. Organisations that embed this line of questioning into their standard vendor onboarding process will be better positioned to identify hidden AI supply chain risks before a breach traces back through them.

The goal is not to treat every AI vendor as a threat. It is to build the institutional habit of asking the right questions consistently — so that the next breach that starts somewhere no one audited does not end at your organisation's data.

You might also like