Is a Vendor Running AI on Your Company Data?
Your business may already have an AI program that nobody formally approved. Part of it lives with employees. The rest may live with your bookkeeper, marketing agency, recruiter, consultant, or outsourced IT provider.
Those vendors often have legitimate access to valuable information. If they process that information through an unapproved AI product, your data may enter a system you cannot see, govern, or audit.
Start with a written internal policy
A practical internal control is a short AI-use acknowledgment that names the tools employees may use, the information they may submit, and the work that requires review.
A signature does not technically prevent misuse. It creates a record and removes ambiguity about what the business communicated. The policy should arrive with a usable approved alternative. A prohibition without an option encourages quiet workarounds.
Vendor risk is a separate problem
Traditional agreements cover confidentiality, ownership, and subcontractors. Many were written before generative AI became part of everyday work.
Two issues deserve separate attention:
- A vendor may reuse AI-assisted work or intellectual property across clients.
- A vendor may process your data in a consumer-tier system with terms you never reviewed.
Some AI tools also receive deep access to a CRM, database, mailbox, or cloud account. A compromise at the vendor can therefore become a path into your business.
Four questions to send every vendor
Ask these questions in writing:
- Are you using any AI tools while working on our account?
- If not, do you plan to use them?
- If yes, which tools and subscription tiers are used, and can the work run in an environment we control?
- Who pays for the approved environment that contains our information?
The goal is not to prohibit useful technology. It is to ensure work you already pay for happens in a place you can understand and control.
Three actions that cost little or nothing
Inventory every outside party with access to business or customer information. Send the four questions and retain the responses. Then update internal policies and vendor agreements with the help of qualified counsel.
For the technical side, favor business environments that provide administrative controls, clear data terms, access logging, and the flexibility to change models as needs evolve. AITS can help map those relationships and build a controlled AI deployment without forcing the organization into one product forever.
The important question is no longer whether vendors use AI. It is whether you know where they use it, what they place into it, and who is responsible for the result.
Adapted from The Digital Dilemma newsletter.
Frequently asked questions
Why does vendor AI use create business risk?
A vendor may place company or customer information into an AI environment you did not approve or configure, making access, retention, ownership, and security difficult to verify.
What should I ask vendors about AI?
Ask whether they use AI on your account, which products and subscription tiers they use, whether your work can run in an environment you control, and who pays for that protected environment.
Should businesses ban vendors from using AI?
Not necessarily. The goal is to make AI use visible, documented, contractually clear, and contained inside an approved business environment.
Never miss an episode
Subscribe to The Digital Dilemma
Straight talk on AI, cybersecurity, and business technology — no hype, no vendor propaganda. Follow on whatever platform you already use: