AI GovernanceVendor RiskData Security

Is a Vendor Running AI on Your Company Data?

Company information flowing through a vendor laptop into an external AI cloud

Your business may already have an AI program that nobody formally approved. Part of it lives with employees. The rest may live with your bookkeeper, marketing agency, recruiter, consultant, or outsourced IT provider.

Those vendors often have legitimate access to valuable information. If they process that information through an unapproved AI product, your data may enter a system you cannot see, govern, or audit.

Start with a written internal policy

A practical internal control is a short AI-use acknowledgment that names the tools employees may use, the information they may submit, and the work that requires review.

A signature does not technically prevent misuse. It creates a record and removes ambiguity about what the business communicated. The policy should arrive with a usable approved alternative. A prohibition without an option encourages quiet workarounds.

An employee and manager reviewing an AI policy beside a secure AI workspace
A clear policy works best when employees also receive an approved tool.

Vendor risk is a separate problem

Traditional agreements cover confidentiality, ownership, and subcontractors. Many were written before generative AI became part of everyday work.

Two issues deserve separate attention:

  • A vendor may reuse AI-assisted work or intellectual property across clients.
  • A vendor may process your data in a consumer-tier system with terms you never reviewed.

Some AI tools also receive deep access to a CRM, database, mailbox, or cloud account. A compromise at the vendor can therefore become a path into your business.

Four questions to send every vendor

Ask these questions in writing:

  1. Are you using any AI tools while working on our account?
  2. If not, do you plan to use them?
  3. If yes, which tools and subscription tiers are used, and can the work run in an environment we control?
  4. Who pays for the approved environment that contains our information?
An executive reviewing approved and unapproved AI paths across outside vendors
Written vendor answers turn invisible AI use into a governable decision.

The goal is not to prohibit useful technology. It is to ensure work you already pay for happens in a place you can understand and control.

Three actions that cost little or nothing

Inventory every outside party with access to business or customer information. Send the four questions and retain the responses. Then update internal policies and vendor agreements with the help of qualified counsel.

For the technical side, favor business environments that provide administrative controls, clear data terms, access logging, and the flexibility to change models as needs evolve. AITS can help map those relationships and build a controlled AI deployment without forcing the organization into one product forever.

The important question is no longer whether vendors use AI. It is whether you know where they use it, what they place into it, and who is responsible for the result.

Adapted from The Digital Dilemma newsletter.

Frequently asked questions

Why does vendor AI use create business risk?

A vendor may place company or customer information into an AI environment you did not approve or configure, making access, retention, ownership, and security difficult to verify.

What should I ask vendors about AI?

Ask whether they use AI on your account, which products and subscription tiers they use, whether your work can run in an environment you control, and who pays for that protected environment.

Should businesses ban vendors from using AI?

Not necessarily. The goal is to make AI use visible, documented, contractually clear, and contained inside an approved business environment.

Free AI Risk Scan
FREE · 90 SECONDS · NO SIGNUP

Most clients like to start here to learn their current AI readiness posture — and how a free 30-minute call, backed by a lot more data, helps you make faster decisions.

Run my free AI Risk Scan →