Third-Party AI Risk
Risks arising from use of external AI systems, APIs, or services in business operations.
Definition
Third-Party AI Risk encompasses all risks introduced through the use of AI systems, models, or services provided by external parties. This includes:
- Operational risk: Dependence on vendor availability and performance
- Compliance risk: Liability for vendor's AI practices and regulatory violations
- Data risk: Exposure of sensitive data to third-party AI systems
- Model risk: Limited visibility into vendor model behavior and updates
- Concentration risk: Over-reliance on single AI providers
Regulators increasingly expect organizations to demonstrate oversight of third-party AI, including due diligence, contractual protections, and ongoing monitoring. The EU AI Act explicitly addresses obligations along the AI value chain.
Sources
- •SR 11-7
- •OCC Third-Party Guidance
Related Terms
Vendor Risk Management (AI)
Framework for assessing and managing risks from third-party AI service providers....
Risk
Combination of harm probability and severity....
AI Due Diligence
Systematic evaluation of AI risks in M&A transactions, vendor selection, and business decisions....
third‑party AI assurance
Independent evaluation services by external organisations....
Risk Management
Systematic process of managing AI-related risks....