#1757248: The AI you can’t see: Bringing third-party shadow AI into the risk picture
| Description: |
You’ll learn: How shadow AI risk extends to your organization’s suppliers How effective third-party AI assessment examines models, agents, permissions, monitoring and governance Why you need continuous visibility into and reassessment of third-party vendors Your vendors are putting AI into products and internal workflows, and they may not be documenting the models, agents, data flows or safeguards involved. Because of this, your organization may be exposed to third-party AI risk even if you've tightly controlled your own deployments. A marketing provider might feed sensitive customer data into an unvetted generative AI service or deploy an autonomous agent with excessive permissions to execute campaigns and alter CRM records, while a support vendor could route sensitive tickets through an unvetted chatbot. Shadow AI makes the problem worse. Suppliers' employees may use personal AI accounts, unmanaged agents or unsanctioned tools that never appear in third-party questionnaires. You need to identify which vendors use AI, understand what data those systems can access, and evaluate how that AI is governed. Third-party risk management must evolve from periodic, questionnaire-driven assessments toward continuous AI-specific assessment and monitoring. |
|---|---|
| More info: | https://www.scworld.com/cybercast/the-ai-you-cant-see-bringing-third-party-shadow-ai-into-the-risk-picture |
| Date added | Oct. 11, 2026, 11 a.m. |
|---|---|
| Source | SC World |
| Subjects |
|
| Venue | Oct. 12, 2026, midnight - Oct. 12, 2026, midnight |
