#1757248: The AI you can’t see: Bringing third-party shadow AI into the risk picture

Description: You’ll learn:

How shadow AI risk extends to your organization’s suppliers
How effective third-party AI assessment examines models, agents, permissions, monitoring and governance
Why you need continuous visibility into and reassessment of third-party vendors

Your vendors are putting AI into products and internal workflows, and they may not be documenting the models, agents, data flows or safeguards involved.

Because of this, your organization may be exposed to third-party AI risk even if you've tightly controlled your own deployments. A marketing provider might feed sensitive customer data into an unvetted generative AI service or deploy an autonomous agent with excessive permissions to execute campaigns and alter CRM records, while a support vendor could route sensitive tickets through an unvetted chatbot.

Shadow AI makes the problem worse. Suppliers' employees may use personal AI accounts, unmanaged agents or unsanctioned tools that never appear in third-party questionnaires.

You need to identify which vendors use AI, understand what data those systems can access, and evaluate how that AI is governed. Third-party risk management must evolve from periodic, questionnaire-driven assessments toward continuous AI-specific assessment and monitoring.

More info: https://www.scworld.com/cybercast/the-ai-you-cant-see-bringing-third-party-shadow-ai-into-the-risk-picture

Date added Oct. 11, 2026, 11 a.m.
Source SC World
Subjects
  • AI/ML - Artificial Intelligence / Machine Learning / GenAI / Artificial General Intelligence - AGI - Various
  • Insider Threats / Third Party / Third-Party / 3rd Party Risks / Managed Service Provider (MSP)
  • PodCasts / Webcast / Webinar / eSummit / Virtual Event etc.
  • Shadow AI - Departmental AI use without letting IT/Finance know
Venue Oct. 12, 2026, midnight - Oct. 12, 2026, midnight