AI can enter a business without anyone buying a new system.
A software vendor adds an assistant to its product. A service provider begins summarising support tickets with a large language model. An adviser uses AI to review documents.
Each choice may create a new data flow and source of risk without triggering a procurement review, contract change or conventional vendor assessment. Risk teams now need to know which AI providers sit behind important services, how vendors use them and whether the resulting risks are controlled.
With Protecht and VISO TRUST, organisations can combine AI-powered evidence collection, assessments and continuous third- and fourth-party monitoring with Protecht’s wider enterprise risk capabilities. Vendor findings can connect with controls, incidents, cyber, resilience, compliance and reporting.
Find out more about Protecht’s AI-enhanced vendor risk management capabilities:
AI has made the vendor map deeper
Third-party risk begins with a direct relationship: a company contracts a software provider, consultant, payment processor or managed service provider.
Fourth-party risk arises from the companies on which that vendor relies, such as cloud platforms, data processors and software libraries. Their own dependencies create fifth-party and wider nth-party risk.
These relationships existed before generative AI. What has changed is the speed and opacity with which new ones appear. A vendor can add a model through a product update, while employees adopt approved or unapproved AI tools. A model may also be hidden within another service.
The contracted vendor may remain the same while the way it handles data, produces outputs and delivers services changes substantially. The exposure comes from how AI is used, not merely from another system appearing in the technology inventory. This is covered in more depth in VISO TRUST’s guide to dealing with fourth-party risk.[1]
What the LiteLLM compromise revealed about hidden dependencies
In March 2026, attackers published two malicious versions of LiteLLM, an open-source package that developers use to connect applications with different AI model providers. They appeared to be routine updates from a legitimate source.
The versions were available through the Python Package Index for about 40 minutes. A developer or automated build process that installed them could have introduced malicious code into its environment. LiteLLM believes the compromise began through Trivy, a security-scanning dependency used in its software release process.
Trend Micro reported that the code attempted to steal cloud credentials, SSH keys, Kubernetes secrets and AI-provider API keys, potentially providing access well beyond the AI gateway itself.[2]
A company might never contract with LiteLLM or know that it is being used. Its software provider could rely on LiteLLM, which in turn depended on another component in its development process. Exposure could therefore arise several steps beyond the company’s direct vendor relationship.
Assessing each vendor separately can conceal this concentration. When a common provider fails or is compromised, the effects may spread across several services at once.
Why conventional assessments miss AI exposure
Security questionnaires, contracts, audit reports, certifications and external monitoring remain useful. Their limits are cadence and scope.
A questionnaire records what a vendor says at one point in time. Assurance reports cover only the systems and controls within scope. External monitoring observes part of the public technology footprint. None will reveal every AI tool adopted later.
AI use also varies in consequence. One vendor may use a model for internal productivity. Another may process customer information through it. A third may rely on AI to make decisions that affect the service delivered.
Asking whether a vendor “uses AI” therefore provides little insight. Risk teams need to understand what it does, what information it receives, who provides it and which controls apply.
AI expands vendor risk beyond cybersecurity
Data security is an immediate concern. Sensitive information may enter an AI tool without clear restrictions on retention, reuse, location or access. But the risk is wider.
Unreliable or biased outputs may influence customer service, recruitment, fraud detection or regulatory reporting. A vendor may be unable to explain an output, while weak human oversight allows errors into a business process.
Critical services may depend on model providers whose availability, pricing or terms can change. Contracts and privacy notices may not reflect new data flows, while records may be insufficient to explain an important decision.
These issues cross cybersecurity, privacy, compliance, procurement, operational resilience and enterprise risk. Treating vendor AI as a narrow technology problem leaves gaps between them.
The audit trail must extend beyond the enterprise
A company can keep detailed records of its own AI systems and still lack a complete view of how AI affects its operations. Part of the record may sit with a vendor, its model provider or cloud platform.
For material AI-supported services, the audit trail may need to show the model used, the data behind an output, the controls applied and any human review. The depth should reflect the use case and its risk.
Model records, decision logs and data provenance can support traceability. Yet internal logging remains incomplete when activity takes place inside a vendor or sub-processor. This is covered in more depth in VISO TRUST’s guide to AI model audit-trail requirements.[3]
The EU AI Act includes requirements for logging, documentation, human oversight, cybersecurity and accuracy in specified high-risk uses[4]. The NIST AI Risk Management Framework provides a voluntary method for managing trustworthy AI[5], while ISO/IEC 42001 sets requirements for an AI management system[6].
Their scope differs, but the operational message is consistent: organisations need an inventory, clear accountability, current evidence and a repeatable way to identify change.
Building an AI-aware vendor risk approach
Effective oversight connects vendor risk management with AI governance rather than creating another isolated process:
- Identify AI use in important vendor relationships – Ask where AI supports the service, internal operations and relevant subcontractors. Record the use case, not merely the product name
- Follow the data – Establish what information reaches the AI system, where it is processed, how long it is retained and whether it may be used for model training
- Assess the consequence of the output – Formatting an internal document is different from recommending a credit decision, handling a complaint or changing production code
- Obtain evidence of governance and control – This may include policies, risk assessments, model documents, test results, approvals, monitoring and records of human oversight
- Monitor material change – New subprocessors, models, incidents and service designs should prompt review rather than wait for the next annual assessment
- Map shared dependencies – Link model providers and other nth parties to the vendors and services that rely on them. This reveals concentration and informs contingency planning.
Connecting continuous assurance with enterprise risk
The answer is not to assess every AI feature as though it were a critical system. The aim is to distinguish material exposure from routine use, then focus effort where failure could affect customers, obligations or important services.
Protecht and VISO TRUST support that approach across the vendor lifecycle. Teams can automate evidence collection, use AI to review evidence and map control coverage, streamline onboarding and due diligence, monitor vendor and fourth-party exposure, and manage findings and actions in connected workflows.
Those insights can link with enterprise risks, controls, incidents, cyber, resilience, compliance and audit. This gives teams a current view of exposure, reveals shared dependencies and strengthens the audit trail.
It also improves vendor engagement. Questions can be tailored to the relationship and use case rather than buried in a generic questionnaire. Risk teams can concentrate on exceptions, weak controls and high-consequence services.
A more dynamic view of vendor risk
AI is accelerating familiar vendor-risk problems: incomplete inventories, hidden dependencies, stale assurance and fragmented accountability.
Good governance now requires more than knowing which companies provide important services. Risk teams need to understand the models, data flows and downstream providers involved, supported by current evidence that controls still operate.
A connected approach to vendor risk, AI governance and enterprise risk management provides that view. It helps the business adopt AI with greater confidence while maintaining accountability across the full chain of delivery.
Request a demo to see how Protecht can help you automate evidence collection, assess vendors, monitor third- and fourth-party exposure and connect vendor risk with the wider enterprise risk picture.
References
[1] VISO TRUST, “Dealing with Fourth-Party Risk”, https://visotrust.com/resources/dealing-with-fourth-party-risk/
[2] Trend Micro, “Your AI Gateway Was a Backdoor: Inside the LiteLLM Supply Chain Compromise”,
https://www.trendmicro.com/en_us/research/26/c/inside-litellm-supply-chain-compromise.html
[3] VISO TRUST, “AI Model Audit Trail Requirements”, https://visotrust.com/resources/ai-model-audit-trail-requirements/
[4] European Commission, AI Act, https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
[5] NIST, “AI Risk Management Framework”, https://www.nist.gov/itl/ai-risk-management-framework
[6] International Organization for Standardization, “ISO/IEC 42001:2023 — Artificial intelligence management system”: https://www.iso.org/standard/42001


