The first three episodes were about what happens inside your walls: the inventory of uses, the roles and the policy, the risks specific to language models. You now know what runs in your organization and who answers for it.
The problem with this episode is that most of your AI exposure is not inside your walls. It sits with your vendors, and they did not ask for your opinion.
What changed without you
Open your list of SaaS vendors. Your ticketing tool, your CRM, your office suite, your payroll provider, your recruiting platform, your accounting software. In eighteen months, every one of them added an assistant, an automatic summary, text generation, smart sorting. None of those features came with a new contract. Most were switched on by an update, sometimes by default, with one line in the release notes.
Concretely, this means your data, your customers' and your employees' data, now flows through a language model you did not choose, hosted by a model provider you do not know, in a region you never validated. Your vendor has become an intermediary to a fourth party, and your security questionnaire, filled in last year, does not say a word about it.
The three risks this creates
1. The data path got longer
The first risk is the most mundane. Your vendor sends the content of your tickets, your emails, your documents to a third-party model to produce a summary. Three questions arise, and the classic questionnaire asks none of them: does the model provider retain that data, and for how long? Is it used to train or improve the model for other customers? Where does the processing happen?
The last question is not theoretical in Quebec. Law 25 requires a privacy impact assessment before any communication of personal information outside Quebec. An assistant enabled by default in your support tool, sending every ticket to a model hosted in the United States, is a communication outside Quebec that nobody assessed.
2. The vendor has a new attack surface, and it is yours
Episode 3 described indirect injection: a model reading content from outside and finding instructions in it. At your vendor, that outside content is your data, and its other customers' data. A booby-trapped email sent to one of its customers can influence what its assistant produces for you, if isolation between customers was not designed for that case.
And the technical chain behind those features is fragile. Last week's review cited the Wiz study: of 3,074 LiteLLM AI gateways exposed on the internet, 9.6% still accepted the example key from the documentation, and two weeks earlier CISA had listed that same gateway in its catalogue of exploited flaws. A gateway of that kind holds the keys to every model provider an organization uses. If your vendor runs one, its configuration is your exposure.
3. A decision made about you by a system you cannot see
The third risk is the one that concerns leadership most directly. More and more vendors use AI not to assist you but to decide: a recruiting tool that shortlists applications, a credit platform that scores a file, an anti-fraud service that blocks a transaction, an HR provider that flags anomalies.
When that decision affects a person, Law 25 has required since 2023 that they be informed the decision was made exclusively by automated processing, be given the chance to submit observations, and that the main factors behind the decision can be explained. If the decision is made by your vendor's system, you are still the one who must be able to explain it. Few contracts provide for the vendor to give you the means.
The ten questions to add to your questionnaire
They apply to any vendor that processes personal information or confidential data on your behalf, and to any vendor whose system makes or prepares decisions about you. Not to your stationery supplier.
Use and data
- Which features of your service rely on an AI model, and which are enabled by default for our account?
- Is our data used to train, tune or improve a model, for us or for other customers? Can we opt out without losing the service?
- What data is sent to the model, where is it processed, and how long is it retained by the model provider?
Supply chain
- Which model providers and AI subprocessors are involved, and do they appear in your contractual subprocessor list?
- Do you notify us when the underlying model is replaced, retrained or moved to another region?
Controls
- How is your customers' data isolated from one another inside the AI features?
- Have you tested your AI features against prompt injection, and do you log model inputs and outputs for our account?
- Are your gateways and API keys to model providers inventoried, protected and rotated, and by whom?
Governance and decisions
- Who at your company answers for AI to your leadership, and do you have a usage policy and a register of uses?
- If your system makes or prepares a decision about a person, can you provide us the main factors behind that decision, within a timeframe that lets us meet our obligations?
A serious vendor answers all ten on one page. A vendor that cannot answer question 2 or question 4 is telling you something important about its own governance.
Three tiers, not a blanket campaign
Do not send these questions to your entire register. Sort first.
Tier 1. The vendor processes personal information or confidential data, or its system makes decisions about people. All ten questions, before renewal, and a contractual clause.
Tier 2. The vendor uses AI on non-sensitive internal data. Questions 1, 2, 4 and 9, by email, with an answer expected within thirty days.
Tier 3. Everything else. One line in the register: "uses AI: unknown", to revisit next cycle.
That sorting is the same one the platform's third-party risk module applies: inherent risk first, depth of assessment second. And the free vendor security questionnaire already contains the sections on data location, retention and subcontractors that these ten questions build on.
The clauses that hold
A questionnaire informs; a contract binds. Four clauses to include in the next renewals of tier 1 vendors.
- No training on our data without written consent, and that consent is not a condition of access to the service.
- An up-to-date list of AI subprocessors, with advance notice before any addition or change of model provider or processing region.
- Explainability of decisions: the vendor commits to providing the main factors behind any automated decision about a person, within a timeframe compatible with our legal obligations.
- Incident notification within 72 hours, including incidents affecting the model provider or the AI gateway, not only the vendor's own systems.
What you should have by Friday
Your vendor register annotated with tier 1, 2 or 3 according to the criterion above. The ten questions sent to your three most exposed tier 1 vendors, with a response date. And a one-page note to your procurement or legal lead, with the four clauses, for the next renewals.
Episode 5, on 1 October, after GoSec: offensive AI. Deepfakes, executive fraud by cloned voice, phishing written to measure. What has really changed in attacks, and the single control that still holds.
Until then, if you are at GoSec on 23 and 24 September in Montreal, come with the vendor question you cannot answer. We will work through it together at the booth.