Skip to main content
ShadowAI Defense GitHub
← All runbooks
RB-008 High

Third-party vendor using AI without disclosure

Discovery that a third-party vendor or service provider has introduced AI capabilities into their service without contractual authorization or disclosure. Detected via DET-MS-MCAS-001 surfacing new AI-related API calls from a vendor's application, or DET-MS-SEN-003 identifying unexpected AI service connections originating from vendor-managed infrastructure.

Triggers

Immediate response (first hours)

  1. AI Governance triage: Assess the scope of data exposure: what organizational data does the vendor have access to, and what data may have been processed by the undisclosed AI capability?
  2. AI Governance triage + Legal: Review the existing contract terms. Determine whether the vendor's use of AI violates data processing agreements, confidentiality clauses, or regulatory requirements. (Within 48 hours)
  3. AI Governance triage: Document the discovery with evidence: traffic analysis, API call patterns, vendor communications, and any public announcements about the vendor's AI features.

Short-term response (within days)

  1. Vendor manager + Legal: Engage the vendor formally. Request written confirmation of: what AI capabilities were introduced, when, what data is processed, whether data is used for model training, and sub-processor details. (Within 10 business days)
  2. AI Governance triage + Privacy: Evaluate the data impact. Conduct a data protection impact assessment (DPIA) if regulated data is involved. Determine whether data subject notification is required. (Within 15 business days)
  3. AI Governance triage: Update the vendor risk assessment in the AI Governance Risk Register. Adjust the vendor's risk tier based on findings.

Long-term response (weeks+)

  1. Procurement + Legal: Update vendor contracts to include AI disclosure requirements. Add standard AI use clauses to the organization's vendor contract templates: mandatory pre-notification of AI introduction, data processing restrictions, model training opt-out, and audit rights.
  2. AI Governance Committee: Add AI disclosure requirements to the standard vendor due diligence questionnaire. Require annual AI use attestations from critical vendors.
  3. AI Governance triage: Establish periodic vendor AI use review cadence. Monitor vendor product announcements and release notes for AI feature introductions.

Decision tree

  • Does the vendor's AI use involve processing organizational data?
    • Yes → Full impact assessment and vendor engagement required.
    • No → Document and update risk assessment; monitor.
  • Does the vendor's AI use violate existing contract terms?
    • Yes → Legal engagement; consider contractual remedies.
    • No → Update contract at next renewal to add AI disclosure terms.
  • Is regulated data (PII/PHI/PCI) involved?
    • Yes → DPIA required; assess notification obligations.
    • No → Standard vendor risk update.

RACI

  • Responsible: AI Governance triage
  • Accountable: AI Governance lead
  • Consulted: Legal, Procurement, Privacy, Vendor manager, Business owner of the vendor relationship
  • Informed: AI Governance Committee, CISO, Audit committee (if regulatory impact)

Metrics to capture

  • Time from discovery to vendor engagement (target: ≤ 10 business days)
  • Time from vendor engagement to written response (track vendor responsiveness)
  • Number of vendor AI disclosures per quarter (trend signal)
  • Percentage of critical vendors with updated AI contract clauses
  • Number of DPIAs triggered by vendor AI discoveries

Comms templates

  • comms-manager-talking-points

Framework mappings

  • NIST AI RMF: GOVERN-4.1, MAP-1.1, MANAGE-2.2
  • ISO/IEC 42001: 8.2, 8.4, A.10
  • NIST CSF: ID.SC-2, RS.AN-1

Related AI Controls Catalog entries