Lesson 10 of 11 · Controls and evidence · 3 min read

Third-party AI risk: governing AI you did not build

In brief

Much of a company's AI comes from vendors: AI features inside SaaS tools, models behind APIs and agents supplied by partners. A third-party AI register records each one with its owner, data and assessment. Credo AI leads on our third-party criterion; Alice does not describe one.

By The Charter Desk, Agentic Governance Compare · Published 2026-09-13 · Vendor pages read 13 September 2026 · Editorial assessment

Why is vendor AI a governance problem?

When a vendor adds an AI feature to a tool you already use, your data may start flowing to a model you did not choose, under terms you did not review. Under the EU AI Act a company using such a system is often a deployer with its own obligations. Under ISO/IEC 42001 the AIMS scope can include AI supplied by third parties. Either way, the system belongs in your register.

What does a third-party AI register record?

  • The vendor, the product and the AI feature.
  • What data the feature receives and where it is processed.
  • The contract terms on training, retention and subprocessors.
  • The vendor's own documentation, certifications and test results, where available.
  • Your assessment and its date, and when it is due again.
  • The internal owner.

What do the platforms describe?

Credo AI names a Third-party AI Registry on its product page, which is why it scores 10 of 10 here. Pillar Security lists third-party AI discovery on its governance page and says its red teaming covers third-party and SaaS AI. Holistic AI, SPLX and Lasso do not describe a dedicated third-party register on the pages we read. Alice's WonderSuite pages focus on the AI apps and agents a company builds and ships, and do not describe third-party AI governance; it scores 1 of 10.

Can you test AI you did not build?

Sometimes. If a vendor's AI is reachable through an interface you control, such as a chat window in your product, you can test it the same way as your own. If it runs inside the vendor's tool, rely on contract terms, the vendor's documentation and monitoring of what data you send. Record which approach you used for each system.

What should contracts with AI vendors cover?

For AI that runs inside someone else's product, the contract is often the main evidence you have. Check that it covers:

  • Whether your data is used to train the vendor's models.
  • How long prompts and outputs are kept, and where.
  • Which subprocessors and model providers are involved.
  • Notice of material changes to the model or its behavior.
  • Access to the documentation and test results you need for your own obligations.

These terms do not replace testing where testing is possible, but they belong in the register entry either way.