AI · Systems · Incentives · Consequences

Edition 1 · 01 / 08

Are You Paying Someone Else to Ask AI?

Your internal AI policy may not follow information into your supplier’s development and support processes.

Most companies now have some form of AI policy. Employees may be told not to paste confidential information into public tools. Developers may be restricted to approved assistants. Sensitive customer records may be excluded from external models altogether.

But what happens when the same organisation sends information to a supplier?

A support ticket can contain logs, screenshots, schemas, configuration details and source code. The supplier may use AI to investigate it, draft a response or prepare a fix. A subcontractor may use another provider. The customer sees a familiar service while the delivery process underneath it changes.

The AI you did not buy

Third-Party Shadow AI is the framing used in this publication for AI inside a supplier’s development, support, operational or delivery processes that creates material customer exposure the customer cannot readily see, understand or govern.

The supplier need not sell an AI product. It could provide ordinary software, consulting, analytics or managed services. The AI can remain entirely behind the scenes. The concern is visibility and control over the resulting exposure, rather than the mere presence of a new tool.

Your AI policy may stop at your front door.

This also reaches beyond personal data. A diagnostic attachment might reveal security architecture, commercial plans, business rules or confidential research. An assurance that customer information is not used for model training does not, by itself, explain who processes it, how long it is retained or which connected tools can access it.

Three questions for every material use

Start with what information enters the system. Then ask what the AI can reach and what it can do. An agent with repository or ticketing access may retrieve information without a person copying it into a prompt. An agent with write permissions can change more than the wording of a support reply.

A useful review follows one real workflow. Trace a ticket from submission through investigation, model processing, tool calls and resolution. Identify each operator, the information available at each stage, the permissions involved and the evidence retained. This gives procurement and security a shared picture to challenge.

The NCSC’s supply chain security guidance provides an established basis for understanding supplier relationships and seeking proportionate assurance. Applying that discipline to hidden AI workflows is the practical extension proposed here.

Match control to exposure

Low risk internal assistance may reasonably remain a supplier decision. Material access to customer information calls for disclosure and assurance. Sensitive information, production access or consequential autonomous actions may justify agreed approval or objection rights.

These are proposed governance tiers, rather than universal legal categories. Their purpose is to keep scrutiny proportionate while making consequential changes visible.

At the next supplier review, ask for a description of how one customer request is actually delivered. The revealing question is: where does AI enter that process, and what protects our information and systems when it does?

References

  • NCSC: Supply chain security. Established supplier assurance principles; the Third-Party Shadow AI framing is this publication’s synthesis.