On 13 July 2026, the Bank of England, the Prudential Regulation Authority and the Financial Conduct Authority began direct oversight of four companies that quietly run much of the UK’s financial infrastructure: Amazon Web Services, Microsoft, Google Cloud and Oracle.
HM Treasury’s decision to designate them the UK’s first “Critical Third Parties” is a signal worth paying attention to well beyond financial services: the organisations that build genuine visibility into their AI and cloud supply chains, ahead of regulators asking for it, are the ones that will move fastest and be trusted most when the next big AI opportunity arrives.
The 30-second take
Most organisations don’t build the AI models they use, host the data behind them, or control when a vendor pushes an update — and that’s fine.
The opportunity isn’t to bring everything in-house; it’s to know your own supply chain well enough to move with confidence.
Research suggests nearly three-quarters of organisations currently lack full visibility into their vendors’ AI supply chains. That’s not a reason for alarm — it’s a wide-open track.
The NSA’s guidance on AI supply chain risk singles out third-party services as the highest-complexity part of the stack precisely because so few organisations have mapped it well yet.
The ones who do it first get a real head start: faster vendor decisions, stronger customer trust, and far fewer surprises when a provider changes something upstream. The AI Signal BoxTM helps get you on the tracks faster.
What good AI vendor oversight is starting to look like
The UK’s Critical Third Parties regime (2026): AWS, Microsoft, Google Cloud and Oracle are now under joint, ongoing oversight by three UK financial regulators — a first-of-its-kind framework built specifically because a Bank of England and FCA survey found those four providers control 73% of UK financial-sector cloud services.
Learning from Navia Benefit Solutions (US, 2026): a single vulnerable API at this third-party benefits administrator exposed data for close to 2.7 million people. The useful takeaway isn’t “vendors are dangerous” — it’s that oversight of a vendor’s technical surface is now a core capability, not a one-off due diligence checkbox.
Organisations that treat vendor oversight as a continuous, living practice catch these issues before they reach customers, and can say so with confidence.
Rather than reading this as a warning, treat it as a preview: this is the standard of visibility and accountability coming to every sector that leans on a handful of AI and cloud providers.
Organisations that already have this map drawn won’t need to scramble when their own regulator, or their own board, asks for it.
Questions that help you build the advantage
- Can you name every vendor whose AI, data or infrastructure your critical processes depend on — and could you show that map to a customer or regulator today?
- If your top AI or cloud vendor changed something tomorrow, how quickly would you know, and how confidently could you respond?
- Does your vendor risk process ask for real evidence, and could you turn that into a trust signal for your own customers?
- Who owns the relationship with each critical vendor, and do they have the standing to raise concerns early?
- Where could stronger AI vendor oversight become something you actively promote to customers and partners, rather than just a compliance line item?
- How would your organisation like to be positioned when this becomes standard practice across your sector — ahead of it, or catching up?
The organisations that get ahead of AI vendor oversight now won’t just avoid disruption — they’ll be the ones customers and partners trust first.
Build your track further with the Innovation of Risk AI tools.

