Your third-party Artifical Intelligence (AI) vendors are your biggest AI risk gap, and the regulator is coming to look.
If your vendor quietly adds AI functionality, updates their model, retrains it on new data, or restructures their service architecture, your risk and compliance position changes — whether you notice or not.
Most organisations won’t notice until something goes wrong.
The 30-second take
AI risk oversight doesn’t stop at onboarding. When your AI vendor changes their internal process, models, data sources, or service design, your exposure changes with it.
Recent regulator focus identified third-party AI vendor risk as the widest gap between current practice and what regulators expect. The ACCC has named AI-washing — including misrepresenting AI capabilities after a vendor update — as an enforcement priority.
Your vendor’s changelog is now your compliance document.
What this means for your vendor contracts
For many entities, the most material AI risk now sits in the supply chain. AI is embedded in vendor platforms with opaque upstream dependencies that remain invisible until something breaks.
Regulators, such as APRA, ASIC and the OAIC, have identified findings on third-party AI vendor risk including that entities lacked contractual rights to be notified of model updates or data handling changes, had no independent audit or inspection rights over vendor AI systems, had not tested exit or portability strategies, and were not actively monitoring vendor AI performance against agreed risk parameters after deployment.
Regulators are now finalising plans that include direct engagement with AI suppliers themselves — a clear signal that the regulators intend to ‘look through‘ regulated entities to the vendors supplying them. Firms that cannot demonstrate structured vendor oversight will find themselves accountable for risks they did not build and cannot see.
The immediate practical step is a rapid third-party AI exposure assessment: which vendors embed AI in their platforms, what contractual protections are in place, whether upstream dependencies have been mapped, and whether material service provider thresholds are being applied to AI supply chains.
The immediate practical step is a rapid third-party AI exposure assessment
Documenting and reviewing AI systems after every update
You need to effectively manage third-party provider risks, ensuring sufficient human supervision over AI-assisted decisions, and documenting and review AI systems — not once, but continuously as your systems and vendors evolve.
This is a significant shift from how most organisations treat vendor AI. Many treat an AI vendor’s tool as a static capability once it passes initial procurement review. The regulatory position is that the obligation to understand what the AI is doing, and to verify it is doing it appropriately, persists through every model update, data change, and service revision.
Where a vendor-driven change affects how customer decisions are made — credit, insurance, advice — the accountability remains with you.
Firms that have not built vendor change oversight into their AI governance frameworks are now operating outside regulatory expectations, not merely behind best practice.
When your vendor’s update becomes your misleading conduct
The risk of an AI vendor changing the rules extends beyond prudential and privacy obligations. The ACCC has named AI-washing as a formal 2025–26 enforcement priority, and in December 2025 dedicated a full section to it in its industry snapshot. The enforcement concern is direct: if your organisation promotes AI-powered capabilities — in product disclosures, marketing, or customer communications — and a vendor update degrades or materially changes those capabilities, you may have made representations that are no longer accurate.
Under the Australian Consumer Law, misleading or deceptive conduct carries penalties of up to $100 million per contravention following the Treasury Laws Amendment (Doubling Penalties for ACCC Enforcement) Act 2026. The ACCC has specifically noted that firms are incentivised to overstate AI functionality, and that misrepresenting AI systems as autonomous or requiring limited human supervision is a named enforcement risk.
A vendor model update that introduces hallucination rates, removes features, or changes decision logic — without a corresponding review of your customer-facing claims — could constitute exactly this kind of misrepresentation.
Third-Party, Vendor and Model Supply Chain Risk
For all organisations there is a criticality of managing AI risks introduced by vendors and their supply chains. Practically, it means treating vendor-driven AI updates as change events that trigger your risk, privacy, and compliance review processes — not as automatic improvements you simply accept.
When a vendor changes their model, you need to know: what changed, what was independently verified, whether your customer-facing obligations still hold, and who in your organisation owns the residual risk.
Leaders should use these questions to shape vendor contracts, internal review processes, and continuous assurance models.
Treating vendors as dynamic risk sources — not static suppliers — is now the baseline expectation from regulators, not an aspirational governance standard.
Questions your organisation should be asking now
- Do our vendor contracts explicitly require notification and evidence when the AI model, data sources, or service architecture changes — and do we enforce those clauses?
- How do we independently verify vendor-provided risk, privacy, and security assessments after every update, rather than accepting vendor attestations at face value?
- Have we mapped which of our vendors embed AI, assessed their upstream dependencies, and applied CPS 230 material service provider thresholds to our AI supply chain?
- Who owns the decision to accept residual risk from a vendor AI update, and how is that decision recorded and reviewed?
- Are our customer-facing claims about AI capabilities reviewed whenever a vendor update changes what the AI actually does?
- How quickly can we pause or roll back AI-enabled features if a vendor change introduces unacceptable risk — and have we tested that capability?
Where to go from here
Regulators have each, in their own way, told regulated Australian organisations the same thing: your AI vendor’s decisions are your compliance problem.
The governance gap between what regulators expect and what most organisations have in place is real, named, and being actively supervised. The organisations that move first on structured vendor AI oversight — contracts with change notification requirements, independent assurance processes, and clear internal accountability — will be better placed when the review comes.
Explore frameworks, readiness tools, and practitioner guidance for managing third-party AI risk at the Innovation of Risk.
Know where your AI governance stands in five minutes.
Use a short diagnostic to test practical AI governance, oversight and risk controls. Get an immediate visual result and suggested next focus areas.
Practical tools for boards, executives, auditors and risk professionals.

