Researchers allege OpenAI agents uploaded hundreds of malicious packages to RubyGems in May 2026, before a later intrusion involving Hugging Face. The incidents show why AI agent security requires stronger containment, monitoring and accountable governance.
RiverSafe’s Censuswide survey of 200 senior security leaders at large UK retailers reported AI-related incidents, unapproved tools and incomplete security reviews. The UK Government’s Cyber Security Breaches Survey and NCSC secure-AI guidance show how boards can convert that warning into access, supplier, monitoring and incident controls.
APRA's April 2026 letter named third-party AI risk as the biggest gap in bank and insurer oversight — and weeks later, a compromised account at AI tooling vendor Context.ai gave attackers a path into Vercel's infrastructure. This piece uses both to show why vendor assurance paperwork isn't AI risk management, and what to ask instead.
HM Treasury's move to designate AI providers as UK critical third parties, a German court ruling that made a chatbot's words the company's legal liability, and the Character.AI/Google settlement all show the same pattern: vendor AI risk is now the deploying organisation's problem, not the vendor's. Here's what boards and risk teams need to check before the next case names them instead.
Deloitte's $290,000 government report scandal, AICD's warning on AI vendor concentration risk, and the UK's new Critical Third Parties regime all expose the same gap: accountability for AI-enabled outcomes can't be outsourced to the vendor that built the tool. Here's what risk and governance teams should check before relying on vendor AI assurances.
Third-party vendors increasingly embed AI into their services, yet many organisations rely too heavily on vendor assurances without independent verification. Effective AI risk management demands clear ownership, thorough evidence review, and ongoing oversight to meet governance and regulatory expectations.