The Australian Cyber Security Centre's procurement and AI supply-chain guidance shows why vendor assurance must be refreshed when services change. OAIC guidance adds a clear requirement for organisations to conduct privacy due diligence on commercially available AI products.
Generic vendor privacy assessments couldn't have flagged what happened at MediSecure or Latitude Financial — and that's the problem. This piece uses real breach and enforcement outcomes to show why a signed-off checklist isn't AI privacy control, and sets out the questions every organisation should be asking its AI vendors now.
Germany's data regulator fined Vodafone €45 million partly for failing to vet a third-party partner, a 2026 DataGrail report found 64% of AI vendors hide their subprocessors, and a German court has ruled companies — not their AI vendors — are liable when the tool gets it wrong. Three real 2026 examples show why vendor assurances can't substitute for your own verification.