When Air Canada's chatbot invented a bereavement discount, a Canadian tribunal made the airline pay $812.02 for it. New data from the Cyber Risk Institute's Treasury-backed AI framework and Ncontracts' 2026 Third-Party Risk Management Survey show why every organisation using vendor AI needs the same accountability before the mistake is theirs.
Three real 2026 outages — AWS's cascading Middle East failure, Microsoft Copilot's five-hour blackout, and Claude's multi-model cascade — show why AI risk management can't stop at the vendor you signed with. With EU AI Act deployer obligations enforceable from August 2026 and Gartner naming \u201cfourth-party\u201d AI risk directly, boards need to map the AI hiding inside their vendors' vendors.
Unclear ownership and weak third-party evidence can stall AI initiatives for months. This article explains why business-led accountability and structured evidence checklists are critical to smooth AI risk management and faster decision-making.
Traditional model risk management falls short for AI. Executives and risk managers must recognise AI model risk as a distinct challenge requiring tailored governance, deeper vendor scrutiny, and proactive controls to protect value and trust.
HM Treasury's move to designate AI providers as UK critical third parties, a German court ruling that made a chatbot's words the company's legal liability, and the Character.AI/Google settlement all show the same pattern: vendor AI risk is now the deploying organisation's problem, not the vendor's. Here's what boards and risk teams need to check before the next case names them instead.
When Replit's AI coding agent deleted a live production database mid-project in July 2025, it exposed a gap most vendor risk frameworks miss: ongoing change monitoring, not just onboarding checks. NIST's GOVERN 6.2 and ISACA's 2025 incident review both point to the same fix — treat vendor AI oversight as a standing control, not a one-time sign-off.
Deloitte's $290,000 government report scandal, AICD's warning on AI vendor concentration risk, and the UK's new Critical Third Parties regime all expose the same gap: accountability for AI-enabled outcomes can't be outsourced to the vendor that built the tool. Here's what risk and governance teams should check before relying on vendor AI assurances.
APRA's April 2026 letter to industry and ASIC's Report 798 both warn that boards are leaning on AI vendor assurances instead of independently verifying them. Here is what Australian organisations should be checking before they trust the compliance pack.