Your organisation doesn’t build the model. It doesn’t hold the training data. It doesn’t control the update schedule. But when the AI embedded in a vendor’s platform gets something wrong, the accountability lands on you — not the vendor, and not the model provider three layers upstream.
That gap between who controls the risk and who owns the consequence is widening fast, and three developments from the past few months show exactly how.
The 30-second take
Regulators are starting to formally treat AI and cloud vendors as systemic dependencies, not just suppliers.
Courts are ruling that a chatbot’s bad answer is the deploying company’s legal problem, full stop. And the vendor assurance letter that used to satisfy a board pack is no longer enough evidence of control.
If your third-party AI governance still consists of a signed data processing agreement and a security questionnaire from onboarding, it hasn’t caught up with where liability is actually landing.
HM Treasury moves to designate AI providers as critical third parties
The trigger is a finding the Financial Policy Committee has been building toward since its 2025 report on AI in the financial system: firms across UK financial services are concentrated on a small number of US technology providers for the AI and cloud infrastructure that now sits inside core financial decision-making.
Designation brings direct regulatory scrutiny of the vendor’s own resilience — not just the firm’s contract with them.
It is a formal admission that “the vendor’s risk register” and “our risk register” are the same document once dependency reaches a certain scale.
German court makes the chatbot’s words the company’s words
The chatbot had described doctors on the platform as “specialists in plastic and aesthetic surgery,” a title those doctors did not actually hold and were not professionally permitted to use. The court’s reasoning didn’t hinge on whether the company intended the claim or even knew the model would generate it — the chatbot spoke for the business, so the business owns the statement.
That’s a materially harder standard than “we relied on the vendor’s model card.”
Character.AI and Google settle, and product liability sticks
In January 2026, Character.AI and Google reached a settlement in the Garcia wrongful-death case and related suits, agreeing to new safety features for minors. Before the settlement, the presiding US District Judge had already ruled that the Character.AI app qualifies as a “product” for product liability purposes — meaning strict liability, negligence, and wrongful-death claims all survived, and the First Amendment defence that the company leaned on was dismissed.
Once an AI system is treated as a product rather than a protected expression, the standard playbook for deflecting harm shifts substantially, and the vendor relationship becomes a supply-chain liability question, not a free-speech one.
What this means if you didn’t build the model
None of these three examples come from the same jurisdiction, the same regulator, or the same legal theory.
That’s the point — the pressure is converging from prudential oversight, tort law, and product liability at the same time, which means a single-lens governance response (just a data processing agreement, just a security review) will keep missing two of the three angles.
Independent validation of vendor claims, not acceptance of them, is what each of these cases would have rewarded.
Questions to take back to your organisation
Do we know which of our AI-embedded vendors would qualify as a critical or concentrated dependency if a regulator asked us to map it?
Who in our organisation independently tests or challenges a vendor’s claims about model accuracy, bias, or safety — or do we take the vendor’s word as the evidence?
If our customer-facing chatbot or AI tool gives a wrong or misleading answer tomorrow, who is legally accountable, and have we actually tested that assumption with legal counsel?
Are our AI vendor contracts written for a world where the vendor is a minor supplier, or updated for a world where the vendor is a systemic dependency?
Do we have a current inventory of every third-party AI capability embedded in our customer-facing products, not just the ones we procured directly?
When did our board last see evidence — not assurance, evidence — of third-party AI risk exposure?
The organisations named above didn’t fail because they used vendor AI. They were tested because the gap between vendor assurance and independent verification was visible enough for a court or regulator to walk through it.
Want to see how exposed that gap is in your own organisation? Try our AI readiness snapshot.
Free 3–5 minute AI diagnostic
Know where your AI governance stands in five minutes.
Use a short diagnostic to test practical AI governance, oversight and risk controls. Get an immediate visual result and suggested next focus areas.
Practical tools for boards, executives, auditors and risk professionals.
Privacy note: your individual results are not stored by Innovation of Risk. Results stay in your browser; we only track aggregate usage such as page views and average score once you leave our page.
AI Readiness Snapshot
Quick Snapshot
Artificial Intelligence Risk Readiness Snapshot
A compact readiness check to help leaders see where AI governance, oversight and risk controls may need attention before moving into the full toolkit.
Privacy note: this Quick Snapshot runs in the browser only. It does not send answers to this site, does not call ChatGPT and does not generate a server-side workbook. Use it as a light indicator, not a complete assessment.
View
Please complete all areas below:
0%
Not startedSelect a group on the left to answer the 10 questions.
Response map
Capable but informal
Responsible AI maturity
Uncontrolled experimentation
Policy theatre risk
Responsible-use behaviour ↑
Formal governance / controls →
Average
Snapshot positionAnswer the groups to move this marker.
Suggested next focus
Complete the snapshot to identify the lowest-scoring areas.
Domain signals
Domain movement guide
Each coloured line on the visual relates to a domain below. Domains already near advanced may show little or no movement line.
Move from snapshot to evidence
The Quick Snapshot is a light indicator. The score uses configurable question weighting and distance from the midpoint so stronger low/high answers move the result more clearly. The full toolkit adds role-based assessment, evidence review, target-state planning, Scenario Lab, Action Plan Map, service-provider maturity and browser-local Excel workbook generation.
Use the left menu to open each question group. The maturity map, score and focus area update as responses are selected.
Note: we do not hold your individual answers or any identifying details from this Quick Snapshot. We only retain the anonymous average outcome of each completed or updated snapshot response to show the overall average for all users.
Strategy & governance
AI use-case ownership, accountability and board or executive visibility.
Strategy & ownership · Q1
AI use cases are identified, documented and owned by the business.
Strategy & ownership · Q8
Accountability is clear across business, risk, compliance, technology and executive teams.
Human oversight · Q10
Board or executive reporting includes AI risk, maturity and responsible-use progress.
EmergingAd hoc or not yet consistent
DevelopingSome practices exist but are uneven
ManagedDefined and mostly embedded
AdvancedMature, monitored and improving
Risk, data & third parties
Risk assessment, escalation, data/privacy/security review and third-party AI oversight.
Assessment & escalation · Q2
AI risks are assessed before pilots, procurement, deployment or material change.
Assessment & escalation · Q3
High-risk AI use cases are escalated for senior approval before they go live.
Data, privacy & security · Q4
Data, privacy, cyber and information-security risks are reviewed before AI tools are used.
Third-party AI · Q6
Third-party AI tools, vendors and embedded AI features are assessed before use.
EmergingAd hoc or not yet consistent
DevelopingSome practices exist but are uneven
ManagedDefined and mostly embedded
AdvancedMature, monitored and improving
Oversight, monitoring & controls
Human oversight, control monitoring and learning from incidents or unintended outcomes.
Human oversight · Q5
Human oversight is defined for AI-supported decisions or outputs that matter to customers, staff or operations.
Monitoring & controls · Q7
AI controls are monitored after implementation, not only checked at launch.
Monitoring & controls · Q9
AI incidents, errors, complaints or unintended outcomes are captured and reviewed.
EmergingAd hoc or not yet consistent
DevelopingSome practices exist but are uneven
ManagedDefined and mostly embedded
AdvancedMature, monitored and improving
How useful was this snapshot?
Your answers are not stored. This short survey only records usefulness and optional feedback.
15
4/5
Email snapshot results
Enter the recipient address and the plugin will send the results through the site email service.
The plugin sends this email through WordPress mail. It does not store the individual snapshot answers.
Sample-data DemoView the controlled demo without opening the paywalled full toolkit.
Sample-data demo
Explore the AI Maturity & Risk Assessment Toolkit
A controlled demonstration using sample data so users can see the toolkit outputs without entering organisational information.
Controlled demo: This demo shows representative maturity outputs, AI risk model classification, action planning and browser-local workbook messaging. Export, email and participant submission paths are disabled in demo mode.
View
Sample organisation snapshot
This view uses realistic sample data to show the type of conversation the full toolkit supports.
62%
Managed, with clear gaps
Governance and monitoring are forming, but third-party AI and data/privacy review need stronger consistency.
Capable but informal
Responsible AI maturity
Uncontrolled experimentation
Policy theatre risk
Responsible-use behaviour ↑
Formal governance / controls →
Domain signals
Strategy & ownership63%
Assessment & escalation55%
Data, privacy & security48%
Human oversight58%
Monitoring & controls72%
Third-party AI38%
Maturity outputs with sample data
The full toolkit combines role-based behaviour signals, detailed maturity scoring, evidence prompts, human-focus indicators and target-state planning.
Demo mode is view-only. Real assessment entry, encrypted save, report email and workbook export remain available only in the full toolkit.
Example management insight
“AI usage is increasing faster than formal control ownership. The next uplift should focus on procurement gates, data/privacy review and post-implementation monitoring.”
AI risk model builder preview
This sample use case shows how the full toolkit helps classify a specific AI initiative and prepare a browser-local workbook.
Use case
Customer-service generative AI assistant using internal knowledge articles.
Initial path
Enhanced review recommended due to customer interaction and data/privacy considerations.
Human risk
Medium-high: customer impact and quality of advice need oversight.
Data/security risk
Medium: internal content, access controls and logging need validation.
In demo mode the workbook download is disabled. In the full toolkit, workbook generation is browser-local.
Action plan map preview
Scenario Lab and target-state actions can seed a practical action map for management discussion.
AI governance and decision rights4 / 5 • 2 plans
Risk assessment, testing and assurance3 / 5 • 1 plan
Data privacy and security controls3 / 5 • 2 plans
Human oversight and responsible decisioning4 / 5 • 2 plans
Monitoring, incidents and control review3 / 5 • 1 plan
2 plans
Program Group 1
Governance foundations and decision rights
Action Plan 1
Confirm named AI decision-rights owner and escalation pathway.
Governance foundation
Action Plan 2
Introduce a lightweight AI approval gate for high-impact use cases.
Governance foundation
2 plans
Program Group 2
Assurance, oversight and control lift
Action Plan 3
Define human-in-the-loop review for customer-facing AI outputs.
Control lift
Action Plan 4
Create post-implementation control indicators and review cadence.
Control lift
Demo privacy and control posture
The demo is intentionally controlled. It uses sample data only and does not ask users to enter real organisational assessment content.
Disabled
Email reports, participant submissions, full workbook export and real assessment save paths.
Shown
Representative visuals, sample scoring, action map examples and privacy messaging.
Purpose
Help users understand the value of the full toolkit before requesting access.
Next step
Use the full toolkit for real assessment work, private session mode, encrypted browser-local save and browser-local workbook generation.
When Air Canada's chatbot invented a bereavement discount, a Canadian tribunal made the airline pay $812.02 for it. New data from the Cyber Risk Institute's Treasury-backed AI framework and Ncontracts' 2026 Third-Party Risk Management Survey show why every organisation using vendor AI needs the same accountability before the mistake is theirs.
Three real 2026 outages — AWS's cascading Middle East failure, Microsoft Copilot's five-hour blackout, and Claude's multi-model cascade — show why AI risk management can't stop at the vendor you signed with. With EU AI Act deployer obligations enforceable from August 2026 and Gartner naming \u201cfourth-party\u201d AI risk directly, boards need to map the AI hiding inside their vendors' vendors.
Many organisations have AI policies, but these often fail to guide day-to-day decision making. To manage AI risks effectively, policies need clear guardrails that business teams can apply consistently. This article explains how to translate high-level AI principles into practical standards and controls that enable confident, accountable AI use.
Unclear ownership and weak third-party evidence can stall AI initiatives for months. This article explains why business-led accountability and structured evidence checklists are critical to smooth AI risk management and faster decision-making.