Author: Tara Sarvnaz Raissi, Beneva
Introduction
Software tools or systems that use artificial intelligence often rely on third party providers to perform core AI functions such as processing user requests (input) and generating responses (output). Many use external AI “models” – complex mathematical and computational systems that analyze vast amounts of data to recognize patterns or make decisions[1] - such as those offered by OpenAI, Google and Anthropic. These models analyze, interpret or respond to user input and produce output in the form of text, images, or speech. Depending on their design and capabilities, AI-enabled products may rely on additional components including open-source libraries, cloud infrastructure, computing resources, servers, and development tools to build, run and maintain AI systems. These building blocks are supplied, hosted or managed by the vendor of the product, its affiliates or by third party providers. The network of external components and third-party service providers that support the operation of an AI product is analogous to a traditional product supply chain in that multiple actors and dependencies contribute to the final product that is delivered to the user.
Some AI systems are built and managed entirely in-house. For example, OpenAI recently announced that it had developed an internal AI tool for its employees, using OpenAI’s own data and workflows, without engaging any outside providers.[2] By contrast, many commercially licensed AI products rely on complex supply chains involving multiple actors who are responsible for different aspects of the system’s training, development, deployment, and operation.[3] As a result, although an organization will contract with a single vendor for the product, it may indirectly depend on multiple third-party services that are part of the broader AI supply chain and are less visible. The security, reliability and operational practices of these external providers can create legal, operational and regulatory risks for the organization using the product.[4]
To gain a better understanding of the AI supply chain, organizations should conduct due diligence on the product, its intended use, the vendor, and the extent to which the product relies on components provided and controlled directly by that vendor rather than third parties, before the contracting stage. Once the parties are at the contracting stage, terms that require disclosure of relevant third-party providers, sub-processors and timely notice of material changes to those dependencies will create an obligation for a vendor to be transparent. In addition, clauses that grant audit rights to the organization will confirm that the vendor is adhering to previously agreed security, privacy and operational controls. Implementing security incident reporting requirements in the contract can ensure prompt notice of cybersecurity incidents or data breaches that have an impact upon the vendor or any of its service providers and can create risk for the organization using the product.
The AI supply chain can be hidden
An AI product’s reliance on complex software supply chains and interconnected infrastructure can introduce security, operational, and legal risks into the organization that uses it.[5] These risks highlight the importance of understanding how the product works, including whether it depends on third-party providers and further sub-processors that are not immediately visible to an organization.
Hidden dependencies in the supply chain can lead to security vulnerabilities and unintended data flows that carry regulatory and legal consequences for an organization. Therefore, an organization procuring AI-enabled products should undertake the same disciplined vendor due diligence they would in any other high-risk engagement. This includes requiring an inventory of providers, models and sub-processors, while assessing whether the vendor applies appropriate governance and risk-management practices. In addition, it is important that an organization verify that a vendor has sufficient financial capacity to respond to potential liability.
Contracting supply chain controls
Vulnerabilities in a product’s supply chain can hinder its performance and lead to the unauthorized disclosure of organizational data. This goes beyond external attacks caused by malicious actors that target a third party’s systems to gain access to an organization’s confidential information. It can also arise from weaknesses in software build, packaging or release controls that inadvertently expose proprietary[6] and sensitive material. Contractual provisions can mitigate some of this risk. For instance, an audit clause allows an organization to confirm a vendor’s compliance with appropriate cybersecurity and data protection obligations. Organizations may require annual independent audit reports, such as security attestations (SOC 2 Type II reports), which cover security, availability, confidentiality and privacy controls. This provision is usually drafted to require vendors to certify that their third-party service providers and sub-processors are subject to equally stringent standards. In addition, organizations should ask that vendors provide a current list of all service providers and sub-processors involved in providing the service or product, with a description of the function each performs, the jurisdiction within which they operate, and the categories of data to which each has access.
Contractual clauses that establish incident reporting requirements help manage supply chain risks by ensuring that organizations receive timely notice of cybersecurity incidents, data breaches, system compromises or operational disruptions affecting AI vendors and third-party providers. These provisions typically require vendors to notify customers within a specific timeframe after discovering a security incident, disclose details about its scope and impact, and take prompt remedial steps. Early notification allows the organization to respond quickly and take steps to limit potential harm.
Conclusion
Supply chain risk, though difficult to detect, can create significant legal, operational and security exposure for organizations using AI-enabled products. Careful due diligence and contractual protections such as disclosure obligations, audit rights as well as incident reporting requirements will strengthen an organization’s ability to increase transparency and improve oversight to better manage the risks associated with third-party dependencies.
[1] AI Models.” IBM Think, IBM, https://www.ibm.com/think/topics/ai-models .
[2] Xu, Bonnie, et al. “Inside OpenAI’s in-house data agent.” OpenAI, 29 Jan. 2026, openai.com/index/inside-our-in-house-data-agent/.
[3]AI Supply Chain Risk: Third-Party Model Governance Guide.” Z Cyber, 1 May 2026, www.ztekcyber.com/resources/ai-supply-chain-risk-third-party-model-governance/ .
[4] Same as above.
[5] Brown, Ian. “Allocating Accountability in AI Supply Chains.” Ada Lovelace Institute, 29 June 2023, www.adalovelaceinstitute.org/resource/ai-supply-chains/.
[6] Capoot, Ashley. “Anthropic Leaks Part of Claude Code’s Internal Source Code.” CNBC, 31 Mar. 2026, www.cnbc.com/2026/03/31/anthropic-leak-claude-code-internal-source.html .