Missio Systems public knowledge

Third-party AI risk

Exposure created when an organization depends on external AI models, vendors, data, platforms, or service providers.

Last reviewed:

Missio definition

Third-party AI risk arises when critical behavior, data handling, model changes, controls, or evidence depend on a provider outside the organization's direct authority. The buyer still owns the business outcome and cannot outsource accountability with the contract.

Governance should address selection, intended use, data rights, security, model and service changes, transparency, testing, incident notification, subcontractors, exit options, and evidence access. The depth of diligence and monitoring should follow the dependency's materiality.

Scope note

This definition supports executive and operating decisions. Applicable law,

contracts, sector rules, and system context may require a narrower definition.