NobleCloak
Category

Your vendors are adding AI without telling you

Author

Audrey

NobleCloak's AI Correspondent · AI-drafted, fact-checked against our sourced evidence before publishing.

Date Published

Think back to your last few vendor calls. Somewhere in one of them, a small tile probably slid into the meeting — "[Vendor]'s Notetaker has joined," or a recording icon lit up, or someone's assistant bot started quietly transcribing. Maybe you noticed. Maybe you didn't. Either way, an AI you never assessed just listened to a conversation that may have included member data, account specifics, or your own security posture — and it did so as an extension of a vendor you did assess, back before it had that capability.

That's the thing nobody warned you about. Your third-party AI surface is not something you're going to choose to expand. It's expanding on its own, from the vendor side, one feature release at a time — and each one lands inside a relationship you already approved.

You diligenced the vendor. You did not diligence the AI they added last quarter. And the gap between those two facts is where 2026's third-party risk actually lives.

The silent expansion

Vendor AI doesn't arrive with a due-diligence questionnaire. It arrives as a product update. A "new AI-powered summary" in your loan-origination system. A "smart assistant" bolted onto your core. A support portal that now routes your tickets — and their contents — through a large language model. A marketing platform that started using your member list to "personalize" with a model you've never heard of. A meeting tool whose notetaker is on by default.

None of these came to you as a decision. They came as a changelog entry, if they came to you at all. The vendor's product team shipped a feature. Your relationship, and your data's exposure, changed underneath a contract that predates the change.

This is why the honest starting posture is "I don't fully know." And it turns out that's the industry's posture too. In Ncontracts' 2026 State of TPRM survey (n=173), 72% of institutions were only partially aware of which of their vendors even use AI — and this from the survey run by the incumbent that owns these buyer relationships. Not partially aware of how the AI works. Partially aware of whether it's there at all. When nearly three-quarters of a profession can't say which vendors are running AI, "my vendor might have added AI and I'd never know" isn't paranoia. It's the base rate.

Why "the vendor added it, not me" doesn't help you

The instinct is to file this under the vendor's responsibility. They enabled it; it's on them. Legally and practically, that instinct fails, and it fails in a way specific to how our regulators structured oversight.

If you're an RIA or broker-dealer, the amended Reg S-P safeguards rule (17 CFR 248.30(a)(5)) requires written policies for ongoing "oversight, including through due diligence and monitoring, of service providers." Read the word ongoing. The rule doesn't ask you to diligence a vendor once at onboarding and file it. It asks you to keep monitoring — which is precisely the muscle a silent AI feature-add is designed to slip past. Every smaller firm's compliance deadline for this was June 3, 2026; the SEC denied the industry's extension request; and Reg S-P is a named exam priority for FY2026. "My vendor turned it on without telling me" is not a defense to "your policies were supposed to catch that."

If you're a credit union, the structure is even starker. Your regulator can't help you here. The GAO confirmed in May 2025 (GAO-25-107197) that the NCUA has no authority to examine third-party technology vendors — so there is no examiner checking your vendor's new AI feature on your behalf, ever. The diligence lands on you by design. The relief is that NCUA's framework (07-CU-13 / SL 07-01) is explicitly proportional: you owe reasonable procedures scaled to how critical and complex the vendor is, not a forensic audit of every changelog. But "reasonable" still means noticing. And you can't scale diligence to a change you never saw.

The uncomfortable synthesis: the obligation to know is yours, the change originates with the vendor, and nobody is going to introduce those two facts to each other unless you build the process that does.

What "noticing" actually requires

You cannot notice a silent change by reading contracts, because the contract didn't change — the product did. Noticing requires two moving parts most compliance programs don't have yet:

A current inventory of which vendors use AI, and for what. Not a one-time list. A list with a date on it and a habit of being re-asked. The question you're really tracking is "has this changed since last time?" — and you can only answer that if there was a last time. Our The AI vendor due-diligence questions that actually matter playbook gives you the dozen questions worth asking, and how to tell a real answer from a marketing one.

A view of what each vendor's AI can actually reach. When a vendor adds an AI feature, the risk isn't the feature's cleverness — it's the access it inherits. The notetaker doesn't just transcribe; it now holds a copy of what was said. The AI summary feature in your core doesn't just summarize; it reads the records it summarizes. The exposure follows the access, and access is visible in your OAuth grants and connector permissions long before it's visible anywhere else. That's the subject of Shadow AI is an access problem not a traffic problem, and the how-to is in Reading OAuth grants — the shadow-AI map in your Workspace and Entra.

Put those together and vendor-side AI stops being a thing that happens to you. It becomes a list you maintain, a set of grants you can see, and a diligence conversation you can actually have — one where you walk into the vendor call already knowing their notetaker is on, rather than finding out when it joins.

The honest part

Here's what I won't claim. No assessment catches a vendor's AI feature the instant it ships. Vendors release on their schedule, not on your review cadence, and there will always be a window between "they enabled it" and "you caught it." A point-in-time review is a snapshot; the whole reason drift is dangerous is that reality moves between snapshots. Anyone selling you a tool that promises to see every vendor AI change the moment it happens, across your entire vendor list, is selling you something that doesn't exist.

What's real is shrinking that window and documenting the watch. An inventory taken today, re-run on a sane cadence, with the access mapped and the vendors asked directly — that turns "I had no idea" into "we review this quarterly, here's the last one, here's what changed, here's what we did." That second sentence survives an exam. The first one starts one.

This is the surface a Discover scan is built to inventory — the vendor AI you know about and, more usefully, the access that reveals the AI you don't. We run it with you, proportional to your risk profile, and we're honest in the report itself about where the snapshot's edges are.

If a notetaker has ever joined a call you didn't invite it to, request your Discover scan — and let's find the rest of them before your examiner does.