Key Takeaways
- Shadow AI is the newest version of a problem TPRM already knows: someone signing up with a third party outside procurement. The difference now is what they upload once they’re in.
- Shadow sign-ups, feature flips on already-approved software, and business-unit integrations are the three doors that let this happen without a vendor review.
- The EU’s Digital Omnibus pushed Article 26’s high-risk monitoring duties from August 2026 to December 2027. Article 50’s disclosure duties did not move, and they apply the moment AI creates content a customer sees.
- Mitratech’s December 2025 research found organizations rate their confidence managing third-party AI risk at 2 to 3 out of 5. That is a maturity score. It does not explain how the AI got in.
- Closing the gap does not require new software built to watch for AI. It requires treating a vendor’s AI feature change with the same rigor as onboarding a new one.
In This Article
- What Makes Shadow AI Different From a Shadow Vendor
- Why AI Vendor Risk Falls Through TPRM’s Intake Process
- How Do AI Tools Enter Without a Vendor Review?
- What Does the EU AI Act Require Right Now?
- Does Your Vendor Contract Cover How a Vendor Uses or Delivers AI?
- Where AI Governance and Third-Party Risk Overlap
- Fix the Front Door, Not a New Program
- Ask Henry: Questions I Get About AI Vendor Risk
In March 2023, a Samsung engineer pasted a block of proprietary source code into ChatGPT while trying to fix a bug. Two colleagues did something similar within the same 20-day span. One used it to clean up meeting notes. Another used it to optimize a test sequence for identifying defective chips. None of them thought they were adding a vendor. Samsung’s vendor risk program had never heard of the tool, because nothing about what they did looked like procurement.
The gap has not closed. It has gotten wider, and it is exactly what most AI vendor risk management programs still are not built to catch. A shadow AI tool does not need a contract to create vendor-level risk. It needs your data, and most of them already have it.
What Makes Shadow AI Different From a Shadow Vendor
Third-Party Risk Management (TPRM) already knows this problem. Someone signs up with a third party that never went through procurement, and the vendor risk program never finds out. Shadow AI is that same problem wearing a new name. The difference is what people do once they’re in. An AI writing tool, a coding assistant, a chatbot, all of them invite the user to paste in exactly the confidential data a formal vendor review exists to protect.
Vendor risk management was built around a single moment: a signature. Procurement logs the vendor, a risk tier gets assigned, and a review cadence begins. Shadow AI skips that moment entirely, which is exactly why it feels new even though the underlying question, who is touching our data, is not, in fact, new at all.
Why AI Vendor Risk Falls Through TPRM’s Intake Process
Most vendor intake processes only trigger when someone logs a new vendor in a procurement system, and AI tools rarely arrive that way. Mitratech’s December 2025 research, conducted with HTF Research, found organizations rate their confidence managing third-party AI risk at just 2 to 3 out of 5.
That number describes how mature a program feels. It does not explain why AI keeps getting in anyway. Third-Party AI: The Blind Spot in Governance already made that maturity case in a December blog. This piece is answering the question that comes right after it: if governance is maturing, why does AI still slip through? The honest answer is structural. Intake is built to notice a new relationship. AI usually arrives without one.
How Do AI Tools Enter Without a Vendor Review?
AI tools enter an organization through three doors that skip vendor review entirely. Shadow sign-ups happen when an employee subscribes to an AI tool directly. Feature flips happen when an already-approved vendor turns on a new AI capability inside a product you already trust. Business-unit integrations happen when a team connects an AI feature to existing software on its own.
Door one, the shadow sign-up, looks exactly like the Samsung story above. No one signed anything. There was no vendor record to tier, no contract to review, and no monitoring assigned, because nothing about typing a question into a chatbot resembles onboarding a supplier. The same pattern plays out today any time an employee expenses a paid AI writing or coding tool without looping in procurement.
Door two, the feature flip, is quieter. Zoom auto-enabled its AI Companion for meeting hosts on July 25, 2024, and again on September 13, 2024, giving admins roughly four days’ notice each time to opt out. Nothing about the vendor relationship changed on paper. The contract was the same one procurement had already reviewed. But the moment that feature started drafting meeting summaries, a new question existed that no one had been assigned to answer.
Door three, the business-unit integration, is the one most likely to touch a customer directly. A sales team connects a generative AI plug-in to the CRM to draft outreach emails. IT never approved the integration. Procurement never saw it. Nothing about connecting two pieces of software you already use looks like adding a vendor. But the moment that plug-in starts writing something a customer receives, it has crossed into territory the EU AI Act already regulates. More on that next.
The cost of missing all three compounds quickly. Breaches involving unauthorized AI tools cost organizations $670,000 more on average than other breaches, $4.63 million versus $3.96 million, and take longer to detect: 247 days versus 241. (IBM, 2025 Cost of a Data Breach Report). Mitratech’s own research found most organizations assess fewer than 100 vendors for AI risk, and many do not require any vendor to disclose its AI governance policies at all.
I have asked vendors that exact disclosure question and watched them pause before answering. The pause tells you as much as the answer does.
What Does the EU AI Act Require Right Now?
Two separate obligations get treated as one, and the difference matters. Article 26’s deployer duties, monitoring a high-risk system, reporting incidents, keeping six months of logs, now apply from December 2, 2027, after the EU’s Digital Omnibus pushed back the original date. Article 50’s disclosure duties took effect on schedule, August 2, 2026, and apply the moment AI creates content or talks to a customer.
The Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force on July 27, 2026, six days before the original deadline, and deferred Article 26’s obligations for standalone high-risk systems by 16 months. Several obligations stayed on schedule regardless: Article 50’s transparency duties, the general-purpose AI provider obligations already in force since August 2025, and the prohibited-practices regime in force since February 2025.
If the sales team’s CRM plug-in from the previous section is generating outreach a customer reads, that is not a high-risk monitoring question. It is a disclosure question, and the clock on it did not move.
The deadline moved. The gap that let a shadow AI tool in without a review did not.
Does Your Vendor Contract Cover How a Vendor Uses or Delivers AI?
Most vendor contracts signed before a vendor added AI features say nothing about how that AI handles data, who trained it, or what happens if it fails. NIST’s AI Risk Management Framework addresses this directly under Govern 6.1, third-party AI policy, and Govern 6.2, contingency planning for third-party AI failures.
Ask what happens if a vendor’s AI feature produces something wrong on a customer’s behalf, and most compliance teams do not have an answer. The contract was signed before the question existed. Govern 6.1 calls for policies that address AI risk from third-party entities specifically. Govern 6.2 calls for a contingency process before a failure happens, not after.
Where AI Governance and Third-Party Risk Overlap
AI governance and third-party risk management run as separate programs at most organizations, but the frameworks that govern them do not draw that line. The EU AI Act, NIST’s AI RMF, and ISO 42001 all treat a vendor’s AI use as squarely in scope, not a carve-out to address later.
A vendor risk assessment that stops at security and financial stability is answering yesterday’s question. The same evidence that feeds a vendor risk record, what the vendor does, whose data it touches, what happens if it fails, is exactly what an AI governance review needs to know about that same vendor. Treating them as two separate reviews means asking a vendor the same underlying questions twice, or asking once and hoping it covers both.
Fix the Front Door, Not a New Program
Closing this gap does not require a new team or new software built to watch for AI. It requires redefining what triggers a vendor review, and adding one new question to the reviews already running. Five changes handle most of it before your next renewal cycle.
- Review existing vendor contracts to confirm they have appropriate coverage for AI-specific risk, starting with your highest-risk vendors.
- Redefine what triggers an intake review, so a subscription or an integration triggers the same immediate reassessment a signed contract would.
- Set a reassessment cadence tied to risk tier, so an approved vendor’s new feature re-triggers review instead of aging quietly for a year.
- Confirm your log retention meets the six-month standard Article 26 will eventually require, and the disclosure practice Article 50 already does.
- Add one question to every vendor questionnaire: does this vendor use AI to process our data, and what changes when it does.
None of this requires a new program. It requires treating the front door as wide as the vendors are actually using it.
See How Mitratech Prevalent Handles AI Vendor Risk
Mitratech Prevalent extends the vendor risk assessment your team already runs to ask the AI-specific questions that assessment was never built to ask.
Learn More About Handling AI Vendor RiskAsk Henry Questions I Get About AI Vendor Risk
GRC Answers from Henry Umney, Managing Director of GRC Strategy at Mitratech
Does an AI feature added to a vendor I already approved count as a new vendor?
What is shadow AI vendor risk?
Does the EU AI Act’s delay to 2027 mean this can wait?
What is the fastest way to find out how many unreviewed AI vendors we already have?
What is the first thing to fix in vendor intake to catch this earlier?
How Mitratech Can Help
Most vendor risk programs were built to catch a signature, not a subscription. Mitratech Prevalent extends the same vendor risk assessment, questionnaire, and continuous monitoring workflow your team already runs to ask the AI-specific questions those workflows were never designed to ask, so an approved vendor’s new AI feature gets the same scrutiny its original onboarding did. The same continuous monitoring that tracks a vendor’s security posture today can catch that feature change instead of waiting for next year’s review. See how Mitratech Prevalent handles AI vendor risk.
