Vendor Risk
AI vendor and third-party risk: due diligence, concentration risk, and the questions to ask before you trust a model provider.
58 articles
Articles about Vendor Risk

Your AI Vendor Count Is Hiding One Foundation Model.
Three contracted AI vendors can still fail as one service when they share a foundation model, cloud control plane or identity layer. Map every service to its common technical roots, then test whether your nominated substitute survives the same failure.
Read article
Your AI Dashboard Is Not Due Diligence: What Officers Need to Know, Ask and Record
A polished AI risk dashboard can support an officer's due diligence inquiry under section 27 of the WHS Act. It cannot perform that inquiry. Here is the duty, the six statutory elements, the Victorian difference, and a six-part evidence file that links every dashboard claim to a source record and an independent workplace check.
Read article
OpenAI Presence Arrived. Decide Who Can Change the Agent.
OpenAI Presence makes post-launch agent improvement part of a managed service. That puts vendor engineers, integrators and customer teams inside one change loop. The contract must specify who may propose, test, approve, release, pause and reverse each production change.
Read article
Your AI Vendor's Breach Starts Your Clock
On 6 July 2026 the OAIC reported the highest number of data breach notifications since the scheme began. Meanwhile organisations have quietly handed personal information to a new class of provider. Under the Privacy Act you hold what your AI provider possesses if you control it, which means the assessment clock and the notification are yours, not theirs.
Read article
The EU Can Enforce Model Duties From 2 August. Your Vendor File Should Show It.
Europe's general-purpose AI rules did not suddenly begin in August. The sharper change is enforcement. Australian financial-services teams with EU exposure now need a version-specific evidence receipt that separates the vendor's duties from their own role and use.
Read article
Every Model You Rely On Has a Retirement Date
Claude Opus 4.1 stops answering on 5 August 2026. OpenAI shut down sixteen model snapshots on 23 July 2026 and will retire its Agent Builder and Evals platform on 30 November 2026. These dates are published, they are not negotiable, and the notice you receive depends on a product tier most teams never consciously chose.
Read article
Agents That Can Pay: Gate the Wallet First
The rails for agents that pay are being laid in public. Google's Agent Payments Protocol, built with more than sixty payment and technology firms, turns an agent's spending authority into a signed, limited, auditable instruction. Before any tool with a wallet reaches an Australian workplace, the practical question is the action gate: which payments an agent may start, at what limit, with whose approval, and what gets logged.
Read article
Your Website AI Assistant Is Someone Else's Code
On 24 June 2026 the Privacy Commissioner published two determinations finding that health providers interfered with privacy by letting third-party tracking pixels collect sensitive information from their websites. The reasoning is not about pixels. It is about who owns third-party code running on a page you control, and the fastest growing category of that code is an AI assistant your customers type into.
Read article
Preventing Double Payment Under the SRC Act: AI Can Flag the Overlap, Not Calculate the Offset
The SRC Act guards against paying twice for the same injury: through third-party damages, an overlapping state workers compensation claim, or a state general compensation scheme. AI can flag a file for a possible overlap early and build the chronology of the parallel claim. Calculating the offset or recovery amount is a determination that stays with the case manager.
Read article
Google Missed Its Own Release Date, and That Is the Story
Google promised Gemini 3.5 Pro for June 2026. It is mid-July and the flagship still is not generally available, held back over quality Google will not sign off. In a market that worships launch velocity, a missed date is the underreported signal, and a live test of your own buying discipline.
Read article
A Real CVE in Your Agent-Building Tools
A critical flaw in Langflow, tracked as CVE-2026-33017, let anyone run code on exposed servers with a single unauthenticated request, and attackers used it to install cryptominers within a day of disclosure. The vulnerability was not in a model. It was in the low-code tool teams use to build agents. Here is what that means for anyone evaluating an agent-building platform.
Read article
AI in Reference and Background Checks: Verify Facts, Not Character
AI is arriving in the verification stage of hiring: tools that draft reference questions, summarise calls, scrape digital footprints and score candidates. The admin is worth automating; the judgement, the collection decisions and the fairness are not. Here is the line, a five-step process that holds it, and two ready prompts.
Read article
Your AI Agent Can Remember Now. Govern What It Keeps.
In 2026 the major labs shipped persistent memory as a first-class agent feature, barely six weeks apart. An agent that remembers across sessions is a different thing to govern, and a new attack surface. Treat the memory store as a governed data asset with write rules, provenance, expiry and rollback, not invisible plumbing.
Read article
More Agents Is Not More Intelligence. Govern the Coordination.
The plumbing for multi-agent AI just got standardised, so building systems where agents talk to each other is now easy. That is exactly why the useful question changed. Not can you wire agents together, but should you, and how do you govern the coordination when more agents is not more intelligence.
Read article
The 2026 AI Governance Talent Market: Assurance Skills Move to the Core
Australia's AI governance market is shifting from principle-setting towards assurance: control design, model testing, data lineage, third-party oversight and evidence a board or auditor can challenge. APRA has named the skills gap, no salary guide prices the role cleanly, and the scarce profile is the practitioner who can move from principle to proof.
Read article
Your Pricing Agent Is Still Your Competition Risk
An AI pricing agent does not sit outside Australian competition law. Businesses must still set prices independently, prevent unlawful competitor coordination and control the data, objectives and vendors shaping every recommendation. Here is the cartel-law map, the five questions GRC must ask and the evidence pack to build before go-live.
Read article
AI's Next Constraint Is Power. Australia Has Started Writing the Rules
Australia is starting to treat AI infrastructure as an energy-system issue. Government expectations now ask new data centres to add clean supply, pay their grid costs and support flexible demand, while a draft AEMC rule would set technical connection standards for large loads.
Read article
Someone Poisoned the Tool Description. The Agent Did the Rest.
Microsoft's incident-response team has documented the first real-world attack on the Model Context Protocol: poison a tool's description and you redirect the agent, without touching its code, its credentials or its prompt. The site's earlier MCP piece predicted this. Here is what "least agency, not just least privilege" means as an operational control, not a slogan.
Read article
A Government Now Vets Who Gets the Model. File It as a Vendor Risk.
For the second time in a month, a US government put a frontier model behind a gate. This time it was an access list: roughly 20 vetted organisations get GPT-5.6, chosen name by name. The capability story is covered. The one that lands on your desk is procurement: government-imposed access conditions are now a vendor-risk category your due diligence has to name.
Read article
A Deadline Is Not a Decision: Greenlighting AI Before the Free Window Closes
OpenAI's free window for ChatGPT's workspace agents closes today, right as the workspace-setup season begins. A vendor's deadline is a fact about the vendor, not a reason for you to decide. Here is the criteria a leader should actually greenlight on: real team need, switching cost, and governance readiness.
Read article
You Are Now Buying Software for Agents, Not People
Gartner says $234 billion of enterprise SaaS spend is exposed to agentic arbitrage by 2030. Read as a vendor problem it is a headline. Read as a buyer it changes how you procure and govern the software you already run, so this piece turns the forecast into an API-parity test you can run this week, a five-clause contract checklist and a Monday workflow.
Read article
Claude Sonnet 5 Became the Default. That Is a Change Event.
Anthropic released Claude Sonnet 5 on 30 June and made it the default in Claude Code and on Claude.ai Free and Pro. Almost nobody chooses a model, so a frontier swap is a silent change to a system you may have already validated. Here is how to treat it as a change event: the prompts, the Monday workflow and the register entry.
Read article
Fable 5 Returns With a Jailbreak Severity Framework
Claude Fable 5 comes back globally on 1 July, three weeks after a US directive pulled it. The return matters less than what came with it: a safety patch that over-blocks routine coding, and a four-dimension jailbreak-severity framework the major labs are building together.
Read article
CPS 230's 1 July Deadline Just Caught Up With Your AI Vendors
From 1 July 2026, pre-existing contracts with material service providers must meet APRA's CPS 230, and a growing share of those arrangements are now AI. Here is the work to do before the deadline, plus a reusable contract-review prompt.
Read article
AI Cyber Defence Just Scaled Up. Mind Your Open-Source Dependencies.
OpenAI pointed its most capable cyber model at the open-source software the world runs on, and found hundreds of real flaws in days. The capability is dual-use. Here is what it means for Australian teams.
Read article
An AI Safety Control Is Still Just a Control. The Duty to Verify It Stays With You.
An AI safety camera or sensor is a control measure like any other, and usually the weakest kind. This guide sets out the WHS duty it touches, where it sits in the hierarchy, and how to deploy and verify one without fooling yourself.
Read article
AML Tranche 2: What AI Can and Cannot Do for Your New Program
From 1 July 2026, tens of thousands of lawyers, accountants, real estate agents and dealers in precious metals become AML regulated for the first time. AI can help them stand up a program fast. It cannot own the risk-based judgement AUSTRAC will hold them to.
Read article
Model Context Protocol: The Standard Wiring AI Into Your Tools
In eighteen months the Model Context Protocol went from an Anthropic experiment to the way AI plugs into your tools and data. Understanding what it is matters less than governing the connectors, because each one is a new door into your systems. Here is the capability and the control work.
Read article
The Strongest Open Model Is Now Chinese. Mind Where Your Data Goes.
On 16 June, China's Z.ai released GLM-5.2 under an MIT licence with no regional limits, the highest-ranked open-weights model on its own coding benchmarks. With Anthropic's Fable 5 pulled by a US directive, the strongest model you can simply download and run is now Chinese. The decision that carries your risk is not the model. It is whether you run the open weights yourself or send your data to the hosted API.
Read article
AI Hiring and Performance Tools Under Australia's Positive Duty: What HR Must Control
AI screening, ranking and performance tools sit squarely inside the positive duty under the Sex Discrimination Act, the Fair Work Act and the Privacy Act. Here is the control framework Australian HR teams need before they deploy.
Read article
Stop Trusting the Leaderboard: Evaluate AI on Your Own Work
A new frontier model lands most months, the public benchmarks they tout are methodologically shaky, and the demo always wins. The only evidence that should move your money is performance on your own work. Here is how to test it, using a private evaluation Project you build yourself.
Read article
The OWASP Agentic Top 10: A Defence Playbook for the Agents You Are Deploying
OWASP has published a Top 10 built specifically for AI agents. It reframes the agent as a privileged user that reads untrusted text and acts with your access. Here is the practical defence playbook.
Read article
AI Is Moving Into the Core Systems of Regulated Work
This week two of the world's largest IT services firms began wiring a frontier model into the core systems that banks, insurers and airlines run on, not the chat window. Here is what it means for regulated work, and what to do this week.
Read article
AI Week in Review, 8-14 June 2026: A Frontier Model Pulled by Government Order
The week a US directive forced Anthropic to suspend two new frontier models worldwide, plus six verified vendor moves and a repeatable method for turning AI news into Monday actions.
Read article
Claude Model Routing for Regulated Work: Which Model to Use for GRC, WC and HR Tasks
Choosing a Claude model is a governance decision, not a speed decision. Route by capability tier, score the task, and keep accountable review with named people, with worked examples for GRC, workers compensation and HR.
Read article
Gold Standard Claude Workspace Setup
A gold standard Claude workspace for Australian enterprise teams. The right surface for each job, the files that carry context, an interview method to build each one, and the data-governance gates that keep it safe.
Read article
Build an Offline GRC Controls Console Without Creating Shadow IT
A single-file controls console can sharpen evidence review without leaking data. Treat it as a governed end-user computing tool, not a free win.
Read article
Claude Fable 5: Frontier Capability, With Conditions Attached
Anthropic has put a Mythos-class model on general release, and the conditions matter as much as the capability. A silent classifier fallback, a mandatory 30-day retention policy and a 23 June billing switch all belong in your next third-party AI assessment.
Read article
Microsoft's Seven MAI Models: The In-House Bet Under Copilot
Microsoft launched seven home-grown MAI models at Build 2026 and started swapping them into Copilot and the Microsoft 365 stack. For practitioners the story is procurement, not benchmarks: data lineage claims, weight tuning, and a billing change in the same week.
Read article
AI Cyber Risk Is Now a Board Governance Issue
ASIC's May 2026 cyber uplift warning highlights that AI-driven cyber risk demands active board and risk committee oversight, not just IT fixes. This article outlines a practical governance operating model for GRC teams.
Read article
From Voluntary AI Guardrails to Audit Evidence
Australia's voluntary AI guardrails only become useful when GRC teams translate them into control objectives, artefacts and assurance tests.
Read article
Small Models, Edge AI and the Next Governance Blind Spot
As AI moves into devices, business apps and smaller specialised models, organisations need governance that looks beyond frontier models and public chatbots.
Read article
AI Incident Response Needs an Evidence Pack, Not Just a Playbook
Prompt injection, data leakage and agentic failures require GRC teams to rethink incident response evidence, escalation and assurance.
Read article
Board AI Literacy Is Now a Control Expectation, Not a Training Nice-to-Have
APRA's April 2026 AI letter signals that board AI literacy is becoming a governance control expectation, not a generic awareness exercise.
Read article
Predictive Analytics and Claims Triage: A Risk Analysis for Scheme Operators
Predictive triage models promise faster decisions and better outcomes. They also concentrate legal, ethical, and procedural fairness risk. Here is how to think about both.
Read article
AI Tools in Workers Compensation Claims: Where Value, Where Risk, Where Governance
AI is now operating across five workflows in workers compensation claims. The value is real. The governance baseline is non-negotiable. A practitioner's map of where each tool fits, what it actually does, and what to never do.
Read article
CPS 234 and AI Vendors: A Due Diligence Framework
CPS 234 has been in force since 2019. AI vendors stretch the framework in specific ways: training data exposure, model update opacity, and inference infrastructure that crosses the standard's information asset boundaries. A practical due diligence framework.
Read article
AML/CTF and Large Language Models: A Compliance View
Large language models are now embedded across AML/CTF programs, from suspicious matter triage to KYC document review. AUSTRAC's posture on these uses is shaping. Reporting entities need a clear governance position now, not later.
Read article
DDO and AI-Driven Personalisation: Where the Boundary Sits
AI personalisation is moving fast inside Australian financial services. The Design and Distribution Obligations were not written with adaptive recommendation engines in mind. The boundary between targeting and personal advice is the line GRC teams need to govern.
Read article
RAG Explained for Non-Engineers: How AI Reads Your Documents
RAG is the architecture behind most enterprise AI tools you will meet in 2026. The acronym hides a simple idea. Here it is, explained in plain English with a working analogy.
Read article
APRA's Model Risk Thematic Review: What to Expect
APRA's AI supervisory work has moved from signal to substance. The April 2026 letter to industry reported a deep-dive on the largest banks, insurers and super trustees, and a forward plan of prudential reviews and thematic activities is being finalised. Where the pressure lands, and the work to do now.
Read article
Choosing Claude, ChatGPT, Gemini or Copilot for Your Job
The four main AI tools have meaningfully different strengths in 2026. The right choice depends on your job, not on the marketing. Here is a working professional's decision guide.
Read article
CPS 230 and AI: A Practical Operational Resilience Playbook
CPS 230 has been live since 1 July 2025, and APRA's amended standard commenced on 1 July 2026. The question for boards and operational risk teams is no longer whether AI tools fall inside the standard. It is how to evidence it.
Read article
How to Read an AI Tool Safety Card and Spot the Red Flags
Every frontier AI vendor publishes a safety card or model card. Most are 30 pages of mixed marketing and substance. Here is how to read one in 20 minutes and walk away knowing what matters.
Read article
On-Device AI at Work: Apple Intelligence and Pixel Gemini Nano
On-device AI is enterprise-ready in narrow ways and not in the ways the demos suggest. Apple Intelligence and Pixel Gemini Nano in April 2026: what works, what does not, and the real privacy story.
Read article
The Open-Source Frontier in April 2026: Llama 4, DeepSeek R2, Mistral Sovereign
Three serious open-weight contenders shipped in April 2026. None of them is the right answer for every workload, but each has carved out a defensible enterprise niche. Here is the comparison.
Read article
Reasoning Budgets in Production: How Teams Are Spending Them
Anthropic shipped reasoning budgets in late March. Six weeks of production data shows the feature pays for itself when teams set the right ceilings. It does not when they leave it on default.
Read article
GPT-5 in the Enterprise: 60-Day Debrief
Sixty days after GPT-5 hit enterprise GA, the tool-use story is real and the pricing story is messier. Three patterns separate the teams getting value from the teams burning credits.
Read article