Your business may already have an AI program that nobody formally approved. Part of it lives with employees. The rest may live with your bookkeeper, marketing agency, recruiter, consultant, or outsourced IT provider.
Those vendors often have legitimate access to valuable information. If they process that information through an unapproved AI product, your data may enter a system you cannot see, govern, or audit.
Start with a written internal policy
A practical internal control is a short AI-use acknowledgment that names the tools employees may use, the information they may submit, and the work that requires review.
A signature does not technically prevent misuse. It creates a record and removes ambiguity about what the business communicated. The policy should arrive with a usable approved alternative. A prohibition without an option encourages quiet workarounds.
Vendor risk is a separate problem
Traditional agreements cover confidentiality, ownership, and subcontractors. Many were written before generative AI became part of everyday work.
Two issues deserve separate attention:
- A vendor may reuse AI-assisted work or intellectual property across clients.
- A vendor may process your data in a consumer-tier system with terms you never reviewed.
Some AI tools also receive deep access to a CRM, database, mailbox, or cloud account. A compromise at the vendor can therefore become a path into your business.
Four questions to send every vendor
Ask these questions in writing:
- Are you using any AI tools while working on our account?
- If not, do you plan to use them?
- If yes, which tools and subscription tiers are used, and can the work run in an environment we control?
- Who pays for the approved environment that contains our information?
The goal is not to prohibit useful technology. It is to ensure work you already pay for happens in a place you can understand and control.
Three actions that cost little or nothing
Inventory every outside party with access to business or customer information. Send the four questions and retain the responses. Then update internal policies and vendor agreements with the help of qualified counsel.
For the technical side, favor business environments that provide administrative controls, clear data terms, access logging, and the flexibility to change models as needs evolve. Fortify AI can help map those relationships and build a controlled AI deployment without forcing the organization into one product forever.
The important question is no longer whether vendors use AI. It is whether you know where they use it, what they place into it, and who is responsible for the result.
Adapted from The Digital Dilemma newsletter.