SecureWorld News

Show Me the Plumbing: Four Questions for Any Vendor with AI Inside

Written by Kip Boyle | Mon | Sep 28, 2026 | 1:40 PM Z

In April 2026, Vercel told its customers it had been breached. Attackers reached the company's internal systems and took environment variables, the saved values an app reads to reach other services. They held API keys, access tokens, and database credentials. If your website ran on Vercel, your credentials may have been among them.

Then the investigation traced the chain backward.

The break didn’t begin at Vercel. A Vercel employee had signed up for a tool from Context.ai, a small AI company. The signup used a Vercel Google Workspace account, and it handed the tool broad OAuth access to that account. In February 2026, a Context.ai employee downloaded game cheat scripts from an untrusted site. That machine picked up credential-stealing malware. The attacker used that OAuth access to get into the Vercel employee’s Workspace account. Vercel’s systems came next.

Context.ai was never on any Vercel customer's vendor list. Those customers had no contract with Context.ai and no way to check how it worked. Some of their credentials were exposed anyway.

People hand me their third-party risk inventory all the time. The AI tools a vendor runs inside its own shop never show up on it. We record the company we pay and stop there.

That habit costs more than it used to. A regular software vendor runs on infrastructure you can name, like AWS or Azure. An AI vendor adds a model someone else built, hosts, and updates on a schedule your vendor may not control. That's surface area your contract never mentions.

A business unit wants an AI tool approved this week. You've got half an hour on a call with the vendor. Ask to see the plumbing: four questions, in plain language, while you’re still on the call.

Where does our data go?

Not "is it encrypted." Does our data feed the model's training, and whose model is it? When we terminate, does deletion reach whatever the model absorbed from us? You want to hear "we don't train on customer data," and you want it in the contract. A privacy policy isn't a commitment, because the vendor can rewrite it whenever they want.

Who validates the output?

Every AI product decides where the human sits. Some put a person on every result. Others act on their own. They send mail, write to databases, and call other systems. Ask what the tool can do with no person approving it. Then ask the more insightful question: where on your system are those checks not applied?

Where's the audit trail?

If this tool handles your data for a year, and your auditor asks what it did in March, who answers? Find out what gets logged and who can read the log. Ask how long it's kept and whether you can export it.

What happens when the model changes?

AI vendors push model updates far more often than software vendors ship releases. A new model can treat your data differently, and return different answers to the same question. Ask for advance notice on material changes, and a window to test before the new model touches your data.

Now, how to read what comes back.

Some vendors publish this before anyone asks. Talairis Law Group is an AI-native law firm that opened in May 2026. Its website lays out the architecture. Each piece of work sits on a record for that one customer. An attorney reviews every deliverable. The firm says it doesn't train AI models on customer data. That's visible plumbing.

Missing answers aren't automatically a no. They tell you where the rest of your diligence belongs. And if a vendor can't name the companies behind their own product, they aren't managing that chain for you.

Legal will push back on this. We can't enforce terms on companies we have no contract with. That's right, and awareness is the goal. Flow-down language does the rest. Your vendor must require the same standard of the companies it buys from. Skipping that puts them in breach of your agreement.

Pick the AI vendor that touches your most sensitive data, and run the four questions this week. Then run them on the AI tools your own people adopted without asking. An unapproved tool is a supplier nobody reviewed.

~~~

Kip Boyle is Founder and CISO of Cyber Risk Opportunities and has spent 30+ years in cybersecurity. His new book, "Gears Don’t Guess: The Executive's Practical Guide to Thriving in the Face of AI Hype and Risk," is out now. The Kindle edition is free through October 2, 2026, available here. More at gearsdontguess.com.