As AI becomes an increasingly critical component in the digital supply chain, tech buyers are struggling to appropriately measure and manage their AI risk. Keeping tabs on emerging risk from the AI technology they use is hard enough. But often the most crucial AI business functions that organizations depend upon aren’t directly under their control or care, but instead are governed by the tech vendors that embed them into their underlying software.
It's a classic vendor risk management challenge, one which Bitsight is intimately aware of. Vendor risk and third-party risk management (TPRM) are, of course, our bread and butter. And on the flip side, we are also a tech vendor ourselves that uses AI to help our products and business to better serve customers. Our company has invested considerable resources into managing the risk around AI. We have well-established policies and procedures that govern how Bitsight embeds AI into its products and how the business uses it internally.
With this expert lens, here’s what we see as the most important questions that tech buyers should be asking about how their vendors use AI today.
1. How do you control which data trains and flows into your models?
At the end of the day, one of the biggest questions Bitsight clients want answered is whether their data will be used to train public LLMs (in our case, that answer is an unequivocal ‘no’). But this points to a more foundational line of questioning that all tech buyers should be pressing their vendors on.
No one wants the public or bad actors to ask questions around your priority data and then get served results that should have been kept secret. Ask for concrete information about whether customer data is used to train the vendor’s models and, if so, get details about how the vendor protects the privacy and integrity of the data that flows through and trains their AI models. Buyers should pointedly ask what measures are taken to protect against model inference attacks that can expose training data and against model poisoning attacks that can weaponize data to disrupt the proper functioning of the model. They may also want to ask whether they can opt out their own data from model training, and what mechanisms the vendor uses to ensure their data isn’t used.
2. Can you describe which features use AI models and how it impacts functionality?
AI stands to transform the way different kinds of technology make on-the-fly decisions, calculations, and judgements that involve many different variables. Whether AI is used to power real-time dynamic pricing changes based on market fluctuations or to trigger predictive maintenance actions in manufacturing equipment, it can be a true game-changer for optimizing business processes.
The first fundamental problem of managing risk incurred by this kind of AI use is one of transparency. Does the business even know when its financial software platform is using AI to trigger pricing changes? Does it know when its manufacturing technology leverages AI to schedule and execute changes to its firmware? If this AI is operating under black box conditions where the end user isn’t even aware of its existence, it becomes very difficult for that organization to enumerate and manage the AI exposures that it could be potentially introducing to its digitally-led business processes.
Our most sophisticated clients at Bitsight are becoming more discerning about how we and the rest of their tech vendors are using AI to make calculations and decisions under the hood. As they make critical choices about risk, they should ask for greater transparency into the algorithms their vendors use and about the data that fuels it all.