
Edition 1
Third-Party Shadow AI
The hidden AI supply chain inside the products your business depends on. Seven connected articles and a practical governance framework.

From the Editor
“The interesting questions are often around the model.”
Your AI policy may stop at your front door. This first edition follows the information, permissions and dependencies that continue beyond it, into the suppliers delivering your software and services. It asks what we should know, what we should control and what we are actually paying for.
Dr Gary Marrs PhD Editor, Beyond the Model
AI governance extends beyond the tools your own employees use. This edition examines the hidden AI in supplier workflows, the permissions behind agentic systems, changing contracts, human expertise and the dependencies underneath the service.
Read the seven articles in sequence, or begin with the question that matters most to your organisation. The closing framework turns those questions into a practical supplier review.
Inside Edition 1
In this edition
Eight connected questions, designed to be read in sequence or entered at the point most relevant to you.
- 01Are You Paying Someone Else to Ask AI?Your internal AI policy may not follow information into your supplier’s development and support processes.
- 02The Prompt Is Not the Security BoundaryAgents turn an information question into a permissions question. What can they reach, and what can they do?
- 03Your Supplier Contract May Describe Yesterday's ServiceThe product may look unchanged while its delivery model, data flows and human oversight have shifted.
- 04What Are You Actually Paying Your Supplier For?The AI Value Chain Test separates access to common technology from expertise, validation and accountability.
- 05What Happens If Your AI Supplier Loses Its AI Supplier?A claim to support multiple models is not the same as a tested plan to keep your service running.
- 06Is Your Supplier Replacing Experience With AI?Watch for patterns in review capacity, service quality and technical ownership, rather than treating layoffs or faster releases as proof.
- 07A Skill File Can Be a Supply-Chain AttackDownloaded instructions, bundled scripts and changing external references can introduce risk into an agent’s workflow.
- 08A Practical Third-Party AI Governance FrameworkEight connected disciplines to carry supplier AI governance from discovery through continuity, exit and value.