← Back to glossary Glossary

Third-Party AI Risk

Reviewed 19 July 2026 Canonical definition Part of: AI Agent Fundamentals →

Third-party AI risk is the exposure an organisation faces from AI models, agents, or services provided by external vendors. Managing it requires due diligence on the vendor's governance, data handling, security practices, and contractual obligations.

§01 / QUESTIONSterm: Third-Party AI Risk
Questions

Common questions.

What is Third-Party AI Risk?

Third-party AI risk is the exposure an organisation faces from AI models, agents, or services provided by external vendors.

How does Third-Party AI Risk work?

Managing it requires due diligence on the vendor's governance, data handling, security practices, and contractual obligations.

Which terms are related to Third-Party AI Risk?

Closely related concepts include MiFID II (AI Agents), Model Risk Management, AI Center of Excellence, AI Maturity. Each is defined in the Prefactor glossary.

§02 / RELATEDnext: where this fits
Keep reading

Where this fits.

See how every agent performs, and make it better

Prefactor helps teams observe, evaluate, and improve their AI agents in production, across every framework and provider.