Under the Hood: The Hidden Dependencies Driving Your AI and Enterprise Risk

By Matt Tippets [ Join Cybersecurity Insiders ]
18

Companies are waking up to an AI hangover after employing third-party AI for everything from website chat to job applicant screening. The mounting pile of lawsuits targets not only the companies that provided the AI models, but the companies that deployed these tools.

A recent Harvard Business Review article by Harvard Kennedy School researchers M. Alejandra Parra-Orlandoni and Paulo Carvão, detailing how outsourced AI risk has come home to roost at leading companies such as Workday, compares enterprise AI deployments to a game of Jenga, where the failure or compromise of any one piece can collapse an entire process or business.

The growing trend of regulators and plaintiffs landing at the feet of those closest to end users, even if the AI itself came from a third-party supplier, highlights the interconnectedness of risk. The financial stakes are becoming concrete: Gartner predicts that through 2027, manual AI compliance processes will expose 75% of regulated organizations to fines exceeding 5% of their global revenue.

Enterprise risk related to third-party dependencies is growing

Reliance on AI model providers is just one form of third-party risk. You also take on risk when you rely on cloud service providers, business process outsourcing companies, and various other vendors and suppliers. All of those third parties have their own partners and suppliers, so incidents and outages they face can flow downstream to your providers and then to you.

Sixty-five percent of large companies now rank third-party and supply chain vulnerabilities as their top resilience challenge, according to the World Economic Forum’s Global Cybersecurity Outlook 2026, up from 54% a year earlier. Among the organizations WEF classifies as highly resilient, the figure is higher still: 78% of those CEOs name supply chain and third-party dependencies as the single biggest obstacle to strengthening resilience further. The same report notes the complexity of the highly interconnected digital supply chain, which WEF explains has dependencies that are typically not clearly mapped.

A 2023 Gartner survey of executive risk committee members revealed third-party risk management “misses” resulted in operational disruption (84%), adverse financial impacts (66%), increased regulatory scrutiny (60%), adverse reputational impact (59%), and regulatory action (33%).

That’s part of why Gartner is telling CISOs this year to stop treating prevention as the primary goal. Its guidance for 2026 reorients security investment around centering on cyber resilience.

Ecosystem dependencies are just one form of AI risk

Enterprise adoption of AI through third-party applications, cloud platforms, data services, and model providers that they may not have visibility into and don’t fully control expands their risk.

But AI risk comes in many forms, including:

  • AI-accelerated cyber risk: Attackers can use AI to scale deepfakes, malware such as ransomware, phishing, reconnaissance, social engineering, and exploit development.
  • AI-embedded business process recovery complexity: Organizations incur heightened risk as they scale AI across the enterprise for things like claims processing, coding, customer support, decision support, fraud detection, HR, risk analysis, and supply chain planning. If an AI-enabled workflow fails, produces incorrect decisions, or becomes unavailable, many organizations do not know the business impact or have a manual fallback path.
  • Model and data dependency: AI outputs are only as reliable as the data, context, and controls behind them.
  • Runtime drift and explainability gaps: AI systems may change behavior over time, especially when models, prompts, integrations, or data sources change.
  • Shadow AI: Employees or teams using unapproved AI tools with sensitive information or business-critical workflows can open the enterprise to new vulnerabilities.

Enterprises need to address these risks because AI agents don’t just generate information, they make decisions and act at a speed no human review process was built to handle. Gartner expects the incident load to follow: by 2028, half of all enterprise cybersecurity incident response efforts will focus on incidents involving custom-built AI-driven applications.

A recent post by Anthropic’s CEO cautioned that within 6 to 12 months, AI agents will advance beyond the industry’s ability to keep them contained and within their intended scope. That is the kind of exposure enterprises open themselves up to when they underestimate AI systems. 

Enterprise AI agents aren’t just another IT asset

Yet most organizations treat AI agents as IT assets to patch, monitor, and eventually replace.

An agent embedded in claims processing, trade settlement, or customer onboarding is part of a critical business process. You need to govern AI agents as such, with defined performance thresholds, reliability expectations, and recovery tolerances for when things fail. A payment engine or call-routing system has a recovery time objective and a tolerance for degraded performance. The agent making decisions inside that process needs the same discipline.

Most don’t have that. And few have the capabilities to answer the four questions that they need answers to, so they can move quickly to reduce their risk in the event of a cyber incident. 

The questions are outlined below:

  1. What is impacted?
  2. What happens next?
  3. What is the financial exposure?
  4. What should be prioritized first?

Organizations must act now to limit their risk

Limiting risk requires enterprises to assign clear ownership, define hard boundaries on what an AI agent can access and do, ensure autonomy levels are tied to risk, do continuous monitoring of AI, and establish the necessary foundations to create an audit trail that holds up after the fact. Organizations also must institute clear escalation paths for the moment an agent hits something outside its authority, because that moment will come, perhaps faster than expected.

The more autonomy and impact an AI agent carries, the more important it is to implement controls to make it defensible when things fail, and you have to explain who knew what, when.

But the first step in building enterprise resilience in your AI-enabled, interconnected enterprise is to map the dependencies of critical operations so that, when disruption hits, you’re ready.

 

Join our LinkedIn group Information Security Community!

No posts to display