
Thursday May 14, 2026
AI Supplier Management
In this episode of InfoSec Insider, Jack Woods and George Ryan, both Consultants at URM, share their insights on how organisations can effectively manage AI suppliers and navigate the emerging risks associated with artificial intelligence in the supply chain.
Jack and George draw on their experience supporting organisations with AI governance and supplier risk management to discuss:
- What AI supplier management is and how it differs from traditional supplier management, including the impact of rapidly evolving AI models and changing service structures
- The key risks associated with AI suppliers, such as data leakage, unauthorised model training, hallucinations, bias, and compliance challenges
- The growing issue of shadow AI, and how a lack of visibility over employee use of AI tools can introduce significant security and governance risks
- How organisations can adapt due diligence processes to assess AI suppliers, including evaluating data handling practices, model governance, human oversight, and security maturity
- Contractual and governance considerations, such as restricting data use, ensuring transparency on model updates, and defining audit and incident response expectations
- The importance of understanding extended AI supply chains, including dependencies on underlying models and fourth-party providers
- Why AI supplier management must be treated as an ongoing activity, with continuous monitoring, internal communication, and reassessment of risk as technologies evolve
Ask Jack and George a question:
https://www.urmconsulting.com/podcasts/aI-supplier-management
If you enjoyed this episode of InfoSec Insider – Talk Cyber, you can leave us a rating and review here: https://ratethispodcast.com/infosecinsider
You can find more episodes of InfoSec Insider here: https://urmconsulting.com/podcasts
Brought to you by URM, the UK’s leading information and cyber security specialists.
No comments yet. Be the first to say something!