CIOs must rethink third-party risk as AI creeps into tools
AI creep is making point-in-time vendor checks less reliable. IT leaders need continuous oversight of the added AI capabilities vendors are putting in place.
As vendors rapidly add agentic capabilities to their products, third-party assurance practices must evolve from periodic assessments to continuous oversight.
The concept of AI creep -- when third-party vendors add AI capabilities to products without customers fully understanding the change -- was a key issue at Gartner's 2026 Enterprise Risk, Audit & Compliance Conference. Multiple sessions focused on helping IT and risk teams understand how those changes are expanding the AI risk surface.
As Gartner senior director and analyst Devanshu Mehrotra pointed out in a session on autonomous agents, traditional third-party assurance relies on three assumptions:
Vendor capabilities change slowly.
Contractual disclosures will flag significant changes.
Vendor attestations accurately reflect what's happening in a product.
However, agentic AI challenges all three assumptions.
"Sometimes capabilities move faster than the vendor can keep up," Mehrotra told TechTarget.
CIOs and risk teams must therefore think about third-party risk as an ongoing process rather than a point-in-time check. They need to look beyond one-time assessments and maintain ongoing visibility into what AI capabilities vendors add, what those capabilities can do and how they affect the organization's risk.
Borrow from highly regulated industries
Agentic governance is relatively new, and best practices are still developing. However, CIOs don't need to reinvent the wheel when it comes to managing the risks of AI capabilities added to third-party software.
In the autonomous agents session, Mehrotra suggested that IT and risk teams look to highly regulated industries, such as pharmaceuticals, for governance practices they can adapt to AI.
For example, a drug isn't approved once and then left alone, he said. Its performance is monitored over time, new information is evaluated, and significant changes are scrutinized.
The same approach can be applied to AI capabilities added to software. Traditional third-party assurance processes often rely on SOC reports, questionnaires, contracts and vendor attestations. Those provide useful information, but they can become outdated when vendors add new AI capabilities after an assessment has been completed.
A bunch of incremental changes can add up to a material change.
Devanshu MehrotraDirector and analyst, Gartner
Companies should seek more operational evidence about what's actually happening in a vendor's systems rather than relying solely on point-in-time assurance, Mehrotra said. He also recommended establishing clear requirements for vendors to disclose material changes to their AI capabilities.
"Have a clear list of what is contractually allowed and not allowed, and a definition of what a material change is, because a bunch of incremental changes can add up to a material change," Mehrotra said in an interview.
The main stage at Gartner's 2026 Enterprise Risk, Audit & Compliance Conference moments before the first keynote.
Questions to ask vendors
CIOs should start by asking basic questions about what AI features can do inside third-party products, said Gartner vice president analyst Kjell Carlsson in an interview with TechTarget.
These questions include the following:
Where is company data going?
Who is involved and accountable?
What can the AI access and do?
Why is the capability valuable?
When will the vendor notify customers about material changes?
How does the organization know the AI remains trustworthy and governed?
Those questions become critical as vendors add new AI features. AI creep can include visible features such as chatbots and agent-building tools, Carlsson said, as well as less visible changes, such as AI-powered search and anomaly detection.
The risks of those capabilities can vary depending on what the AI can do within the application, Mehrotra said. For example, an autonomous agent that provisions user access could grant someone access to sensitive information that they should not have.
By contrast, an agent that simply summarizes emails each morning presents a much smaller risk, he said. That's why organizations need to assess not only an application's risk but also the capabilities of an AI agent within it.
Keeping track of what AI agents can actually do across an organization's software environment can be difficult, said Valence Howden, an advisory fellow at Info-Tech Research Group. Companies should maintain a registry that tracks the AI tools and agents they use, what those systems do and where accountability resides, Howden said.
Tim Murphy is a reporter covering IT strategy for Informa TechTarget, with a focus on IT leadership, governance, workforce skills and AI strategy. His enterprise technology coverage has earned multiple Azbee Awards.