Summary: Third-party AI risk is the exposure a bank inherits when a vendor ships an agent, or when a core-system vendor turns on agent features inside a release already in production. Interagency third-party guidance still covers the vendor life cycle from planning through termination. After the April 2026 model-risk letter left generative and agentic systems outside its scope, those vendor agents sit with the bank’s third-party program. The phrase names that inherited exposure inside the broader field of AI governance.
What the term names in 2026
Third-party AI risk is inherited vendor exposure from an agent the bank did not build.
A September 21, 2023 MIT Sloan report found that 78 percent of organizations use third-party AI tools and that 55 percent of AI failures come from those tools. That survey is a 2023 pre-agent baseline.
Singapore’s IMDA Model AI Governance Framework for Agentic AI version 1.5, published 20 May 2026 and updated 5 June 2026, is written for organizations that deploy agentic AI in-house or through third-party agentic solutions. Version 1.5 separates platform providers from system providers or app developers.
A February 6, 2024 definition still treats the term as licensed models, data pipelines, or decision-support tools inside a vendor relationship. The 2026 object is narrower: an agent that can act, or an agent feature that arrives inside a production release.
What the 2023 interagency letter already covers
OCC Bulletin 2023-17, issued June 6, 2023 by the OCC, the Board of Governors of the Federal Reserve System, and the FDIC, is the interagency guidance on third-party relationship risk management. It outlines the third-party risk management life cycle and identifies principles for each stage. It clarifies that not all third-party relationships present the same level of risk or criticality, and that practices should be commensurate with the bank’s risk profile and the criticality of the activity the third party supports.
The Federal Reserve’s May 2024 community-bank guide restates that duty. Engaging a third party does not diminish or remove a bank’s responsibility to operate in a safe and sound manner and to comply with applicable legal and regulatory requirements, including consumer protection laws, just as if the bank performed the activity itself. The guide names five stages: planning, due diligence and third-party selection, contract negotiation, ongoing monitoring, and termination. An AI vendor is still a third party. The 2023 letter did not need an AI subtitle to apply.
What the 2026 carve-out moves onto the third-party program
OCC Bulletin 2026-13, dated April 17, 2026, still includes a section on vendor and other third-party products. Customized vendor products, including data, parameter values, or complete models, can present unique challenges for validation. Because certain components may be proprietary, banking organizations may not receive the underlying code, data, or methodology they would have for an internal model. The principles of model risk management remain applicable to those in-scope products.
The same bulletin states that generative AI and agentic AI models are novel and rapidly evolving, and are not within the scope of that guidance. Ordinary risk-management and governance practices should guide tools the letter does not cover. For a vendor-shipped agent, that practice is third-party risk management (TPRM). The 2026 model-risk carve-out as a regime map lives elsewhere.
Two shapes of the exposure
The first shape is buying an agent platform. IMDA’s value chain labels model developers, tooling providers, platform providers, system providers or app developers, the deployer, and end users. The bank is the deployer. The vendor is the platform or system provider. Organizations may play overlapping roles: an organization that develops its own agents and then deploys them is both system provider and deployer. That overlap is the point for a bank that buys a platform or wraps a vendor agent.
IMDA also names third-party SaaS agentic platforms as a standing enterprise fact. Agents from external parties can be difficult to observe and control.
The second shape is a core or SaaS vendor shipping agents inside a release the bank already runs. PwC records vendors embedding AI into off-the-shelf software, often without full customer visibility, and service providers using AI without clients’ explicit awareness. Both shapes stay on the 2023 life cycle. They are different buying events. A mid-contract change in what the agent can do is adjacent procurement, treated separately when the billable unit changes mid-contract.
Why “AI for TPRM” is a different phrase
Search results mix two meanings. Pages that discuss vendors embedding or shipping AI, including PwC, MIT Sloan, and OneTrust, name a risk category: exposure the buyer inherits. Other pages use the same words for software that scores vendors or automates assessments. That second use is a tooling category. The definition here is the inherited-exposure meaning.