← Blog
compliancefinancial-servicesgovernance

What Is Third-Party AI Risk

Third-party AI risk is the exposure a bank inherits when a vendor ships an agent, or when a core vendor turns on agent features inside an existing production release already under contract.

MightyBot ·
A navy vendor cube opening to release glass orbs, linked by frost-white supply-chain pieces with one amber hinge.

Summary: Third-party AI risk is the exposure a bank inherits when a vendor ships an agent, or when a core-system vendor turns on agent features inside a release already in production. Interagency third-party guidance still covers the vendor life cycle from planning through termination. After the April 2026 model-risk letter left generative and agentic systems outside its scope, those vendor agents sit with the bank’s third-party program. The phrase names that inherited exposure inside the broader field of AI governance.

What the term names in 2026

Third-party AI risk is inherited vendor exposure from an agent the bank did not build.

A September 21, 2023 MIT Sloan report found that 78 percent of organizations use third-party AI tools and that 55 percent of AI failures come from those tools. That survey is a 2023 pre-agent baseline.

Singapore’s IMDA Model AI Governance Framework for Agentic AI version 1.5, published 20 May 2026 and updated 5 June 2026, is written for organizations that deploy agentic AI in-house or through third-party agentic solutions. Version 1.5 separates platform providers from system providers or app developers.

A February 6, 2024 definition still treats the term as licensed models, data pipelines, or decision-support tools inside a vendor relationship. The 2026 object is narrower: an agent that can act, or an agent feature that arrives inside a production release.

What the 2023 interagency letter already covers

OCC Bulletin 2023-17, issued June 6, 2023 by the OCC, the Board of Governors of the Federal Reserve System, and the FDIC, is the interagency guidance on third-party relationship risk management. It outlines the third-party risk management life cycle and identifies principles for each stage. It clarifies that not all third-party relationships present the same level of risk or criticality, and that practices should be commensurate with the bank’s risk profile and the criticality of the activity the third party supports.

The Federal Reserve’s May 2024 community-bank guide restates that duty. Engaging a third party does not diminish or remove a bank’s responsibility to operate in a safe and sound manner and to comply with applicable legal and regulatory requirements, including consumer protection laws, just as if the bank performed the activity itself. The guide names five stages: planning, due diligence and third-party selection, contract negotiation, ongoing monitoring, and termination. An AI vendor is still a third party. The 2023 letter did not need an AI subtitle to apply.

What the 2026 carve-out moves onto the third-party program

OCC Bulletin 2026-13, dated April 17, 2026, still includes a section on vendor and other third-party products. Customized vendor products, including data, parameter values, or complete models, can present unique challenges for validation. Because certain components may be proprietary, banking organizations may not receive the underlying code, data, or methodology they would have for an internal model. The principles of model risk management remain applicable to those in-scope products.

The same bulletin states that generative AI and agentic AI models are novel and rapidly evolving, and are not within the scope of that guidance. Ordinary risk-management and governance practices should guide tools the letter does not cover. For a vendor-shipped agent, that practice is third-party risk management (TPRM). The 2026 model-risk carve-out as a regime map lives elsewhere.

Two shapes of the exposure

The first shape is buying an agent platform. IMDA’s value chain labels model developers, tooling providers, platform providers, system providers or app developers, the deployer, and end users. The bank is the deployer. The vendor is the platform or system provider. Organizations may play overlapping roles: an organization that develops its own agents and then deploys them is both system provider and deployer. That overlap is the point for a bank that buys a platform or wraps a vendor agent.

IMDA also names third-party SaaS agentic platforms as a standing enterprise fact. Agents from external parties can be difficult to observe and control.

The second shape is a core or SaaS vendor shipping agents inside a release the bank already runs. PwC records vendors embedding AI into off-the-shelf software, often without full customer visibility, and service providers using AI without clients’ explicit awareness. Both shapes stay on the 2023 life cycle. They are different buying events. A mid-contract change in what the agent can do is adjacent procurement, treated separately when the billable unit changes mid-contract.

Why “AI for TPRM” is a different phrase

Search results mix two meanings. Pages that discuss vendors embedding or shipping AI, including PwC, MIT Sloan, and OneTrust, name a risk category: exposure the buyer inherits. Other pages use the same words for software that scores vendors or automates assessments. That second use is a tooling category. The definition here is the inherited-exposure meaning.

FAQ

Frequently Asked Questions

What is third-party AI risk?

Third-party AI risk is the exposure a bank inherits when a vendor ships an agent, or when a core vendor turns on agent features inside a release the bank already runs. A February 6, 2024 definition treated the term as licensed models, data pipelines, or decision-support tools inside a supplier product. After OCC Bulletin 2026-13 left generative and agentic models outside model-risk scope, the narrower object is a vendor agent that can act.

Does OCC Bulletin 2023-17 already cover AI vendors?

OCC Bulletin 2023-17 is the June 6, 2023 interagency guidance on third-party relationships. It outlines a life cycle and tells banks to scale practices to the criticality of the activity the third party supports. An AI vendor is still a third party under that letter.

What did OCC Bulletin 2026-13 change for vendor AI?

OCC Bulletin 2026-13, dated April 17, 2026, still discusses vendor and other third-party products for models that remain in scope. The same letter places generative and agentic models outside that scope and sends uncovered tools back to the bank's ordinary risk-management and governance practices. For a vendor-shipped agent, that ordinary practice is third-party risk management.

How is third-party AI risk different from using AI to run TPRM?

Third-party AI risk is a risk category: exposure inherited from vendors that use or ship AI, including agents. AI for TPRM is a tooling category: software that scores vendors or automates assessments. The two phrases share search words and name different jobs.

Who is accountable when the bank deploys a vendor agent?

Under Singapore's IMDA Model AI Governance Framework for Agentic AI version 1.5, deployers remain accountable for the decisions and actions of agents. Organizations may play multiple overlapping roles across the value chain. A bank that wraps or extends a vendor agent can be both system provider and deployer.

What happens when a core vendor turns on agent features inside a release already under contract?

The exposure is still third-party AI risk, arriving as a change to a relationship already on the June 6, 2023 life cycle rather than as a new platform purchase. PwC records vendors embedding AI into products without full customer visibility. The Federal Reserve's May 2024 guide keeps the bank's duty with the bank through ongoing monitoring, not only at initial selection.