A lack of transparency about how vendors are using AI can create new risks for firms. Vendors are not only offering AI tools and solutions but also incorporating it behind the scenes to streamline their operations. To help firms navigate the operational and data security risks posed by third-party use of AI, ACA Aponix partner Michael Pappacena and director John de Freitas discussed the ever-expanding use of AI by third-party service providers, the evolving AI risk landscape, appropriate implementation of AI, AI governance best practices and incident response. This article distills their insights. See “Pain Points and New Demands in AI Contracts” (Jun. 18, 2025).