hbr.org Enterprises Face Legal Risks from Outsourced AI Systems
Article Content
- •Enterprises are legally responsible for third-party AI risks.
- •65% of large companies rank third-party vulnerabilities as their top challenge.
- •Gartner warns of potential fines exceeding 5% of revenue for non-compliance.
Companies are increasingly held accountable for risks associated with third-party AI systems they deploy. Recent research indicates that enterprises may lack visibility into how these AI models are trained, yet they face lawsuits and regulatory scrutiny when these systems cause harm or discrimination. The interconnectedness of AI risks, including dependencies on cloud service providers and other third-party vendors, complicates the landscape. Gartner predicts that by 2027, 75% of regulated organizations could face fines exceeding 5% of their global revenue due to inadequate AI compliance processes. A World Economic Forum report highlights that 65% of large companies now view third-party vulnerabilities as their top resilience challenge. As AI adoption grows, so does the complexity of managing these risks, with many organizations unaware of their supply chain dependencies.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Common questions
What are the legal responsibilities for using third-party AI?
How can organizations manage third-party AI risks?
What are the potential financial implications of AI compliance failures?
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…