‹‹ Back

AI ACT – What to expect and how to adapt your cyber strategy?

ia act

AI Act and Supplier Risk Management: A New Challenge for TPRM Programmes

Artificial intelligence is profoundly transforming supply chains and business processes across companies and public-sector organisations. Its use is becoming increasingly widespread and raises questions about cyber risk management and compliance. With the adoption of the European Regulation on artificial intelligence (AI Act), companies must not only be accountable for their own AI systems, but also monitor those used by their suppliers.

The AI Act complements a demanding legal and regulatory framework for cybersecurity. This article explains its scope, obligations and direct impacts on Third-Party Risk Management (TPRM) programmes.

The AI Act: Securing the Use of Artificial Intelligence Within the European Union

Extended AI Risk Management

The AI Act is the new European Regulation governing the use of artificial intelligence within organisations. Its objective is not solely legal: above all, it aims to create a trusted framework for all economic stakeholders, including their partners and suppliers. Indeed, certain uses are considered high-risk, particularly in sectors such as healthcare and finance. Both public and private organisations must therefore ensure that their AI models are secure and subject to human oversight.

The AI Act introduces requirements that fall within the scope of TPRM (Third-Party Risk Management). It requires particular attention to be paid to the use of AI throughout the supply chain. As a result, assessing AI risks among third parties is becoming just as essential as securing the use of AI within internal teams. This approach to managing cyber risk applies to all providers, regardless of their type or role: hardware suppliers, service providers, SaaS software vendors, and more.

Obligations That Impact Cyber Governance

The AI Act complements existing methods for assessing cyber compliance. It requires an assessment of AI solutions used within the company, as well as those used by its providers. Systems considered high-risk must be subject to rigorous controls, including technical documentation, human oversight, data assessment and traceability.

For procurement and legal departments, these obligations involve new supplier management practices:

  • Integrating AI compliance clauses into contracts;
  • Requiring transparency regarding algorithms and datasets;
  • Verifying the presence of CE marking for high-risk systems;
  • Documenting decision-making and oversight processes.

The objective is to better manage AI-related cyber risks that could be introduced by third parties.

In practice, this new regulation encourages economic stakeholders to strengthen their Third-Party Risk Management (TPRM) approach. Indeed, risk mapping must include AI-enabled systems and processes, as well as providers that use AI.

The AI Act is not limited to a technological scope. Its requirements for transparency, documentation and risk management align with those of NIS2 and DORA. Companies and public entities must now manage a unified compliance framework. TPRM therefore becomes the common thread.

AI Act and Cyber Strategy: A New Challenge for Third-Party Cyber Risk Management (TPCRM)

The AI Act as a Driver of Cyber Maturity

The AI Act strengthens security requirements across the entire supply chain, much like the obligations imposed by ISO 27001 certification or the GDPR. Organisations are encouraged to audit and document their artificial intelligence models and demonstrate the robustness of their algorithms against threats.

The AI Act requires organisations to:

  • Trace the origin of data;
  • Verify the integrity of training processes;
  • Ensure human oversight.

CIOs, CISOs and compliance managers are directly involved in ensuring that the use of artificial intelligence is compliant and secure. They become responsible for its use within every department of the company. Governing practices and strengthening security are becoming the cornerstones of the organisation's cyber maturity.

The introduction of the AI Act enhances the supplier risk management approach. Beyond verifying technical or financial compliance, CISOs must now assess the compliance of artificial intelligence systems embedded in suppliers' technology solutions.

Indeed, transparency around AI models used by third parties is becoming an essential part of TPRM. First, this concerns the data used to feed them. Where does it come from? Is it reliable? How is it secured? The relevance, quality and updating of data require particular attention, both to ensure the reliability of AI systems and to protect their integrity.

Second, training methods must be traceable, reproducible and incorporated into risk management processes. Each new use case must include bias and robustness testing and be integrated into TPRM and cybersecurity programmes, including supplier questionnaires and cyber testing.

Finally, overseeing AI technologies requires human monitoring mechanisms, such as validating outputs, stopping the system and conducting regular audits, in order to limit cyber risks across the supply chain.

The AI Act at the Heart of TPCRM and Cyber Risk Analysis

AI compliance is becoming an essential criterion in supplier assessment, selection and contracting processes. Third-Party Cyber Risk Management (TPCRM) programmes must therefore incorporate the AI Act into their assessment frameworks, audits and recurring pentests. This mapping of third-party cyber risks enables a precise analysis of each supplier's exposure to AI-related risks.

More broadly, strengthening the TPCRM approach through the assessment of suppliers' AI risks is part of a wider Cyber Threat Exposure Management (CTEM) strategy. Ultimately, the objective is to continuously monitor the external attack surface and anticipate cyber threats originating from the supply chain.

The emergence of artificial intelligence and its large-scale deployment among SaaS suppliers are increasing the exposure of companies' external attack surfaces. Companies must now adopt a proactive approach to manage their cyber strategy effectively. To achieve this, CISOs are equipping themselves with tools that help them better identify and remediate vulnerabilities, particularly those originating from third parties. This risk is exacerbated by the growing number of providers within the supply chain. CISOs therefore seek to measure and identify dependency levels in order to understand the impact that a third-party failure could have on the company's overall operations.

This approach also involves legal teams. From the supplier contracting phase onwards, adding security clauses helps define the provider's responsibilities and encourages it to take the appropriate action to reduce risks and comply with requirements, particularly those of the AI Act.

Board of Cyber: Solutions to Support Your Cyber Strategy

In this context, the SaaS solutions provided by Board of Cyber help organisations improve their information security. They create an effective toolkit for analysing and improving the cyber resilience of companies and public-sector organisations. As a genuine management platform, they provide a detailed view of criticality levels and make it possible to identify gaps against the main French and European regulations.

The combination of cyber rating, attack surface analysis and cyber governance solutions provides the foundation for an effective TPRM approach. Identifying cyber vulnerabilities originating from third parties is both a compliance and cyber resilience challenge.

With Security Rating, organisations can automate the assessment of their third parties and scale their monitoring from several dozen to several thousand suppliers. A score from 0 to 1000 is assigned within seconds, helping identify suppliers considered to be "at risk". This continuous rating generates a detailed report that can guide remediation actions with suppliers.

The AI Act is the first legal framework specifically dedicated to artificial intelligence. This Regulation builds on existing legislation such as DORA and NIS2, which are themselves based on cyber risk assessment. Artificial intelligence creates opportunities for companies, which are therefore investing heavily in its deployment, without always fully assessing its actual impact on security and data processing. This is why it is becoming essential for organisations to incorporate the AI compliance of their third parties into their overall cybersecurity strategy. The stakes are compliance, cyber resilience and data governance.

Enjoyed this article? Subscribe to our newsletter so you never miss a new post!

Subscribe