Quaintitative

AIRG and third-party AI

AIRG and third-party AI: you cannot outsource the accountability

Third-party AI is where the final MAS AIRG tightened most, and where most firms' real exposure sits.

Published 7 October 2026.

Third-party AI is where the final AIRG tightened most, and where most firms' real exposure sits. I developed the AIRG while leading AI risk supervision at MAS. In short, what it now expects for AI you did not build:

  • You retain primary accountability for AI you buy. The decision to onboard and use a third-party model is the firm's, and so is the risk.
  • Limit, suspend, or replace the provider if you cannot bring the residual risk within your appetite.
  • Independent assessments, not self-attestations. External certifications or assessments must come from independent, competent parties.
  • Find the AI you did not procure on purpose. Identification now has to reach AI embedded inside material third-party services, and the shadow AI staff use without telling anyone.

Practically: surface embedded and procured AI into your inventory, run your own compensatory testing on your own data and population rather than accepting vendor assurance as validation, and hold the contract rights that matter, including audit, liability, change-notice, and an exit you could actually use.

Read more

On the discipline behind this, see governing third-party AI and supervising third-party AI. For the overview, see the AIRG is final and what changed from the consultation. Subscribe for the detailed analysis.

Subscribe for updates