Why It’s Important
Organisations need to be aware that many of the AI capabilities provided within their SaaS platforms are called external AI services (from Azure, AWS, OpenAI, Google, etc.). Each of these AI services has its own terms and conditions of use and may process data from your SaaS solutions in ways that are not transparent. Therefore, your SaaS vendor has extended your organisation’s data processing agreements by proxy.
Who’s Impacted
- CEO
- AI developers
- IT teams
What’s Next?
IBRS believes that AI will be embedded in all SaaS products by early 2024.
However, this will also give rise to what IBRS is calling the ‘AI kill chain’. That is, as SaaS solutions embed AI services, these services represent potential new attack vectors as well as legal (contractual and legislative) risks. Furthermore, these AI services the SaaS solutions are using, also make use of other specialised Cloud services, such as vector or graph databases, embedding solutions and so forth. Over time, IBRS expects the AI kill chain will become as convoluted and complex as tracing Open Source software dependencies. New services will likely emerge to assist organisations in understanding the network of interdependencies with AI.
Related IBRS Advisory
1. Five Things to Consider When Evaluating AI… and Five Dangerous AI Misconceptions