Third-party AI APIs extend the data boundary
Sending data to an AI provider moves it outside your organisation, whatever the feature is called.
The questions are the ordinary ones for any processor: how long is it kept, is it used for training, who can see it, where is it processed and what happens on termination. The answers differ sharply between providers and between tiers of the same provider. It is a data protection decision, and it is frequently made by whoever was building the prototype.
More on AI supply chain
- A model file is executable trust in another formIt looks like data until you open it
- Dataset provenance matters for security and governanceWhere did this batch come from?
- Model version changes can be security changesOne plate swapped inside
- Evaluation data can leak into trainingIt has already seen the exam
- Fine-tuning credentials are production credentialsThe bench feeds the floor
- Open models shift responsibility toward the operatorThe engine comes with the engine room
