Auditen
sector watch

Where Does the AI Liability End?

The recent breach of AI infrastructure impacting north of 2,500 companies is being framed by the affected firms as an act of God, or at least an act of an incredibly sophisticated adversary. It's the usual script: a "massive supply chain attack" that no one could have foreseen. But if you actually read the NIST guidelines or the technical requirements tucked away in the EU AI Act, the surprise is entirely manufactured.

The reality is that most organisations treating AI as a plug-and-play utility have ignored the plumbing. They've spent the last two years obsessing over "prompt engineering" and whether their chatbots might hallucinate a fake legal precedent, while completely ignoring who owns the servers those bots live on.

This isn't a failure of technology. It's a failure of paperwork.

Under the EU AI Act, providers of high-risk AI systems are required to implement a risk management system that is continuous and iterative. That doesn't mean sending a 50-question spreadsheet to a vendor once a year and filing the response in a digital drawer. It means understanding where your data actually sits. When you outsource your intelligence layer to a third party, who then outsources their infrastructure to a fourth party, you haven't offloaded your risk; you've just obscured it.

The industry has developed a dangerous habit of treating a SOC 2 Type II certification as a holy relic. If the vendor has the certificate, the compliance officer ticks the box and goes to lunch. But a SOC 2 report is a snapshot of a specific set of controls at a specific point in time; it isn't a guarantee that the underlying infrastructure hasn't been compromised by a lateral move from a neglected API.

The most serious event this week proves that fourth-party risk is no longer a theoretical exercise for academics. If 2,500 companies are all leaning on the same compromised AI foundation, they aren't diversified. They're just standing in the same queue for the same disaster.

Some will argue that it's impossible to audit every link in the chain. They’ll claim that requiring a firm to verify the security of their vendor's vendor is an unreasonable burden that stifles innovation.

This is nonsense. You don't have to audit the chip manufacturer personally, but you do have to ensure your contract mandates specific, verifiable security standards and provides for independent verification. Most current AI contracts are laughably vague on this point. They promise "industry standard security," a phrase that means absolutely nothing in a court of law because it doesn't define which industry or which standard is being used.

The second-order effect here will be felt by the professional indemnity insurers.

Until now, insurers have been happy to write policies based on the assumption that AI risk is primarily about data leakage or intellectual property infringement. They haven't accounted for a systemic collapse of the underlying infrastructure. When those 2,500 companies start filing claims, the insurers will look at the due diligence files. If they find that "due diligence" consisted of a single PDF sent via email and a checkbox marked 'Yes', they'll likely argue that the policyholder failed to exercise reasonable care.

We can already see the first signs of genuine caution creeping in. Fluency, for instance, has blocked AI from touching live ad spend across budgets totalling $3 billion. That is a pragmatic response to a systemic risk. It's an admission that the "black box" isn't just opaque: it's potentially volatile.

Meanwhile, the regulators are shifting their gaze. The SEC’s launch of FRAU indicates a move towards more aggressive accounting enforcement, which sounds distant from AI infrastructure until you realise that many of these AI "solutions" are being capitalised on balance sheets as intangible assets. If the underlying tech is breached or proven unstable, those asset valuations may need to be written down.

The question for any compliance officer this week isn't whether their AI vendor is "secure". That's a binary answer to a complex problem. The real question is: who does your vendor trust?

If you can't name the fourth party providing the compute or the data orchestration, you aren't managing risk; you're just hoping for the best. Hope is not a regulatory strategy.

I suspect we'll see a spike in "emergency audits" over the next quarter as firms realise their current vendor questionnaires are useless. They'll look for a silver, sorry, they'll look for a quick fix to prove they've done their homework.

But there isn't one. You either map your supply chain or you accept that you're an accidental passenger in someone else's breach. I’ll be watching the upcoming filings to see how many firms suddenly "discover" a need to update their risk disclosures regarding third-party dependencies. It usually happens just before the fine arrives.

Sources

The reporting this piece was written from. Check the originals before relying on anything here.

  1. Supply Chain Attack Exposes 2,500+ Companies in Largest AI Infrastructure Breach of 2026 So Far - CX Today Data Privacy (Google News)
  2. US SEC’s Consolidated Audit Trail faces overhaul, Atkins says - MLex Compliance Week (Google News)
  3. Steam Data Breach: CEVA Logistics Hack Hits Buyers [2026] - tech-insider.org Data Privacy (Google News)
  4. SEC launches FRAU: A new era in accounting enforcement - Norton Rose Fulbright Compliance Week (Google News)
  5. SEC accuses crowdfunding firm Netcapital of inflating revenue by 345 percent - InvestmentNews Compliance Week (Google News)
  6. IDC Quanta: Your AI Vendor’s Security is Only as Strong as the Vendors It Trusts - IDC | Trusted Tech Intelligence InfoSec Compliance (Google News)
  7. Benjamin Tesfaye Made $18K Trading Calliditas on His Girlfriend’s Merger Tip - hannahhowell.com Compliance Week (Google News)
  8. SEC's Atkins Floats Takeover Of Key Market Surveillance Tool - Law360 Compliance Week (Google News)

How stories are selected and assessed