Your suppliers are using AI – So are you paying less?

Your suppliers are using AI – but are you paying the same for less? | Better AI Decisions

Home / AI Risks

AI RISKS

Your suppliers are using AI — but are you paying the same for less?

You’ve thought carefully about how you use AI in your own business. Good. But your accountant is using AI. So is your marketing agency, your courier, your IT provider, and quite possibly your payroll platform. Their AI decisions – good or bad – can land squarely on your desk, your data, and your bank balance.

Every supplier who touches your data, your money, or your customers is now probably using AI somewhere in their process, whether they’ve told you or not. That creates two separate risks: they may be cutting their own costs with AI without passing any of the saving on to you, and they may be creating data protection or service problems that become legally and financially your responsibility, not theirs.

This is a starting point. It sets out the six places supplier AI risk usually hides, and links through to a detailed article on each one, plus a full audit checklist you can actually use.

The short answer

You don’t need to interrogate every supplier about every technical detail. But you should know enough to answer five basic questions:

  1. What are they using AI for?
  2. What information are they giving it?
  3. Who else gets that information?
  4. Who checks the results?
  5. And who pays the price when it goes wrong?

There’s a sixth question worth asking too: if AI has made their service cheaper to deliver, how are you benefiting?

The fix is simple to describe, if not always simple to do: ask each supplier what AI they use, where your data goes, and who’s on the hook if it goes wrong.

We’ll send a password for the resource area and regular UK-focused AI updates. Unsubscribe anytime.

It’s not just your AI. It’s your suppliers’ AI too.

Most of the advice about AI and small business focuses on the tools you use directly – ChatGPT, Copilot, whatever’s plugged into your own systems. That’s useful, but it’s only half the picture.

Think about how many other organisations already touch your business data in a normal month. Your accountant sees your financial records. Your marketing agency sees your customer list. Your courier sees your delivery addresses. Your IT provider, your payroll platform, your booking system – all of them hold a slice of your business.

Think about all the information you’ve given to suppliers:

  • customer information
  • employee information
  • financial records
  • invoices
  • marketing data
  • sales information
  • passwords and system access
  • confidential business information
  • commercially sensitive information

You gave them that information because you trusted them to provide a service. But what happens when they introduce AI? You might not even know they’ve done it. That’s the first problem.

The second is that their AI-related mistake can become your problem.

A supplier’s AI could produce an incorrect document. A marketing agency could publish inaccurate information about your business. A software provider could change how your data is processed. A courier’s automated system could send customers the wrong information. An AI system could expose confidential information.

And you may still be the business that has to explain what happened to your customer.

The ICO’s guidance specifically recommends due diligence when organisations use third parties for AI systems or outsourced AI processing. It also says organisations should regularly review outsourced services because new risks and compliance considerations can arise after deployment.

So the question isn’t simply:

“Are we using AI safely?”

It’s:

“Are the businesses we trust using AI safely with our information, our customers and our reputation?”

Tip

Start with one supplier, not all of them

Don’t try to audit every supplier relationship in one afternoon. Pick the one that holds your most sensitive data, or the one you’d struggle most without, and start there. Working through one properly beats sending the same vague email to twenty suppliers and getting twenty vague replies.

The question nobody asks

Here’s an uncomfortable one. Your suppliers are using AI to cut their own costs – less staff time, faster turnaround, work that used to take a person an hour now taking a few minutes. That’s a legitimate business decision on their part.

The question is what happens to that saving. Most suppliers will simply keep it. Nobody’s obliged to pass efficiency gains on to you, any more than you’re obliged to pass yours on to your customers. But you’re entitled to ask.

Imagine you pay an external marketing company £1,000 a month. Previously, they employed someone to write your social media content. Now they use AI to create the first drafts in a few minutes. Their costs have fallen. But your bill hasn’t.

Perhaps that’s perfectly reasonable. They still provide strategy, editing, account management, creative direction and other services. But perhaps you’re paying the same amount for a significantly cheaper service. You won’t know unless you ask.

Ask your supplier:

“You’re using AI to make this work more efficient. How does that efficiency benefit us?”

That’s a much better question than:

“Are you using AI?”

And you can go further:

“Has AI changed the amount of human work involved in delivering our service, and has that affected your pricing?”

You aren’t accusing your supplier of doing anything wrong. You’re asking a perfectly reasonable commercial question. AI is changing the cost of delivering many services. You should understand how that affects your relationship with the supplier.

Your accountant’s AI

Your accountant or bookkeeper may already be feeding your financial data into AI tools – for reconciliation, tax planning, forecasting, or flagging anomalies. That can be genuinely useful. It can also go wrong quietly, because financial data is exactly the kind of information you don’t want mishandled.

Your accountant probably has access to some of the most sensitive information about your business. Depending on your relationship, they may handle:

  • accounts
  • invoices
  • payroll information
  • employee details
  • tax information
  • bank information
  • business performance
  • forecasts
  • commercially sensitive information

Now imagine some of that information is being processed through an AI system. You need to know what’s happening. Not because your accountant is necessarily doing anything wrong. AI can potentially make accounting work faster and more efficient. The question is whether you understand the system being used.

Worth knowing before your next conversation with them: where does the data go once it leaves their system, who actually owns the output an AI tool produces on your behalf, and what happens if the AI gets something wrong on your tax return or management accounts?

Ask your accountant:

  • Are you using AI to process any information relating to my business?
  • What AI tools are you using?
  • What information is being sent to those tools?
  • Is any of my personal data being processed?
  • Is my information being used to train an AI model?
  • Where is the information processed and stored?
  • Are any third-party AI providers involved?
  • Are those providers acting as processors or in another capacity?
  • How is AI-generated work checked by a human?
  • Who is responsible if the AI produces an incorrect result?
  • Has your use of AI changed the way my information is handled?

You don’t need to understand the technology. You need to understand what happens to your information.

The ICO says organisations need to establish the roles and responsibilities involved when personal data is processed through AI, and that organisations outsourcing AI systems should carry out appropriate due diligence.

“A high street accountancy firm using AI to speed up a VAT return is one thing. Not knowing whether that AI tool was trained on client data, or where it’s hosted, is another.”

Your marketing agency’s AI

If you use a marketing, SEO, or branding agency, there’s a good chance AI is already involved in your campaigns – drafting copy, generating images, planning content, even writing your social posts. Some of this is fine. Some of it quietly damages your brand, because generic AI content tends to sound generic, and customers notice.

Marketing may be one of the areas where AI has changed supplier costs most dramatically. Your agency might now use AI to:

  • write first drafts
  • generate social media content
  • produce advertising variations
  • create images
  • analyse campaigns
  • research audiences
  • generate ideas
  • create video
  • personalise content

Again, none of this is automatically a problem. The problem is not knowing what you’re paying for and what happens to your information.

Ask:

“Which parts of the work are now being produced or assisted by AI?”

Then ask:

“Which parts are still being done by a human?”

And:

“Has your use of AI changed what I’m paying for?”

There’s a sharper risk too. If your agency has used your customer data – email lists, purchase history, past campaign results – to train or fine-tune an AI tool, that can amount to a data protection problem you didn’t sign up for. The ICO notes that if you’re using a third-party tool, it’s worth thinking about what data is being shared and how the platform will use it, including whether it’s used for training purposes.

Before that information is put into an AI system, you need to understand what is happening to it. The ICO says contracts involving processors should clearly establish what personal data is processed, why it is processed, how it is protected and what happens if sub-processors are used.

So don’t accept:

“Don’t worry, our AI is secure.”

Ask for something more useful:

“Which AI systems process our information, what information do they receive and what happens to that information?”

Caution

Generic AI content under your name

If your agency is using AI to write blog posts, social captions or ad copy on your behalf, ask to see examples before they go live under your business name. AI-drafted content that hasn’t been properly edited tends to read the same regardless of which business it’s for – which undermines exactly the thing a good agency is meant to give you. A customer doesn’t care that your agency used an impressive AI system. They care whether your business sounds authentic.

Your courier and logistics partners’ AI

If your business relies on couriers, delivery firms, or a removals and haulage partner, AI is now doing a lot of the invisible work – route planning, delivery time predictions, automated customer notifications, even chatbot-handled queries when something goes wrong.

Courier and logistics businesses increasingly use technology to help with:

  • route planning
  • delivery scheduling
  • estimated delivery times
  • tracking
  • warehouse operations
  • customer notifications
  • demand forecasting
  • vehicle utilisation

Most of the time this makes deliveries faster and more predictable. When it fails, though, it fails in a way your customer experiences as your problem, not your courier’s.

Imagine you run an independent online furniture business. A courier’s automated system tells your customer their £2,000 dining table will arrive on Tuesday. It doesn’t. The customer contacts you. You contact the courier. The courier tells you the system made an error.

Your customer doesn’t care whose AI made the mistake. They’re angry with you.

That’s the important distinction. Your supplier’s technology may be their problem operationally. But the customer relationship is still yours.

A parcel marked “delivered” that never arrived. An automated notification with the wrong time window. A chatbot that can’t answer a real question about a late order. Your customer doesn’t ring your courier. They ring you.

A small e-commerce brand or a local retailer that ships nationally is particularly exposed here, simply because so much of the customer relationship after checkout sits with a delivery partner you don’t fully control.

Ask your logistics supplier:

  • How much of your delivery operation is automated?
  • Where is AI used?
  • What happens when the system produces an incorrect result?
  • Is there human oversight?
  • How quickly can an automated decision be overridden?
  • What happens if the system goes down?
  • How are customers notified when information is wrong?
  • Who contacts customers when a delivery problem occurs?
  • What is your escalation process?

You don’t need a technical explanation. You need to know:

“If your system gets this wrong, what happens next?”

That’s a business continuity question. Your supplier’s automation can become your reputation problem.

This is particularly important for businesses where customer experience is part of the brand. A small luxury gift retailer, for example, may have spent years building a reputation for excellent service. If its courier sends customers automated messages containing incorrect information, customers don’t blame an algorithm. They blame the retailer.

That’s why supplier AI needs to be part of your wider supplier management.

Your IT and software providers

This is probably the area where you need to pay particularly close attention.

AI is being added to business software at an extraordinary rate. Your:

  • CRM
  • accounting system
  • HR platform
  • email system
  • document management system
  • customer service platform
  • website software
  • cloud storage
  • cybersecurity system

may now have AI features.

And because these systems already contain your information, the AI may have access to information you’ve already given the supplier. You may not have actively decided to put that information into an AI system. It may simply have appeared as a new feature.

The AI feature you never asked for

Imagine you run a small recruitment company. Your CRM contains candidate CVs, names, addresses, employment history, telephone numbers, email addresses and interview notes.

Your CRM supplier introduces an AI assistant. It can summarise candidate records. Sounds useful.

But what information can it access? Where is that information processed? Is it optional? Can you turn it off? Does enabling it change the supplier’s terms? Are additional providers involved?

These are not theoretical questions. They are questions you should ask whenever a supplier introduces a significant new AI capability into a system holding your information.

At the same time, many providers have been updating their terms and conditions to allow broader use of your data, including for AI training, in ways that weren’t there when you first signed up. This is worth an actual five minutes of reading, not just clicking accept.

A veterinary practice using AI-assisted scheduling software, or a recruitment agency running candidate data through an AI-enabled applicant tracking system, should know what “we may use your data to improve our services” actually covers.

Ask:

  • What does the AI feature do, and can you turn it off if you don’t want it?
  • Have the terms and conditions changed recently, and what changed?
  • Is your data used to train models that other customers’ AI features then benefit from?
  • Who do you contact if the AI feature gets something wrong?

Read the small print

Don’t just read the sales page. Look at:

  • terms and conditions
  • privacy notices
  • data processing agreements
  • AI-specific terms
  • sub-processor information
  • acceptable-use policies
  • changes to service descriptions

Look particularly for language concerning: training, service improvement, analytics, machine learning, AI, third-party providers, sub-processors, data retention, and international transfers.

The presence of these words doesn’t automatically mean your supplier is doing something wrong. But they should prompt a question.

Don’t assume “it’s our software, so it’s our data”

The contractual position can be more complicated. Who controls the information? Who processes it? What does the supplier do with it? Are they acting on your instructions? Are they using it for their own purposes? Are other processors involved?

The ICO says that organisations need to determine controller and processor roles based on what actually happens to the data, not simply on what the contract happens to call the parties.

Here’s the part that catches most small business owners out. When you share data with a supplier, you’re trusting them to protect it. But under UK data protection law, that trust doesn’t transfer the responsibility away from you.

UK GDPR holds you accountable as the data controller even when a third-party processor causes a breach. If a supplier’s AI tool leaks data, gets hacked, or mishandles something, the ICO can hold you responsible if you failed to carry out adequate due diligence, lacked a compliant data processing agreement, or couldn’t demonstrate that you’d assessed the supplier’s security.

In other words: their mistake, but potentially your fine.

This isn’t theoretical. One of the UK’s most well-known data breaches happened after an attacker used compromised credentials from a third-party supplier to move through the retailer’s own systems – a reminder that supply chain weaknesses can become front-page problems for the business whose name is on the door, not the supplier’s.

Every time you give information to a supplier, you’re extending your business’s information environment beyond your own walls. Your accountant has information. Your marketing agency has information. Your IT company has information. Your payroll provider has information. Your CRM has information. Your courier may have customer addresses and contact details.

You may have excellent security internally. But what happens if one of those suppliers doesn’t?

This is why supplier security isn’t just an IT issue. It’s a business risk.

Caution

A Data Processing Agreement isn’t optional

If a supplier processes personal data on your behalf – customer names, addresses, payment details, anything identifiable – you should have a written data processing agreement in place, not a verbal understanding or an assumption that “they’ll have sorted all that.” If a supplier can’t produce one, or waves the question away, treat that as a warning sign, not a technicality. A small professional services firm, a private dental clinic, or a home care agency – all handling sensitive client information day to day – carry more exposure here than most, simply because of what’s in the data they share with suppliers.

You don’t have to trust every supplier equally

Not every supplier needs the same level of scrutiny. There’s a big difference between a supplier that delivers stationery and a supplier that stores your entire customer database.

The ICO recommends proportionate due diligence when selecting processors and says organisations should consider the sensitivity of the personal information involved, the likely threats and the impact of loss, damage or disruption.

High-risk supplier? Ask more questions:

  • What information do you hold?
  • Why do you need it?
  • Who can access it?
  • Which third parties process it?
  • Are AI systems involved?
  • Where is it stored?
  • How is it protected?
  • What happens if there is a security incident?
  • How quickly will you tell us?
  • What happens when our contract ends?
  • Will our information be deleted or returned?

What happens when you leave?

This is an easy question to forget. Suppose you change CRM suppliers. Or move accountants. Or change payroll providers. Or move your marketing agency. What happens to the information they hold?

The ICO’s guidance says processor contracts should include provisions concerning what happens to personal data at the end of the contract, including deletion or return where appropriate.

So ask:

“When we leave, what happens to our data and any copies held by your AI or sub-processors?”

That’s a much more useful question than simply asking:

“Is our data secure?”

What happens when their AI gets it wrong?

This is perhaps the biggest issue of all.

AI can make mistakes. Your supplier can make mistakes. Put the two together and you have a risk you need to understand.

Imagine your HR provider uses AI to help analyse employee information. Or your marketing agency uses AI to create claims about your products. Or your accountant uses AI as part of a financial workflow. Or your IT supplier uses AI to detect threats. Or your courier uses AI to make delivery decisions.

The key question is: where does the human responsibility sit?

You shouldn’t assume:

“The supplier uses AI, so the supplier is responsible for everything.”

Your contract may not say that. And even where the supplier is contractually responsible for something, that doesn’t necessarily remove the practical consequences for your business. Your customer may still contact you. Your regulator may still contact you. Your staff may still be affected. Your reputation may still suffer.

Ask about human oversight

For important services, ask:

  • What decisions does AI make?
  • What decisions does AI recommend?
  • Which decisions are reviewed by a human?
  • When is human intervention required?
  • Can an AI decision be reversed?
  • Who is accountable for the final decision?
  • What happens when the AI produces an obviously wrong result?
  • How are errors recorded?
  • How are customers or clients informed when something goes wrong?

The ICO’s AI guidance specifically highlights accuracy and human review as areas that need consideration when organisations use AI.

You don’t need to ban AI from your supply chain. You need to understand where human responsibility remains.

The complete supplier AI audit

You don’t need a legal team to get a reasonable handle on this. You need a consistent set of questions you ask every supplier who touches your data, your money, or your customers, and a habit of actually reading the answers rather than filing them away.

A proper supplier AI audit covers four areas:

1. AI usage

  • Where is AI being used?
  • What is it being used for?
  • How much of the service is automated?
  • Where is human oversight provided?

2. Data

  • What information is processed?
  • Where is it stored?
  • Who can access it?
  • Are third-party AI systems involved?
  • Are sub-processors used?

3. Cost

  • Has AI changed the cost of delivering the service?
  • Has the amount of human work changed?
  • Has the supplier’s pricing changed?
  • Are you receiving any benefit from increased efficiency?

4. Risk and responsibility

  • Who is responsible when AI gets something wrong?
  • What happens when the system fails?
  • How quickly are incidents reported?
  • What happens when the contract ends?
  • What happens to your data?

You don’t necessarily need every supplier to answer all 18 questions in the same depth. A stationery supplier doesn’t present the same risk as your payroll provider. Use the audit proportionately.

Five questions you can ask every supplier today

If you don’t have time to conduct a full audit, start here.

1. Are you using AI to provide any part of the service you provide to us?

Don’t stop at yes or no. Ask what it’s being used for.

2. Does your AI process any information belonging to us, our customers or our employees?

You want to know exactly what information is involved.

3. Are any third-party AI providers or sub-processors involved?

If so, who are they? The ICO says processor arrangements should address the use of sub-processors and the required contractual protections.

4. How is AI-generated work checked?

This tells you where the human responsibility sits.

5. Has your use of AI changed the cost or level of human work involved in providing our service?

This is the commercial question that many businesses simply don’t ask.

Don’t make this adversarial

There’s an important point here. This isn’t about accusing suppliers of using AI. AI can make their businesses more efficient. That’s potentially good for everyone. You want suppliers who use technology intelligently.

The goal is simply to understand:

  • what they’re doing
  • what information is involved
  • what you’re paying for
  • and what happens when things go wrong

A good supplier should be able to have that conversation with you. And if they can’t answer basic questions about how they handle your information or how AI is being used to deliver your service, that’s useful information too.

Most suppliers are ordinary businesses trying to do good work, same as you. A local courier firm or a family-run accountancy practice isn’t hiding anything sinister – they may simply not have thought through the AI questions any more than you had before reading this.

Asking these questions isn’t awkward if you frame it well. Most reasonable suppliers will respect a client who asks sensible questions about data and cost. The ones who bristle at being asked are usually telling you something useful about how seriously they take it.

Your suppliers’ AI is part of your AI risk

You don’t have to control how your suppliers use AI. You do need to understand the consequences for your business.

Your accountant’s AI can affect your financial information. Your agency’s AI can affect your brand. Your courier’s AI can affect your customers. Your software provider’s AI can affect your data. Your IT provider’s AI can affect your systems. And any supplier’s AI can potentially create problems that you end up having to deal with.

That’s why supplier AI belongs on your business risk checklist. Not because AI is inherently dangerous. Because you are responsible for the business decisions you make about who you trust with your information, your customers and your reputation.

Supplier AI Risks AI and Data Protection Small Business UK Business Practical AI

AI FAQs

Questions people ask about supplier AI risks

These are the practical questions UK business owners are asking about AI in their supply chain.

Do I need to ask every supplier whether they use AI?

Not necessarily. Prioritise suppliers according to the information they hold, the importance of their service and the consequences if something goes wrong. A supplier handling sensitive customer information deserves more scrutiny than one delivering office supplies.

Is my supplier allowed to use AI with my business data?

There isn’t a simple yes-or-no answer. It depends on what data is involved, what the supplier is doing with it, the legal basis and the contractual relationship. If the supplier is processing personal data on your behalf, UK GDPR processor requirements can apply.

Is it a GDPR breach if my marketing agency puts customer data into AI?

Not automatically. The circumstances matter. You need to understand what personal data is being processed, why, by whom, under what legal basis and through which processors or sub-processors. The ICO recommends appropriate due diligence and clear contractual arrangements when third parties are involved in AI processing.

Am I liable if my supplier has a data breach?

Potentially, yes. Under UK GDPR, you remain accountable as the data controller even when a third-party processor causes the breach, particularly if you didn’t carry out reasonable checks on the supplier or have a proper data processing agreement in place. Liability can be shared between you and the supplier depending on where the failure actually occurred.

Do I need a data processing agreement with every supplier?

You need one with any supplier who processes personal data on your behalf – most accountants, marketing agencies, IT providers, and payroll platforms fall into this category. Suppliers who act as independent controllers of their own data don’t need one from you, but it’s still worth understanding how they handle information about your business.

Can I ask my supplier whether they use AI?

Absolutely. In fact, it is a sensible commercial question, particularly where AI may affect how your service is delivered, how your information is processed or how much human work is involved.

Can I ask a supplier to reduce my bill because they use AI?

You can certainly ask. Whether you’re entitled to a reduction will depend on your contract and the nature of the service. AI making a supplier more efficient does not automatically mean your contractual price must fall. But it is reasonable to ask whether increased efficiency is reflected in pricing or service levels.

Who is responsible if my supplier’s AI makes a mistake?

That depends on the circumstances and your contract. Don’t assume that the supplier automatically carries all the consequences. Your business may still have to deal with the customer, financial or reputational impact even when the original error happened in a supplier’s system.

Should I stop using suppliers that use AI?

No. AI can make suppliers faster, more efficient and potentially better. The issue isn’t whether they use AI. It’s whether they use it appropriately and whether you understand the resulting risks.

What should I do if a supplier won’t tell me how it uses AI?

Start by explaining why you’re asking and identify the specific information you need. If the supplier handles sensitive information or provides a critical service and refuses to provide reasonable assurances, consider whether that supplier presents an unacceptable risk.

What is a supplier AI audit?

It’s a structured set of questions that helps you understand how a supplier uses AI, what information is involved, what third parties are involved, how AI-generated work is checked, how costs may have changed and what happens when something goes wrong.

How do I know if my current suppliers are already using AI?

Many won’t volunteer it unless asked. Start with the checklist referenced in this article, and ask directly. If a supplier’s pricing or turnaround time has changed noticeably in the last year or two without an obvious explanation, AI adoption is often part of the reason.

Sources

  1. Information Commissioner’s Office — Contracts and third parties (AI risk toolkit) ★★★★★ Data protection
    Official ICO guidance on the contractual risks and control measures needed when third parties are involved in AI processing on your behalf.
  2. Information Commissioner’s Office — How do we ensure lawfulness in AI? ★★★★★ Data protection
    ICO guidance on the data protection considerations when implementing or relying on third-party AI systems, including purpose limitation.
  3. Information Commissioner’s Office — AI and accountability ★★★★★ Data protection
    The ICO explains how controller and processor relationships can operate in AI systems and specifically discusses organisations outsourcing or purchasing third-party AI solutions.
  4. Information Commissioner’s Office — Contracts and data sharing ★★★★★ Data protection
    The ICO recommends proportionate due diligence, written contracts, supplier reviews and maintaining records of processor relationships.
  5. Information Commissioner’s Office — IT supplier relationships ★★★★★ Data protection
    The ICO recommends risk assessments, due diligence, appropriate contractual security requirements and periodic reviews of IT supplier arrangements.
  6. Sprintlaw UK — Who is responsible for a data processor’s actions under UK GDPR ★★★★☆ Legal
    Explains how liability can be shared between controllers and processors, and the practical steps businesses should take to manage supplier risk.
  7. Harper James Solicitors — Are you liable if your supplier suffers a data breach? ★★★★☆ Legal
    Sets out the legal position on controller liability for supplier-caused data breaches under UK data protection law.
  8. ITC UK — Third party risk management: UK GDPR & NIS2 ★★★☆☆ Data protection
    Practical explanation of how the ICO assesses due diligence failures when a breach originates with a supplier rather than the business itself.
  9. Wikipedia — British Airways data breach ★★★☆☆ Case study
    Background on a well-documented UK case where a supply chain weakness through a third-party supplier led to a major data breach.

⚠️ Evidence note: The legal position on controller and processor liability described here reflects established UK GDPR principles and ICO guidance, and is well supported. Exactly how liability is apportioned between you and a supplier in any specific incident depends on your contracts, what due diligence you carried out, and the facts of the case, so treat the general principle as reliable and the specifics as something to check with a data protection professional if you’re ever facing an actual incident.

There is an important distinction between a supplier using AI and a supplier using AI unlawfully or irresponsibly. AI use by itself does not establish a data-protection breach. The legal position depends on the data involved, the purpose of processing, the roles of the organisations involved, the contractual arrangements, the safeguards and other circumstances.

Similarly, a supplier becoming more efficient through AI does not automatically mean that its prices should fall. That is a commercial negotiation rather than an automatic legal entitlement.

The purpose of this article is therefore not to tell you that suppliers shouldn’t use AI. It is to give you the questions you need to decide whether their use of AI is acceptable for your business.

This article is general guidance, not legal advice.

Make one supplier AI decision better

You can’t audit every supplier relationship this week, and you don’t need to.

Pick the one supplier who holds your most sensitive data or matters most to your customers, and ask them one direct question:

“Are you using AI to provide services to us, and if so, what does that mean for our data, our service and our responsibilities?”

Then listen carefully to the answer.

You may discover that your supplier has excellent controls. You may discover that AI has made their service considerably more efficient. Or you may discover that you’ve been trusting a system you never knew existed.

The important thing is that you know.

Explore more practical guidance →