DataGrail: 64% of AI vendors fail to disclose subprocessing activity
A DataGrail report indicates that 63.6% of AI vendors fail to disclose sub-processing activity, raising compliance concerns under frameworks like the EU AI Act and CCPA. This lack of transparency complicates vendor due diligence for organizations integrating third-party AI technology into their workflows.
Key Takeaways
- 63.6% of third-party AI vendors fail to disclose subprocessing activity conducted by additional AI providers.
- 32.8% of reviewed AI systems self-disclosed engagement in high-risk processing or automated decision-making.
- Traditional Data Processing Agreements (DPAs) are becoming unreliable as engineering speeds outpace legal documentation.
- Shadow AI creates a 'one-to-many' risk profile, complicating standard web-traffic monitoring used for cloud discovery.
- Under the EU AI Act, organizations may inadvertently breach legislation by failing to identify their role as a 'deployer' of undisclosed AI.
Why It Matters
The streaming industry’s reliance on third-party AI for recommendation engines, ad targeting, and content moderation is now a major compliance bottleneck. Undisclosed subprocessors mean platforms cannot guarantee data residency or consumer privacy rights, potentially exposing them to GDPR and EU AI Act penalties despite existing vendor due diligence. As engineering teams ship features faster than legal can audit, the risk of 'shadow AI' entering the production stack grows. Watch for the emergence of specialized AI screening tools as a mandatory layer in the procurement process to verify subprocessor claims.
Additional Context
The transparency gap identified by DataGrail coincides with the fast-approaching August 2, 2026, deadline for Article 50 of the EU AI Act. This provision requires providers and deployers of generative systems to ensure AI-generated content is identifiable and that users are notified when interacting with AI. Per Wavect (July 2026), these transparency duties apply to 'limited-risk' systems like simple chatbots, making subprocessor visibility critical for companies that may not realize their secondary vendors have integrated generative components. Failure to meet these machine-readable marking and disclosure duties can result in fines of up to €15 million or 3% of worldwide turnover.
Domestic regulations are adding further pressure on vendor governance. In California, the Privacy Protection Agency (rebranded as CalPrivacy) enacted rules effective January 1, 2026, requiring businesses to conduct mandatory risk assessments for any processing that presents a secondary risk to consumer privacy, including the use of automated decision-making technology. According to Wiley Law (October 2025), businesses must submit certifications of these assessments by April 2028, but the underlying work must begin now. For streaming platforms, this means every vendor in the ad-tech and personalization stack must be audited for undisclosed AI that could trigger these high-stakes reporting requirements.
The scope of the problem is amplified by employee behavior. Recent data from Teramind (July 2026) suggests that up to 89% of workplace AI use currently escapes formal enterprise governance. While IT teams may believe their stack is compliant through signed DPAs, the reality of the 'one-to-many' relationship in AI means that a single approved vendor using multiple undisclosed subprocessors can create a cascade of regulatory liability. This 'invisible epidemic' has already led to estimates that shadow AI-related breaches cost organizations an average of $670,000 more than sanctioned IT incidents, per IBM (2025).
Read full article at iapp.org
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source