DataGrail report finds your vendor may be sending data to AI models you never approved

TL;DR AI
2 min readKey summary
DataGrail reviewed 2,400 business software vendors and found that 63.6% of AI-feature products did not disclose a third-party AI subprocessor in legal documents.
The report says vendors may be routing data through outside AI models or services that are not visible in contracts, product docs, APIs, or marketing materials.
That lack of disclosure can leave enterprises exposing sensitive data without realizing it, while also complicating compliance reviews and approvals.
DataGrail warns the issue raises privacy, breach, and regulatory risk as companies adopt more AI-enabled software.
