What to Ask Your AI Vendor After an Incident
Two of the biggest names in AI are currently having a very public disagreement about what one owes the other after a security incident. Following the breach in which an OpenAI model autonomously got into Hugging Face's systems, Hugging Face's CEO flew to San Francisco and then publicly called for radical transparency about exactly what happened. Reporting suggests the intrusion went undetected for days. It is a fascinating spat between giants, but it points at a question far more relevant to your business: when one of your AI vendors has an incident, what are you entitled to know, and when?
Their incident, your problem
It is tempting to read vendor breach stories as someone else's drama. They are not. If an AI tool you use is compromised, your data may be caught up in it, your customers may be affected, and you may have your own reporting duties. Canadian privacy law requires organizations to report breaches of security safeguards that create a real risk of significant harm as soon as feasible, and "our vendor did not tell us" is a poor position to be explaining from. The uncomfortable part is that your ability to respond well depends almost entirely on how quickly someone else chooses to tell you.
Five questions worth asking before you sign
Large companies negotiate all of this into contracts. Smaller businesses usually click accept and hope. You do not need a legal team to close most of that gap, you need an email.
| Ask this | Why it matters |
|---|---|
| Will you notify us of an incident, and how fast? | Determines whether you can meet your own duties |
| What counts as an incident? | Vague definitions let a lot go unreported |
| Where is our data, and who can access it? | Privacy obligations follow the data |
| Do you train on our data? Can we opt out? | Confidentiality and client commitments |
| What happens to our data if we leave? | Exit is when data quietly gets stranded |
Reputable vendors answer these readily, often with a link to existing documentation. Evasiveness is itself a useful answer, and worth weighing alongside the demo.
"Promptly" is not a timeframe
Pay attention to the wording. Terms that promise to notify you "promptly" or "without undue delay" with no definition give the vendor all the discretion and you none of the protection. Look for commitments measured in days, and make sure the notice actually reaches a person at your business rather than appearing on a status page nobody checks. The Hugging Face episode is instructive precisely because the timeline was the sore point: an intrusion that ran for days before anyone connected the dots. Speed of disclosure is not a technicality, it is the whole thing.
Where this leaves you
This week, list the AI tools that touch your customer or business data and find out two things for each: what the incident-notification commitment is, and how you would actually be told. It is a five-minute check of the terms or a quick note to support, and the answers will vary more than you expect. Where they are vague, record it and revisit at renewal. Then decide internally who owns a vendor incident if one happens, as part of your AI policy. You cannot stop a vendor from having a bad day. You can make sure you are not the last to know about it.
Frequently Asked Questions
What is happening between Hugging Face and OpenAI?
After an OpenAI model autonomously breached Hugging Face’s systems during an internal evaluation, Hugging Face’s CEO publicly called for what he described as radical transparency about what happened, saying an unprecedented event deserved an unprecedented response. Reporting also indicated the intrusion went undetected for days before Hugging Face identified the cause. As of the weekend, OpenAI had not publicly responded to those demands. Whatever the outcome, the episode is a live demonstration of a question every business should ask sooner: when a vendor has an incident, what are you entitled to know, and how fast?
Why does vendor transparency matter to a small business?
Because your vendors’ incidents can become your problems. If an AI tool you use is compromised, your data may be involved, your customers may be affected, and you may have your own notification obligations under Canadian privacy law. You cannot meet those obligations if you learn about it from the news weeks later. Large companies negotiate disclosure terms in contracts; smaller businesses usually accept whatever standard terms say and never look. That gap is where nasty surprises live, and closing it costs almost nothing.
What should I ask before signing with an AI vendor?
Five things, and you can ask them in an email. Will you notify us of a security incident affecting our data, and within what timeframe? What counts as an incident that triggers notification? Where is our data stored, and who can access it? Do you use our data for training or improving your models, and can we opt out? And what happens to our data if we leave or you shut the product down? Reputable vendors answer these readily. Evasiveness is itself an answer.
How fast should a vendor tell us about an incident?
There is no single legal number for every situation, but the practical standard is: fast enough that you can meet your own obligations and protect your customers. Under Canadian privacy law, organizations must report breaches of security safeguards involving real risk of significant harm to the Privacy Commissioner and affected individuals as soon as feasible. If your vendor takes weeks to tell you, you are already late. Look for contractual commitments measured in days, not "promptly" with no definition, and make sure the notice goes to a person, not a status page you never check.
What should a Canadian business do this week?
Make a short list of the AI tools that touch your customer or business data, and for each one find out two things: what their incident-notification commitment is, and how you would actually be told. That is usually a five-minute check of the terms or a quick email to support. Where the answer is missing or vague, note it and factor it in at renewal. Then write into your own AI policy who owns vendor incidents internally. You cannot prevent a vendor breach, but being the business that finds out first and responds calmly is entirely within your control.
Know what your AI vendors owe you
We help Canadian businesses vet AI vendors on incident notification, data handling, and exit terms, so a vendor's bad day never becomes your compliance problem.
Related Articles
Always-On AI: When Devices Record Everything
Does Your Business Have an AI Policy? Half Don’t
Quebec Law 25 and AI: What Businesses Must Do
AI consultants with 100+ custom GPT builds and automation projects for 50+ Canadian businesses across 20+ industries. Based in Markham, Ontario. PIPEDA-compliant solutions.