Whose AI Is Inside the Software You Buy?
Here is a question most business owners have never asked about software they use every day: when you click the AI button, whose AI is actually answering? Very few vendors build their own models. They wrap someone else's. A data-protection company just launched an AI product built around Anthropic's tools, and the same pattern runs quietly through countless business applications. Which means buying software with AI features usually means entering a relationship with at least two companies: the one that invoices you, and the one whose model is doing the thinking.
The chain you did not know you joined
This arrangement makes complete sense from every direction. A company that specializes in accounting software or backup and recovery should not be trying to build frontier AI models, and you are better off with them using a strong external model than a weak homemade one. Nobody is doing anything shady. But the effect is that a dependency exists which you never evaluated and probably cannot name. If someone asked you today which AI provider powers the assistant inside your CRM, could you answer? Most owners cannot, and that gap is the whole issue.
Three reasons it actually matters
This is not an abstract governance concern. Each link in the chain creates a practical question you may need to answer.
| What is at stake | Why it can bite |
|---|---|
| Where your data travels | Privacy duties and client confidentiality follow it |
| Continuity of the feature | A provider swap can change quality overnight |
| Who answers when it breaks | Your vendor may be waiting on someone else |
That middle row catches people off guard. The AI feature you built a process around can behave differently next quarter because your vendor changed what is underneath it, and nobody sent an announcement.
One question does most of the work
You do not need a vendor-risk programme. Ask this: which AI providers do you use for these features, and does our data go to them? That surfaces nearly everything that matters. Good vendors answer immediately, often by pointing you at a published list, because larger customers have been asking for years. A vague or reluctant answer tells you something useful too. If you want one follow-up, ask whether they will notify you when they change providers, since that is the change most likely to affect you quietly. Both questions fit in a single short email.
Where this leaves you
Make this a standard question at purchase and renewal rather than a special project. For the handful of AI-enabled tools that touch customer or confidential information, find out which providers sit behind them and whether your data reaches those providers, then write the answers down beside your other AI notes. It is precisely the detail a larger client, or eventually a privacy question, will ask you for, and it pairs naturally with being able to prove you govern AI well. One email per vendor turns an invisible dependency into something you can explain in a sentence.
Frequently Asked Questions
What does "AI supply chain" mean?
It means the chain of companies whose AI ends up inside the product you actually bought. Very few software vendors build their own models. Instead they wrap someone else’s, a data-protection company recently launched an AI product built around Anthropic tools, and countless business applications quietly run on models from OpenAI, Anthropic, Google, or an open-weight provider. So when you buy software with AI features, you are usually entering a relationship with at least two companies: the one that sends you an invoice, and the one whose model is doing the thinking.
Why should I care who is behind the AI features?
Three practical reasons. Data flow: your information may travel to a company you have never heard of, which matters for privacy obligations and client confidentiality commitments. Continuity: if your vendor changes model providers, the behaviour and quality of the feature you rely on can shift underneath you without warning. Accountability: when something goes wrong, you need to know whether your vendor can actually answer for it or is dependent on someone further up the chain. None of these are reasons to avoid embedded AI. They are reasons to know what you bought.
Is embedded third-party AI a bad thing?
No, it is usually the sensible choice for everyone involved. A software company that specializes in accounting or storage should not be trying to build frontier AI models, and you benefit from them using the best available rather than a weak in-house attempt. The problem is not the arrangement, it is the invisibility. Most buyers have no idea which models sit behind the AI features they use daily, which makes it impossible to answer basic questions about where data goes. Transparency, not avoidance, is the fix.
What is the one question to ask?
Ask your vendor: "Which AI providers do you use for these features, and does our data go to them?" That single question surfaces almost everything that matters. Good vendors answer it immediately, often pointing to a published subprocessor list, because enterprise customers have been asking for years. A vague or reluctant answer is itself informative. If you want a follow-up, ask whether they will notify you if they change providers, since that is the change most likely to affect you quietly.
What should a Canadian business do about it?
Make it a standard question at purchase and renewal, not a special investigation. For your handful of AI-enabled tools that touch customer or confidential data, find out which AI providers sit behind them and whether your data reaches those providers. Most vendors publish this. Record the answers alongside the rest of your AI notes, since it is exactly the kind of detail a larger client or a privacy question will eventually ask for. It takes one email per vendor, and it turns an invisible dependency into something you can actually explain.
Know what is really behind your AI features
We help Canadian businesses map their AI supply chain and data flows, so you can answer any client or regulator question without scrambling.
Related Articles
Your Business Software Is Quietly Growing Agents
Do You Know How Many AI Agents You Are Running?
A $500 Model Beat the Frontier at One Job
AI consultants with 100+ custom GPT builds and automation projects for 50+ Canadian businesses across 20+ industries. Based in Markham, Ontario. PIPEDA-compliant solutions.