**Before connecting customer data to an AI vendor, ask who can access it once it's connected, what happens to it if you cancel, and whether the vendor has actual access controls on the AI system itself.** Verizon's 2026 breach report found a third party involved in 48% of all breaches, up 60% in a year, and IBM's 2026 report found 92% of organizations that suffered an AI-related breach had no real access controls on the AI in the first place.
Why does AI vendor security matter for a small or multi-location business?
Because the vendor is now part of your business's attack surface, whether it's a five-person shop or a five-location group. Verizon's 2026 Data Breach Investigations Report, built from breaches worked between November 2024 and October 2025, found breaches involving a third party jumped to 48% of the total, a 60% increase in a single year (Verizon, 2026). The same report found something specific to AI: unapproved AI tool use by employees — 'shadow AI' — surged from 15% to 45% of employees in a single year (Verizon, 2026). A business doesn't need to run its own AI model to be exposed. It needs one employee pasting a customer list into a tool nobody vetted, or one vendor with broader access to your data than the contract implies.
What did the 2026 breach reports actually find about AI?
IBM's 2026 Cost of a Data Breach Report, based on 602 organizations breached between March 2025 and February 2026, found AI-enabled attacks now account for one in four malicious breaches — up 56% from the year before — and those breaches cost an average of $6 million, about $1 million more than the global average (IBM, 2026). The more useful number for a business picking a vendor isn't the cost, though. It's the cause: among organizations that had an AI-related breach, 92% lacked proper access controls on the AI system, and only 40% of all organizations surveyed had put access controls on their AI models and data at all (IBM, 2026). The failure wasn't the model. It was nobody deciding who's allowed to query it.
| 2026 finding | Figure | Source |
|---|---|---|
| Breaches involving a third party | 48% of all breaches, up 60% year over year | Verizon 2026 DBIR |
| Employees using unapproved ('shadow') AI tools | 45% of employees, up from 15% a year earlier | Verizon 2026 DBIR |
| AI-enabled breaches, share of malicious breaches | 1 in 4, up 56% year over year | IBM 2026 Cost of a Data Breach Report |
| Breached orgs with no real AI access controls | 92% of orgs with an AI-related breach | IBM 2026 Cost of a Data Breach Report |
What should you actually ask an AI vendor before connecting customer data?
- Who can access the data once it's connected — the vendor's support staff, a subcontractor, or only the system itself?
- What happens to the data if you cancel — is it deleted on a defined schedule, or does it sit in the vendor's system indefinitely?
- Is your data used to train or fine-tune the vendor's model for other customers, and can you opt out?
- Is data encrypted both in transit and at rest, and can the vendor show that in writing rather than just claim it?
- For a regulated business — medical, dental, legal, financial — will the vendor sign a business associate agreement or data processing agreement?
- Does every connected integration have access scoped to only what it needs, or does one login open everything?
None of these questions are AI-specific. They're the same due diligence that applies to any software vendor touching customer data. What changed in 2026 is that a business can no longer assume a vendor has answered them just because the product works well in a demo — the IBM data above says most haven't.
Off-the-shelf AI app vs. a system built on infrastructure you own
| Off-the-shelf AI app | Custom-built, on owned infrastructure | |
|---|---|---|
| Where customer data lives | Inside the vendor's shared platform | In accounts and databases the business controls |
| Access if you switch vendors | Often starts over — data doesn't travel with you | Data and history stay with the business |
| Who sets access controls | Whatever the vendor built for every customer | Scoped to exactly what this business needs |
| Compliance agreements (BAA/DPA) | Depends on the vendor's plan tier | Negotiated directly for the business |
When is an off-the-shelf vendor's standard security actually enough?
For a lot of businesses, it is — and saying otherwise would be spin, not honesty. A low-volume business with no regulated data (no health records, no payment card storage, no Social Security numbers passing through the call) that picks a reputable vendor with a public security page, stated encryption practices, and a real support team behind it is taking a reasonable risk. The calculus changes for a multi-location group — a three-office dental practice in Missoula, a property management company running units across Bozeman and Kalispell, a law firm's intake line — where one vendor now touches customer data across every location at once, and where the type of data (health, tenant, or client information) raises the cost of getting it wrong. That's the case where asking for a signed agreement and scoped access, not just a security page, is worth the extra step.