self-service analytics tools

Your Vendor's Data Pacts May Be Sending More Than You Approved

A new report from DataGrail reveals a troubling reality for companies utilizing AI-driven software: 63.6% of vendors fail to disclose third-party AI subprocessors in their data processing agreements (DPAs). This…

3 min readVentureBeat
Your Vendor's Data Pacts May Be Sending More Than You Approved

The insights from DataGrail's recently released *Privacy and AI Trends Report 2026* highlight a critical and troubling trend: the foundational trust in data processing agreements (DPAs) is eroding. An alarming 63.6% of software vendors that promote AI capabilities fail to disclose third-party AI subprocessors within their legal documentation. This raises significant concerns for businesses that rely on these agreements to ensure the safety of their customers' data. With the rapidly evolving landscape of AI technologies, organizations may be unwittingly subjecting sensitive information to models and processes they have not evaluated or approved. As highlighted in our coverage of AI’s expanding role in finance with articles like Robinhood now lets your AI agents trade stocks, the implications of such oversight could extend into various sectors, affecting not just privacy but operational integrity as well.

The findings indicate a growing chasm between the legal frameworks that companies depend on and the actual practices of their software vendors. Daniel Barber, DataGrail’s CEO, underscores the urgency of this issue by stating that the evolution of AI technologies is outpacing the governance structures designed to manage their risks. When companies invest in AI tools, they typically conduct due diligence on the vendor’s DPA. However, if undisclosed AI subprocessors are involved in data processing, the potential for data breaches escalates, leading to severe financial and reputational repercussions. This situation is particularly alarming given that organizations with significant shadow AI—unregulated or unauthorized use of AI tools—face breach costs that are significantly higher than those with controlled environments, as noted in IBM's 2025 Cost of Data Breach Report.

The report also shines a light on regulatory pressures that are intensifying around data privacy. In 2025 alone, U.S. states imposed $3.425 billion in privacy-related fines, reflecting a growing trend of stringent enforcement actions. With the implementation of new laws such as the California Consumer Privacy Act (CCPA), companies will be required to conduct thorough risk assessments for any processing activities that pose significant privacy risks. The implications are clear: organizations must not only adapt to the complexities of modern AI applications but also ensure that their compliance measures are robust enough to withstand an increasingly vigilant regulatory landscape. As we discussed in the article TechCrunch Disrupt 2026 Early Bird ticket savings end in 3 days, the pressure for companies to innovate while maintaining compliance has never been greater.

Moving forward, the challenge lies in how organizations will navigate this intricate web of accountability and innovation. As AI technologies continue to proliferate, the risk of unvetted data processing will only escalate, particularly with the advent of agentic AI, which could autonomously distribute data across systems without human oversight. Companies must rethink their data governance frameworks and prioritize transparency in vendor relationships. The question remains: how can businesses ensure they are not only compliant but also resilient in a rapidly changing technological landscape? The need for a proactive approach to privacy and AI governance is paramount, and organizations that can adapt swiftly will likely emerge as leaders in this new data-driven era.

From VentureBeat

The data processing agreement (DPA) — the bedrock contract companies use to evaluate how vendors handle personal data — can no longer be trusted at face value. That is the central, and arguably most alarming, conclusion of DataGrail's Privacy and AI Trends Report 2026, released today.

Read the original at VentureBeat