The Vendor Assurance Letter Is No Longer Enough
For years the standard executive response to AI vendor risk has been to commission a security review, request an assurance letter and move on. The Australian Signals Directorate has now said, in as many words, that this is not sufficient.
ASD’s guidance, reported by iTnews, names foreign control of AI vendors as a board-level risk. Read that as a governance signal rather than a technical one. It closes a gap a good number of executives have been quietly sheltering in.
What ASD Is Saying
The guidance is notable less for what it introduces than for what it stops tolerating. Who ultimately controls an AI vendor — not who owns the local entity or signs the enterprise agreement, but who controls the model, the training infrastructure, the data pipelines and the corporate parent — has been an awkward question for Australian organisations to raise, and vendors have had every incentive to keep it awkward.
Naming it as a board-level risk removes the awkwardness, and with it the cover. Ownership opacity has been legal’s problem, or procurement’s, or the vendor’s. There is now a document from Australia’s signals intelligence body telling boards it is theirs.
The Vendor Market Has No Incentive to Fix This
The AI vendor market is structurally opposed to making foreign control legible to customers, which is not something you will read in vendor-led content.
The major platforms are predominantly US-domiciled, with capital structures, board compositions and government relationships only partially visible to enterprise buyers. Some have parent companies carrying significant foreign investment. Several operate under legal frameworks that create compelled disclosure obligations to foreign governments. None of them gain anything commercially by making that clear during a sales cycle.
The assurance letters confirm security controls, data residency commitments and compliance certifications. They are not designed to address what happens when a foreign government makes a request the vendor cannot lawfully refuse, or when a restructure moves control of a critical model into a jurisdiction with different rules. That is the architecture of the market as it stands, not a hypothetical.
Plausible Deniability Has a Shelf Life
The executive calculation has been rational, up to a point. If regulators and guidance bodies were not pressing the question, and vendors were not volunteering the answer, there was limited incentive to surface a problem that might stall a business-critical AI deployment.
That calculation no longer holds. ASD has put foreign control on the board agenda. CPS 234 already requires boards to understand material risks in their information security arrangements, the SOCI Act carries obligations for critical infrastructure operators that get more relevant every time AI is embedded further into operations, and Privacy Act reform keeps tightening expectations around data governance. The direction of travel is accountability for decisions executives have been treating as vendor decisions.
An executive who approved an AI deployment on the strength of an assurance letter, without asking who controls the vendor, is exposed today in a way they were not last year. The risk did not change. The standard of care did.
What Boards Should Ask
The meeting where someone holds up the ASD guidance and asks “are we covered?” is coming. For most organisations running enterprise AI tools the honest answer is that nobody has looked in any meaningful way.
The questions are structural rather than technical:
- Who is the ultimate beneficial owner of this vendor, and has that changed in the last 18 months?
- What legal jurisdiction governs compelled disclosure obligations for this vendor’s infrastructure?
- If the vendor’s corporate structure changes — acquisition, restructure, government intervention — what contractual protections does the organisation have?
- Has the board been told which AI systems are now material to operations, and what the dependency looks like?
No vendor will volunteer answers to these. The organisation has to ask, write down what it hears, and escalate what it does not.
The Uncomfortable Position for CIOs and CTOs
There is a particular tension here for technology executives. Plenty of CIOs and CTOs have been advocates for AI adoption, often correctly, and have built the vendor relationships now sitting at the centre of the capability roadmap. They are also the people the board will turn to for assurance about those same relationships.
The professional risk in that is real. If you championed a deployment without surfacing the control question, and an ASD document has just raised it at board level, the instinct is to defend the original decision. It is worth resisting. The stronger position, and the one that protects your standing, is to say plainly that the standard of scrutiny has moved, commission a structured review of AI vendor arrangements against the ASD framework, and give the board a clear account of what is known, what is not, and what needs deciding.
The Takeaway
Guidance bodies rarely name a specific category of commercial relationship as a board-level risk without softening it on the way out. ASD has. Foreign control of AI vendors has stopped being a procurement matter and become a governance one.
Treating it as a compliance exercise — another review, another letter, another sign-off — puts you in the same position in eighteen months, when the next iteration of the guidance arrives with more teeth behind it. The work that will still be worth something then is genuine visibility into who your AI dependencies actually answer to.