Skip navigation Jump to main navigation

The Party of Three Nobody Wanted to Attend

By Tahmina Day, Part-Time Lecturer in the Enterprise Risk Management (ERM) Program, School of Professional Studies; Global Head of ESG and TPRM, Archer Technologies

On April 19, 2026, Vercel disclosed that attackers had reached its internal systems. The breach did not come from a flaw in Vercel’s own defenses. It came through a third-party vendor tool, an AI assistant called Context.ai used by one of Vercel’s employees, that had been quietly infected months earlier. From that single foothold, attackers reached source code, API keys, and employee records. 

The damage did not stop with Vercel. Because Vercel hosts the front ends of hundreds of thousands of companies, the breach reached organizations that had no relationship with Context.ai at all. They had never used it, never assessed it, and never knew it existed, yet they spent the following days rotating credentials to protect themselves from a compromise that began inside their vendor’s vendor.

This is no longer the exception. The 2026 Verizon Data Breach Investigations Report, an annual study of real-world breaches, found that breaches involving a third party had reached 48%, nearly half of all breaches, up from 30% a year earlier. The harm increasingly enters through the vendor, not through the front door of the organization itself.

The Domain Few Understood

For years, third-party risk management (TPRM) was misunderstood, starting with its own name. People struggled to say what “third-party risk” even meant, or who the third party actually was. It sat at the awkward intersection of security, procurement, compliance, and enterprise risk, owned fully by none of them, and over time it was flattened into a “checklist.” You confirmed a vendor was solvent, collected a security report, filed the evidence, and moved on. The assessment was a formality performed once, because the dependencies underneath it were assumed to hold still.

The one thing that changed all of this is the rapid adoption of artificial intelligence. Most organizations do not build their own AI. It arrives through third parties, embedded in the tools, platforms, and services a company licenses rather than constructs. That makes the third party the first place AI enters the organization, and therefore the first place it has to be governed. The same Verizon report found that unapproved “shadow AI” use inside companies tripled to 45% in a single year, much of it flowing in through outside tools nobody formally assessed. TPRM has become the place where you inventory what external AI tools are coming in, and where you learn how exposed you have become because of it. The “checklist” has become the front door for AI risk.

Taking Center Stage

This is not a temporary spike. It is the beginning of an expansion, and new branches are growing out of TPRM itself. Assessing a vendor can no longer mean confirming solvency and a clean security report. It increasingly means evaluating that vendor across the full range of risks the business faces. AI risk now sits alongside geopolitical exposure, climate disruption, and the erosion of trust as AI makes deception cheap and convincing. Each of these is hardening into its own line of inquiry inside TPRM, and a single vendor assessment now reaches across nearly every risk domain the enterprise recognizes.

Agentic AI deepens this further. Traditionally, vendors delivered a fixed technology product, something a company evaluated once and could expect to behave the same way over time. An AI agent does not work that way. It takes actions on its own, continuously, on behalf of the business that adopted it, while remaining a system that business did not build and cannot fully see inside. Governing a dependency that acts independently is not a once-a-year review. It is continuous oversight of an outside party operating inside your organization.

Moving forward, TPRM becomes the entry point for AI governance. It is increasingly a strategic discipline of its own, a focused practice for everything that originates outside the business but acts upon it from within. The party of three was always there. We sat at the far end of the table and tried not to look at it. It is now the most important guest in the room.

Views and opinions expressed here are those of the authors, and do not necessarily reflect the official position of Columbia University School of Professional Studies or Columbia University.


About the Program

The Master of Science in Enterprise Risk Management (ERM) program at Columbia University prepares graduates to inform better risk-reward decisions by providing a complete, robust, and integrated picture of both upside and downside volatility across an entire enterprise. For both the full-time and part-time options, students may take all their courses on Columbia’s New York City campus or choose the synchronous online class experience.

Learn more about the program here.


Sign Up for the SPS Features Newsletter

 

Authors

Related News

All News
Matthias Kuhlmey

Saved by the Bell: Crisis Canceled

All News