Technology and AI

Due Diligence on Your AI Agent Vendor's Subprocessors

Pratik Chothani

Pratik Chothani

Software Development Engineer

·

August 2, 2026

·

5 min read

·

Updated August 2, 2026

Due Diligence on Your AI Agent Vendor's Subprocessors

Quick answer

Before signing any AI agent vendor contract, request the vendor's complete subprocessor list, verify that your contract extends data protection obligations to those subprocessors, confirm that the vendor notifies you before adding or changing subprocessors, and assess whether any subprocessor represents a concentration risk or a jurisdiction risk that your own compliance obligations prohibit.

Why subprocessors matter more for AI vendors than for most SaaS vendors

A typical SaaS vendor's subprocessors handle infrastructure tasks: hosting, database, email delivery, analytics. Their impact on your data is bounded and relatively predictable.

An AI agent vendor's subprocessors may include the foundation model provider (which processes every customer interaction), a retrieval infrastructure provider (which may hold your knowledge base and customer query data), a speech-to-text vendor (which processes audio of customer conversations), and a compliance or content filtering layer (which sees all inputs and outputs).

Each of these subprocessors has direct access to your customer data in a more substantive way than a typical infrastructure subprocessor. And unlike a hosting provider, the AI layer subprocessors' behavior directly shapes what your customers experience. If the foundation model provider changes its model, your agent's behavior changes. If the retrieval vendor goes down, your agent loses its knowledge base. The subprocessors are operational dependencies, not just data processing dependencies.

What to request before signing

The current complete subprocessor list. Not categories. Not a summary. The actual list with the name of each entity, their role, the data they process, and the jurisdiction in which they operate. If a vendor cannot or will not provide this, treat it as a significant red flag.

The update notification mechanism. Your contract should require the vendor to notify you at least 30 days before adding or significantly changing a subprocessor, with a contractual right to object if the new subprocessor creates a compliance problem for you. This is standard GDPR practice and a reasonable ask in any jurisdiction.

The data protection agreement chain. The vendor should have a data processing agreement with each subprocessor that imposes equivalent obligations to those in your contract with the vendor. Ask to see the subprocessor DPA template or confirm in your contract that the vendor is required to have one.

The subprocessor audit rights. Your right to audit the vendor should flow through to meaningful assurance of the subprocessors' practices. This typically means the vendor's right to audit its subprocessors, with you receiving the results, or a certification requirement (SOC 2 Type II, ISO 27001) that applies to each subprocessor.

The concentration risk assessment

After you have the subprocessor list, run a concentration risk assessment. Ask two questions.

Does any single subprocessor represent a single point of failure for the AI agent? If the foundation model provider has an outage, does your agent go down completely? If the retrieval provider loses data, does your agent lose the ability to answer questions? Concentration risk is not automatically unacceptable, but it should be disclosed in your business continuity planning.

Does any subprocessor represent a jurisdiction risk? If your compliance obligations prohibit customer data from being processed in certain jurisdictions (common in government, healthcare, and financial services), and a subprocessor in the vendor's stack is in one of those jurisdictions, you have a compliance problem before the contract is signed. This is much easier to address before signing than after.

Foundation model provider: the special case

The foundation model provider deserves separate due diligence because it is not just a subprocessor for data purposes. It is also a provider of the AI capabilities that define your agent's behavior. Questions specific to this relationship:

Does the vendor's contract with the foundation model provider prohibit the model provider from training on your customer data? If the vendor cannot confirm this, you do not know whether your customer interactions are contributing to a model you do not control.

What is the vendor's plan if the foundation model provider discontinues the model, changes its API, or significantly changes its pricing? Foundation model providers have done all three of these things to enterprise customers. Ask how the vendor has handled or would handle each.

Is the foundation model provider itself subject to regulatory oversight in your jurisdiction? Emerging AI regulations in the EU and elsewhere may impose obligations on foundation model providers that flow through to their downstream customers.

The contract terms to negotiate

In addition to the standard data processing terms, negotiate the following specifically for subprocessors.

A subprocessor change notice period of at least 30 days. Shorter notice periods may not give you enough time to assess a compliance problem and object.

A termination right that activates if the vendor adds a subprocessor you have formally objected to on compliance grounds. Without this right, the vendor can add a problematic subprocessor and your only recourse is to live with it or terminate the entire agreement.

A representation that the vendor's subprocessor agreements impose obligations equivalent to your data protection requirements. This does not give you direct rights against the subprocessors, but it creates a representation you can enforce against the vendor.

FAQ

What if the vendor says their subprocessor list is confidential? Request a confidential version under NDA. If the vendor will not share it even under NDA, that is a red flag. You have a right to know who is processing your customer data.

Our vendor is small and may not have formal subprocessor DPAs with everyone. Is that a dealbreaker? It depends on your own compliance obligations. If GDPR applies to your data, your vendor is required to have DPAs with its subprocessors. That is not optional. For jurisdictions with less specific requirements, the lack of formal DPAs is a risk management judgment call.

What if a subprocessor changes after we've signed? That is why the change notification term matters. If your contract requires 30 days notice, you have the window to assess the new subprocessor and object if needed. Without that term, you have no process rights when the subprocessor list changes.

Should we include subprocessor requirements in our vendor security questionnaire? Yes, and specifically, it should ask for the subprocessor list and the DPA chain. Many security questionnaires ask about the vendor's own security practices but do not flow through to subprocessors.

Related reading:

Related posts