Default-On AI: Are SaaS Vendors Outsourcing Their Risk To You?
SaaS vendors are increasingly enabling AI features by default, often with minimal notice, creating significant governance and risk challenges for client organizations. This 'default-on' approach shifts the burden of managing data residency, retention, consent, and legal compliance onto the customer. The article highlights examples from Zoom, Microsoft 365, and Google Workspace, urging organizations to proactively manage these risks and demanding better communication and control from vendors.
The Silent Rollout of AI Features and Its Implications
The rapid integration of AI into enterprise SaaS applications, often enabled by default and with little warning, presents a growing challenge for internal audit and assurance professionals. This trend, dubbed 'default-on AI,' means that new AI functionalities, such as smart recordings, AI summaries, and enhanced data retention, are automatically activated within an organization's systems without explicit consent or sufficient lead time for IT and security teams to assess and manage the associated risks. This practice effectively transfers the responsibility for governance, compliance, and data security from the SaaS vendor to the client organization, often without their full awareness or preparation.
Key Risks and Compliance Concerns for Assurance Professionals
The 'default-on' nature of these AI features introduces several critical risks that assurance professionals must address:
- Legal and Regulatory Non-Compliance: Features like automatic recording or transcription can violate two-party consent laws (e.g., wiretap laws in various U.S. states) or data privacy regulations if not properly managed. The article cites examples from Zoom, where multiple capture mechanisms are enabled by default, creating significant legal exposure.
- Data Sprawl and Retention Issues: AI-driven features often lead to increased data capture and longer retention periods (e.g., two years for Zoom chat cloud retention), exacerbating data sprawl and complicating e-discovery processes. This can create unforeseen liabilities and compliance burdens.
- Security and Governance Gaps: When AI features are enabled without adequate notice, organizations lack the opportunity to evaluate their security implications, configure appropriate controls, or update internal policies. This can lead to sensitive data being processed by generative AI models without proper oversight, potentially violating data residency or contractual obligations.
- Operational Burden and Change Fatigue: The unannounced or short-notice activation of AI features generates a surge of support tickets, questions from users, and a measurable drag on productivity as IT, security, and governance teams scramble to understand and manage these new capabilities.
Recommendations for Proactive Risk Management
Given that vendors are unlikely to immediately change their 'default-on' approach, internal audit and assurance professionals must adopt a proactive stance. This includes treating tenant configuration reviews as a recurring operational task to identify and mitigate risks associated with newly activated AI features. Organizations should document every 'default-on' incident and escalate these concerns with their SaaS account teams, using these patterns to inform future renewal decisions. Ultimately, the article advocates for a shift in vendor behavior, urging them to provide structured notifications well in advance, publish risk matrices aligned with common compliance standards (e.g., SOC 2, ISO 27001), and offer ready-to-use training materials. This would allow organizations a proper evaluation window, measured in weeks rather than days, to ensure responsible AI adoption and maintain customer trust.
Read more