AI/TLDR

Lema AI · 2026-09-11 · notable

Lema AI Governance — third-party AI found, assessed and monitored

Lema AI added AI Governance to its third-party risk platform. It inventories AI inside vendor products, checks vendor claims against evidence Lema observes, maps the model providers behind vendors, and flags drift from the approved state.

Cover graphic for Lema AI's Third-Party AI Governance announcement
Lema AI

Lema AI Governance finds the AI a vendor added after you approved it, scores the exposure it creates, and watches it for drift.

What is it?

AI Governance is a new capability in Lema AI's third-party risk management platform. It identifies and classifies AI across third parties and their products — model providers, AI-native applications, and ordinary products with AI features embedded in them. Unsanctioned tools that employees adopt on their own are treated as what Lema calls shadow AI: unvetted sub-vendors that never went through review.

How does it work?

Assessment is forensic rather than questionnaire-based. Lema cross-checks a vendor's claims against the artifacts it submits, looks for contradictions inside that evidence, and compares both with what Lema can observe independently through connected systems. Assessment scopes and controls include NIST AI RMF alongside custom ones. Exposure is judged by what the AI can actually do — agent behaviour, code execution, web search and MCP server connections — and by which model providers sit behind a vendor, which is where concentrated fourth-party dependencies show up.

Why does it matter?

Vendor approval is a snapshot, and AI moves after it. Continuous monitoring surfaces AI-specific risks such as data used for model training, excessive collection, retention problems and fourth-party data sharing, plus scope drift when a vendor's real footprint grows past the approved state. Lema's argument is that this belongs inside the third-party workflows a team already runs — discovery, vendor inventory, fourth-party mapping, assessments and monitoring — not in a separate AI inventory nobody reconciles.

Who is it for?

TPRM, GRC and security teams reviewing vendor AI

Try it

Request a demo at https://www.lema.ai/demo

Sources

Tags

  • tprm
  • third-party-risk
  • vendor-risk
  • ai-governance
  • ai-inventory
  • shadow-ai
  • fourth-party-risk
  • nist-ai-rmf
  • mcp
  • security
  • compliance

← All releases · Learn AI