AI/TLDR

Lema AI

Agentic third-party risk management, with an AI Governance module for the AI your vendors bring with them

Third-Party AI Risk (TPRM)Commercial
Updated
11 Sep 2026
License
Proprietary (commercial SaaS)
Coverage
1 story

What's new

11 Sep 2026

Lema AI announced AI Governance, extending its third-party risk platform with a third-party AI inventory, forensic AI assessment against NIST AI RMF and custom scopes, fourth-party model-provider mapping, and continuous monitoring for capability changes and scope drift.

Latest news

Overview

Lema AI is a third-party risk management platform built on the argument that vendor risk is a security problem, not a compliance checklist. Instead of scoring a vendor from the questionnaire it fills in, Lema works forensically: it reads the reports and artifacts a vendor submits, pulls open-source reconnaissance on that vendor, and maps the access, permissions and data flows the vendor actually holds inside your environment — what the company calls blast-radius monitoring — so the output is an exposure path rather than a risk score. The company was founded in 2023 and came out of stealth in February 2026 with $24 million from Team8, F2 Venture Capital and Salesforce Ventures.

AI Governance, announced on 11 September 2026, applies that model to the AI inside a vendor portfolio. It identifies and classifies AI across third parties and their products, covering model providers, AI-native applications and ordinary products with AI capabilities embedded in them. Shadow AI — tools employees adopt without review — is treated as an unvetted sub-vendor rather than a separate problem. Mapping which vendors sit on which model providers also exposes fourth-party concentration, where one provider is reachable through many suppliers at once.

The assessment side cross-checks vendor claims against the submitted artifacts, looks for contradictions inside that evidence, and compares both against what Lema observes through connected systems. Dedicated AI assessment scopes and controls include NIST AI RMF alongside custom controls, and exposure is weighed by what the AI can do: agent behaviour, code execution, web search and MCP server connections. Monitoring then continues after approval, surfacing data used for model training, excessive collection, retention issues, fourth-party data sharing, and scope drift when a vendor's real footprint moves past the approved state. All of it runs inside the third-party workflows already in the platform — discovery, vendor inventory, fourth-party mapping, assessments and monitoring — rather than as a separate AI register.

What it does

  • Third-party AI inventory: identifies and classifies AI across vendors and products, including model providers, AI-native apps and embedded AI capabilities
  • Forensic AI assessment that cross-checks vendor claims against submitted artifacts, internal contradictions in the evidence, and what Lema observes through connected systems
  • Dedicated AI assessment scopes and controls, including NIST AI RMF, plus custom controls
  • Exposure weighed by capability — agent behaviour, code execution, web search and MCP server connections
  • Fourth-party mapping that shows where dependencies on a single model provider are concentrated across the portfolio
  • Continuous monitoring for AI-specific risks (training-data use, excessive collection, retention, fourth-party sharing) and for scope drift past the approved state
  • Blast-radius monitoring of vendor access, permissions and data flows, modelling how a vendor compromise would reach critical assets
  • Open-source reconnaissance on vendors, feeding the same third-party risk workflows as the rest of the platform

Getting started

Lema AI is a commercial platform, not a package you install: access starts with a demo, and AI Governance runs inside the third-party workflows the platform already provides.

Request a demo

The platform is sold through Lema's demo request form at lema.ai/demo. There is no public download or self-serve install.

texttext
https://www.lema.ai/demo

Connect your systems

Lema's assessments compare vendor claims against what it can independently observe through connected systems, and its blast-radius view is built from the access, permissions and data flows a vendor holds in your environment. Those connections are what make the forensic checks possible.

Review the third-party AI inventory

AI Governance classifies AI across your vendors and products — model providers, AI-native applications, embedded AI — and surfaces previously unreviewed AI applications that need to be brought into the governance process.

Assess AI in context

Run the dedicated AI assessment scopes and controls, including NIST AI RMF or your own, and read the forensic assessment: the contradictions between what the vendor says, what its artifacts show, and what Lema observes.

Watch for drift

Keep monitoring after approval. Lema surfaces AI-specific risks such as training-data use, excessive data collection, retention and fourth-party sharing, and flags scope drift when a vendor's actual footprint grows beyond the approved state.

Commands and code are distilled from the project's own documentation — always check the official docs for the latest.

When to use it

  • Reach for it when your vendor inventory is accurate but you cannot say which of those vendors added AI features after they were approved
  • Reach for it when shadow AI is the real gap — tools staff signed up for that never reached review and now act as unvetted sub-vendors
  • Reach for it when you need to know how many suppliers route back to the same model provider before that concentration becomes an incident
  • Reach for it when a TPRM programme needs evidence rather than questionnaire answers, and someone has to reconcile vendor claims with observed behaviour