Data Sovereignty / Source date:

Subprocessor Chains Get Longer With Every AI Feature

Each embedded model provider extends the disclosure chain that customers must review and approve.

Illustration of technicians examining cable junctions hidden beneath a communications-room floor panel.

Pull the subprocessor list for any major software product you licensed three years ago and compare it with the one published this month. It is longer. In several cases it is substantially longer, and the additions are almost all model providers, inference infrastructure, vector storage and speech services added to support features you may not have asked for. That expansion is the quiet cost of the assistant era, and it lands on whoever signed the data processing agreement.

Every artificial intelligence feature your vendor ships adds at least one company to the list of organisations that can read your data, and you find out by checking a web page

That is the mechanism, and it is worth understanding before the next renewal.

How the chain grows

A software vendor adds a summarisation feature. It calls a model provider, because building a model is not its business. The model provider runs on an infrastructure operator's accelerators. The feature needs retrieval, so a vector database joins the chain. Transcription arrives, adding a speech service. Evaluation and safety tooling adds another. Each of these is a reasonable engineering decision and each one extends the set of entities processing your content. The contractual position is that your vendor remains responsible and the subprocessors are bound by equivalent terms flowed down the chain. That is true and it is also thinner than it sounds by the fourth link, because your ability to verify anything past the second is essentially nil.

What your agreement probably says

Most data processing agreements give the vendor general authorisation to appoint subprocessors, with notice of changes and a right to object. Read the three operative details. How you receive notice. If it is a web page you are expected to monitor, you will not monitor it. Ask for email notification to a named address, which most vendors will agree to and almost no customer requests. How long the notice period is. Thirty days is common. Work out what you could realistically do in thirty days, which is usually nothing. What objecting achieves. Typically your remedy is to terminate the affected service. That is not a negotiation, it is an exit, and for a platform your business runs on it is not a credible threat. Knowing that in advance changes how you approach renewal rather than how you approach the notice.

Three terms to inspect before renewalQualitative contract-review questions from the article; actual rights depend on the agreement.
TermReview question
NotificationHow are changes delivered, and who receives them?
Notice periodWhat can the team realistically assess or change within the period?
Objection remedyDoes objection lead to a negotiated option, service termination or another remedy?

Qualitative summary of this article's source text, not a measured outcome or performance estimate.

The practical response

Stop trying to control the chain and start managing the exposure. Classify your content so you know which categories genuinely cannot tolerate an unknown fourth party. For most organisations this is a minority of what sits in the platform, and identifying it narrows the problem to something you can actually act on. Find out which features route content externally and whether they can be disabled by administrative policy rather than by asking staff not to use them. Feature-level control is worth more than contractual objection rights. Keep a record of the chain as it stood at each renewal. When a client or regulator asks who processed their data in a given year, a dated list is the only answer available, and nobody reconstructs this later. And raise it at renewal rather than at notice. Renewal is when you have leverage; a subprocessor notification is when you have none.

Practical Guidance for Subprocessor Chain Review

  • Request email notification to a named address, not a web page.
  • Pull current lists for your top ten vendors and compare with the originals.
  • Identify which additions are model and inference providers.
  • Classify content so the hard requirement covers a defined minority.
  • Check for administrative feature controls, not user guidance.
  • Date and archive each subprocessor list at renewal.
  • Ask what the vendor does when its own model provider changes chain.
  • Negotiate at renewal, because objection rights are not leverage.

The Regional Angle

The first problem is that regional client contracts are frequently stricter than the software contracts sitting underneath them. Professional services engagements, government and semi-government work, and banking arrangements here routinely carry undertakings that client data will not be disclosed to third parties without written consent — drafted long before anybody imagined a chain four entities deep. Your vendor's general authorisation to appoint subprocessors is, from your client's perspective, a disclosure you agreed to on their behalf. That mismatch is usually discovered during a client audit rather than before it. Reconcile the two directions deliberately: know which client contracts require consent, and either obtain a general approval covering your platform's chain or keep that work off the platform entirely. The second is a jurisdictional question the published list will not answer. A subprocessor is disclosed by corporate name and, if you are fortunate, by processing location — but regional residency undertakings and public-sector requirements care about the law the entity is subject to, which follows the parent's incorporation rather than the data centre's postcode. A model provider operating from a European region, owned in another jurisdiction, satisfies your storage clause and not your client's sovereignty expectation. When you request the list, request the entity of contract and the country of incorporation alongside the processing location. Vendors can supply it and rarely volunteer it, and it is the field that actually determines the answer you will have to give a regulator. The third is about the practical asymmetry of being a mid-sized regional buyer. A global platform will not negotiate its subprocessor terms for a two-hundred-seat contract, and pretending otherwise wastes procurement's time. What is achievable is different and more useful: local reseller and distributor relationships, which many regional organisations buy through, can often deliver commitments the vendor's standard paper does not — named notification, advance warning of feature enablement, and a human who will answer a question within a day. That is worth more in an incident than an objection right you would never exercise. Push the requirement to the party that actually wants your renewal, and make notification quality an explicit criterion when you choose which reseller to buy through.

The objection worth taking seriously

The strongest objection is that this is a demand for information nobody can use. Even with the complete chain, entity by entity, with incorporation details and processing locations, a mid-market organisation has no capacity to assess whether a vector database three links down has adequate controls, no right to audit it, and no realistic alternative if the answer is unsatisfactory. Collecting the list produces a spreadsheet, a quarterly review meeting and a false sense of diligence, while the actual security of the arrangement rests entirely on the primary vendor's engineering — which is where it rested before you asked. That is largely correct about assurance. Nobody in the mid-market is meaningfully auditing a fourth-party subprocessor, and anyone claiming to is describing a document review. The value is not assurance, it is answerability and timing. When a client's counsel asks who processed their material, when a regulator asks whether a new category of processor was added mid-contract, or when a subprocessor suffers an incident and you need to know within hours whether you are affected, the organisations with a dated list answer in an afternoon and the rest spend three weeks asking their vendor. And the act of pulling the lists changes procurement behaviour in a way the spreadsheet does not capture: teams that have seen how quickly the chain grew stop assuming that a feature toggle is a small decision. That is the real return, and it arrives from doing the exercise once rather than from maintaining it perfectly.

Common Questions

Is the vendor still responsible for its subprocessors?

Contractually yes, and that responsibility is real. It does not tell you where your data went, which is a separate question you may have to answer to someone else.

Can we refuse a new subprocessor?

Usually only by terminating the affected service. Treat the objection right as information rather than as control.

Do we need to tell our own customers?

If you are a processor, check your own agreements — many require you to pass the notification down, and that obligation is frequently missed when the chain grows through a feature release rather than a contract change.

What should we expect over the next twelve months?

Expect lists to keep lengthening as assistant features multiply, and expect model providers to appear in chains where no artificial intelligence was procured. Expect enterprise buyers to begin demanding feature-level administrative controls as a condition of renewal. Expect at least one significant incident at a shared inference or vector provider to make chain visibility a board-level question. And expect the vendors who publish clear, dated, jurisdiction-labelled lists to start winning regulated deals on that basis alone.


Subprocessor Chain Review — we map who is actually processing your content today, and get the notification terms fixed at renewal.

Continue reading

Talk to OPS

Start with the operating problem.