
How AI Agents Will Negotiate Your Vendor Contracts
Source: YouTube · Cloud Security Podcast · published May 27, 2026 · 37:43
Third-party risk management is evolving from a tedious bureaucratic exercise into an automated, agent-driven necessity to address the severe vulnerabilities introduced by unregulated AI adoption and shadow IT.
Key Takeaways:
• Traditional third-party risk management has become a meaningless "paper exercise" relying on manual checklists that provide little actual security value 0:00-0:06.
• Security professionals describe current AI tooling adoption as frustratingly archaic, comparing the experience to the computing landscape of 1979 0:07-0:13.
• A CISO warned that enabling AI tools for untrained non-technical staff is like giving a "nuclear bomb" to a kindergarten, highlighting the catastrophic risk of unmonitored access 0:16-0:21.
• Employees frequently bypass security protocols by creating personal workspaces or using unauthorized Model Context Protocol (MCP) servers to fetch sensitive data from systems like Salesforce 0:22-0:36.
• The industry is moving toward an "agent-to-agent" future by 2027, requiring new frameworks for trust and risk assessment that treat autonomous agents like contracted workforce members 0:36-0:38.
Organizations must urgently shift from manual vendor assessments to automated, continuous monitoring of both third-party vendors and internal AI agents to prevent significant data breaches.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Third-party risk management, not the sexiest topic. >> This month, it becomes a paper exercise where you you do something for the sake of doing it. >> The process of like using the tools on the market felt like I've been like catapulted like to 1979. It was like the worst experience of my professional career. >> A CISO called me and he said like, "We have just given a kindergarten a nuclear bomb." >> People just create a personal workspace and they just enable that feature and everything feels solvable just like one toggle away. >> Or maybe John built it themselves. And then he found an MCP that he has spun up and now it's going to Salesforce and like fetching whatever it wants. >> I've heard it many times. 2027 is the year of agent to agent. There is no place for humans in that loop. >> T…