What changed
Your vendors run AI on your data. Most of them say so somewhere: a trust center, a DPA, a sub-processor list updated quietly on a Tuesday. The AI Sub-Processor Register reads those pages, turns them into a posture record you can attest, and lays the result out so you can see which AI providers actually sit underneath your vendor stack and how much of it lands on the same one.

Why it matters
Almost nobody reads vendor trust-center updates, and almost no one can answer the question that follows from them: which AI providers actually sit underneath my vendor stack, and how much of it lands on the same one? The register answers it, with the source quoted next to the field it filled.
Discovery does the reading, but it does not make the record. Discovered entries land marked for review and stay that way until a person on your team confirms or corrects them. The register is your attested position, not a scrape. Where it judges a posture against an expectation, the cell tells you the rule it applied and the framework it derives from, so a flag always traces to a source and a reviewer can disagree with it on specific grounds.
Evidence your vendors have already given you in questionnaires feeds the same picture, so the register reflects what they told you, not only what they published. And each vendor’s assessment page carries an AI Posture tab with the same discovered-then-confirmed record, so AI posture gets reviewed where vendor review already happens.
Availability
Shipping today to every vCISO Lite customer. The register is included in vendor risk on all plans.
Open any vendor assessment and look for the AI Posture tab, or see the vendor risk overview for where the org-wide register fits. The export produces a PDF suitable for an auditor, a board, or a customer security review that asked what AI touches their data.
Known limitations
Discovery is only as rich as what the vendor has published. Vendors with no public trust center or DPA show as blanks on the register until you fill them manually or send a questionnaire that asks.
Industry regime judgements this cycle cover NDPA, COPPA, and FERPA. Other sector regimes land in the next cycle.
The org-wide view counts concentration by vendor, not by spend or data volume. Weight your reading accordingly when a handful of small vendors sit on top of the same model as a few large ones.