Home๐Ÿ“– About ARIA๐Ÿš€ Launch ARIA๐Ÿ“– About Shape B๐Ÿš€ Launch Shape BInsightsEngage with AggiAbout UsContact Us โ†’
ARIA Platform โ€” enterprise continuous complianceยทARIA Shape B โ€” self-serve testing, $30/batch
Third-party AI is your risk now โ€” an insight from Dr. Prasad Golla, Aggi Technologies LLC

Third-party AI is your risk now

News
August 26, 2026 ยท Aggi Technologies LLC

Between March 10 and March 16 this year, attackers were inside one of CareCloud's Amazon Web Services environments. Six days.

CareCloud sells cloud EHR software โ€” EHR being the electronic health record, the digital chart your doctor's office keeps on you โ€” along with billing and practice management. More than 45,000 healthcare providers run on it.

In early July, state filings put the number of affected people at roughly 350,000. In August the federal breach tracker at Health and Human Services listed 3,371,508. The next day it read 3,756,469.

Names. Addresses. Dates of birth. Social Security numbers. Driver's license numbers. Bank account and card numbers. Medical and health insurance information.

Almost none of those 3.7 million people have heard of CareCloud. They were patients of practices that chose a vendor.

Two things stay with me, and neither is about blame

First: four months passed between "we contained it" and "we know what left," and the count grew roughly tenfold along the way. That is not negligence. Reconstructing an exfiltration โ€” working out exactly which records left the building โ€” is genuinely hard work. But it tells you how long the honest answer takes.

Second, the question I cannot put down. Data forensics is a mature discipline. Slow, painful, but it works. There are logs. There are artifacts. Eventually you can say what happened.

Now ask the same question one layer over.

If an attacker spent six days near your AI systems โ€” the models, the prompt templates, the retrieval corpus they draw on โ€” could anyone reconstruct whether the behavior changed? There is no exfiltrated file to recover. A model that starts answering differently leaves no artifact at all, unless somebody was measuring it beforehand.

Most organizations have no behavioral baseline

Not through carelessness. Nobody told them they needed one.

So the honest question for anyone running vendor AI โ€” AI inside software you bought rather than built โ€” is whether you have any way to tell whether its behavior changed last month, or whether that visibility stops at the vendor's front door.

We work in AI compliance, so we have a horse in this race. We raise it anyway, because we do not think the answer is comfortable for anyone right now, vendors included.

ARIA tests whether an AI system actually follows the policy it is supposed to follow โ€” continuously, with each finding mapped to the framework clause it touches. Start a conversation โ†’

โ† Back to Insights
Related reading
AI โ€” Security, Responsibility, and Governance

One email a month. Three signals, one principle, one bottom line.

Written for people who have to make decisions about AI. What happened, why it matters, and what to do about it โ€” with every source linked so you can check the work yourself.

Or read it on LinkedIn โ†’

Monthly, never more. Your address is not sold or shared, and one word in a reply gets you off the list. Privacy Policy