AI Vendor Risk Index

Monthly intelligence across 6 risk dimensions: government relations, political contagion, technical, business, compliance, and supply chain.

OpenAI
63
HIGH
xAI
62
HIGH
Anthropic
55
HIGH
Microsoft
45
MODERATE
Google
33
LOW
Meta
30
LOW

Get the full report + methodology

Weekly risk score updates, analysis, and alerts when scores change. Built for TPRM teams.

Why this matters

Half of the major AI vendors are now rated HIGH risk — but for very different reasons. OpenAI's risk is political entanglement. Anthropic's is political exclusion. xAI's is governance collapse. Your existing GRC tools don't track any of this.

What we track — 6 risk dimensions

Who this is for

CPS 230: Your AI vendor is probably a material service provider

APRA's CPS 230 has been in effect since July 2025. Under Paragraph 49, any service provider you rely on for critical operations — including AI APIs — is a material service provider. Paragraph 50 goes further: "core technology services" are material by default unless you can justify otherwise.

If your organisation uses OpenAI, Anthropic, or Google AI in production, they almost certainly belong on your CPS 230 material service provider register. Our Risk Index maps directly to CPS 230 assessment requirements — political risk, operational resilience, service disruption probability, and compliance posture for each vendor.