Xither Staff Writer

What happens downstream when an AI vendor changes a page

On 11 September 2026 we read AssemblyAI’s sub-processor list and found four companies on it that had not been there when we read it before: Stytch, Stripe, Pendo and Metronome. The page carried no announcement. Every company that embeds AssemblyAI acquired four sub-processors that day, and so did every enterprise those companies sell to.

Source: assemblyai.com/legal/subprocessors, read 11 September 2026. All four names are on the page as published.

What a change looks like from the outside

A sub-processor list is a table. It has a name, a purpose, and usually a country. AssemblyAI’s new rows described Stytch as providing authentication and authorization, Stripe as payment processing, Pendo as a customer experience platform, and Metronome as a metering service. None of those is alarming. Two of them probably do not touch customer content at all.

That is the ordinary case, and it is the case that breaks the process. A dramatic change would get noticed. Four routine rows appearing in a table on a Thursday will not, because nothing about the page announces that it is different from the page that was there on Wednesday.

The same week we recorded two more. Replit added SideGuide Technologies, Inc., trading as Firecrawl, to its list. 6sense removed FingerprintJS, Inc., which its list had described as an account fraud and takeover service. Additions and removals both matter, and they matter to different people: an addition is a new party in the chain, and a removal is a party your last answer to a customer still names.

replit.com/subprocessors and 6sense.com/legal/subprocessors, both read 11 September 2026.

“We will notify you” is not one mechanism

Every data processing agreement that permits a vendor to add sub-processors also says how the vendor will tell you. Those clauses do not agree with each other. We hold 36 of them that state an objection period, quoted from the agreements themselves, and the notice mechanism differs across them.

Some define notice as publication. The list changes, and that is the notice:

At least ten (10) days before enabling any new Sub-Processors the new Sub-Processor will be added to the List.

Vespa https://vespa.ai/data-processing-agreement · read August 31, 2026

Under a clause like that, nothing arrives. No email is sent and no message is owed. The page changes and the period starts, and the only way to be inside it is to have been reading the page.

Others send an email, but only to addresses that subscribed to a notification list first. That is a reasonable arrangement and it has a failure mode: the person who subscribed leaves, the address is a personal one, and the notice goes to a mailbox nobody reads.

The company that embeds the vendor

Take a company that put speech-to-text in its product. It signed AssemblyAI’s data processing agreement. It also signed agreements with its own customers, and those agreements almost certainly say that it will disclose who processes their data and tell them before that set changes.

On 11 September that company acquired four sub-processors it did not choose, did not evaluate, and was not told about. Its disclosure to its own customers became incomplete the same day. Nothing it did caused this, and no reasonable process it runs internally would have caught it, because the change happened on somebody else’s website.

The clock is the part that hurts. Of the 36 objection periods we can quote, 14 are ten days or shorter and 14 are thirty days. The shortest we hold is 5 business days.

Customer may object to the Processing of Customer’s Personal Data by the New Sub-Processor, for reasonable and explained grounds, by providing a written objection to [email protected] within 5 business days following Gong’s written notice to Customer of the intended engagement with the New Sub-Processor.

Gong https://gong.io/legal/data-processing-addendum · read August 31, 2026

Five business days is a week and a half of calendar. It is also less time than most companies take to notice that a page they do not own has been edited. The period does not begin when you find out. It begins at the vendor’s notice, and under a publication clause that means it began when the page changed.

A missed period is not a decision deferred. At least one agreement in our record states what silence means:

The Customer may only object in writing to Mistral AI's appointment of a new Subprocessor within ten (10) days of such notice by providing a written objection to privacy@mistral.ai, provided that such objection is based on reasonable grounds relating to the Applicable Data Protection Law, otherwise such new Subprocessor will be deemed approved.

Mistral AI https://legal.mistral.ai/terms/data-processing-addendum · read August 31, 2026

The removal nobody files

6sense’s list described FingerprintJS, Inc. as an account fraud and takeover service. On 11 September the name was gone. It is not on the page today.

An addition creates a review task, and most companies can imagine the workflow even if they do not run it. A removal creates a correction task, and almost nobody has a workflow for that at all. The last disclosure you sent a customer names a company that is no longer in your chain. That answer was accurate when you gave it and is now wrong, in writing, in a document a security reviewer keeps.

For the enterprise the same fact lands differently. Its register overstates. An auditor comparing the register against what suppliers actually publish finds a discrepancy, and the discrepancy sits in the enterprise’s own document rather than the supplier’s. The work of explaining it falls on the party that did nothing wrong.

In our record removals have been more common than additions: 14 against 7. Both counts are small and the window is short, so that ordering is an observation rather than a trend. What it does establish is that a process built only to catch new names catches less than half of what moves.

The enterprise at the end of the chain

The enterprise customer never signed anything with AssemblyAI. It signed with the company that embeds it. Its right to know reaches through that contract, and so does its exposure.

This is the asymmetry that makes the problem expensive rather than annoying. The enterprise carries the larger obligation and has the worse view. Its regulator, its auditor and its own customers expect a register of who processes personal data on its behalf, and under Article 28 of the GDPR a processor engaging another processor needs the controller’s authorization, with an opportunity to object to changes. That obligation is transitive. Visibility is not.

The enterprise also moves more slowly, for good reasons. A supplier change goes to procurement, then to security review, then to whoever owns the risk register. That process is measured in weeks. The objection periods above are measured in days. When the two meet, the period usually wins.

Scale makes it worse rather than better. A large company has hundreds of suppliers, and a meaningful number of them now embed AI from somebody else. Each one is a chain of the kind described here. One edit at the top of one chain can touch several internal systems, and the enterprise has no way to see the edit at all unless the supplier in the middle tells it.

The practical result is that the enterprise learns about upstream changes at renewal, from a questionnaire it sent, answered by a supplier who is reconstructing the answer from memory. That is not a register. It is an annual reconstruction, and both parties know it.

The other clock, which lands on a different team

Not every downstream change is a compliance question. Some are engineering deadlines, and they travel the same chain.

V7’s changelog carried this, dated 8 September 2026:

Gemini 2.5 Pro has been retired: It no longer appears as a selectable model, so nothing can be pointed at a model on its way out.

V7 — v7labs.com/changelog · read 10 September 2026

That is the chain, visible in one entry. A model was retired upstream, and a company that embedded it told its own customers what changed in their product. Anyone building on V7 who had pinned that model found out through V7’s changelog, two links from the decision.

The dates are the part that costs money. Google Cloud’s release notes, read 12 September 2026, carried a change effective 25 January 2027: write permissions removed from the chronicle.readonly OAuth scope, restricting it to read operations. Any integration writing through that scope has a date on which it stops working, and the date is four months out.

Dates also move. The same release notes carried the deprecation of Looker Mobile (Legacy) postponed to 31 January 2027. A date captured once and filed in a spreadsheet is not a date you can rely on, in either direction.

We watch 9 retirement pages and hold 62 retirement entries from 6vendors. That is thin coverage and these are illustrations rather than a rate. The point they illustrate is structural: the retirement clock and the objection clock arrive at the same company on different pages, and they land on teams that do not read each other’s.

How often this actually happens

We read 1,078 pages across 186 vendors on a schedule, including 116 sub-processor lists and 88 data processing agreements.

Between September 2, 2026 and September 13, 2026 11 days — 145 of those sub-processor and DPA pages differed from the copy we held before, across 50 vendors whose sub-processor list changed at all.

Most of those differences do not matter. A footer date, a reordered row, a cookie banner. Of the 145 page differences, 13 carried a change to a stated fact. That ratio is the reason this is hard to do by hand and hard to do naively: watch the pages without filtering and you generate alarms nobody reads, and the real change arrives in the same inbox as the noise.

Two limits on those numbers. The archive spans 11 days, which is short, and a rate measured over 11 days should not be projected across a year. And every date here is the date we read a page, not the date a vendor edited it. We cannot see edit history. We can only say that on one date a page held one thing and on a later date it held another.

What a working process looks like

The mechanism is not complicated. Re-read each page on a schedule. Keep a dated copy of every reading. Compare each reading to the last one. When something differs, quote the lines that moved, name the date, and carry the vendor’s own objection period so the deadline is a date rather than a worry.

Three things make that harder than it sounds. Vendors publish these documents at no consistent URL, so the list of pages to read has to be built by hand and maintained. Ours is published. Some vendors block automated readers, which is their right and has to be recorded as a refusal rather than as an absence. And the filtering problem above is real: without it, the process produces noise at a rate that guarantees it gets switched off.

For the company in the middle, the output of that process is the answer to two questions it will be asked anyway. Who processes our customers’ data, and how do you know when that changes. Both turn up in every security questionnaire.

For the enterprise, the useful demand is narrower than a questionnaire and more effective. Ask each supplier which upstream pages it monitors, how often it re-reads them, and what it will send you when one changes. A supplier that can answer has a process. A supplier that says it reviews annually has told you when it will find out, which is at the same time you do.

What this article rests on

Every vendor observation above comes from a dated copy in this record, with the page it was read from. The additions to AssemblyAI’s and Replit’s lists were confirmed present on those pages before publication, and FingerprintJS was confirmed absent from 6sense’s. Clause quotations are rendered from the record when this page is served, so they cannot drift from what we hold. Counts are read at the same moment for the same reason.

The single source outside our own record is the GDPR text on EUR-Lex. No survey, no analyst report and no third-party statistic appears here.

This is not legal advice, and the agreements quoted are published documents rather than your contract. A negotiated addendum governs over anything on this page.

By a Xither Staff Writer. Published 12 September 2026. Corrections go to contact; a vendor that believes we have its record wrong can correct it for free.