AI Governance Institute logo
AI Governance Institute

Intelligence for Compliance and GRC Teams

← News
Research2026-08-18

Vendor AI Usage Reports Systematically Filter Harmful Behavior, Study Finds

What happened

The AI Observatory, a new independent research initiative led by researchers from Stanford and MIT, published findings on August 18, 2026, based on analysis of more than 24,000 real AI conversations. The study, covered by MIT Technology Review, concludes that usage reports issued by AI companies including Anthropic and OpenAI are shaped by a consistent methodological filter: they focus on workplace and productivity interactions while excluding personal, recreational, and off-topic conversations. That exclusion, the researchers found, understates the actual prevalence of sensitive behaviors such as harassment, hate speech, and adult content by a significant margin. The AI Observatory's dataset was drawn from consenting users across a range of real-world contexts, providing a broader baseline than company-curated samples. For enterprise governance teams, the implication is direct: any vendor risk assessment, AI system intake review, or board-level risk report that treats company-published usage statistics as representative data is working from a selectively filtered baseline.

Why it matters

  • ·Third-party AI vendor risk assessments are undermined when the underlying usage data is vendor-curated rather than independently verified. Compliance programs built around vendor self-reporting may be systematically miscalibrating risk classifications for tools already deployed across the enterprise.
  • ·Regulated industries face heightened exposure. Firms in financial services and healthcare that have documented vendor AI risk assessments for regulatory purposes may need to revisit those assessments, as regulators increasingly expect evidence-based rather than vendor-represented risk characterizations.
  • ·Board and audit committee AI risk reporting is only as credible as its inputs. If the usage data informing enterprise AI risk registers reflects vendor commercial interests rather than actual behavioral distributions, governance disclosures to boards and investors may misrepresent the true risk profile of deployed AI tools.

Governance controls affected

What to do now

  • Audit all current third-party AI vendor risk assessments to identify where vendor-published usage reports were used as an evidence source, and flag those assessments for review.
  • Update your vendor due diligence questionnaire to require AI vendors to disclose the methodology, scope exclusions, and data sources underlying any usage or behavior statistics they publish.
  • Establish a policy requiring that risk classifications for high-use AI vendor tools be supported by at least one independent or internally generated data source, not solely vendor documentation.
  • Brief your board AI risk committee on the structural limitation of vendor self-reported usage data and document that briefing as part of your governance record.
  • Engage your AI vendor contracts team to assess whether existing vendor agreements include any representation warranties on usage data accuracy, and determine whether those warranties are enforceable given this research.

What to watch next

Compliance teams should monitor whether regulators in the EU, US, and UK cite the AI Observatory findings or similar independent research when issuing guidance on third-party AI vendor oversight. The EU AI Act's general-purpose AI transparency provisions and the H.R.8094 - AI Foundation Model Transparency Act of 2026 both contemplate disclosure standards for AI developers, and independent research of this kind is likely to inform how those standards are shaped or enforced. Organizations subject to the California Transparency in Frontier AI Act should also assess whether vendor-published usage summaries meet the evidentiary bar that act may require. More broadly, the emergence of independent AI usage observatories signals a maturing assurance ecosystem, and compliance teams should begin building monitoring workflows that incorporate third-party behavioral data alongside vendor documentation.

Stay ahead of stories like this

Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Corporate Policy2026-08-18

White House Finalizes Voluntary Frontier AI Safety Testing With Top Labs

The White House has finalized a voluntary safety testing program for advanced U.S. AI models, inviting Meta, Anthropic, Google, and OpenAI to participate in government-coordinated pre-release evaluations. The program covers national-security risk assessment and third-party model evaluation. While participation is voluntary, the framework establishes a de facto pre-deployment review baseline for frontier model developers.

Corporate Policy2026-08-12

Anthropic's 'Project Panama' Exposes Training Data Sourcing as a Supply-Chain Risk

Reports from rare booksellers and a 2025 lawsuit have revealed that Anthropic ran a covert program called 'Project Panama' under which millions of print books were purchased and destroyed to extract training data. The accounts raise concerns about deceptive procurement, irreplaceable cultural loss, and undisclosed data sourcing practices. Enterprise compliance teams that rely on commercially-licensed AI models now face heightened exposure across training data provenance, vendor due diligence, and IP risk programs.

Corporate Policy2026-08-17

OpenAI Dissolves Preparedness Team, Leaving Frontier Risk Oversight Fragmented

OpenAI disbanded its preparedness team at the end of July 2026, redistributing its frontier model risk assessment responsibilities across domain-specific teams focused on areas such as biosecurity and cyber. The move follows the earlier dissolution of OpenAI's AGI readiness and superalignment teams, and the departure of multiple senior safety leaders. Critics have raised concerns that the structural dismantlement of centralized safety functions signals a shift in organizational priorities ahead of an anticipated IPO.