Vendor AI Usage Reports Systematically Filter Harmful Behavior, Study Finds
What happened
The AI Observatory, a new independent research initiative led by researchers from Stanford and MIT, published findings on August 18, 2026, based on analysis of more than 24,000 real AI conversations. The study, covered by MIT Technology Review, concludes that usage reports issued by AI companies including Anthropic and OpenAI are shaped by a consistent methodological filter: they focus on workplace and productivity interactions while excluding personal, recreational, and off-topic conversations. That exclusion, the researchers found, understates the actual prevalence of sensitive behaviors such as harassment, hate speech, and adult content by a significant margin. The AI Observatory's dataset was drawn from consenting users across a range of real-world contexts, providing a broader baseline than company-curated samples. For enterprise governance teams, the implication is direct: any vendor risk assessment, AI system intake review, or board-level risk report that treats company-published usage statistics as representative data is working from a selectively filtered baseline.
Why it matters
- ·Third-party AI vendor risk assessments are undermined when the underlying usage data is vendor-curated rather than independently verified. Compliance programs built around vendor self-reporting may be systematically miscalibrating risk classifications for tools already deployed across the enterprise.
- ·Regulated industries face heightened exposure. Firms in financial services and healthcare that have documented vendor AI risk assessments for regulatory purposes may need to revisit those assessments, as regulators increasingly expect evidence-based rather than vendor-represented risk characterizations.
- ·Board and audit committee AI risk reporting is only as credible as its inputs. If the usage data informing enterprise AI risk registers reflects vendor commercial interests rather than actual behavioral distributions, governance disclosures to boards and investors may misrepresent the true risk profile of deployed AI tools.
Governance controls affected
What to do now
- ☐Audit all current third-party AI vendor risk assessments to identify where vendor-published usage reports were used as an evidence source, and flag those assessments for review.
- ☐Update your vendor due diligence questionnaire to require AI vendors to disclose the methodology, scope exclusions, and data sources underlying any usage or behavior statistics they publish.
- ☐Establish a policy requiring that risk classifications for high-use AI vendor tools be supported by at least one independent or internally generated data source, not solely vendor documentation.
- ☐Brief your board AI risk committee on the structural limitation of vendor self-reported usage data and document that briefing as part of your governance record.
- ☐Engage your AI vendor contracts team to assess whether existing vendor agreements include any representation warranties on usage data accuracy, and determine whether those warranties are enforceable given this research.
What to watch next
Compliance teams should monitor whether regulators in the EU, US, and UK cite the AI Observatory findings or similar independent research when issuing guidance on third-party AI vendor oversight. The EU AI Act's general-purpose AI transparency provisions and the H.R.8094 - AI Foundation Model Transparency Act of 2026 both contemplate disclosure standards for AI developers, and independent research of this kind is likely to inform how those standards are shaped or enforced. Organizations subject to the California Transparency in Frontier AI Act should also assess whether vendor-published usage summaries meet the evidentiary bar that act may require. More broadly, the emergence of independent AI usage observatories signals a maturing assurance ecosystem, and compliance teams should begin building monitoring workflows that incorporate third-party behavioral data alongside vendor documentation.
Stay ahead of stories like this
Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.
