
Cloud Security Podcast · 2026-05-27 · 38 min
Third-Party Risk Management (TPRM) has historically been a tedious, 200-page paper exercise that felt like being catapulted back to 1979. But AI is changing that. In this episode, Ashish sits down with Igor Andriushchenko (CISO at Lovable) and Jasper Mills (CEO of Ethira) to discuss the collision of TPRM and AI. We dive into the hidden risks of Shadow AI, exploring the chaos that ensues when non-technical teams spin up unauthorized AI tools without security oversight. Jasper and Igor explain why the future of vendor risk involves treating AI agents like a contracted workforce, managing their lifecycles, and preparing for the 2027 era of "agent-to-agent" negotiations where humans are entirely removed from the loop. We also cover the impact of DORA (Digital Operational Resilience Act) regulations, the Build vs. Buy debate for AI security tooling, and how to use autonomous agents to finally automate tedious vendor questionnaires.