Security researchers from Kaspersky and legal experts from LegalVision have warned global businesses about severe risks tied to using unverified third-party AI proxies and relying on a single AI provider.
The warning was issued on July 1, 2026.
A study by the Oxford China Policy Lab found that cheap AI proxies often rely on illicit account farming, stolen credentials, and compromised credit cards to bypass vendor limits.
These unauthorized intermediaries capture corporate prompts, reasoning paths, and outputs, exposing organizations to data leaks, intellectual property theft, and compliance violations under privacy laws.
Testing by the CISPA Helmholtz Center showed that rogue proxies swap premium models for cheap open-source alternatives to maximize profits.
For example, a complex medical query sent directly to Google Gemini 2.5 achieved 83% accuracy, but accuracy dropped to 37% when routed through a rogue proxy.
Legitimate aggregation platforms like OpenRouter, Poe. ai, and Hugging Face offer transparent model routing aligned with official vendor rates.
Organizations can also use self-hosted API proxies built on LiteLLM to maintain direct contracts with major AI vendors while centralizing security.
Single Provider Dependency Risks
Commercial vulnerabilities also arise when companies build critical workflows around a single official AI supplier without proper legal safeguards.
Lauren McKee, Practice Leader at LegalVision, said the main risk is losing control when external factors change.
McKee noted that businesses often overlook key contract terms regarding data ownership and liability limits.
She advised checking whether the provider can use prompts or outputs to train models, how they handle confidentiality and data security, compliance with privacy laws, service levels, and liability limits.
Exit rights are also crucial to avoid lock-in.
LegalVision recommended documented fallback arrangements, registers of approved AI systems, and strict approval rules to limit unsanctioned AI use.
McKee said organizations should design AI use around business processes, not one provider's product, and set approval rules to prevent staff from building critical workflows on unapproved tools.
The firm emphasized that operational continuity depends on preparing for rapid shifts in AI pricing, performance, and regulatory compliance.
McKee concluded that AI access can change quickly, and businesses should not build essential operations on assumptions they do not control.