<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Cimbiotic Blog</title>
    <link>https://www.cimbiotic.ai/insights</link>
    <description />
    <language>en-us</language>
    <pubDate>Wed, 16 Sep 2026 20:17:45 GMT</pubDate>
    <dc:date>2026-09-16T20:17:45Z</dc:date>
    <dc:language>en-us</dc:language>
    <item>
      <title>AI is already inside your certification program. The question is where.</title>
      <link>https://www.cimbiotic.ai/insights/ai-is-already-inside-your-certification-program-the-question-is-where</link>
      <description>&lt;p&gt;Most writing about AI risk in associations is about communications. A newsletter goes out with an error in it. A chatbot says something wrong. Embarrassing, fixable, forgotten in a quarter.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Most writing about AI risk in associations is about communications. A newsletter goes out with an error in it. A chatbot says something wrong. Embarrassing, fixable, forgotten in a quarter.&lt;/p&gt; 
&lt;p&gt;Credentialing is a different category. If your organization certifies people, the credential is not a programme you run — it is the asset the organization is built on. Members pay for it, employers rely on it, and in some professions a regulator points at it. Its entire value rests on a belief: that the standard is real and consistently applied.&lt;/p&gt; 
&lt;p&gt;That belief is not robust to surprises.&lt;/p&gt; 
&lt;h2&gt;AI is probably already in the process&lt;/h2&gt; 
&lt;p&gt;Not as a decision anyone announced. As features that arrived inside tools you already use, and as sensible shortcuts staff adopted because the work is hard and the deadlines are real.&lt;/p&gt; 
&lt;p&gt;Five places worth checking, in rough order of how quietly they tend to appear:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;strong&gt;Item development.&lt;/strong&gt; Draft exam items generated or rewritten with AI assistance, then reviewed by a subject-matter expert. The review is real; the provenance is often unrecorded.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Item analysis and forms assembly.&lt;/strong&gt; Statistical tooling that now ships with AI-assisted recommendations about which items to retain, retire or place.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Scoring support.&lt;/strong&gt; Anything beyond a straight key — essay scoring, performance rubrics, practical assessments — where a model contributes to or triages a human judgement.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Eligibility screening.&lt;/strong&gt; Reviewing applications for experience, education or supervised hours. This is where AI is most useful and least visible, because it looks like admin rather than assessment.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Candidate preparation.&lt;/strong&gt; Adaptive study tools, often licensed from a vendor, sometimes trained on your own item bank.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;The last one deserves particular attention, because the exposure runs in an unexpected direction. If preparation material is derived from live items, the integrity question is not about the AI at all — it is about whether your item bank leaked into a training set.&lt;/p&gt; 
&lt;h2&gt;Why this is different from other AI risk&lt;/h2&gt; 
&lt;p&gt;An error in a member newsletter damages a relationship. An unexplained irregularity in a certification decision damages the thing the relationship is based on.&lt;/p&gt; 
&lt;p&gt;Consider how a challenge actually unfolds. A candidate fails, appeals, and asks a reasonable question: was any part of this decision automated, and if so, how was it checked? For most credentialing bodies today, answering that requires a scramble — and the scramble itself is the finding. If you cannot describe your own process confidently, the appeal stops being about one candidate and starts being about the programme.&lt;/p&gt; 
&lt;blockquote&gt;
 &lt;p&gt;A credential is worth exactly what the market believes about its rigour. That belief does not survive a story about an algorithm deciding who passed — even if the algorithm did no such thing.&lt;/p&gt;
&lt;/blockquote&gt; 
&lt;p&gt;Note the last clause. The reputational damage does not require the AI to have made the decision. It only requires that you cannot demonstrate it did not.&lt;/p&gt; 
&lt;h2&gt;The legal edge is closer than most realize&lt;/h2&gt; 
&lt;p&gt;Emerging US state law is converging on the idea of a &lt;em&gt;consequential decision&lt;/em&gt; — one that materially affects someone's access to employment, education, credit, housing or similar. Where such decisions are made or substantially assisted by automated systems, the pattern in recent legislation is a set of duties around disclosure, explanation and human review.&lt;/p&gt; 
&lt;p&gt;Colorado replaced its 2024 AI Act in May 2026 with SB 26-189, the Automated Decision-Making Technology Act, effective 1 January 2027, and it centres on exactly those duties. California's CCPA automated decision-making provisions arrive in January 2027. The EU AI Act's high-risk obligations land in August 2027, which matters if you certify anyone in Europe.&lt;/p&gt; 
&lt;p&gt;A certification decision that determines whether someone can practise, or be hired, looks a great deal like a consequential decision. Whether any specific statute reaches any specific credentialing programme is a question for your counsel, not for a blog post, and the answer will depend on your jurisdictions, your candidates and how your process actually works.&lt;/p&gt; 
&lt;p&gt;But the direction is not ambiguous, and the practical implication is the same either way: you will be expected to describe where automation touches decisions about individuals, and to show that a person remains accountable. Organizations that can already answer that will find this straightforward. Organizations that cannot will be doing archaeology under time pressure.&lt;/p&gt; 
&lt;h2&gt;What accreditors and boards will ask&lt;/h2&gt; 
&lt;p&gt;Your board is likely to get there first. NACD found roughly 72% of directors say their boards lack sufficient expertise to oversee AI effectively — and in our experience that gap does not produce silence. It produces a written question to staff, usually phrased broadly, usually with a deadline.&lt;/p&gt; 
&lt;p&gt;Meanwhile the general state of practice offers little cover. In ISACA's 2026 poll of more than 3,400 professionals, only around 18% of organizations both require and enforce disclosure of AI use, while roughly a third have no requirement at all. We wrote about that gap &lt;a href="https://www.cimbiotic.ai/insights/almost-everyone-expects-ai-disclosure-almost-nobody-enforces-it"&gt;here&lt;/a&gt;. Being typical is not a defence when the asset at stake is your credential's authority.&lt;/p&gt; 
&lt;h2&gt;Four things worth doing&lt;/h2&gt; 
&lt;p&gt;None of these require a policy project.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Map where AI touches the candidate.&lt;/strong&gt; Walk your certification lifecycle end to end — application, eligibility, item development, form assembly, delivery, scoring, appeals, recertification — and mark every point where an automated system contributes. Include vendor tooling. This is a two-hour exercise and it is usually the whole finding.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Record the human decision.&lt;/strong&gt; Wherever a determination is made about an individual, capture who made it and on what basis. Not a new process in most cases — just writing down what already happens. This is the single artifact that answers an appeal, a regulator or a board.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Ask your exam vendors two questions in writing.&lt;/strong&gt; Where does AI operate in the services you provide us, and is any of our item bank or candidate data used to train models? Get it in writing, because the answer sometimes turns out to be a configurable setting rather than a contractual commitment.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Draft the appeal answer now.&lt;/strong&gt; Write the paragraph you would send a candidate who asks whether their result was automated. Writing it while nothing is contested is considerably easier than writing it afterwards, and the difficulty tells you which of the other three to do first.&lt;/p&gt; 
&lt;h2&gt;What we do not know&lt;/h2&gt; 
&lt;p&gt;There is no good survey of how credential holders specifically respond to AI in certification processes. The evidence cited here comes from professionals reporting on their own organizations, from directors, and from general consumer research. It is directionally consistent, but the precise figures should not be treated as census data, and nobody should claim to know what your candidates think.&lt;/p&gt; 
&lt;p&gt;The legal position is also genuinely unsettled. We have described the direction of travel, not a determination about your programme.&lt;/p&gt; 
&lt;p&gt;What is not uncertain is the asymmetry. The cost of mapping where AI touches your credentialing process is a couple of hours. The cost of not being able to describe it, at the moment somebody insists you do, is the authority of the credential itself.&lt;/p&gt; 
&lt;h2&gt;Where to start&lt;/h2&gt; 
&lt;p&gt;Our &lt;a href="https://www.cimbiotic.ai/scorecard"&gt;AI Trust Readiness Scorecard&lt;/a&gt; includes the question about automated decisions affecting individuals, alongside fifteen others. It takes about five minutes and there is no sign-up to see your result. If you would rather see how we assess this in depth, the &lt;a href="https://www.cimbiotic.ai/framework"&gt;framework is published&lt;/a&gt;.&lt;/p&gt;  
&lt;img src="https://track-na2.hubspot.com/__ptq.gif?a=247028282&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.cimbiotic.ai%2Finsights%2Fai-is-already-inside-your-certification-program-the-question-is-where&amp;amp;bu=https%253A%252F%252Fwww.cimbiotic.ai%252Finsights&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Wed, 16 Sep 2026 20:17:33 GMT</pubDate>
      <author>rick@cimbiotic.ai (Rick Bawcum)</author>
      <guid>https://www.cimbiotic.ai/insights/ai-is-already-inside-your-certification-program-the-question-is-where</guid>
      <dc:date>2026-09-16T20:17:33Z</dc:date>
    </item>
    <item>
      <title>Almost everyone expects AI disclosure. Almost nobody enforces it.</title>
      <link>https://www.cimbiotic.ai/insights/almost-everyone-expects-ai-disclosure-almost-nobody-enforces-it</link>
      <description>&lt;p&gt;Sooner or later a member emails and asks how you use AI. Not as a complaint — just as a question. Which tools, what happens to their data, whether a person reads the thing before it reaches them.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Sooner or later a member emails and asks how you use AI. Not as a complaint — just as a question. Which tools, what happens to their data, whether a person reads the thing before it reaches them.&lt;/p&gt; 
&lt;p&gt;Most associations cannot answer it. That is not a failure of diligence. It is what happens when software you already pay for starts shipping AI features without asking, and staff quite reasonably adopt tools that make their week easier. The tools arrived faster than anyone's ability to describe them.&lt;/p&gt; 
&lt;p&gt;What makes this worth attention now is that the question has stopped being hypothetical.&lt;/p&gt; 
&lt;h2&gt;The numbers&lt;/h2&gt; 
&lt;p&gt;The clearest evidence comes from inside the association world itself. ISACA — a professional association of digital trust practitioners — surveyed more than 3,400 members for its 2026 AI Pulse Poll. These are the people best equipped to govern AI, reporting on their own organizations. Asked whether their organization requires disclosure when AI has been used to create or substantially assist a work product:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;Around &lt;strong&gt;18%&lt;/strong&gt; both require disclosure and enforce it&lt;/li&gt; 
 &lt;li&gt;About &lt;strong&gt;20%&lt;/strong&gt; require it but do not enforce consistently&lt;/li&gt; 
 &lt;li&gt;Roughly &lt;strong&gt;32%&lt;/strong&gt; have no disclosure requirement at all&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;Set that against what people expect. Fractl's Q2 2026 survey of 1,008 US consumers found roughly 84% want AI-assisted written content labelled, rising for audio, images and video. Association members are consumers too, and they do not suspend that expectation when they open a message from their professional body.&lt;/p&gt; 
&lt;p&gt;So: roughly four in five organizations cannot stand behind a disclosure practice, while roughly four in five people expect one.&lt;/p&gt; 
&lt;h2&gt;Requiring is not the same as enforcing&lt;/h2&gt; 
&lt;p&gt;The middle number is the one worth sitting with. Around a fifth of organizations have a disclosure requirement that is not consistently applied.&lt;/p&gt; 
&lt;p&gt;Under scrutiny, that is a weaker position than having no policy at all. A missing policy is a gap. A policy that exists on paper but is not operating implies a control that is not working — and it invites exactly the follow-up question you least want. If a board member asks whether you disclose AI use and the answer is "we have a policy", the next question is how you know it is being followed.&lt;/p&gt; 
&lt;p&gt;This is the difference between having a rule and being able to show the rule works. For an organization whose authority rests on standards it sets for others, that distinction is not academic.&lt;/p&gt; 
&lt;h2&gt;The trap: disclosure on its own can backfire&lt;/h2&gt; 
&lt;p&gt;The obvious response to a gap this wide is to start disclosing. Done without care, the evidence suggests that makes things worse.&lt;/p&gt; 
&lt;p&gt;The same Fractl research found the share of people who say heavy AI use would &lt;em&gt;reduce&lt;/em&gt; their trust in an organization they favour roughly doubled between 2025 and 2026 — from about 20% to around 40%. Only about 14% said it would increase their trust. The effect was strongest among younger respondents, at roughly 54% of Gen Z, and stronger among women than men.&lt;/p&gt; 
&lt;p&gt;Those are the cohorts most associations are working hardest to recruit and retain.&lt;/p&gt; 
&lt;blockquote&gt;
 &lt;p&gt;Disclosure on its own reads as an admission. Disclosure backed by evidence reads as competence. Same sentence, opposite effect.&lt;/p&gt;
&lt;/blockquote&gt; 
&lt;p&gt;An organization that says "we use AI" invites the penalty and offers nothing to weigh against it. An organization that says "we use AI, here is what it touches, here is where a person decides, here is who is accountable" is making a materially different claim. The second one is harder to write, which is precisely why it carries weight.&lt;/p&gt; 
&lt;h2&gt;What generic guidance misses about associations&lt;/h2&gt; 
&lt;p&gt;Most AI governance writing is aimed at companies. Four things are specific to membership organizations, and each raises the stakes.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Credentialing.&lt;/strong&gt; AI now touches exam item generation, adaptive preparation, scoring support and eligibility screening. A credential is worth exactly what the market believes about its rigour, and that belief does not survive a story about an algorithm deciding who passed.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Members whose careers AI threatens.&lt;/strong&gt; National polling in March 2026 found around 70% of Americans expect AI to reduce job opportunities, rising to roughly 81% among Gen Z. Using AI carelessly on the very members whose livelihoods feel exposed is a particular kind of misstep, and they read it that way.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Member-company data.&lt;/strong&gt; Trade associations hold pricing, volume and wage data from competing companies under long-established antitrust discipline. Whether that data reaches an AI tool, and whether a vendor trains on it, is a question with no clean equivalent in the general market.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Chapters and components.&lt;/strong&gt; Local chapters adopt tools independently, under the national brand, usually with no governance capacity at all. The risk is federated. The reputation is not.&lt;/p&gt; 
&lt;h2&gt;Four things worth doing&lt;/h2&gt; 
&lt;p&gt;None of these require budget or a consultant.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Build the inventory.&lt;/strong&gt; One spreadsheet: tool, owner, what data it touches, whether a person reviews the output. Go system by system through your AMS, LMS, certification platform, CRM and email tools and list what AI is switched on. Most organizations find something they did not know about. Half a day of work.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Decide what always gets human review.&lt;/strong&gt; Write down which categories of output a person must approve before they go out, and which may go automatically. Ambiguity here is where incidents come from.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Write the paragraph you would send.&lt;/strong&gt; Draft the reply you would give if a member asked tomorrow. If it is hard to write, that difficulty is the finding — and it tells you exactly which of the other three to do first.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Name someone accountable.&lt;/strong&gt; One person, written into a role description, responsible for answering to leadership on AI use. Not who operates the tools — who answers for them. This costs nothing and changes how every other question gets answered.&lt;/p&gt; 
&lt;h2&gt;What this evidence does not tell you&lt;/h2&gt; 
&lt;p&gt;Worth being straight about the limits, since this piece is arguing for candour.&lt;/p&gt; 
&lt;p&gt;None of the research above asks association members directly how their organization's AI use affects their view of it. ISACA surveyed professionals about their own organizations. Fractl surveyed consumers in general. The closest stakeholder research sits in the charitable sector, and members are not donors — dues are not gifts, and the relationship is different.&lt;/p&gt; 
&lt;p&gt;The direction of travel is consistent across sources and well corroborated. The precise percentages should not be treated as census data, and we try not to quote them that way.&lt;/p&gt; 
&lt;p&gt;That gap is itself worth naming. Nobody has published credible research on how members respond to their association's AI use. Until someone does, everyone in this conversation — including us — is reasoning from adjacent evidence.&lt;/p&gt; 
&lt;h2&gt;Where to start&lt;/h2&gt; 
&lt;p&gt;If you want a structured view of where your organization actually sits, our &lt;a href="https://www.cimbiotic.ai/scorecard"&gt;AI Trust Readiness Scorecard&lt;/a&gt; walks the same five areas in sixteen questions. It takes about five minutes, there is no sign-up to see your result, and if the answer is that you are in reasonable shape, it will say so.&lt;/p&gt;  
&lt;img src="https://track-na2.hubspot.com/__ptq.gif?a=247028282&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.cimbiotic.ai%2Finsights%2Falmost-everyone-expects-ai-disclosure-almost-nobody-enforces-it&amp;amp;bu=https%253A%252F%252Fwww.cimbiotic.ai%252Finsights&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Wed, 16 Sep 2026 20:16:23 GMT</pubDate>
      <author>rick@cimbiotic.ai (Rick Bawcum)</author>
      <guid>https://www.cimbiotic.ai/insights/almost-everyone-expects-ai-disclosure-almost-nobody-enforces-it</guid>
      <dc:date>2026-09-16T20:16:23Z</dc:date>
    </item>
    <item>
      <title>You did not choose most of the AI in your association. Your vendors did.</title>
      <link>https://www.cimbiotic.ai/insights/you-did-not-choose-most-of-the-ai-in-your-association-your-vendors-did</link>
      <description>&lt;p&gt;Ask an association executive which AI tools their organization uses and you will usually get a short, confident list. Ask which AI features are running inside the software they already pay for, and the answer changes shape.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ask an association executive which AI tools their organization uses and you will usually get a short, confident list. Ask which AI features are running inside the software they already pay for, and the answer changes shape.&lt;/p&gt; 
&lt;p&gt;That second category is almost always larger. Your AMS, your LMS, your certification platform, your email tool, your community software and your events system have all shipped AI capability over the past two years. Most of it arrived in a release note. Some of it arrived switched on.&lt;/p&gt; 
&lt;p&gt;None of that was a decision your organization made. It was a decision your vendors made, and then told you about — in a changelog, in a webinar you could not attend, in a footer of an email about something else.&lt;/p&gt; 
&lt;h2&gt;This is not a story about bad vendors&lt;/h2&gt; 
&lt;p&gt;It is worth being fair here, because the vendor-bashing version of this argument is both wrong and useless.&lt;/p&gt; 
&lt;p&gt;Your software vendors are not being careless. They are doing exactly what their incentives and their customers demand: shipping useful capability quickly, in a market where being six months behind on AI is an existential problem. Defaults are set to on because a feature nobody discovers is a feature that does not renew.&lt;/p&gt; 
&lt;p&gt;The asymmetry is not about competence or good faith. It is that &lt;strong&gt;your vendor's job is to ship value fast, and your job is to be able to answer for what runs on your members' data.&lt;/strong&gt; Both are legitimate. They simply do not produce the same answer about what should be enabled, when, and with what disclosure.&lt;/p&gt; 
&lt;p&gt;Which means the gap is yours to close. Nobody else in that relationship is incentivised to close it for you.&lt;/p&gt; 
&lt;h2&gt;"We take security seriously" is not evidence&lt;/h2&gt; 
&lt;p&gt;The standard response to a governance question is a trust page: a security overview, a compliance badge, a paragraph about responsible AI. These are not worthless — a vendor that has thought about the question is better than one that has not.&lt;/p&gt; 
&lt;p&gt;But they are self-attestation. The vendor is describing its own practice, against criteria it selected, with no independent party checking and no consequence for overstating. That is a marketing artifact, not assurance.&lt;/p&gt; 
&lt;blockquote&gt;
 &lt;p&gt;A vendor cannot credibly certify itself. Not because vendors are dishonest, but because an assessment nobody can fail is not an assessment.&lt;/p&gt;
&lt;/blockquote&gt; 
&lt;p&gt;This matters more than usual right now because there is no established floor. In ISACA's 2026 poll of more than 3,400 professionals, only around 18% of organizations both require and enforce disclosure of AI use. When general practice is that thin, a confident trust page tells you very little about what is actually happening inside the product.&lt;/p&gt; 
&lt;h2&gt;Four questions worth putting in writing&lt;/h2&gt; 
&lt;p&gt;Not a procurement overhaul. Four questions, by email, to each vendor that touches member data. The written answer is the point — it creates a record, and it tends to produce more careful responses than a call.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;1. Where does AI operate in the services you provide us?&lt;/strong&gt; Ask for the specific features, not a philosophy. You are building an inventory, and this is the fastest way to fill in the part you cannot see from your own admin console.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;2. Is any of our data used to train your models, or any third party's? Is that a contractual commitment or an account setting?&lt;/strong&gt; This distinction is the one that catches people out. A great many vendors will tell you truthfully that your data is not used for training — because a toggle in your account is currently set that way. A setting can be changed by anyone with admin access, or reset in a migration. A contractual term cannot.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;3. Which model providers and subprocessors are involved, and where does the data go?&lt;/strong&gt; Your vendor is usually not the party running the model. The answer determines who actually holds your members' data, and under whose terms.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;4. How will you notify us before enabling a new AI feature on our instance?&lt;/strong&gt; The most useful question of the four, because it is forward-looking. If the answer is a release note, you now know that your governance depends on someone reading release notes.&lt;/p&gt; 
&lt;h2&gt;The question almost nobody asks: can you turn it off?&lt;/h2&gt; 
&lt;p&gt;Incident response is where vendor-run AI gets genuinely uncomfortable. If a tool starts producing wrong output at scale — an inaccurate answer repeated across thousands of member queries, a misfiring automated message — who can stop it, and how fast?&lt;/p&gt; 
&lt;p&gt;The ISACA poll found roughly 56% of professionals are unsure how long it would take to halt an AI system during a security incident, and around 39% do not know whether a documented shutdown or override process exists at all. Those are respondents whose profession is digital trust, reporting on systems their own organizations run.&lt;/p&gt; 
&lt;p&gt;When the system belongs to a vendor, the answer usually involves a support ticket. That is worth knowing before you need it, not after. It is a reasonable thing to ask, and a reasonable thing to have in writing.&lt;/p&gt; 
&lt;h2&gt;A specific warning for trade associations&lt;/h2&gt; 
&lt;p&gt;If you are a trade association, one of these questions carries weight the others do not.&lt;/p&gt; 
&lt;p&gt;You hold pricing, volume, wage and market data submitted by companies that compete with each other, under antitrust discipline that predates all of this by decades. The controls around that data were designed for a world where the risk was a person seeing something they should not.&lt;/p&gt; 
&lt;p&gt;An AI feature that summarises, searches or surfaces patterns across your member data operates differently. Whether that data reaches a model, whether it is retained, and whether it could inform output shown to another member company are questions your existing information-sharing policies almost certainly do not address. This is a competition-law question as much as a privacy one, and it is worth raising with the counsel who advises you on information sharing rather than treating it as an IT matter.&lt;/p&gt; 
&lt;h2&gt;What this does not tell you&lt;/h2&gt; 
&lt;p&gt;We have no systematic data on how association software vendors actually handle AI defaults, training rights or notification — nobody has published it, ourselves included. The pattern described here comes from what organizations find when they look, not from a survey of vendors.&lt;/p&gt; 
&lt;p&gt;It is also entirely possible that your vendors answer all four questions well. Several will. The point is not that the answers will be bad; it is that you currently do not have them in writing, and the asking costs an afternoon.&lt;/p&gt; 
&lt;p&gt;We have written before about &lt;a href="https://www.cimbiotic.ai/insights/almost-everyone-expects-ai-disclosure-almost-nobody-enforces-it"&gt;the gap between expecting disclosure and enforcing it&lt;/a&gt;, and about &lt;a href="https://www.cimbiotic.ai/insights/ai-is-already-inside-your-certification-programme-the-question-is-where"&gt;where AI has already entered certification programmes&lt;/a&gt;. This is the same problem approached from the supply side: you cannot disclose what you do not know, and you do not know what your vendors have not told you.&lt;/p&gt; 
&lt;h2&gt;Where to start&lt;/h2&gt; 
&lt;p&gt;Two of the sixteen questions in our &lt;a href="https://www.cimbiotic.ai/scorecard"&gt;AI Trust Readiness Scorecard&lt;/a&gt; deal specifically with vendor-enabled features and model-training terms. It takes about five minutes, and there is no sign-up to see your result. If you would rather see how we assess this properly, the &lt;a href="https://www.cimbiotic.ai/framework"&gt;framework is published&lt;/a&gt;.&lt;/p&gt;  
&lt;img src="https://track-na2.hubspot.com/__ptq.gif?a=247028282&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.cimbiotic.ai%2Finsights%2Fyou-did-not-choose-most-of-the-ai-in-your-association-your-vendors-did&amp;amp;bu=https%253A%252F%252Fwww.cimbiotic.ai%252Finsights&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>#aiassurance</category>
      <category>aiaudit</category>
      <category>aicompliance</category>
      <category>aitrust</category>
      <pubDate>Wed, 16 Sep 2026 20:14:23 GMT</pubDate>
      <author>rick@cimbiotic.ai (Rick Bawcum)</author>
      <guid>https://www.cimbiotic.ai/insights/you-did-not-choose-most-of-the-ai-in-your-association-your-vendors-did</guid>
      <dc:date>2026-09-16T20:14:23Z</dc:date>
    </item>
  </channel>
</rss>
