As enterprise applications become AI-enabled, an emerging “model layer” is becoming a recognisable feature of the cloud technology stack. The model layer is where applications transmit prompts and contextual data to one or more AI models hosted by third parties, receive outputs, and then surface them to users. This architectural pattern is now common in applications that summarise work items, draft communications, or recommend next steps.

Consider, as an example, a typical AI-enabled CRM (we’ll walk through the diagram). An employee uses the CRM via a web browser. The application can access internal data sources: historic orders, email and support ticket systems, and a knowledge base containing manuals and policies. To generate an output, the CRM may package user prompts together with selected content from those data sources and send them via API to external model providers. In practice, different model providers may be used for different tasks, one optimised for summarisation, another for drafting, another for recommendations, perhaps.
That simple data flow – out of the application, into a third party’s systems, and back – creates a concentrated “AI risk interface” for the business. Some risks are obvious: privacy, confidentiality, and information security. Organisations need to understand what data is being sent, how much is included, whether anything is redacted or scrubbed, and whether the content contains third-party confidential information. Intellectual property concerns often follow: order databases may contain pricing, imagery, and product descriptions among other things – information that can be highly sensitive in competitive markets.
Regulatory questions can also arise quickly. If AI is influencing “next best actions” or how customer interactions are handled, organisations need to consider whether they are approaching GDPR automated decision-making territory and what other frameworks may be triggered in regulated sectors. There is also a contractual permissions issue: the fact that data can be technically shared does not mean it can be legally shared under existing customer terms.
There’s a broader commercial risk here too: if tacit knowledge and business logic leak through model interactions that the organisation does not control, the model layer becomes not just a technical dependency but a way an enterprise’s value leaks out to third parties. Managing that exposure starts with understanding and documenting the model layer as part of the operational stack, because governance and contracting can’t address what the business hasn’t mapped out. We are looking at this theme and some other implications of the “AI Platform Shift” for enterprise software in our ongoing “AI Contracting Playbook” webinar series. The first episode took place in mid-February 2026. Please get in touch at chris.kemp@kempitlaw.com for a copy of the slides and recording. The next one will be on Wednesday 1 July 2026. You can sign up here.