AI tool risk isn't static.
Security teams spend a lot of time evaluating AI tools before approving them. Where is data stored? Is customer data used for training? How long is it retained? What certifications does the vendor have? What happens to intellectual property? Which third parties can access the data?
Those are all important questions.
But there is another question that gets much less attention:
What happens after you approve the tool?
AI vendors are changing incredibly quickly. Privacy policies get rewritten. Training practices change. Companies get acquired. New security incidents are disclosed. Terms of service change. New regulatory issues emerge.
A tool that passed your security review a few months ago isn't necessarily the same risk you approved.
We see this firsthand because we continuously maintain the risk analysis behind the Verax AI Tool Risk Center.
Here's what changed in August.
August 2026 at a Glance
Between our baseline and August review, we identified policy-driven changes affecting several AI tools.
Five increased in risk. One decreased. One had mixed changes that left its overall score unchanged.
The largest movement was Cursor, which increased from 4.57 to 6.29 (+1.72).
Other notable changes included Meta AI (6.71 → 7.14), Perplexity (5.86 → 6.29), ElevenLabs (4.43 → 4.86), and Claude (4.29 → 4.71).
Not every change increased risk. ChatGPT improved from 5.00 to 4.86, while Otter.ai remained at 5.43 after positive and negative developments offset each other.
The numbers are interesting, but what's more important is why they changed.
Cursor: 4.57 → 6.29
Cursor saw the largest increase in our August review, moving 1.72 points on our 1-10 risk scale.This wasn't the result of a single policy change.
Our analysis identified several developments that materially affected Cursor's risk profile, including changes related to ownership, developer code being used for model training, and a security incident involving developer code exposure.
The result was increased risk across multiple dimensions, including training, sharing, retention, legal, sovereignty, IP, and security.
This is a good example of why AI risk can't be treated as a fixed property of a product.
The application may look exactly the same to an employee. The underlying risk to the organization can still change substantially.
Perplexity: 5.86 → 6.29
Perplexity provides a different example.
Its overall risk score increased from 5.86 to 6.29 after changes to its privacy policy resulted in less explicit commitments around training opt-outs and data retention.
Nothing needed to change in the user experience for the organization's risk exposure to change.
The terms governing the relationship between the user, their data, and the AI provider changed.
For security and governance teams, that matters.
Meta AI: 6.71 → 7.14
Meta AI already had one of the higher risk scores among the tools included in this month's update. Its score increased further, from 6.71 to 7.14.
The change followed developments around the use of AI conversation content for advertising and reduced opt-out controls.
Again, an employee opening Meta AI may not notice anything different.
From a data governance perspective, however, the conditions under which that employee is sharing information with the service have changed.
Claude and ElevenLabs Also Increased
Claude moved from 4.29 to 4.71 following changes related to biometric data collection and disclosure provisions. Importantly, the changes identified in our analysis applied to consumer plans, not Team, Enterprise, or API plans.
ElevenLabs increased from 4.43 to 4.86, driven by changes related to content rights and the absence of user IP indemnification in its new Image & Video Terms.
These examples also highlight why evaluating an AI vendor purely at the company level isn't always enough.
The specific plan, product, and terms under which an employee uses an AI service can materially affect its risk.
Risk Can Move in the Other Direction Too
Continuous risk assessment isn't only about identifying new problems.
ChatGPT's score actually decreased from 5.00 to 4.86 after OpenAI added IP indemnification for paid plans.
That's important.
A useful risk model shouldn't be designed to continuously make vendors look worse. It should reflect material developments in either direction.
If a vendor improves its contractual protections, privacy practices, security posture, or enterprise controls, those improvements should be reflected in its risk profile just as negative developments should.
Otter.ai provides another interesting example. Its overall score remained unchanged at 5.43, but that doesn't mean nothing happened.
Our analysis found an improvement in cross-border compliance alongside increased legal risk. The two movements offset each other in the overall score.
That's another reason why the number alone never tells the whole story.
Why Point-in-Time AI Assessments Aren't Enough
Traditional third-party risk management was largely designed around a relatively slow process.
A vendor goes through procurement. Security reviews its documentation. Legal reviews the terms. Someone completes a questionnaire. The vendor gets approved.
Maybe the assessment happens again next year.
That model becomes increasingly difficult to apply to AI.
AI services can change quickly. Models, features, integrations, training policies, enterprise controls, ownership, and terms can all evolve between formal vendor reviews.
At the same time, employees aren't necessarily waiting for procurement before adopting new AI tools.
That creates two different visibility problems.
Organizations need to know which AI tools are being used.
But they also need to know whether the risk behind the tools they've already discovered and evaluated has changed.
Solving the first problem without the second still leaves a significant blind spot.
What We're Watching Next
Continuous assessment also means identifying developments that haven't yet justified a score change but may require one later.
Based on our August review, we're monitoring three areas for the next update:
GitHub Copilot for policy alignment developments.
Gemini for privacy policy updates.
Midjourney for developments related to ongoing IP litigation.
We haven't assigned new risk-score changes based on these items. They're simply areas we're continuing to monitor.
From "Is It Safe?" to "Is It Still Safe?"
Security teams often ask:
"Is this AI tool safe for our employees to use?"
It's a reasonable question, but increasingly it's an incomplete one.
Organizations should also be asking:
What is the risk of using this tool today?
What conditions are we relying on when we approve it?
And, continuously:
Are those conditions still true?
That's why we maintain the analysis behind the Verax AI Tool Risk Center continuously rather than treating AI risk assessment as a one-time exercise.
The goal isn't simply to assign a number to an AI tool. It's to understand what sits behind that number, what changed, and whether those changes should affect how an organization allows the tool to be used.
Because approving an AI tool shouldn't be the end of the assessment.
The real question is whether it's still as safe as when you approved it.


