Third-Party AI Providers in SAP AI
In some AI scenarios, SAP services may interact with third-party model providers. This is particularly relevant in generative AI use cases, where large language models may be accessed to process natural language requests.
In many SAP AI architectures, access to such models is mediated through SAP-managed services, such as the Generative AI Hub. This introduces a controlled interaction model, where requests are routed through SAP layers rather than directly from applications to external providers.
This approach supports governance by allowing SAP to apply controls and manage how external models are accessed.
How SAP Ensures Transparency
When third parties are involved in data processing, transparency becomes essential. Organizations need to understand who processes their data and for what purpose, especially to meet data protection and compliance requirements.
To support this, SAP provides documentation and transparency mechanisms that help customers identify subprocessors and understand how data is handled.
SAP provides access to relevant information through the SAP Trust Center: https://www.sap.com/about/trust-center/data-privacy.htmlThis includes:
- Subprocessor lists: These identify SAP affiliates or third parties that may process personal data on behalf of SAP and its customers.
- Data Transfer Factsheets: These documents help customers understand how data is transferred and processed, supporting compliance assessments such as Transfer Impact Assessments.
These resources allow organizations to review which parties may be involved and how data processing is structured.
Control Over Data Processing
Even when external models are used, SAP defines clear boundaries for data handling:
- Data is processed only for the purpose defined by the customer.
- External providers are contractually restricted in how customer data can be used.
- Access to external models is managed through SAP services.
In some scenarios, additional controls can be applied before data is sent to external models, such as:
- Data masking or anonymization
- Content filtering
- Structured prompt handling
These controls help reduce exposure of sensitive information and support compliance with data protection requirements.
Why This Matters
Using third-party AI providers introduces additional considerations for data protection and compliance. SAP’s approach focuses on three key pillars:
- Transparency
- SAP makes relevant information on data processing available, including subprocessor and data transfer documentation through resources such as the SAP Trust Center and applicable customer agreements, helping organizations understand how data is handled.
- Control
- Interactions with external models are mediated through SAP-managed services.
- Defined responsibilities
- Contractual agreements and roles (such as data controller and processor) define how data is handled.
This allows organizations to use external AI capabilities while maintaining oversight of how their data is processed.
Lesson Summary
When third-party AI providers are involved, SAP ensures that access is managed through controlled architectures and supported by contractual and transparency mechanisms. Customers can review subprocessor information and data transfer documentation in the SAP Trust Center, helping them understand and govern how their data is handled.