AI is going crazy, and you can build your own but generally you need to look at a supplier, so it's worth understand management of Vendors, you as the controller using their service are at risk of them not making their AI operations transparent. It's a big business risk to my clients.
GDPR is closely linked to AI, and if you use a service/vendor, the reputation and fine risk may fall on you as the provider. Need visibility into each vendor, how they are using AI, in turn they are using vendors so it's a nice complex dependency problem. You need to be aware of what you are relying on.
Ensure contracts with vendors consider AI, how the process your data and how their sub process vendors do the same.
Track website customer behaviour, we use a vendor to clean up the data. In turn, I have no idea that they are using AI outside of the UK or EU. Follow the dependency chains as all this needs to be transparent to the end customer if needed.