Skip to content

AI supply chain security

  • Draft
  • v0.3.0
  • Security architects and engineers
  • Reviewed 2026-09-28

An AI system depends on more than software packages. It also depends on models, adapters, datasets, prompts, tool servers and hosted AI services, and any of them can be tampered with or withdrawn. OWASP lists supply chain as LLM04:2026 and, for agents, ASI04. MITRE ATLAS covers it as AML.T0010, with sub-techniques for AI software, data, models, container registries and agent tools.

Inventory of AI components

Component Record
Models and adapters Name, version, source, license, hash, signature, intended use, evaluation results
Datasets Source, license, collection date, preprocessing, hash, known limitations
AI software Frameworks, runtimes, inference servers, with versions
Prompts and policies Versioned system prompts and guardrail configurations
Tools and MCP servers Publisher, version, tool definitions, permissions requested
Hosted AI services Provider, model version, region, data terms, fallback

AI bill of materials

An AI bill of materials (AI-BOM) extends a software bill of materials (SBOM) to models and datasets. Two open formats support it.

Format AI support
CycloneDX Machine learning BOMs since version 1.5. The current version is 1.7.
SPDX Version 3.0 adds AI and Dataset profiles

CISA and G7 partners published Software Bill of Materials for AI: Minimum Elements on 2026-05-12. Use it to decide which fields your AI-BOMs must carry. Generate the AI-BOM in the build pipeline, store it with the release, and ask suppliers for theirs.

Integrity and provenance

Control How
Sign models OpenSSF model signing (v1.0 released 2025-04-04) signs model files with Sigstore bundles, using keyless signing, certificates or keys
Verify before loading Check the signature and hash at deployment and at load time, and refuse unsigned artifacts
Build provenance Produce SLSA provenance for training and packaging pipelines. SLSA v1.2 adds a Source track.
Safe formats Prefer weight formats that cannot execute code on load, and scan formats that can
Pin versions Pin model, dataset and tool versions, and alert on changes, including hosted model version changes
Mirror Load models and packages from an internal registry, not straight from public hubs

Suppliers and hosted services

  • Assess each AI supplier's security, data handling and incident notification terms.
  • Record which controls the supplier provides and which you inherit.
  • Plan an exit: a fallback model or a degraded mode if a supplier fails or changes terms.
  • Watch for concentration risk, where many systems depend on one provider.

Sources

Checked 2026-09-28.