Skip to content

AI Supply Chain Security

Managing the risks of third-party models, datasets, libraries and tools in AI systems.

Editorial team 1 min read

AI systems depend on many external components. Each is a potential route for attack.

Components at Risk

  • Pre-trained models downloaded from hubs.
  • Datasets used for training, fine-tuning and evaluation.
  • Libraries and frameworks for ML and AI applications.
  • Plugins, tools and MCP servers connected to assistants.
  • Model APIs from providers.

Specific Threats

  • Model files that execute code when loaded, through unsafe serialisation formats.
  • Backdoored or poisoned models and datasets.
  • Typosquatted packages with names similar to popular libraries.
  • Compromised maintainers or accounts.
  • Malicious tool integrations.

Controls

  • Use trusted sources and verified publishers.
  • Prefer safe model formats such as safetensors over formats that allow code execution.
  • Pin versions and verify hashes.
  • Scan models and packages.
  • Maintain an inventory of models, datasets and dependencies — sometimes called an AI bill of materials.
  • Review licences and terms.
  • Test third-party components before production use.

Ongoing

Monitor for vulnerabilities and advisories affecting your components, and update deliberately.

More in AI security

All AI security guides →
AI security Guide · 1 min

Introduction to AI Security

What AI security covers — attacks on models, data and AI applications — and how it differs from traditional security.

AI security 1 min read 29 Jun 2025

AI security Guide · 1 min

The OWASP Top 10 for LLM Applications

An overview of the widely used list of the most critical security risks for applications built on language models.

AI security 1 min read 28 Jun 2025

AI security Guide · 1 min

Jailbreaks: How They Work and How to Defend

How people try to get models to bypass their safety training, common techniques, and layered defences.

AI security 1 min read 27 Jun 2025

AI security Guide · 1 min

Indirect Prompt Injection

How attackers hide instructions in web pages, emails and documents that AI systems read, and why it's so dangerous for agents.

AI security 1 min read 26 Jun 2025