AI threat catalogueSupply Chain and ProvenanceSupply Chain
Supply Chain – Infrastructure
Attackers compromise the technical environment in which an AI system is developed and operated: cloud services, development tools, and third-party software components. This gives them access to systems, data, and models.
Description
An AI system is never built in isolation: it relies on cloud platforms, code libraries, development tools, and services from external providers. Any of these components can contain vulnerabilities or be deliberately manipulated. Attackers exploit, for example, vulnerable or counterfeit software packages, openly reachable AI servers, or unsecured container registries (storage locations for ready-to-run software packages) to slip in unnoticed. Once inside, they can take over systems and networks, extract data, or alter the model itself. The risk spans the entire chain from training to live operation and often originates outside your own organization, with a provider or supplier.
Possible impact
A compromised infrastructure can disrupt or halt the AI system and destroy the integrity of the model, so its results can no longer be relied on. Confidential data such as training data, access credentials, or customer records can leak. The fallout includes recovery and investigation costs, notification and liability exposure under the GDPR and the EU AI Act, and reputational damage with customers and partners.
Example
A development team installs a popular AI code library. Attackers have slipped a counterfeit dependency into the official package channel that silently sends credentials and system information to an external server during installation. This is exactly what happened to users of a preview build of a widely used AI framework.
Recommended mitigations (4)
Every mitigation states its control type, effect, implementation level and the reason for the classification.
Use trusted suppliersContracts & third-party management
- Effect
- Preventive
- Implementation level
- Supply chain
- Complementary control type
- Organizational & process-based
- Reason for the classification
- “Use trusted suppliers” is primarily a contracts and third-party management control: Selection, verifiable commitments, and audit or enforcement rights toward third parties enable the protective effect; complemented by binding workflows.
Infrastructure hardeningTechnical
- Effect
- Preventive
- Implementation level
- Infrastructure
- Reason for the classification
- “Infrastructure hardening” is primarily technical: Safe formats, restrictive defaults, or protective layers reduce unsafe execution paths and exploitable attack surface.
Supply chain security auditsContracts & third-party management
- Effect
- Preventive, Detective
- Implementation level
- Supply chain
- Complementary control type
- Organizational & process-based
- Reason for the classification
- “Supply chain security audits” is primarily a contracts and third-party management control: Contractual audit, information, and remediation rights enable control; binding audit workflows put those rights into practice.
Continuous monitoring of hosting environmentsTechnical
- Effect
- Detective
- Implementation level
- Infrastructure, Use & operations
- Complementary control type
- Organizational & process-based
- Reason for the classification
- “Continuous monitoring of hosting environments” is primarily technical: Software or analytical tools systematically produce and evaluate measurements, deviations, or attack indicators; complemented by binding workflows.
Framework mappings
Verified locations in OWASP, NIST AI RMF, MITRE ATLAS, the EU AI Act and further frameworks. The mappings are taxonomic, not evidence of compliance.
Verified references (13)
Every reference states the framework, the exact location and the publishing organisation.
- OWASP LLM Top 10 LLM03:2025 Supply ChainLLM03:2025 Supply Chain, official category page OWASP FoundationOriginal
- NIST AI RMF Section 2.12 Value Chain and Component IntegrationSection 2.12, p. 12 National Institute of Standards and Technology (NIST)Original
- NIST AI RMF GOVERN 6.1 GOVERN 6.1GOVERN 6.1, p. 24 National Institute of Standards and Technology (NIST)Original
- NIST AI RMF MAP 4.1 MAP 4.1MAP 4.1, p. 27 National Institute of Standards and Technology (NIST)Original
- NIST AI RMF NISTAML.05 Supply Chain AttacksTaxonomy Index, pp. x–xi; Section 3.2, pp. 41–43 National Institute of Standards and Technology (NIST)Original
- MITRE ATLAS AML.T0010 AI Supply Chain CompromiseATLAS.yaml technique object with id AML.T0010 (pinned release v5.6.0) MITREOriginal
- EU AI Act Article 25(4) Responsibilities along the AI value chainArticle 25(4) European Union (EUR-Lex)Original
- EU AI Act Article 53(1)(a) Obligations for providers of general-purpose AI modelsArticle 53(1)(a) and Annex XI European Union (EUR-Lex)Original
- EU AI Act Article 55(1)(d) Obligations of providers of general-purpose AI models with systemic riskArticle 55(1)(d) European Union (EUR-Lex)Original
- BSI R1 Abhängigkeit vom entwickelnden/betreibenden Unternehmen (Text, Bild, Video)Kap. 4, R1, p. 13 Bundesamt für Sicherheit in der Informationstechnik (BSI)Original
- BIML BIML-LLM inference:9 HostingPDF p. 19, [inference:9:hosting] Berryville Institute of Machine Learning (BIML)Original
- BIML BIML78 inference:4 HostingPDF p. 20, [inference:4:hosting] Berryville Institute of Machine Learning (BIML)Original
- BIML BIML78 raw:3 StoragePDF p. 10, [raw:3:storage] Berryville Institute of Machine Learning (BIML)Original
Related threats
More entries from the topic group Supply Chain and Provenance.
Assess this threat in your own system
The live demo contains all 52 threats of this catalogue, including the EU AI Act and GDPR assessment. The free single modules cover AI risk, the EU AI Act and GDPR. No sign-up; the assessment runs locally in your browser.
Cite this entry
For reports, policies or internal documents; the link leads directly to this entry.
“Supply Chain – Infrastructure”. Versatile AI Risk Assessment, AI threat catalogue, as of July 2026. https://www.versatile-ai-risk-assessment.com/en/wissensbasis/threats/supply-chain-infrastructure/