Versatile AI Risk Assessment

AI threat catalogueSupply Chain and ProvenanceSupply Chain

Supply Chain – Infrastructure

Attackers compromise the technical environment in which an AI system is developed and operated: cloud services, development tools, and third-party software components. This gives them access to systems, data, and models.

As of: July 2026 · Catalogue version 2026.07.17.3 · 4 mitigations · 13 verified sources

Description

An AI system is never built in isolation: it relies on cloud platforms, code libraries, development tools, and services from external providers. Any of these components can contain vulnerabilities or be deliberately manipulated. Attackers exploit, for example, vulnerable or counterfeit software packages, openly reachable AI servers, or unsecured container registries (storage locations for ready-to-run software packages) to slip in unnoticed. Once inside, they can take over systems and networks, extract data, or alter the model itself. The risk spans the entire chain from training to live operation and often originates outside your own organization, with a provider or supplier.

Possible impact

A compromised infrastructure can disrupt or halt the AI system and destroy the integrity of the model, so its results can no longer be relied on. Confidential data such as training data, access credentials, or customer records can leak. The fallout includes recovery and investigation costs, notification and liability exposure under the GDPR and the EU AI Act, and reputational damage with customers and partners.

Example

A development team installs a popular AI code library. Attackers have slipped a counterfeit dependency into the official package channel that silently sends credentials and system information to an external server during installation. This is exactly what happened to users of a preview build of a widely used AI framework.

Recommended mitigations (4)

Every mitigation states its control type, effect, implementation level and the reason for the classification.

Framework mappings

Verified locations in OWASP, NIST AI RMF, MITRE ATLAS, the EU AI Act and further frameworks. The mappings are taxonomic, not evidence of compliance.

OWASP LLM Top 10 LLM03:2025NIST AI RMF Section 2.12 · GOVERN 6.1 · MAP 4.1 · NISTAML.05MITRE ATLAS AML.T0010EU AI Act Article 25(4) · Article 53(1)(a) · Article 55(1)(d)BSI R1BIML BIML-LLM inference:9 · BIML78 inference:4 · BIML78 raw:3

Verified references (13)

Every reference states the framework, the exact location and the publishing organisation.

More entries from the topic group Supply Chain and Provenance.

Assess this threat in your own system

The live demo contains all 52 threats of this catalogue, including the EU AI Act and GDPR assessment. The free single modules cover AI risk, the EU AI Act and GDPR. No sign-up; the assessment runs locally in your browser.

Cite this entry

For reports, policies or internal documents; the link leads directly to this entry.

“Supply Chain – Infrastructure”. Versatile AI Risk Assessment, AI threat catalogue, as of July 2026.
https://www.versatile-ai-risk-assessment.com/en/wissensbasis/threats/supply-chain-infrastructure/

← Back to the full catalogue