risk

AI supply-chain compromise and provider concentration

Because the organization relies on third-party pretrained models, datasets, and libraries that may carry backdoors, malicious code, or bias, and concentrates on a few external AI API providers, AI-dependent workflows are exposed to both supply-chain compromise and provider outage or insolvency, resulting in compromised model behaviour or sudden loss of AI capability.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

category
ai_governance
domain
  • AI Governance
  • Third-Party / Supply-Chain Risk
  • Secure Development (SDLC) & Application Security
taxonomy
  • nist-ai-rmf-risk
  • iso-23894-ai-risk
  • eu-ai-act-risk
inherent_rating
high

Details

risk_id
ai-supply-chain-concentration
category
ai_governance
likelihood
medium
impact
high
inherent_rating
high
treatment
mitigate
taxonomies
  • nist-ai-rmf-risk
  • iso-23894-ai-risk
  • eu-ai-act-risk

Source

No record-specific source URL is provided.

Connections