AI Supply Chain Security: Models, Data, Code, and Provenance
An operational AI supply-chain guide covering models, datasets, code, containers, prompts, services, provenance, release controls, and incident response.
Independent technology publication
Independent coverage and analysis of AI security, web vulnerabilities, model benchmarks, and the technologies shaping secure artificial intelligence.
Explore latest analysisLatest coverage
An operational AI supply-chain guide covering models, datasets, code, containers, prompts, services, provenance, release controls, and incident response.
A developer-focused architecture guide to LLM trust boundaries, authorization, retrieval, output validation, tool safety, secrets, and monitoring.
A year-to-date evidence synthesis for 2026, separating durable engineering lessons from incomplete or still-unresolved claims.
A dated evidence review for securing open-source and open-weight model artifacts from repository to isolated serving.
A dated technical change log for NIST, EU, and standards-body updates, with control mappings and evidence to retain.
A dated guide to reading cyber-capability results without confusing benchmark performance with real-world compromise probability.
Current RAG security evidence separates poisoning, leakage, access control, and provenance, then maps research claims to defensible controls.
A dated research synthesis separates attack detection from damage prevention and evaluates when prompt-injection defense evidence transfers beyond one benchmark.
Three documented evaluation incidents reveal how weak boundaries, inferred authorization, and delayed detection propagate into real impact. Evidence reviewed 2026-09-17.
An evidence-led review of GPT-6 Astra's September 2026 system card, using supported, partial, unestablished, and unreported claim statuses without ranking models.
A release-led comparison of OWASP's 2026 and 2025 LLM Top 10, with exact counterparts, date caveats, and a control-impact map for existing applications.
A dated analysis of NIST's agent-security RFI, NCCoE identity concept paper, and standards initiative, with practical control translations and explicit draft-status limits.
September 2026 month-to-date review of AI security research, with evidence cards, limitations, and actions for testing agentic systems.
How to read frontier model evaluations as dated evidence about capabilities, safeguards, and limits—and turn the results into bounded security decisions.
A practical framework for reporting test-time compute, samples, search, tools, retries, quality, latency, and cost in reasoning benchmarks without hiding the budget.
A practical framework for detecting benchmark saturation and choosing whether to keep, complement, refresh, or replace an AI evaluation.
A practical audit for benchmark contamination, data leakage, tool exposure, and evidence-based LLM evaluation claims.
A practical method for validating LLM judges with human reference evidence, bias testing, calibration, slice analysis, and drift monitoring.
A practical guide to measuring agentic systems as evaluated workflows, including tools, environments, recovery, safety constraints, and reproducibility.
How to interpret AI security benchmark attack-success rates with clear denominators, attacker budgets, defenses, utility, uncertainty, and evidence.
A practical guide to interpreting coding AI benchmarks: compare function completion, repository repair, agent scaffolds, test quality, and reproducibility.
A practical guide to evaluation harness reproducibility: identify hidden variables, report the full evaluated system, and label benchmark comparisons honestly.
A practical architecture for building private LLM evaluation data that measures real tasks without leaking the holdout into development.
A workload-first method for turning production requirements into a defensible AI model selection decision.
How to give vendors enough evidence to reproduce, assess, and fix an AI vulnerability without overstating the claim.
How to triage an untrusted model repository using provenance, scanning, isolation, and evidence.
Why model formats and loaders matter when an AI system receives an untrusted artifact.
How to determine whether a vulnerability in an LLM framework or dependency actually affects your deployed AI application.
A defensive method for analyzing containment escapes across AI code interpreters, training jobs, agents, and shared infrastructure.
How to identify, prioritize, patch, mitigate, and verify vulnerabilities across GPU-backed AI infrastructure.
How security teams can connect CISA KEV exploitation evidence to real AI infrastructure, exposure, ownership, and verification.
A practical guide to using CVSS 4.0 for AI vulnerabilities without confusing technical severity with local risk.
An evidence framework for distinguishing model behavior, product weakness, boundary failure, and actionable prompt-injection vulnerability disclosures.
A defensive workflow for deciding whether an SSRF advisory affects an AI fetcher, proving reachability, applying mitigations, and verifying closure.
A hands-on worksheet for mapping AI security advisories to your exact component, version, configuration, reachability, evidence, fix, and verified closure.
A practical, evidence-led method for deciding whether an AI CVE or advisory affects your models, runtimes, frameworks, services, and deployments.
Keep provider, database, cloud, OAuth, webhook, and tenant credentials out of browsers and models with scoped access, rotation, and auditable brokers.
Design tenant-aware LLM caches that preserve personalization without leaking responses, retrieval results, tool data, or stale permissions.
A practical resource-governance guide for limiting LLM, agent, tool, queue, and external API spend without mistaking every spike for abuse.
A practical guide to separating authentication sessions, conversations, agent runs, and memory so multi-turn AI applications remain authorized and revocable.
A practical defensive guide to authenticating webhooks and safely triggering AI workflows, tools, jobs, and side effects.
Defensive guidance for securing AI document uploads before parsing, OCR, chunking, embedding, indexing, or LLM retrieval.
A practical guide to enforcing trusted, tenant-bound API authorization for model-proposed tool calls, background jobs, and delegated agents.
A practical architecture for preventing cross-tenant leakage across LLM prompts, RAG, memory, caches, tools, credentials, jobs, logs, and billing.
Defensive guidance for securing AI-agent URL fetching against SSRF with destination policy, DNS validation, egress controls, redirects, and response limits.
A practical CSP guide for AI-generated interfaces, streamed responses, remote assets, workers, frames, and safe browser defense in depth.
Practical browser security guidance for rendering model-generated text, Markdown, links, code, HTML-like content, and structured output.
A practical architecture and checklist for securing web applications that combine LLMs, RAG, uploads, streaming, tools, and multi-tenancy.
An operational matrix connecting AI threats to controls, evidence, response, verification, and ownership.
What system prompts can guide, what they cannot enforce, and how to place them within defense in depth.
A current defensive guide to MCP hosts, clients, servers, tools, resources, trust boundaries, consent, and least privilege.
Implementation guidance for making model-proposed tool calls bounded, validated, authorized, and observable.
What to log and trace so teams can explain AI-agent actions, approvals, tool calls, and side effects.
A practical architecture for containing AI-generated code, shell commands, browser actions, and artifacts.
A repeatable worksheet for threat modeling LLM, agent, RAG, memory, and model-supply-chain boundaries.
A practical trust graph for securing delegation and message boundaries between autonomous agents.
A defensive pipeline for finding and containing data and model poisoning before it changes production behavior.
A practical model-artifact security chain for protecting weights, adapters, checkpoints, and deployment bundles.
A practical guide to preventing context and memory poisoning through controlled writes, provenance, scoped retrieval, expiry, and recovery.
A practical framework for placing meaningful human approval controls around consequential AI-agent actions without causing approval fatigue.
A practical guide to credential brokers, short-lived tokens, secret stores, per-tool isolation, multi-tenant boundaries, safe logging, and incident response.
A practical identity architecture for AI agents: separate user, workload, service, and delegated principals while preserving accountability across every tool call.
A practical method for threat-led AI red teaming, safe test design, model-versus-system evidence, severity, remediation, and regression testing.
An end-to-end RAG security architecture for source governance, retrieval authorization, tenant isolation, poisoned content, safe output, and audit evidence.
A threat-boundary guide to indirect prompt injection through external content, with attack-path analysis, containment architecture, testing, and developer controls.
A practical authorization model for AI agents covering tool policy, scoped credentials, human approval, multi-tenant boundaries, and audit evidence.
A complete engineering guide to AI agent identity, permissions, tools, credentials, data, memory, isolation, approvals, monitoring, and testing.
A threat-model-driven guide to direct and indirect prompt injection, attack paths, impact containment, tool authorization, output validation, testing, and monitoring.
A source-led analysis of four Claude cyber-evaluation incidents, their limits, and the controls needed to keep autonomous security testing contained.
A practical framework for interpreting AI benchmark evidence across datasets, metrics, harnesses, model settings, reliability, cost, and security.