Why is nobody talking about AI agent supply chain security
Just had a realization that we have a full supply chain security program for normal software but almost ignore AI supply chain security.
I started thinking about what our ai agents are actually pulling at runtime. What third party skills they depend on, what model extensions they import, what those things import downstream. Could not answer a single one of those questions. We have agents running in prod that can take real actions in our systems and we have never even produced a list of their dependencies.
It hit me that we have better visibility into a random npm package than we do into the supply chain of an agent that can execute tool calls against our own infrastructure. Anyone else realizing their ai supply chain is a complete blind spot or did we just miss something obvious.