Say Easy, Do Hard - AI Governance in the Supply Chain - Richard Bird, Nick Mistry - BSW #407
文章讨论了AI供应链的安全威胁与治理需求,指出随着开源软件和协作平台的扩展,第三方AI组件和服务带来的安全风险日益增加。专家探讨了数据隐私、恶意代码、缺乏测试工具及模型风险等挑战,并强调需要更新供应链管理流程以应对这些威胁。 2025-8-6 09:0:0 Author: sites.libsyn.com(查看原文) 阅读量:7 收藏

Aug 6, 2025

Recent findings of AI ecosystem insecurities and attacks show the importance of needing AI governance in the supply chain. And this supply chain is rapidly expanding to include not only open-source software but also collaborative platforms where custom models, agents, prompts, and other AI resources are used. And with this expansion of third-party AI component and services use comes an expanded security threat often not included in traditional supply chain management processes. It's time to update our supply chain management process to include AI governance. Easier said than done.

In this Say Easy, Do Hard segment, we invite three CISOs to discuss the challenges of AI and the supply chain, including:

  • Data privacy concerns
  • Flaws and malicious code in AI dependencies
  • Lack of security tools to test for AI
  • Vibe coding risks

and more. But we also do the hard part, by discussing the changes needed to your supply chain management process to address these concerns.

Visit https://www.securityweekly.com/bsw for all the latest episodes!

Show Notes: https://securityweekly.com/bsw-407


文章来源: http://sites.libsyn.com/18678/say-easy-do-hard-ai-governance-in-the-supply-chain-richard-bird-nick-mistry-bsw-407
如有侵权请联系:admin#unsafe.sh