TLDR: The widespread adoption of AI-driven platforms and increasingly complex software supply chains is significantly elevating cybersecurity risks globally. New vulnerabilities, particularly in generative AI systems, are creating fertile ground for sophisticated attacks, prompting urgent calls for enhanced security measures and robust governance frameworks.
Organisations worldwide are grappling with a new era of cybersecurity challenges as the integration of AI-driven platforms and intricate software supply chains introduces unprecedented vulnerabilities. Experts are sounding the alarm, highlighting that the convergence of artificial intelligence, Software-as-a-Service (SaaS), and supply chain complexity is forging a perilous new risk landscape that demands immediate, cross-functional attention.
Recent security research has already identified critical flaws, such as a vulnerability in Salesforce’s Agentforce AI platform, which could potentially expose sensitive CRM data to unauthorised access. This incident underscores a growing concern surrounding generative AI’s inherent limitations, particularly its struggle to accurately differentiate between legitimate instructions and malicious input data. This fundamental weakness affects numerous AI agent platforms, making them susceptible to manipulation.
The threat landscape is evolving rapidly. Supply chain attacks, while not new, have been transformed by AI into highly adaptive, large-scale assaults. Since 2023, supply chain-related breaches have surged by nearly 40%, incurring billions in global costs for businesses. AI supercharges these attacks by enabling algorithms to scan thousands of suppliers in minutes, identifying vulnerabilities far quicker than human teams. This automation accelerates reconnaissance and exploitation, allowing attackers to compromise hundreds of suppliers simultaneously.
According to the Gartner Hype Cycle for Supply Chain Strategy, 2025, while supply chain cybersecurity has reached the ‘Peak of Inflated Expectations,’ generative AI has entered the ‘Trough of Disillusionment.’ Despite this, GenAI continues to pose new threats to secure supply chains. Mark Atwood, Managing VP, Research, with the Gartner Supply Chain practice, emphasised the immense difficulty of oversight in this environment, particularly with the large number of multi-tier partners involved.
Organisations are urged to embed security throughout their technology environments, encompassing AI agents, network infrastructure, and software code. Soby, a cybersecurity expert, advised a strong focus on understanding the capabilities and potential impact of AI agents within IT environments. He cautioned, ‘Organisations should consider the capabilities and blast radius of agents as the primary indicator of risk. It’s inevitable: Agents can and will be tricked to exercise those capabilities in unwanted ways.’ He also recommended continuous monitoring to detect risky or malicious behaviours by AI-driven systems.
The rise of generative AI also makes supply chain risk increasingly opaque. AI systems now generate code, process sensitive data, and simulate human interactions, creating a ‘black box’ risk. Key questions for organisations adopting AI include: Who trained the model? What data was used and who influenced it? Where is the model hosted and managed? And do we understand the potential exposure to ‘data poisoning’ attacks, where adversaries push harmful data to influence model output?
To mitigate these risks, organisations should: establish robust governance frameworks for AI procurement and deployment; audit AI-generated outputs for integrity and bias; vet AI vendors for transparency, jurisdiction, and data handling practices; and ensure a clear understanding of data lineage and model provenance. Regulatory pressures, such as the EU NIS2 Directive and DORA, are also increasing compliance requirements, further highlighting the need for comprehensive security strategies.
Also Read:
- AI’s Impact on Cyberattacks: Insights from Wiz Chief Technologist Ami Luttwak
- The Perils of AI in Court: Why Self-Represented Litigants Risk Their Cases and Finances
The Australian Government has also taken measures to address foreign interference in technology supply chains, including the launch of the Technology Foreign Interference Taskforce (TechFIT) in early 2025 and enhanced visa screening measures for critical technology.


