惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

云风的 BLOG
云风的 BLOG
TaoSecurity Blog
TaoSecurity Blog
V
Visual Studio Blog
The GitHub Blog
The GitHub Blog
Apple Machine Learning Research
Apple Machine Learning Research
Vercel News
Vercel News
The Register - Security
The Register - Security
月光博客
月光博客
M
MIT News - Artificial intelligence
B
Blog RSS Feed
博客园 - 叶小钗
Last Week in AI
Last Week in AI
Application and Cybersecurity Blog
Application and Cybersecurity Blog
T
The Blog of Author Tim Ferriss
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Microsoft Azure Blog
Microsoft Azure Blog
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
C
Check Point Blog
Attack and Defense Labs
Attack and Defense Labs
The Cloudflare Blog
Cloudbric
Cloudbric
O
OpenAI News
Security Archives - TechRepublic
Security Archives - TechRepublic
Help Net Security
Help Net Security
Google DeepMind News
Google DeepMind News
Stack Overflow Blog
Stack Overflow Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
V
V2EX
大猫的无限游戏
大猫的无限游戏
www.infosecurity-magazine.com
www.infosecurity-magazine.com
V2EX - 技术
V2EX - 技术
Google Online Security Blog
Google Online Security Blog
博客园 - Franky
雷峰网
雷峰网
J
Java Code Geeks
L
LINUX DO - 最新话题
T
Tenable Blog
爱范儿
爱范儿
Engineering at Meta
Engineering at Meta
T
Tailwind CSS Blog
Spread Privacy
Spread Privacy
H
Heimdal Security Blog
S
Schneier on Security
量子位
N
Netflix TechBlog - Medium
G
Google Developers Blog
T
The Exploit Database - CXSecurity.com
Cyberwarzone
Cyberwarzone
F
Full Disclosure
S
Securelist

Forbes - Innovation

Why Do Humans Have Fingerprints? Hint: It’s Not What You Think Booking.com Confirms Data Breach, Reservation PIN Codes Changed Why Major News Sites Are Blocking The Internet Archive’s Wayback Machine iPhone Fold Release Date: New Report Details Frustrating Apple News Comet Tracker: How To See Pan-STARRS And Three Planets On Wednesday NYT Mini Crossword Today: Tuesday, April 14 Hints And Answers Today’s NYT Strands Hints, Spangram, Answers: Tuesday, April 14 (It’s A Little Unclear) Today’s Wordle #1760 Hints And Answer For Tuesday, April 14 Most Of The Microplastics In Urban Air Come From Tires Today’s Wordle #1759 Hints And Answer For Monday, April 13 NYT Mini Crossword Today: Monday, April 13 Hints And Answers NYT Pips Today: Hints, Answers And Walkthrough For Monday, April 13 The YC Chief Who Codes 10,000 Lines A Day Has A Simple Secret Samsung Expands One UI 8.5 Beta To More Galaxy Owners Why You Should Stop Using Your iPhone If It’s On This List Chamath Says Firms That Treat AI As A Strategy Hand Rivals Their Edge 3 Unexpected Habits Of Secure Couples, By A Psychologist The First Lamp That Folds Your Clothes Samsung’s Disappointing Price Update For Galaxy Phone Buyers 3 Subtle Signs Someone Is Falling In Love With You, By A Psychologist Do Mantis Shrimp See More Colors Than Humans? A Biologist Explains NYT Connections Answers Explained For Monday, April 13 (#1,037) NYT Connections Hints Today: Monday, April 13 Clues And Answers (#1,037) LEGO Luigi & Mach 8 (72050) Review: 2026’s Best Set Yet? Marc Andreessen Says AI Productivity Will Trigger A Hiring Boom 3D Printing Is The Ultimate Hack To Reduce Household Spending Apple iPhone Fold: Striking Design Revealed In Leaked Photos Apple Smart Glasses: New Leak Reveals A Major Design Twist To Beat Meta Tested: The AI Coming To The Rivian R2 Quordle Hints Today: Monday, April 13 Clues And Answers Companies And H-1B Employees Endure Immigration Waits At Consulates 3 Easy Ways To Turn Anxiety Into Sustained Focus, By A Psychologist Here’s The Most Affordable Humanoid Robot You Can Buy Now UFC 327 Results: 5 Biggest Takeaways From A Wild Night In Miami UFC 327 Results, Bonus Winners, Highlights And Reactions Dana White Announces Huge New Fight For UFC White House Today’s NYT Strands Hints, Spangram, Answers: Sunday, April 12 (Get Ready) Tesla ‘Model 2’ Rises From The Ashes Today’s Wordle #1758 Hints And Answer For Sunday, April 12 NYT Pips Today: Hints, Answers And Walkthrough For Sunday, April 12 Tyson Fury Vs. Arslanbek Mahkmudov Results: Highlights and Reaction NYT Mini Crossword Today: Sunday, April 12 Hints And Answers How Shadow AI Culture Is Destroying Your Business Venture Capital Funds That Market Like Startups Win More Deals Conor Benn Vs. Regis Prograis Results: Highlights and Reaction Samsung’s Disappointing Price Update For Galaxy Phone Buyers Artemis Reached The Moon. The Grid Can Reach The 21st Century A Biologist Explains How Archerfish Shoot Down Prey. Hint: Their Aim Rivals Human Throwing Is It Time For Apple To Forget About The MacBook Air NYT Connections Hints Today: Sunday, April 12 Clues And Answers (#1036) Trump’s 2027 Budget To Reshape U.S. Environmental And Energy Policy CDC Delays Reporting Of COVID-19 Vaccine Benefits—Here’s What To Know Oura Has Designed A Solution To A Big Smart Ring Problem Netflix’s Best New Show Has A Near-Perfect 95% Rotten Tomatoes Score Coachella 2026 Is Being Taken Over By Creator Streams Quordle Hints Today: Sunday, April 12 Clues And Answers This Startup Wants To Use AI To Help Digitize History How To Get The Best Shield In ‘Crimson Desert’ Microsoft Venom Attack Targets C-Suite Executives ‘Maul: Shadow Lord’ Sets Even More Star Wars Rotten Tomatoes Records 3 Ways Happy Couples Argue Differently, By A Psychologist Success For Leapmotor Might Have Negatives For Stellantis New Names Surface As Potential Rogue And Wonder Woman In The MCU And DCU 4 Reasons Artemis Mission Matters Even If You Think It Is Wasteful Fast ‘Crimson Desert’ Patch Adds New Moves, Shield Hiding And One Great Feature Why Do Humans Blush? An Evolutionary Biologist Explains The Signal We Can’t Control Apple iPhone Fold: Striking Design Revealed In Leaked Photos Adobe Attacks Underway—Windows And Mac Users Given 72 Hours To Update iOS 26.4.1 Release: Crucial iPhone Feature Update Arrives, But No Security Fix Fury vs. Makhmudov Full Card, Ring Walk Times and How to Watch Can’t Stand Liquid Glass? This New Hidden iPhone Setting Is A Game-Changer Test-Driving The 2026 Changan Deepal S05: Italian Style Made In China NSA Warning—Reboot Your Internet Router Now Ways That Human-AI Collaboration Slides People Into ‘AI Brain Fry’ And Cognitive Downturns Stop Using These Networks—Google, NSA And TSA Warn NASA Changes Moon Plan: Landing Now Depends On SpaceX Or Blue Origin Samsung Expands One UI 8.5 Beta To More Galaxy Owners The Evolution Of Programmable Hardware At Xilinx NYT Mini Today: Saturday, April 11 Hints And Answers Today’s NYT Strands Hints, Spangram, Answers: Saturday, April 11 (You’re Putting Me On) Splashdown! NASA’s Artemis II Returns To Earth After Moon Mission Attention Is All You Need. The Human Kind Is Still The One That Counts Today’s Wordle #1757 Hints And Answer For Saturday, April 11 NYT Pips Today: Hints, Answers And Walkthrough For Saturday, April 11 Android Circuit: Galaxy S27 Pro Emerges, Honor 600 Pre-Order Offers, Pixel 11 Display Leaks Apple Loop: iPhone 18 Pro Leak, Urgent iOS Update, MacBook Neo Issues Morgan Stanley Has Mostly Positive Outlook On Tesla Robotaxi, FSD V15 Running Out Of AI Tokens Faster Than Ever? Here’s Why CoreWeave Shares Pop 13% After Anthropic Deal ‘Euphoria’ Season 3’s Rotten Tomatoes Score Crashes, Has Lost Key Player People Don’t Agree On What AI Can Do, But They Don’t Even Use The Same Product ‘Overwhelming’—Google Issues Gemini Update For Gmail Users NYT Connections Hints Today: Saturday, April 11 Clues And Answers (#1035) Quordle Hints Today: Saturday, April 11 Clues And Answers The Costly Dream Of Space-Based AI Infrastructure Can You See The Watcher In This ‘Daredevil: Born Again’ Shot? Adobe Attacks Underway—Windows And Mac Users Given 72 Hours To Update You Just Watched The Backdoor Pilot For ‘The Pitt: Night Shift’ Are Nicotine Pouches Like Zyn And VELO Safe To Use? A Doctor Answers Human Resources (HR) Is The Key To AI Success Per WalkMe ( SAP)
AI Supply Chain Security: Welcome To The Cloud Native Age
Harvendra Singh · 2026-06-25 · via Forbes - Innovation

Harvendra Singh, IT Delivery Manager - Cloud Engineering & Architecture, driving innovation through cloud and AI-led digital transformation.

getty

​For decades now, software supply chain security has been focused squarely on code. Companies worried about vulnerable libraries, compromised packages or insecure dependencies making their way into production.

​That was a legitimate concern, and it still is, but modern, AI-driven systems are taking that problem to the next level.​

Modern cloud-native applications are increasingly powered not just by code but also by ML models, vector databases, prompt pipelines, external datasets, AI agents and third-party inference services.​ In fact, in many organizations today, teams are adopting these capabilities faster than they can be secured.

​We’re calling this challenge AI supply chain security.​​

​Unlike software supply chains of the past, AI systems bring complexity that many organizations aren’t prepared for.

​First, let’s review how traditional software supply chains differ from those driven by AI.​

​How The Supply Chain Has Changed​

Think of a traditional application. Odds are it’s deterministic. Code can be inspected. Dependencies can be validated. Expected behavior can be tested in a staging environment.

​AI systems are different. A cloud-native application that includes AI may also source:​

• External models trained with unknown data

• Dynamically generated prompts

• Third-party APIs

• Autonomous agents that make decisions in real time

• Continuously updated models

​Each of these components adds a security risk.​

The issue is that traditional supply chain security focuses on securing the infrastructure. But what about the “brains” powering that infrastructure? As AI gets baked into cloud-native platforms, the potential attack surface increases exponentially.​

Today’s software supply chain security focuses on securing code. But the AI supply chain also includes things like data, models, prompts, context and decisions.​

Why Traditional Security Techniques Fall Short​

When it comes to cloud security, most teams think about infrastructure and identity. Secure the network. Harden your workloads. Manage access. Monitor logs.​

That’s not wrong. But AI introduces security risks that don’t conform to traditional thinking.​

Take a few examples:​

• A manipulated dataset can influence how a model behaves, without changing the application.

• Prompt injection can trick a model into producing a specific output.

• Model drift can slowly alter output over time, without teams noticing.

• Using third-party AI services can create blind spots in governance and visibility.​

The problem is that a lot of traditional security fails when it comes to AI. You can have all the logging in the world but still not know your models are biased, vulnerable or making unsafe decisions.​

That’s a risky proposition.​

AI Risks Compounded In Cloud-Native Systems​

Cloud-native systems are built to support rapid innovation. They’re modular, distributed and almost infinitely scalable. AI fits perfectly into these types of systems. It’s easy to plug a model into an API, workflow, automation pipeline or operational technology system.​

The challenge is that speed often overcomes governance.​

In my work with teams building AI-driven applications, I’ve seen too many examples of teams rushing to deploy AI capabilities without asking how those models are sourced, trained, monitored or updated over time.​

“It’s from Amazon/Azure/Google.” I often hear teams say that and assume the model is safe.​

But what if it’s not?​

Like any other software component, there is risk when integrating third-party services. With AI, those risks can be harder to see, but they are still very real because AI components aren’t like typical software. They aren’t static. They learn and adapt over time, evolving as data changes and they’re exposed to new contexts.​

Why Continuous Validation Matters​

What happens if your model starts making unpredictable decisions?​

If you don’t have a way to validate AI behavior, you won’t know. That’s why continuous validation of AI components is one of the most important shifts we’ll see over the next few years.​

Traditional software testing operates on the assumption that your system will behave the same way every time it’s executed. But AI doesn’t behave that way. That’s why teams are looking to continuous validation, including:​

• Monitoring AI behavior and outputs

• Analyses for anomalous outputs and decisions

• Continuous validation of prompts and workflows

• Monitoring for model drift​

Continuous validation allows you to create a feedback loop where you’re constantly evaluating security rather than checking it at one point in time.​

Trust That Comes Downhill From Engineering Teams​

One other critical shift happening now is that security and validation are moving from IT organizations into engineering teams.​

AI isn’t something you secure. AI is something you build with confidence.​ That means engineering teams should own the trust and validity of their AI-driven decisions.​

Look at Uber. Who’s responsible for a self-driving car hitting a pedestrian? The security team?​

Security needs to be part of the conversation. But everyone from architects to developers, platform engineers and data teams all play a role in AI supply chain security.​

Security and engineering teams need to work together to create a culture of trust.​​

Traits Of AI-Secure Applications​

To help bring this idea to life, here are a few traits of AI-secure applications that we’ve seen teams build successfully:

• Ownership: Clear teams “own” AI systems and their dependencies.

• Visibility: Teams have visibility into where their models come from and how they are updated.

• Observability: Can teams observe AI behavior?

• Automation Guardrails: Teams have guardrails for any automated decisions.

• Incremental Adoption: Teams don’t rush AI adoption. They expand capabilities gradually.​

Engineering teams own the trust behind their applications. Everything else flows from there.​​

The Future Of Cloud Native Security​

Everything we’ve talked about points to one thing. As more AI capabilities get integrated into cloud-native applications, security teams must shift their focus from securing infrastructure to securing decisions.​

Yes, application and infrastructure security are important. But teams must develop a new discipline around trusting the decisions their applications are capable of making.​

Because someday soon, we won’t be asking if our servers are secure.​

We’ll be asking if we can trust them.


Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?