White Paper

Securing the AI Software Supply Chain

Securing the AI Software Supply Chain

Pages 50 Pages

As AI features become common in software, security risks are growing rapidly. This paper outlines a strategy for securing the AI supply chain using provenance data, building on tools like BAB, SLSA, and Sigstore. While AI introduces new risks compared to traditional software, many existing practices remain useful. Each organization must tailor its approach based on its own systems, focusing on quick, high-impact improvements. The paper begins with a general lifecycle overview, then explores AI-specific risks, controls, and guidance adaptable to various teams and maturity levels.

Join for free to read