Skip to content
AI.info

Research

Identifying the Supply Chain of AI for Trustworthiness and Risk Management in Critical Applications

Overview Research area: AI governance and risk management, specifically supply chain risk in AI systems used for critical applications. Technical level: Intermediate. The paper is conceptual rather th

arXiv
2511.15763
Published
2025-11-19
Authors
Raymond K. Sheh, Karen Geappen

AI summary

Overview

Research area: AI governance and risk management, specifically supply chain risk in AI systems used for critical applications.

Technical level: Intermediate. The paper is conceptual rather than mathematical — it surveys existing risk work and proposes a taxonomy — and the authors explicitly aim to serve stakeholders who do not have extensive AI expertise, though some familiarity with how AI systems are assembled from components will help.

Scope: The paper surveys AI risk assessment and management as it relates to the chain of data sources, models, agents, and services behind an AI system's output, and proposes a taxonomy for categorizing AI supply chain entities to support risk management in critical sectors.

What This Paper Is About

A great deal of research already addresses risks that show up in AI behavior, such as algorithmic bias and model hallucinations. What is missing, according to the authors, is systematic assessment of a different class of risk: the risks introduced by the complex web of data sources, pre-trained models, agents, services, and other systems that combine to produce a modern AI system's output. This omission matters most where AI is embedded in critical applications such as food supply, healthcare, utilities, law, insurance, and transport. The paper's goal is to bridge the gap between the current state of AI governance and the need for actionable supply chain risk assessment, chiefly by offering a taxonomy that helps stakeholders inventory their dependencies and ask the right questions.

Key Contributions

  1. A survey of current AI risk assessment and management practice, with attention to the supply chain of AI and to risks tied to the behavior and outputs of AI systems.
  2. A proposed taxonomy for categorizing AI supply chain entities, intended to give structure to the otherwise tangled set of components that contribute to an AI system's output.
  3. A tool aimed at non-specialist stakeholders, designed to help people without extensive AI expertise identify the right questions to ask about their organization's AI systems.
  4. A bridge between AI governance and operational practice, connecting existing governance efforts to the need for actionable risk assessment and management when AI is used in critical applications.

Main Findings

  • Behavioral risks are well covered; supply chain risks are not. Risks such as algorithmic bias and model hallucinations have received extensive research attention across the AI community, from researchers to end-users, but the abstract identifies a gap in systematic assessment of supply chain risk.
  • Modern AI outputs are composite. The paper frames AI systems as drawing on a complex web of data sources, pre-trained models, agents, services, and other systems — meaning an output can carry risk inherited from many upstream contributors.
  • The gap is most consequential in critical applications. The authors highlight food supply, healthcare, utilities, law, insurance, and transport as domains where an unexamined AI supply chain is particularly problematic.
  • A taxonomy can function as a practical inventory tool. The proposed categorization is positioned as a way for stakeholders to systematically inventory dependencies across their organization's AI systems rather than reason about risk in the abstract.
  • Non-expert stakeholders are a design target, not an afterthought. The taxonomy is framed around helping people without deep AI expertise "consider the right questions."

Note: the abstract reports no quantitative results, evaluations, or comparative benchmarks. Any performance claims, validation studies, or case results are not described in the abstract and are therefore not summarized here.

Methodology in Plain English

The approach is conceptual and survey-based rather than experimental. The authors first review the existing landscape of AI risk assessment and management, narrowing their focus to two things: the supply chain that produces an AI system, and the risks associated with what the system does and outputs. From that review they construct a taxonomy — a structured set of categories — for classifying the entities that make up an AI supply chain. The taxonomy is designed to be usable by people who are not AI specialists, so that an organization can work through its AI systems in an organized way, identify what each one depends on, and surface the right questions to ask about those dependencies. The abstract does not describe how the taxonomy was derived, tested, or validated.

Why This Matters

Impact on research. The paper points to a blind spot: risk research has concentrated heavily on model behavior and outputs, while the upstream web of data, pre-trained models, agents, and services that shape those outputs has received less systematic treatment. A shared vocabulary for supply chain entities gives researchers a basis for analyzing and comparing risks that originate upstream rather than inside a single model.

Real-world applications. The authors name the critical domains where this matters most:

  • Food supply — systems that inform production, distribution, or safety decisions along a chain.
  • Healthcare — clinical or administrative systems where an inherited upstream flaw can affect patient-facing outcomes.
  • Utilities — infrastructure operations where reliability and safety are at stake.
  • Law and insurance — domains where decisions about people carry legal and financial consequences.
  • Transport — safety-critical operations where component failures propagate.

Industry relevance. Organizations increasingly assemble AI capabilities from third-party data, pre-trained models, agents, and services rather than building everything themselves. That makes dependency inventory a practical governance need, and the abstract frames the taxonomy as a way to make risk assessment actionable for the people who actually have to ask the questions — including those without deep AI backgrounds.

Future Directions

  • Operationalizing the taxonomy. The abstract presents a taxonomy but does not describe how it would be applied in practice; turning it into concrete checklists, audit procedures, or assessment workflows is a natural next step.
  • Validation with real organizations. Whether the categories hold up when applied to actual AI systems in the named critical sectors — and whether non-experts can use them effectively — is an open question the abstract does not address.
  • Alignment with existing governance frameworks. The paper positions itself as bridging AI governance and operational need; how the taxonomy maps onto or complements established governance and regulatory regimes remains to be worked out.
  • Extending from inventory to mitigation. The abstract emphasizes identifying dependencies and asking the right questions. How an inventory translates into prioritized mitigation, monitoring, or accountability across supply chain participants is left open.

Target Audience

Risk managers, compliance and governance officers, regulators, and procurement or assurance staff who need to reason about AI systems they did not build themselves. It is also suited to engineers and product owners who integrate third-party models, data, and services and want a structured way to think about the dependencies they inherit. Researchers working on AI risk and governance will find the supply chain framing useful, particularly because the taxonomy is explicitly designed for stakeholders without extensive AI expertise.

Authors’ abstract

Risks associated with the use of AI, ranging from algorithmic bias to model hallucinations, have received much attention and extensive research across the AI community, from researchers to end-users. However, a gap exists in the systematic assessment of supply chain risks associated with the complex web of data sources, pre-trained models, agents, services, and other systems that contribute to the output of modern AI systems. This gap is particularly problematic when AI systems are used in critical applications, such as the food supply, healthcare, utilities, law, insurance, and transport. We survey the current state of AI risk assessment and management, with a focus on the supply chain of AI and risks relating to the behavior and outputs of the AI system. We then present a proposed taxonomy specifically for categorizing AI supply chain entities. This taxonomy helps stakeholders, especially those without extensive AI expertise, to "consider the right questions" and systematically inventory dependencies across their organization's AI systems. Our contribution bridges a gap between the current state of AI governance and the urgent need for actionable risk assessment and management of AI use in critical applications.

Read the original paper