June 2026
Intermediate
478 pages
12h 25m
English
The dependency did not look dangerous. It had a familiar name, clean documentation, a normal release history, and enough downloads to feel boring. A team pulled it into an AI workflow because the package solved a small problem they did not want to reimplement. Nothing about that decision felt reckless.
That is how supply-chain risk usually enters AI systems. It does not arrive wearing a villain costume. It arrives as a model checkpoint, a tokenizer, a vector database integration, a notebook helper, a Python package, a hosted inference API, a dataset, a container image, or a vendor SDK that lets the team move faster.
AI systems are built from other people's code, data, models, ...
Read now
Unlock full access