Library Header Image Library Header Image

AIBOM in Action: Lessons from the First AI Supply Chain Audits


Posted on in Podcasts

As AI systems move into production, managing supply chain risk goes beyond traditional SBOMs. This podcast episode shares lessons from the first cycle of AI Bill of Materials (AIBOM) audits—where theory met reality in contracts, disclosures, and accountability. With the rapid adoption of AI agents and foundation models in enterprise environments, organizations face new challenges in visibility, provenance, and third-party AI risk. Attendees will take away practical strategies for enforceable controls, adaptable schemas, and continuous assurance in an evolving AI supply chain landscape.

Access the Video Version and Bonus Clips of Select Cyber at the Top Episodes with Your Free RSAC Membership

Your RSAC™ Membership also includes AI-powered summaries, historical Conference presentation slides, Group Discussions with peers and experts, plus more. Watch Now >>

Podcast Transcript

Welcome to the RSAC Cyber at the Top Podcast, where security leaders across industries share the strategies, hard lessons, and real experiences shaping modern cybersecurity and AI. Insights are grounded in community and built for every level of profession.

Hello, listeners. Welcome to this edition of our RSAC cyber the top podcast series. Thank you for tuning in. I'm Tatyana Sanchez.

And I'm Kacy Zurkus.

And we are your RSAC podcast hosts. Kacy, what are we going to discuss today?

Well, AI enabled supply chain attacks are exploding in scale and sophistication.

And according to JFrog's twenty twenty six software supply chain security state of the union report, malicious packages surged a whopping four hundred and fifty one percent year over year to more than a hundred and seventy one thousand unique instances.

This really makes last year the most dangerous on record for developers, which is why it's so important for organizations to understand what an AI bomb is. It's an AI bill of materials, and it helps defend against these kinds of supply chain attacks. So we're excited to be joined today by Noosheen Begum, who will break down what AI bomb is and why it's important, especially to supply chain in the era of AI. We'll get into the key findings and unexpected insights uncovered in the first wave of AI bomb audits, what practical frameworks organizations can start using today, and what the future of regulation and oversight looks like from here.

And before we get started, we wanna remind our listeners that here at RSAC, we host podcast twice a month, and we encourage you to subscribe, rate, and review us on your preferred podcast app so that you can be notified when new tracks are posted. And now we would like to ask our guest to formally introduce herself before she dives in. Nousheen?

Thank you so much for the wonderful introduction. It's an honor to be here on RSAC's Cyber at the Top podcast.

I am Nousheen.

I am a CSSP with ten years of experience in cybersecurity spanning GRC, security operations, incident response, vulnerability management.

My career has taken me through wonderful companies, IBM, SecureWorks, Credit Suisse, UBS, and Accenture.

And most recently, I have stepped into a compliance officer role at a health care SaaS company in the pharmaceutical supply chain space where AI governance and supply chain security intersect directly with my day to day work.

Beyond my day job, I am deeply embedded in the Wisconsin cybersecurity community, which I'm mostly proud of doing that.

I serve as a vice president of women in cybersecurity Wisconsin chapter, and I'm on the boards of ISACA Milwaukee and ISC two Wisconsin chapters.

AI security, especially AI bill of materials and what I call defending the AI supply chain has become a major focus of my research and speaking work over the past year.

Thank you so much, Nousheen. Thank you for being here today. And we have seen an explosion of bombs at RSAC 2026 conference, especially since software bill of materials known as SBOM took hold. We've been seeing people talk about CBOM, HBOM, and now AIBOM. So, Nushin, for those who may not be familiar with the term AIBOM, can you unpack what an AI bill of materials actually is, and why is it becoming so critical for AI supply chain security?

So you do. And you have taken a few critical words, AI bomb, H bomb, S bomb.

I would like to start in the easiest way explaining and going in-depth how and what critical terms AI bomb would be included in the organization.

So the easiest way to understand AI bomb is through an analogy most security professionals already know.

The SBOM, software bill of materials.

And SBOM is essentially an ingredient list of software.

It tells you every open source library, every dependency, every component inside an application.

So when a vulnerability like lock for shell hits, you can immediately answer. Are we affected without guessing?

And now AI bomb does the same thing.

But for AI system specifically, it inventories every AI component in your environment.

The models you are using, who trained them, what data they are trained on, the frameworks they depend on, the API they call, the fine tuning layers applied on top.

It answers the questions, like what is actually inside the AI and where did it come from.

These are very critical basic foundation things every organization must focus on.

And the reason this is becoming a cornerstone of supply chain security is straightforward because AI systems have a fundamentally different attack surface than traditional software, which we have seen in SBOM.

With code, you can audit the logic. With AI, the risk lives in the training data. The model waits, the fine tuning process.

As attacker can poison a model at the data layer, and you would never catch it in the code review.

Without an AI bomb, you cannot even begin to ask the right question about your AI provenance.

So that is the visibility gap is a critical liability, which is why AI bomb is necessary.

So AI supply chain attacks are definitely on the rise. Right? And we've seen everything from phantom squatting where attackers register the fake domains, LLMs hallucinate in order to intercept AI generated traffic to even AI package poisoning attacks. So what key findings and unexpected insights have come out of your early AI supply chain audits, and what does this tell us?

It's a great question.

This question actually gets at something that genuinely surprised me when I started doing this work.

The gap between what organizations think their AI exposure looks like and what it actually looks like.

So one of the single biggest finding across early AI bomb audits is what I call the shadow AI problem.

For example, organizations would tell me we have approved two to three AI tools. And then when we did a real inventory, we could find dozens.

Employees using Charge GPT, GitHub, Copilot, Grammarly, AI plug ins in their browsers, which are just an example.

There are many more.

AI features embedded in the software as service tools they already subscribed to.

None of it is documented.

None of it is in the scope of any security review.

That is the invisible attack surface which we have spoke in our first question.

And what phantom scrapping and package poisoning tell us is that attackers are now specifically targeting that invisibility.

When an LLM hallucinates a package name and they do that regularly, A developer installs it without verifying.

That is an AI bomb failure.

Without verification and installation is a vulnerability in any organization.

I would say insights I take from this is that AI supply chain risk is not a future problem.

It is a current operation problem.

The organizations being hit are not the ones who ignored AI entirely, but the ones who adopted it quickly without building the governance layers.

So the AI bomb gives you that governance layer. It forces the question, can I account for every AI component in my environment, trace its origin, and verify it has been tampered with?

Answer to this question is the visibility of your attack surface in your organization.

Thank you, Noosheen. And as we know, AI is increasing and attackers are using it, which we'll see more regulations around that. So can you tell our listeners what emerging regulations should organizations have on their radar regarding AI bombs? And where do you see AI bomb heading next in the AI supply chain oversight?

The big data to be land landscape is moving faster than most organizations realize, And the convergence point is clear.

The AI bomb documentation.

Because it is going to become a compliance requirement, not just a best practice.

Here's what is on the radar right now.

I can specify few acts which have been implemented.

The EU AI act is already in force for high risk AI systems, and it explicitly requires transparency about the data and systems used in the developed AI. That is AI bomb language.

Even if it doesn't use the term, And, also, we have seen NIST has published the AI risk management framework already, which calls for documentation of AI components and supply chain dependency through the AI life cycle.

And if I talk about specifically in health care sector, the FDA is developing a guidance on AI and machine learning in medical device, which is directly related to a supply chain.

Beyond regulation, I see AI bomb heading in two directions simultaneously.

The first one is standardization, and the second direction is automation.

If I talk about the second direction more specifically, the same way SCA tools can code repositories for vulnerable dependencies.

We have seen AI governance tools that continuously monitoring your AI component inventory and alert models now.

So the organizations are building this muscle now, and they are coming towards this regulation.

So, Nushin, you mentioned So, mentioned earlier that AI bomb is becoming a cornerstone of AI supply chain security.

I'm just curious to know where should an organization actually start? What are the first concrete steps to begin implementing a strong AI bomb today?

I think people talk about AI bill of materials and immediately assume it requires a massive framework before they can do anything useful. But, actually, it is not.

The first step is simple.

Ask your people what AI tools they can actually using and what is approved, what is actually in use.

Send a survey.

Hold a team meeting.

Ask your developers in your organization, your analyst, your HR team, your finance team.

You will be surprised and probably alarmed by what you find.

The discovery steps is zero, and your AI bomb foundation starts over there.

From that point of discovery, each tool you discover, you want to answer four questions.

First is, who builds this model?

What data was it trained on?

What does it have access to in our environment?

What input are we providing?

What happens to the data we send to it?

Answering to these questions do form a backbone of an AI component inventory.

After doing this survey and getting answers to these questions, step two is building that inventory into a living document.

Having your policy documented created according to the survey, your AI bomb needs to be maintained the same way a software dependency list is maintained with stakeholders, owners, and the process of flagging new addition in every review cycles.

And I would say the third step is every organization is skipping most often, establishing a minimum baseline for AI procurement.

Before any new AI tool gets approved, we need to have a vendor communication to our questions and having the answers to the four basic questions we have set in our organization in the same way to our vendor.

Following this process, having a proper documentation and AI governance policy in place, this is how you stop the shadow AI problem before it starts.

I think that's probably one of the greatest challenges for most organizations, right, is, like, that AI procurement process and understanding, you know, who is using what AI tools across the whole of the company. So that's great guidance, Nousheen. Thank you so much.

Really appreciate you being here with us today. Listeners, thank you for tuning in. Please keep the conversation going in our RSAC membership platform by visiting OneRSAC.com/membership, and be sure to check OneRSAC.com for new content posted year round. Until next time.


Participants
Nousheen Begum

Cybersecurity Leader | GRC & AI Security | CISSP, WiCys


Share With Your Community