Third Party Threat Hunters

Shadow AI Supply Chain Risk with Ken Huang

• Gregory Rasner • Season 2

Send us Fan Mail

Your vendor’s product might be running an LLM you never evaluated and that silent dependency can become the cleanest path into your data. We sit down with Ken Huang, author and AI security researcher, to unpack what “third-party AI supply chain” really means when GenAI features are stitched together from embedded models, vector databases, RAG pipelines, agent frameworks, and downstream APIs you do not directly control. 

We get practical about the risks security teams are actually facing: indirect prompt injection where poisoned “data” becomes “instructions,” data exfiltration through third-party processing, and the way agentic AI turns a text problem into an action problem. Ken explains why overprivileged agents create a massive blast radius, and why identity for agents is still undefined enough that teams need to think in terms of blended identity with intent. We also dig into reward hacking and how multi-agent behavior can push toward unsafe shortcuts in the name of completing a task. 

On governance, we talk about where frameworks help and where they stop. We reference OWASP Top 10 for LLM Applications, Cloud Security Alliance guidance, and NIST AI RMF, then connect them back to threat modeling that accounts for autonomy, indeterminism, and hallucinations. Finally, we translate all of it into vendor risk management upgrades: layer-by-layer questions about models, data/RAG sources, agent tooling, auth and identity pass-through, deployment, evaluation for drift, and observability plus options like AI endpoint detection and response to reduce blind spots. 

If you’re trying to move beyond annual questionnaires toward continuous AI risk monitoring, this conversation gives you a clear map and a few immediate next steps. Subscribe, share this with your third-party risk team, and leave a review with the one AI supply chain question you wish every vendor had to answer.

Support the show