Identifying the Supply Chain of AI for Trustworthiness and Risk Management in Critical Applications

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Sheh, Raymond K., Geappen, Karen
Format: Preprint
Publié: 2025
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866914164805468160
author Sheh, Raymond K.
Geappen, Karen
author_facet Sheh, Raymond K.
Geappen, Karen
contents Risks associated with the use of AI, ranging from algorithmic bias to model hallucinations, have received much attention and extensive research across the AI community, from researchers to end-users. However, a gap exists in the systematic assessment of supply chain risks associated with the complex web of data sources, pre-trained models, agents, services, and other systems that contribute to the output of modern AI systems. This gap is particularly problematic when AI systems are used in critical applications, such as the food supply, healthcare, utilities, law, insurance, and transport. We survey the current state of AI risk assessment and management, with a focus on the supply chain of AI and risks relating to the behavior and outputs of the AI system. We then present a proposed taxonomy specifically for categorizing AI supply chain entities. This taxonomy helps stakeholders, especially those without extensive AI expertise, to "consider the right questions" and systematically inventory dependencies across their organization's AI systems. Our contribution bridges a gap between the current state of AI governance and the urgent need for actionable risk assessment and management of AI use in critical applications.
format Preprint
id arxiv_https___arxiv_org_abs_2511_15763
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Identifying the Supply Chain of AI for Trustworthiness and Risk Management in Critical Applications
Sheh, Raymond K.
Geappen, Karen
Artificial Intelligence
Cryptography and Security
Software Engineering
Risks associated with the use of AI, ranging from algorithmic bias to model hallucinations, have received much attention and extensive research across the AI community, from researchers to end-users. However, a gap exists in the systematic assessment of supply chain risks associated with the complex web of data sources, pre-trained models, agents, services, and other systems that contribute to the output of modern AI systems. This gap is particularly problematic when AI systems are used in critical applications, such as the food supply, healthcare, utilities, law, insurance, and transport. We survey the current state of AI risk assessment and management, with a focus on the supply chain of AI and risks relating to the behavior and outputs of the AI system. We then present a proposed taxonomy specifically for categorizing AI supply chain entities. This taxonomy helps stakeholders, especially those without extensive AI expertise, to "consider the right questions" and systematically inventory dependencies across their organization's AI systems. Our contribution bridges a gap between the current state of AI governance and the urgent need for actionable risk assessment and management of AI use in critical applications.
title Identifying the Supply Chain of AI for Trustworthiness and Risk Management in Critical Applications
topic Artificial Intelligence
Cryptography and Security
Software Engineering
url https://arxiv.org/abs/2511.15763