Supply Chain World Volume 13 Issue 4 August 2026 | Page 12

________________________________________________________________________________________________________________________
that awareness into action – Protect in cybersecurity and Manage in AI – that score lowest across the board. The real headline for me isn’ t that AI adoption is outpacing security. It’ s that organizations know exactly what they should be doing and still aren’ t doing it at anywhere near the same rate.
7. The report describes AI turning third-party risk into a‘ moving target’. What does that look like in practice and how can organizations regain visibility? Supply chains used to consume data and services from third parties in a deterministic way, classic APIs. Now, that’ s shifting toward agents talking to agents, and consuming vendor systems via MCP. Everyone wants their own platform to be able to connect to and pull from a vendor automatically. That’ s the core of the transition: from deterministic API usage to agent-to-agent, MCP-based data flow.
On visibility, at a basic level it’ s a question of AI visibility generally, understanding things like token consumption and what your agents are pulling from third parties. On risk specifically, the emerging risks are things like inaccuracy, injection, and operationalcontinuity risk. Because a vendor’ s agent output is itself AI-generated, it can introduce real problems. For example, a ticketing agent fed by a vendor’ s agent could generate a ticket recommending deletion of part of a production environment because it looks‘ unstable’, or recommend elevating a user’ s privileges unnecessarily. These aren’ t hypothetical, variations of this have already happened in real incidents. sanctioned, the ones you haven’ t, and a supply chain you can’ t fully see. The numbers back that up starkly. Shadow AI exposure, meaning AI use that’ s outside an organization’ s visibility or governance, is 71 percent in transportation and 62 percent in energy, against just five percent in financial services. That’ s roughly a fourteentimes gap between the most and least exposed sectors, and it lines up almost exactly with supply-chain-heavy, criticalinfrastructure industries versus the most tightly regulated one.
The reason isn’ t that transportation and energy companies are careless, or that banks face fewer threats. It’ s regulation. Financial services has spent two decades building mandatory visibility and governance requirements around technology risk, so when AI showed up, the infrastructure to catch it was already there. Supply chain-adjacent industries mostly haven’ t faced that same regulatory pressure yet, so AI use is spreading faster than anyone is tracking it.
What the leaders show is that compliance should be treated as a floor, not
8. Why are supply chain-adjacent industries lagging in terms of AI exposure, and what can they learn from the leaders? As we put it in the report, the AI attack surface is already here: in the tools you’ ve
12