Shadow IT has given way to shadow AI. Enter AI-BOMs
ID: 407f3ffb-d4be-5f52-a03b-351705057616
STIX ID: report--407f3ffb-d4be-5f52-a03b-351705057616
Feed Name: The Register (Security)
The article argues that traditional SBOMs are inadequate for AI-rich environments and promotes AI-BOMs and model provenance tooling (including open-source releases from Cisco and others) to inventory models, datasets, agents, prompts, identities, and dependencies. It highlights risks such as model and skills poisoning, malicious open-source packages, and criminal use of agentic AI for reconnaissance and prompt tampering — citing an incident where attackers altered internal system prompts to force data exfiltration — and recommends continuous scanning and state tracking to detect and contain such supply-chain and runtime AI threats.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
