Most of an AI system is made of things you did not build: pretrained weights, public datasets, Python packages, a coding assistant, a handful of MCP servers. Each of those is a trust decision. An AI supply chain compromise is what happens when an attacker exploits one of them.
Source: [Dev.to](https://dev.to/wasa-confidence/ai-supply-chain-compromises-7-entry-points-your-security-review-probably-misses-29o6)