Global AI Assurance · Layer 09

    AI Supply Chain Graph

    The model is one component. Between the foundation model and the customer sit a provider, a hosting arrangement, inference infrastructure, an adapter, an agent framework, a tool server, tools, datasets, an application and a person. Third-party risk assessment that stops at the model vendor has assessed one link in twelve.

    Twelve links

    01Foundation model
    02API provider
    03Hosting
    04Inference infrastructure
    05Model adapter
    06Agent framework
    07Tool server
    08Tool
    09Dataset
    10Application
    11Human
    12Customer

    Each link is a typed object in the Trust Graph, so blast-radius traversal answers the question a resilience test actually asks: if this link goes, what stops working.

    Concentration risk

    Concentration is what turns a supply-chain map into a resilience instrument. Illustrative readings from a sample estate.

    73 per cent of the sample estate

    Critical workflows resting on a single model provider

    Single-provider withdrawal is a service-continuity event, not a procurement one.

    41 agents

    Critical agents on one tool-server dependency

    One infrastructure fault removes a set of controls simultaneously.

    28 per cent of governed calls

    Inference performed outside the home jurisdiction

    Residency and compellability questions apply to more of the estate than the register shows.

    39 systems

    Embedded models with no institutional owner

    Obligations exist with nobody assigned to discharge them.

    Supply-chain depth feeds the third-party workbench and the resilience position, not a separate AI report.