Spoke at the Secure Software and AppSec Summit today on lessons from the software supply chain and what they teach us about securing AI.
My argument was that the risks AI is introducing are not new in shape, even if they are new in scale. Developers picking, trusting, and depending on open source components created the same governance and trust problems years ago that we are now seeing with models, training data, and AI tooling. If we already have hard won lessons from securing the software supply chain, we should be applying them rather than treating AI security as a blank page.
And I like to quote what Brian Fox once said “If you don’t know what you’re shipping, you’re not moving fast, you’re flying blind”.
I also noticed that there were lots of overlap in topics across the day. Andrew Dean from Chainguard spoke just before my session on software supply chain risk, and Rob Williams from GitLab, whose session was right after mine, covered AI DLC governance. Three different speakers, three different angles, all converging on the same point.
Was also great catching up with everyone and making new connections at this event. Thanks Stephanie Tolmie and the team at clutch for the invite and for running the event.
