https://taxonomy.eticas.ai/risk/supply-chain-vulnerabilities
Maturity: established
Risks introduced through third-party components, pre-trained models, data sources, or other dependencies not fully under the deployer’s control.
System type: ADM and LLM systems
Lifecycle stages: Pre Processing, In Processing
| Framework | Reference |
|---|---|
| ISO/IEC 42001:2023 — AI Management System | Third-party and customer relationships |
| EU AI Act (Regulation 2024/1689) | Article 25 — value-chain responsibilities |
| NIST AI 600-1 — Generative AI Risk Profile | Value Chain and Component Integration |