{
  "id": 7818089,
  "title": "Securing Inherited AI: Models, Runtimes, and Tools Inside Vendor Software",
  "url": "https://urgent.news/2026/09/16/securing-inherited-ai-models-runtimes-and-tools-inside-vendor-software",
  "topic": "ai",
  "section": "AI",
  "published": "2026-09-16T15:07:11.000Z",
  "source": {
    "name": "HackerNoon",
    "slug": "hackernoon",
    "url": "https://hackernoon.com/securing-inherited-ai-models-runtimes-and-tools-inside-vendor-software?source=rss"
  },
  "original_language": "en",
  "account": "A research report from Wiz revealed that 68% of organizations running self-hosted AI models actually ingest those models through third-party software. This means that two out of three companies with AI models running on their own infrastructure did not intentionally run those models. The security team often did not sign off on these models because they were quietly shipped inside vendor products, such as knowledge tools, code assistants, or support routers, without their knowledge. This situation highlights the challenges of supply chain security in the age of AI, where new software is embedded faster than the tooling that can monitor it.\n\nThe scenario described is not a typical supply chain problem, as it involves a structural blind spot in current tools and processes. When an organization inherits a vulnerable log4j vulnerability, they can read the code and understand the failure. However, when an LLM is inherited through a bundled product, the artifact is a pile of weights that cannot be read or statically analyzed. The attack surface includes text and data, not just code, making it a fluid and unpredictable risk.\n\nThe implications of this issue are significant. If a bundled product indexes an internal corpus for retrieval, a well-crafted prompt can quietly pull data across trust boundaries that were not intended by the original vendor. This data exposure through embedded retrieval is a major concern, and it can lead to compliance issues, such as those outlined in the EU AI Act. Additionally, if a product exposes MCP (Model Control Plane) servers that overprivilege internal APIs, lateral movement becomes possible through these servers, which traditional network segmentation cannot detect.",
  "summary": "AI models can enter your infrastructure through vendor software. Learn how to inventory inherited AI, assess its permissions, and manage supply chain risk.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}