Skip to content

Data Integrity

AI Data Poisoning Is a Knowledge-Supply-Chain Problem

Originally published in 2024; substantially revised in 2026 to deepen the analysis and incorporate additional sources.

NIST’s warning about adversarial manipulation of AI systems should change how organizations define the security boundary. Conventional software security focuses heavily on code, dependencies, infrastructure, identity, and configuration. AI systems add another attack surface: the evidence from which system behavior emerges.

Training corpora, feedback data, retrieval indexes, evaluation sets, model artifacts, prompts, and operational context all influence what an AI system learns or produces. If an adversary can shape those inputs, the system may remain technically available while becoming epistemically compromised.

AI expands the software supply chain into a knowledge supply chain. Security must protect not only what the system executes, but what it is permitted to believe.

READER-NEUTRAL SUBSCRIPTION

Follow Field Notes via RSS.

Copy this address into the RSS reader you already use. New notes will appear there automatically—no account, email address, or tracking required.