Related Big Read: The dependency nobody vetted: how AI tooling became a supply chain vulnerability
Related assets: Can you still trust your localhost?; AI supply chain verification
The AI trust gap is moving inside the stack.
Events in March showed that the problem was not simply that AI could help attackers or defenders move faster. The tools meant to improve productivity and security were themselves becoming paths through which security could fail.
AI coding assistants, security copilots, workflow plugins, cloud APIs, agent skills, and CI/CD components all carry trust. They touch code, secrets, repositories, decisions, alerts, tickets, and operational workflows.
That makes them useful.
It also makes them targets.
Why trusted tools need threat models
Security programmes often divide the world into tools that protect and systems that need protecting.
AI makes that separation less stable.
A coding tool can influence production code. A cloud API can carry command-and-control traffic while looking legitimate. A plugin or agent skill can extend capability while importing supply-chain risk. A security assistant can shape decisions about which events get escalated and which get ignored.
If a tool can influence a security outcome, include it in your security model.
Use this checklist before an AI-enabled tool is trusted with production code, sensitive data, security decisions, or operational workflows. The purpose is to identify what the tool can influence, what it depends on, and how quickly it could be removed if it became suspect.
High-level checklist: when the tool becomes the target
Critical tooling scope
Trusted platform monitoring
AI supply chain
Human accountability
Governance discipline
The executive test
Ask procurement, security, and engineering to identify the five AI-enabled tools with the greatest ability to influence production outcomes.
Sign-off rule
What can these tools access, what can they change, what do they depend on, and how quickly could you remove them if they became suspect?
If the answer is vague, the tool has already become part of the target surface.