AI Supplier Risks Are Manufacturing’s Next Weak Link

AI

Manufacturers have spent years perfecting safety, uptime, and quality disciplines on the shop floor. That operational muscle is now being applied to industrial AI, yet a new report suggests the sector’s governance frameworks are not keeping up with how deeply AI is being woven into production systems, supply chain coordination, and maintenance workflows. The Kiteworks 2026 Forecast Report finds that while manufacturers excel in human oversight and real-time monitoring, they remain underprepared for the growing category of AI-specific cyber, compliance, and third-party risks now emerging across global networks.

Operational Strengths Mask Persistent Cyber Blind Spots

Kiteworks’ survey of 225 security, IT, compliance, and risk leaders, including 27 from manufacturing, shows the industry leading in production-critical AI controls. Nearly two-thirds of manufacturers maintain human oversight of AI-driven processes, and more than half route AI data flows through gateways designed for reliability and safety. These practices mirror decades of operational rigor across industrial environments.

Yet that same rigor is not being applied to hostile threats. Only 7% of manufacturers conduct adversarial testing or AI red teaming, less than half the global average. As AI increasingly influences production scheduling, inspection workflows, predictive maintenance, and supplier-facing coordination, this gap represents a growing vulnerability. Recent industry reporting has highlighted how manufacturing remains one of the most targeted sectors for cyberattacks, particularly as attackers shift toward manipulating data and models rather than breaching traditional IT perimeters.

Kiteworks’ chief strategy officer, Tim Freestone, captured the tension bluntly: reliability-focused controls prevent accidental failures, not intentional ones. Without stress-testing models against malicious inputs, manufacturers may be unknowingly expanding their attack surface even as they strengthen oversight.

Supplier AI Risks and Regulation Outpace Readiness

The report flags a second imbalance: compliance maturity is not keeping pace with AI deployment. Only 15% of manufacturers conduct privacy impact assessments, and less than one-fifth maintain audit-ready evidence trails, controls that regulators increasingly expect as AI accountability frameworks mature across the U.S., EU, and Asia. Limited documentation could complicate investigations, delay root-cause analysis, or hinder a manufacturer’s ability to defend AI-driven decisions during customer or regulatory reviews.

Beyond internal controls, Kiteworks identifies a systemic risk in the AI used by suppliers, logistics providers, and technology vendors. While manufacturers have longstanding quality and safety frameworks for physical components, few apply equivalent scrutiny to external AI models that now influence forecasting, logistics planning, and upstream production flows. According to trade reports, a rising share of supply chain cyber incidents originate in third-party systems, where visibility and governance are weakest. Kiteworks warns that failures in supplier AI will increasingly manifest as factory disruptions rather than isolated IT incidents.

AI Governance Enters Its Supply Base Phase

A growing body of industry reporting shows that most operational disruptions linked to cyber activity are now propagated through suppliers, software partners, and service providers, not through the enterprise systems manufacturers directly control. This trend suggests that the next meaningful gains in AI resilience will come from scrutinizing how external partners design, test, and secure their models. Manufacturers that already conduct rigorous supplier audits for quality, sustainability, and continuity can extend those same frameworks to AI dependencies, creating a level of transparency that many partners have never been asked to provide. As more critical workflows hinge on predictive models and autonomous decision engines upstream, this shift toward supply-base governance could become one of the most consequential operational resets of the coming year.

Subscribe to Newsletter

Don’t miss tomorrow’s supply chain industry news

Let Supply Chain 360’s free newsletter keep you informed, straight from your inbox.

Tip: select one or more digests.

EVENTS

03 MAR
LIVE EVENT | The Belfry, Birmingham, UK

SupplyChain360 Summit

3rd & 4th March 2027
06 OCT
LIVE EVENT | Soho Hotel London

SupplyChain360 Forum

6th October 2026