The ITSPmagazine Podcast

AI Has Its Own Supply Chain | A Full Sponsor Brand Briefing at Black Hat USA 2026 with Daniel Bardenstein, CEO and Co-Founder of Manifest Cyber | Hosted by Sean Martin

Episode Summary

AI is arriving in the enterprise faster than most security teams can inventory it, and the models, datasets, and agents coming with it carry a supply chain of their own. Daniel Bardenstein explains what security leaders are asking for right now, and why the answer still tends to arrive as phone calls, emails, and spreadsheets.

Episode Notes

At Black Hat USA 2026 in Las Vegas, Daniel Bardenstein, CEO and co-founder of Manifest Cyber, starts with a gap his team measured in a survey of security leaders and practitioners. Leadership described one version of what is happening with AI inside the enterprise. The people doing the hands-on work described another. Adoption keeps moving, and security teams are working to catch up.

So what is the real risk in AI security? Bardenstein puts less weight on non-determinism than most and more on ordinary poor software security, because AI is software. He walks through the OpenAI and Hugging Face incident, where models got out of sandboxes because the sandboxing was weak and the guardrails were missing. When Hugging Face went to use its own AI to defend and run forensics, the guardrails read the request as cyber activity and declined.

That fallback to an open weight model points to why he expects open weight adoption to accelerate. With frontier models, the provider sets the system prompt and treats it as intellectual property, so development teams inherit whatever was decided upstream. Open weight leaves more room to control the system prompt, the training data, and how the model gets deployed.

What does it mean to say AI has its own supply chain? Unless an organization controls how training data is sourced, housed, labeled, tagged, and modified, it is relying on something someone else built. Public datasets carry whatever is inside them, including personal and health data, licensing exposure, and material no one examined until models were trained and deployed. Models hosted on public hubs sit in the same category.

Two asks come up in most CISO conversations with Manifest Cyber. Visibility is one, and few organizations have an AI inventory covering which models run where, inside which applications, and which agents teams have stood up on their own. Third party risk is the other, since AI is getting built into vendor products whether a buyer asks for it or not. That turns model provenance into a trust question about the vendor.

Bardenstein started Manifest Cyber four years ago after responding to Log4Shell from the Pentagon, where the question was where one affected piece of code was running across everything the organization had built and bought. Years later, he finds few security leaders who could answer that question quickly about a poisoned model or dataset. His advice for CISOs is to know what is inside what the organization builds and buys, with particular attention to the parts it does not build.

This is a Brand Spotlight. A Brand Spotlight is a ~15 minute conversation designed to explore the guest, their company, and what makes their approach unique. Learn more: https://www.studioc60.com/creation#spotlight

GUEST

Daniel Bardenstein, CEO and Co-Founder, Manifest Cyber
On LinkedIn: https://www.linkedin.com/in/bardenstein/

RESOURCES

View all of our Black Hat USA 2026 coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas

Learn more about Manifest Cyber: https://www.manifestcyber.com

Beyond the Black Box: How AI is Forcing a Rethink of Software Supply Chain (research report): https://www.manifestcyber.com/beyond-the-black-box-ai-report

Manifest Cyber on LinkedIn: https://www.linkedin.com/company/manifestcyber/

Are you interested in telling your story?
▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full
▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight
▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight
▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings

KEYWORDS

daniel bardenstein, manifest cyber, sean martin, brand story, brand marketing, marketing podcast, brand spotlight, ai supply chain security, software supply chain security, ai inventory, shadow ai, third party cyber risk, open weight models, frontier models, model provenance, hugging face, log4shell, ciso, agentic ai, black hat usa 2026

Episode Transcription

AI Has Its Own Supply Chain | A Brand Spotlight at Black Hat USA 2026 with Daniel Bardenstein, CEO and Co-Founder of Manifest Cyber | Hosted by Sean Martin

[00:00:00] Sean Martin: Daniel, I'm doing weird stuff with my hands.

[00:00:13] Daniel Bardenstein: I know, right? What does one do with one

[00:00:14] Sean Martin: hand? That's right. Open source. Uh, and gestures. Here I don't. Ah, so good to see.

[00:00:20] Daniel Bardenstein: Likewise, here

[00:00:20] Sean Martin: we are in, uh, the nice cool breeze of, of, uh, Vegas Valley

[00:00:25] Daniel Bardenstein: surviving the 110 degree heat by not going in it as much as possible.

[00:00:29] Sean Martin: Exactly. We have to go to all these different, like four seasons. Like do we go faster outside? No. No, certainly not. You take the long journey inside.

[00:00:38] Daniel Bardenstein: I already took a quick walk to lunch the other day outside and that was a great mistake, not advisable. That was a mistake,

[00:00:42] Sean Martin: not advisable. Uh, those are decisions we make. We take a look at what's going on. We make a decision

[00:00:49] Daniel Bardenstein: and live with the consequences.

[00:00:51] Sean Martin: Live with the consequences. Exactly. Live with the consequences. Sometimes people don't make a decision, they just go and do things as well. I'm sure we'll talk a little bit about that. Um, [00:01:00] so we're here at Black Hat. We're gonna talk about all the good stuff you're doing and, uh, first with a few words about who you are and what you're up to. Yeah.

[00:01:10] Daniel Bardenstein: Daniel Bardenstein, CEO and co-founder of Manifest Cyber. We're a 4-year-old startup that focuses on all things software and AI supply chain security. So we help Fortune 500 companies and governments understand what's actually in the software and AI that they build and buy. Somehow. It's 2026, almost 2027, and that's still not the case, and I still can't figure out why.

[00:01:33] Sean Martin: There's a lot going on, a lot going on.

[00:01:35] Daniel Bardenstein: Say that again?

[00:01:35] Sean Martin: A lot going on. So. Let, let's start there actually. So what, yeah, what are some of the things you're hearing? Who do you get to talk to different perspectives on this?

[00:01:44] Daniel Bardenstein: Interestingly, we, uh, released a research report around AI security and AI usage, uh, across, uh, practitioners around the world. And one of the most interesting things we found that was not security related was the gap between what security, leadership and [00:02:00] management thinks is the reality of the enterprise versus the practitioner. That was a kind of interesting finding. So for that reason, especially, you know, I spent a lot of time talking with CISOs and security leaders, but you know, whether it's me directly through my team, also understanding what the pain points are of the actual hands-on users who are of course, securing this stuff. I mean, at a high level, not surprising to anybody. AI is still the topic of the day. Everyone's going faster to adopt it. The security team is still behind. Some of them are just starting to get budgets and tooling to try to get their arms around it, but it's been hard to keep up. And we've already heard of some pretty high profile issues that have come up with, uh, unrestrained or uncontained AI.

[00:02:39] Sean Martin: So let's, let's talk about some of that. 'cause I mean, say in the old days, you would define a product, you'd define an architecture, you design it. You have multiple builds. You hopefully have some QA involved there and you kind of knew even if you had to pick the libraries you're building with, you kind of knew what was gonna be in [00:03:00] there.

[00:03:00] Daniel Bardenstein: Yep.

[00:03:01] Sean Martin: Agents now pulling stuff from all over the place, multiple agents working together.

[00:03:07] Daniel Bardenstein: Yeah.

[00:03:07] Sean Martin: Meaningfully or purposefully or no, otherwise, so how does, how does the landscape look now from a, I guess from a coding perspective and a, and what's being used to build things?

[00:03:19] Daniel Bardenstein: Yeah, I think from, from a risk perspective, one of the words that we hear a lot, I used to use a lot is, you know, deterministic or non-deterministic, right? The biggest risk of AI is that it's non-deterministic. You don't know that it will consistently give the same output every single time. So whether you're writing code or searching for vulnerabilities or trying to patch the vulnerability, the sense or the, or the concern that it may not get the same thing consistently run over run oftentimes is kind of lifted up as like one of the main risks. My slightly hot take on that is I actually don't think that's the major risk. I think it's actually just poor software security. We think about the OpenAI Hugging Face debacle. That happened what? A few weeks [00:04:00] ago. Um, the agents escaped, or the, the models escaped from sandboxes that they were supposed to be put in. Wasn't because it was non-deterministic. It was because it was sandboxed poorly, and there weren't guardrails in place. And then when Hugging Face was trying to use its own AI to defend the attack, the guardrails and constraints in place said, oh, this feels too much like you're doing something cyber related. I'm not even gonna help you defend or run forensics. And so Hugging Face had to resort to an open weight model. So I think everyone is, is using AI, especially for coding, for finding vulnerabilities, for fixing vulnerabilities. I guess a hot take of mine is everybody's focused on the non-deterministic nature of AI as the major risk. I think it's just poor security in general just continues to be the major risk because AI is software,

[00:04:49] Sean Martin: right? So from a risk perspective, if you know what the risk is, you can mitigate it, right? With some other tooling or other controls or other mitigations. [00:05:00] Um, this open weight was a way that Hugging Face mitigated the inability to use AI. Mm-hmm. Yeah. So how, how do you see organizations preparing for that, regardless of what the risk is, uh, with AI?

[00:05:18] Daniel Bardenstein: Yeah. The advantage of open weight, as we've known since the beginning, is you have greater control over what the model is, what it does, how it comes from, et cetera. And I think that's, that's one of the major risks and gaps when organizations use, uh, frontier models. Um, and we know everybody does, but you don't know and you don't have any control over what the system prompt of a GPT model or a Claude model is. Right. OpenAI and Anthropic set that and that's their intellectual property. And when you're using it inside your development environment, you're subject to whatever they decided was the system prompt.

[00:05:51] Sean Martin: So, or, or the government in some cases

[00:05:52] Daniel Bardenstein: or the gov. Yeah. Or the government, right. Whether. Models from other countries or the US government deciding to, you know, rip something out. [00:06:00] So the advantage of open weight models, uh, and you know, I can share a prediction about this in a sec, but the advantage is organizations have more control. Mm-hmm. Uh, they can, it's easier to implement guardrails. They can control everything from the system prompts to the training data to how it's actually deployed. And I think given everything we've seen the last three months, I'm expecting the adoption of open weight models to really accelerate.

[00:06:22] Sean Martin: And so forgive my ignorance, but the training piece. I guess if, if you have your own environment to train on, that's great, but if you're relying on bigger picture stuff, how does that, how does that play into the,

[00:06:36] Daniel Bardenstein: it goes back to one of the things I find myself saying a lot these days, which is that AI has its own supply chain, right? Software supply chain has been a very hot topic, uh, since the days of. You know, executive order a few years ago talking about software, bills of material. We see all the, uh, research, uh, market research firms putting out software supply chain briefs. Uh, but I don't see many people talking about AI supply chains. What I mean by that, uh, unless you control [00:07:00] every single step of the training data, how it's housed, modified, and tweaked and labeled and tagged, and then the models and every single step, you're relying on something that someone else made or built. And so we've encountered this with some customers of ours where. They've take a model and train it on someone else's dataset, right? There are lots of public data sets and you take on risk from that dataset, right? Do you trust what's in it? There's no PII or PHI. There's nothing illegal. There's been a couple of instances, unfortunately, of major commonly used data sets, having child pornography in them, uh, and no one's spending the time to go look into that until it's too late and deployed. So data sets are its own supply chain, uh, element of the AI supply chain. Open weight models on Hugging Face are as well. So even though there are advantages to using open weight models and and public data sets, you still have to do your due diligence to assess risk and make sure you're, you're not unintentionally bringing in risk into your organization.

[00:07:56] Sean Martin: So what do the conversations sound like? Let's [00:08:00] CISOs security leaders, what do they come to you with and say, Manifest, Daniel. We need to, we, we, we have something already or we haven't done something yet. What, what do they start to talk, talk to you about?

[00:08:17] Daniel Bardenstein: I'd say they're two things, visibility and third party risk.

[00:08:21] Sean Martin: Okay.

[00:08:21] Daniel Bardenstein: So on visibility, the, I still haven't met many organizations or CISOs that have. A really good AI inventory and what that means is what models are being used across the enterprise and what applications, and I've heard increasingly agents as well, right? Okay. Now that everyone is using agents or organizations are encouraging, you know, sales teams spin up an agent, marketing teams spin up agents, uh, product teams spin up agents. It's more attack surface and it's just another thing that a CISO needs to make sure that they are inventorying, they're aware of, they can continuously monitor, et cetera. So CISOs come to us saying, Hey, we need visibility into [00:09:00] what's actually deployed, right? One thing if everyone is just using Claude Code, but we're already moving beyond that. And the second really interesting thing is, is third party risk, right? AI is getting baked into every vendor product, whether one likes it or not, and. That poses risk as well. So a lot of CISOs come to us given the work we do in third party cyber risk, and ask us, can you tell us what models are in my third party tech and how does that let me trust my vendor or not? Right? It's one thing if they're just using an Anthropic model, an OpenAI model, or, or a Google model. But did they just get something random off of the internet on a Hugging Face? Did they train their own? How do I know if one of their open weight models isn't a Chinese model or something that violates their policies or a competitor or a Yeah. And so that remains a massive visibility gap, and that just also relates to the larger, uh, in my opinion, broken nature of third party cyber risk. So AI is just one element of that.

[00:09:55] Sean Martin: Right? And so how, what's the. [00:10:00] What's the path out of, out of this world of the wild West? It's the frontier, the wild west, right?

[00:10:07] Daniel Bardenstein: I think it's, it's returning to the less sexy stuff. Okay. Everyone's excited about

[00:10:10] Sean Martin: fundamentals.

[00:10:11] Daniel Bardenstein: Way back to the fundamentals, right? I know it's it. It never makes good headlines, but while everyone is excited to talk about agentic security and this and that. Let's start with like knowing what's in your enterprise, right? You can't defend what you don't know about, whether it's stuff that you're building or deploying or where your agents are running or what's in your third party tech. I mean, part of why I started the company four years ago was from my experience responding to Log4Shell from the Pentagon and is a very simple question like where is this one affected piece of code running in everything I've built? Right and bought. Here we are six years later, CISOs say that, oh, we're tired of hearing about these sorts of stories from vendors, which I, I understand, but I still haven't found a CISO that if I went up to and said, Hey, if I told you that a data set or a model was poisoned or [00:11:00] somehow, uh, compromised, how quickly could you answer that question for me? Right. Where is your company using this model? And if so, where and who owns the, the application or which of your vendors are affected phone calls, emails, spreadsheets. So it's six years later. And as I'm, I am fearing, uh, we're just repeating the same mistakes of the past, but with AI,

[00:11:20] Sean Martin: right? Yeah. They'll, they'll know when the, the availability of the triad, uh, hits. Yes. It's when the model gets pulled or something. 'cause it, 'cause it is too risky to run.

[00:11:30] Daniel Bardenstein: Unfortunately. It's, I think it's gonna be one of those situations where, uh, something bad has to happen for people to really wake up and be like, oh, I probably should have been doing this the whole time.

[00:11:39] Sean Martin: Yeah. So, final word, Daniel. Words to, yeah, CISOs, how can they, well, how can they connect with you and start a conversation that brings the business into line with what they're trying to handle as well?

[00:11:55] Daniel Bardenstein: I'm pretty easy to find, fortunately. Uh, so, you know, manifestcyber.com is our [00:12:00] website. People can find me on LinkedIn and reach out. I spent a lot of my time. Uh, not selling with, but just having conversations, learning about what their pain points are, but also, you know, giving them some, even telling other stories that we've seen from other organizations. And the number, number one piece of advice is just know what's inside, what you're building and buying, and especially everything that you don't build right? Uh, open source software. Your developers don't build third party tech. Your developers don't build. You have a good handle and you clearly vet your employees, but you can't do that for open source developers and for your vendors. The best way to reduce for enterprise risk is to keep it out in the first place.

[00:12:35] Sean Martin: Can't be an ostrich anymore.

[00:12:36] Daniel Bardenstein: Exactly. Alright,

[00:12:38] Sean Martin: well Daniel, pleasure to see you.

[00:12:39] Daniel Bardenstein: Always a

[00:12:40] Sean Martin: pleasure. Thanks for the chat and, uh, thanks everybody for listening. Connect with Daniel and the Manifest team and uh, stay tuned for more here from Black [00:13:00] Hat.