ai-cybersecuritytrade-pressNewsThe Broadside1 min read

Boards blind to AI model dependencies, Walden warns

The former ONCD chief tells corporate directors that outsourcing an AI model doesn't outsource the accountability when it fails, and most boards can't answer basic transparency questions about their third-party models.


TL;DR

Former Acting National Cyber Director Kemba Walden told an ISA-NACD webinar on Sept. 15 that corporate boards routinely lack visibility into their third-party AI model dependencies, what data the model retains, who the subcontractors are, and how fast they could replace the service during an incident. "An organization may not always know how a provider's AI model will develop. This is why transparency is really important, but you might not always get it," Walden said. Kyndryl's Kris Lovejoy framed third-party AI risk as an enterprise-resilience problem, not a vendor-management checkbox.

Walden, now president of the Paladin Global Institute, anchored her warning in a framework her institute has been developing, a five-layer AI tech stack model (Data, Model, Infrastructure, Application, and Governance) that she argues should structure how policymakers and boards approach AI security. But the webinar's focus was narrower and more operationally pointed: the gap between what boards assume about their AI supply chain and what they actually know.

She pressed directors to ask three questions when selecting an AI model: what information the model retains, who the subcontractors are, and "how quickly services can be replaced" if the provider goes down. On open-source AI models, Walden noted they create "another visibility challenge because organizations may depend on components that they didn't directly purchase, and they may have limited insight into them or their maintenance and downstream use."

Lovejoy sharpened the framing: "The result is that organizations can have strong security controls themselves but still be significantly disrupted by a failure that is outside its direct control." That's a dynamic compliance directors already know from cloud shared-responsibility models under FedRAMP and DFARS 7012. Walden's formulation ("just because an organization can outsource a service, it cannot outsource the accountability for the consequences") extends that same logic to AI model dependencies, a conversation most boards haven't started.

Walden did offer one note of optimism, pointing to AI-enabled tools that could improve supply-chain visibility, though she acknowledged those tools "introduce a new platform and new risk into digital infrastructure." The broader policy context she's operating in includes CISA's support for a G7 effort to develop minimum elements guidance for AI supply-chain transparency, building on the SBOM model, and NIST's ongoing work to integrate AI Bill of Materials guidance into a cybersecurity framework profile.


Published ·Deep Fathom