HOME / SERVICES / AI SECURITY / OWASP TOP 10
ASI04 - AGENTIC SUPPLY CHAIN
An agent goes into production after a proper review. Behind it sit a hosted model, two connector servers installed from a public registry, a vector database, an orchestration framework pulled from a package manager, an OAuth grant into your customer relationship system, and a plugin somebody added in week three. Agentic supply chain risk in South Africa is the gap between the thing you reviewed and the eleven things it trusts, and POPIA operator obligations plus Joint Standard 2 of 2024 both attach to that gap. ASI04 is the fourth entry in the OWASP Top 10 for Agentic Applications, published 9 December 2025 by the OWASP Agentic Security Initiative.
YOU TESTED YOUR AGENT. YOU DID NOT TEST THE ELEVEN THINGS IT TRUSTS.
DEFINITION
WHAT THIS RISK ACTUALLY IS
Traditional software supply chain risk was about code you compiled. Agentic supply chain risk is broader, because an agent trusts things at runtime that never appear in a build.
The estate typically includes the model provider, which is an operator processing personal information on your behalf. The orchestration framework and its dependency tree. Connector or tool servers, increasingly implemented as Model Context Protocol servers, many installed from public registries with default configurations. Vector databases and the embedded content inside them. Third-party plugins and skills. OAuth grants held by SaaS products that connect to your systems on the agent’s behalf. Prompt templates and system instructions maintained by a vendor and updated without notice.
Then there is the acquisition path. Agent components are installed by developers in minutes, from public registries, using defaults. This is exactly the population KnowBe4 is describing when it reports that 64% of South African organisations say their AI use is unapproved or ungoverned, and the producer does not publish the sample size. Gartner forecasts that 40% of enterprise applications will feature task-specific AI agents by 2026, up from under 5% in 2025. Each of those applications drags a dependency chain behind it.
Ask the practical version: can anyone in your organisation produce a current list of every external component your agents depend on, including the ones added since go-live?
DOCUMENTED CASE
WHAT IT LOOKS LIKE IN PRACTICE
Two documented cases, showing the two ends of the chain.
- The component
- In April 2026, OX Security research identified a design-level flaw in Model Context Protocol rooted in unsafe defaults in the STDIO transport configuration, enabling arbitrary command execution. 10 CVEs issued and counting, per OX Security. The affected server population runs into the thousands. The important detail is the phrase unsafe defaults. Nobody misconfigured anything. Teams installed a component the documented way, and the documented way was the exposure. If your developers installed connector servers from a registry and did not change the transport configuration, you inherited this without a single decision being recorded.
- The Integration
- In August 2025, attackers stole OAuth and refresh tokens belonging to an AI chat agent in the Salesloft Drift compromise and used them to reach connected customer relationship systems. Fourteen companies publicly confirmed impact. Those fourteen organisations did not run the compromised agent. They had connected to it. Their exposure came through an integration, and the failure was token hygiene and third-party integration visibility, not model security.
- Put them together and the pattern is complete. One end of the chain gives an attacker code execution through a default nobody changed. The other end gives an attacker authenticated access to your customer data through a vendor you never tested. In both cases the organisation harmed had a passing vendor questionnaire on file, because a questionnaire asks about policies and neither of these was a policy failure.
WHAT THIS MEANS UNDER SOUTH AFRICAN LAW
DISCOVERY
NEWORDER connects to CI/CD pipelines to automatically discover and inventory every homegrown AI application, and integrates directly with AWS Bedrock, Google Vertex AI, Salesforce, and other cloud and third-party platforms for visibility into AI agents. Each AI system is profiled across its model, system prompt, tools, guardrails, policies, and configurations, and the inventory stays current on every change. You cannot secure what you cannot see; discovery is the non-negotiable first step.
AI SECURITY POSTURE MANAGEMENT (AI-SPM)
NEWORDER conducts a static analysis of every application’s configuration, policy coverage, and third-party dependencies and identifies any policy gaps. In addition, it maps each agentic application to its coverage of major frameworks, including NIST, OWASP, and MITRE. This gives you a clear, measurable view of your AI security posture before a single adversarial test is run, turning assumptions into evidence and compliance into a continuous output rather than a periodic exercise.
AI RED TEAMING
NEWORDER’s automated AI red teaming covers the complete kill chain from reconnaissance to exploitation. It proactively discovers exploitable vulnerabilities through automated reconnaissance and adversarial testing purpose-built for agentic applications. Static attacks draw from a 300K+ payload library with 100% MITRE and OWASP LLM and Agentic Top 10 coverage, running comprehensive sweeps of known jailbreak patterns, content moderation bypasses, and obfuscation techniques. Dynamic attacks use multi-turn and continuous probing to test how an application holds up across extended adversarial sequences, not just a single interaction. High-agency attacks deploy extremely customised, bespoke attack techniques through probing tailored specifically to the intent and design of each application.
RUNTIME PROTECTION
NEWORDER offers policy enforcement and AI threat protection at the proxy, API, or AI Gateway layer. Protection adapts as the applications evolve and as new capabilities are added. When an attack hits production, whether a jailbreak, a prompt injection, or any other AI threat, it is blocked in real time and an immediate alert is sent with full context, including what happened, which application was targeted, what the impact is, and what to do next. Key performance metrics include 98.6% threat detection accuracy, 1.4% false positive rate, sub-200ms time to detect, sub-50ms real-time blocking, and immediate mean time to respond.
POPIA sections 20 and 21
An operator processing personal information on behalf of a responsible party must do so only with your knowledge or authorisation and must treat the information as confidential, and you must have a written contract requiring the operator to establish and maintain the security measures in section 19. A hosted model provider processing customer text is an operator. A connector server vendor with access to your records is an operator. If you cannot name them all, you cannot contract with them all, and an uncontracted operator is a section 21 breach that exists today, before anybody attacks anything.
POPIA, liability
An operator processing on your behalf does not transfer your liability. The data subject’s rights run against you. A vendor indemnity is a commercial recovery mechanism. It is not a defence to the Information Regulator.
POPIA section 22
Where personal information has been accessed or acquired by an unauthorised person, notification goes to the Information Regulator and to affected data subjects. When the compromise happens at your supplier, the notification duty is still yours, and you will be drafting it using facts you do not control.
Joint Standard 2 of 2024
, in force 1 June 2025, applying to banks, insurers, asset managers, retirement funds and credit rating agencies. It requires that third-party controls be equivalent to your own, documented evidence of control testing including vulnerability scans, penetration tests and simulated incidents, and a maintained testing calendar. The board is ultimately accountable under a board-approved cyber risk charter. Equivalent to your own is a testing standard, not a paperwork standard. If you penetration test your own systems and accept a questionnaire from the vendor whose connector executes commands inside your environment, the controls are not equivalent, and material incidents may still need to reach the FSCA or Prudential Authority within 24 hours using information the vendor has not yet given you.
King V
, effective for financial years beginning on or after 1 January 2026. The governing body is accountable for the effective, compliant and ethical acquisition, development, use and distribution of technology, with periodic assurance. Acquisition is named explicitly. A developer installing a connector from a public registry is performing an act of technology acquisition on behalf of the governing body, whether or not anybody told the governing body about it.
Cybercrimes Act 19 of 2020, section 2
Unlawful access is an offence. Where a compromised component gives an attacker execution inside your estate, the offence is theirs. The regulatory consequence, the notification and the customer conversation are yours.
QUESTIONS TO ASK BEFORE YOUR NEXT AGENT GOES LIVE
- Can we produce, today, a complete list of every external component and integration our agents depend on, including everything added since go-live?
- Which of these suppliers are operators under POPIA, and do we hold a written contract with each one covering the section 19 security measures?
- Were our connector or MCP servers installed with default configurations, and has anybody reviewed the transport settings since April 2026?
- Which third parties hold live OAuth or refresh tokens into our systems, and how fast can we revoke each one?
- What evidence of control testing, not policy attestation, do we hold for each of these suppliers, and does it meet the equivalence expected by Joint Standard 2?
- If a supplier is breached tomorrow, who inside our organisation drafts the section 22 notification, and what facts do we already hold without needing the supplier to answer?
FREQUENTLY ASKED QUESTIONS
FAQ
What is the agentic supply chain?
It is ASI04 in the OWASP Top 10 for Agentic Applications, published 9 December 2025. It covers every external component an agent depends on at runtime: model providers, orchestration frameworks, connector and MCP servers, vector databases, plugins, prompt templates and third-party integrations holding credentials into your systems. Unlike classic supply chain risk, the trust is executable, because these components can cause actions inside your environment.
Does a vendor questionnaire satisfy Joint Standard 2 for AI suppliers?
Joint Standard 2 of 2024, in force since 1 June 2025, requires third-party controls equivalent to your own and documented evidence of control testing including simulated incidents. A questionnaire evidences a policy position, not a control. Where a supplier’s component can execute inside your environment, equivalence means testing at the same depth you apply to your own systems.
Are we liable if our AI vendor is breached?
Under POPIA, yes, in the ways that matter. An operator processing personal information on your behalf does not transfer your liability, and notification to the Information Regulator and to affected data subjects under section 22 remains your obligation. Contractual indemnities may recover cost afterwards. They do not move the regulatory duty or the conversation with your customers.
WHERE TO GO FROM HERE
- Start at the hub, The OWASP Agentic Top 10 for South Africa, which carries the full regulatory mapping table across all ten risks.
- Book an AI Exposure Review. You get a full agent inventory, an identity and permissions picture, and one live adversarial test against one production agent, so you can see this for yourself.
TAKE ACTION
TEST IT BEFORE SOMEBODY ELSE DOES
Thirty minutes on your agent estate and what this risk looks like in your environment.