AI coding tools are breaking software supply chains

code editor displaying react source code

AI coding tools are shipping vulnerabilities faster than any audit process can catch them. That problem just got significantly more expensive for anyone selling software in Europe.

The SBOM problem

A Linux Foundation survey of more than 600 global respondents found that 94% of organizations are using or piloting GenAI coding tools, and 48% said those tools have increased their use of open source software. More open source dependencies means a wider attack surface, and traditional software bills of materials are not keeping up.

According to Omdia analyst Torsten Volk, an AI agent can pull old open source code with known CVEs attached, copy it directly into an application, and carry those vulnerabilities forward without the original component ever appearing in the SBOM. Static analysis that assumes agents will always disclose re-used code is not a reliable control.

3D rendered ai text on dark digital background

EU CRA adds liability on top

The EU Cyber Resilience Act’s vulnerability-reporting mandates took effect in September. Open source dependencies, previously treated as separate from commercial products, now fall under the liability of organizations that ship software in Europe. SBOMs will be formally required under the CRA as of December 2027.

Microsoft co-chairs the Open Source Security Foundation’s Launchpad Special Interest Group, which is building machine-readable CRA due diligence baselines that cover open source dependencies. Ryan Waite, Microsoft’s director of open source ecosystems and incubations, said at the Summit that similar regulations are appearing outside Europe, and that shared tooling will help organizations meet those requirements globally.

Slopsquatting and vibe coding risks

Beyond agents pulling in vulnerable code, there is a separate attack vector called slopsquatting. An attacker asks an AI model like Claude to list libraries. The model invents names for libraries that do not exist. The attacker publishes those invented names on npm or PyPI with exploitable code. A developer installs the package in good faith, not knowing the attacker now has access to their application. The SBOM fails because the library name was fabricated.

Vibe coding introduces a related risk. Using AI to configure YAML files or set up Kubernetes clusters without strictly following documentation can expose ports, secrets, and other sensitive data. This is not a theoretical concern: the Linux 7.2 kernel release in August included 1,111 commits tagged Assisted-by, compared with 31 in Linux 7.0, and Linus Torvalds noted at the Summit that some of those patches stem from AI-generated vulnerability noise rather than real issues.

red padlock on black computer keyboard

️ What teams are actually doing

Kubermatic’s Mario Fahlandt described a GitHub Action that runs every Sunday and spawns 2,500 workers to scan CNCF project repositories. The workers generate SBOMs from release tags and store them in an Amazon S3 bucket currently holding 16,000 SBOMs. Continuous scanning, not one-time static analysis, is the operative word.

Container security vendor Edera is taking a different angle: wrapping AI agents and container workloads in hardware-isolated microVMs inside Kubernetes. Each agent gets its own microVM and private Linux kernel, limiting the blast radius if a vulnerability is exploited. Kavitha Daula, Edera’s VP of engineering, noted that open source Kata containers solve a similar problem but can be costly to run at scale.

The operator takeaway: static SBOMs are not sufficient when AI can inline code from anywhere. If your team ships software in Europe, the CRA liability clock is running. Continuous scanning and tighter runtime isolation are the two directions the field is moving.

Stay on top of AI & Automation with BizStack Newsletter
BizStack  —  Entrepreneur’s Business Stack
Logo