
Chainguard CISO: AI Just Rewrote Software Supply Chain Security
Chainguard's CISO says AI agents now choose the dependencies in your code while attackers use frontier models to chain minor bugs into working exploits, pushing security from detection toward prevention.
AI coding tools have sharply accelerated software development, and have done the same for the people attacking it. The software supply chain is where those two trends collide, says Quincy Castro, CISO at Chainguard.
More code, written faster
GitHub's numbers show the scale: the platform processed about one billion commits in 2025, and by April 2026 it was handling roughly 275 million a week, according to COO Kyle Daigle.
"I don't think any of our engineers have written a line of code by themselves in the past year," Castro said, adding that hand-coding now feels "quaint," like illuminating manuscripts while the printing press is out there going to town.
AI also widened the pool of builders: HR, finance and business intelligence teams now produce their own tools, often without seeing which libraries an agent picked.
Three problems at once
Castro describes three simultaneous shifts: frontier models finding unknown vulnerabilities, attackers using agents to exploit flaws organizations have not fixed, and sustained attacks on the open source ecosystem.
Findings rated low or medium once sank to the bottom of the remediation queue. Models with advanced cyber capabilities, including Anthropic's Claude Mythos Preview and OpenAI's GPT-5.6-Cyber, released in August, can now chain those minor weaknesses into a workable attack path. Mandiant reports mean time-to-exploit fell from 63 days in 2018-19 to an estimated minus seven days in 2025, so attacks can start before a patch exists.
Supply chains are the third front. Castro cited the TeamPCP campaign, which compromised widely used projects including Aqua Security's Trivy, pushing malicious code into trusted components picked up downstream.
Prevention before detection
The familiar loop - scan, alert, triage, chase a fix - weakens when output multiplies and exploits land before patches. Chainguard builds containers and libraries from verified, buildable source, with provenance about how they were created, then controls how they enter the environment.
"There's no point in bringing inherently secure components into the environment if you don't have a technical control that says this is the only way people developing code can consume these things," Castro said.
Fixing open source at AI speed
Through Athena, a coalition Chainguard launched to turn findings from frontier AI programs into fixes, the group had processed more than 40,000 vulnerabilities as of July: 42% rated critical or high, 86% network reachable. Fixes go back to members and upstream to maintainers.
Developers will not abandon coding agents, any more than companies will abandon open source; the aim, Castro argues, is to cut risk before software reaches a developer or an agent.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.