When Procurement Gets an AI Assist, Security Gets a New Attack Surface
10:33
Wed | Aug 12, 2026 | 4:51 AM PDT

McKinsey's latest look at distribution, "How AI is redefining category management in distribution," reads like good news for the supply chain: generative AI "category agents" are becoming virtual partners for procurement teams, aggregating spend data, market intelligence, and supplier performance into a single interface that can recommend sourcing decisions, draft RFPs, and track execution around the clock.

McKinsey's own research puts real numbers behind the pitch—category agents are already driving 5 to 20 percent in additional value across procurement functions, with teams capturing 15 to 30 percent efficiency gains by automating non-value-added work.

For CFOs and chief procurement officers, that's a compelling case for AI adoption. For CISOs, it's something else: a description of a brand-new, largely ungoverned set of systems that will soon sit inside the sourcing, supplier-selection, and payment workflows of the business—with access to contracts, pricing, supplier relationships, and increasingly, the authority to act on that data without a human in the loop.

From its surveys of CISOs and equivalents who serve as the steering committees (Advisory Councils) for SecureWorld conferences across the U.S., AI governance is overwhelmingly the number one concern/topic. The topic, and related AI topics, are prominent across all of SecureWorld's fall events.

Efficiency is the headline. Exposure is the fine print

McKinsey isn't alone in describing this shift. Across the distribution sector, roughly 95 percent of distributors say they're actively exploring AI use cases across the value chain—but fewer than a third say they have the in-house talent to scale those efforts responsibly, and fewer than 10 percent have a prioritized AI roadmap at all. That gap between enthusiasm and readiness is exactly where cybersecurity risk accumulates.

The category agents McKinsey describes aren't passive dashboards. They ingest structured and unstructured data from both internal and external sources—contracts, news feeds, supplier records—and increasingly act as autonomous or semi-autonomous agents that can execute steps in the sourcing and RFP process on their own. That's the same functional pattern security researchers have flagged as the defining risk of 2026: agentic AI systems that pull in third-party models, plugins, and "skills" at runtime, each one a new, fast-changing dependency that traditional supply-chain security tooling was never built to track.

What security leaders are saying

Security researchers have been explicit that this isn't a hypothetical. Forrester's 2026 threat intelligence outlook names AI agent risk as a top concern for CISOs, noting that agentic AI turns models, tools, and skills into sprawling, fast-changing third-party dependencies, with open-source frameworks representing the most visible exposure since any model or tool pulled into an agentic workflow introduces potential provenance risk. Forrester's recommended response mirrors what application security teams already do for code: inventory every AI component, require AI Bill of Materials (AI-BOM) transparency, apply supply-chain controls, and enforce least-agency so each agent operates with only the access it strictly needs.

That risk isn't theoretical. Researchers cited by Bitsight uncovered a campaign called ClawHavoc in February 2026 that seeded hundreds of malicious skills into a public agent registry—roughly 12 percent of the entire registry—deploying infostealers and reverse shells that exfiltrated browser credentials, SSH keys, and crypto wallets, with the malicious skill count more than doubling within 15 days. Swap "agent registry" for "approved supplier network" and the scenario should sound familiar to anyone who has run a third-party risk program—except the vetting cycle for an AI skill or plugin moves at a fraction of the speed of a traditional vendor onboarding process.

Analysts describe the identity dimension as just as pressing. Forrester's 2026 supply chain category now explicitly includes the skills and plugins agents call at runtime, meaning a compromise in a third-party tool that a personal or corporate agent uses can become a path into the enterprise without any direct vulnerability in the organization's own stack. CSO Online's rundown of priorities for CISOs this year makes a similar point about scale: the global AI agents market was estimated at $5.4 billion in 2024 and is projected to reach more than $50 billion by 2030, and that growth is already creating identity-control challenges including spoofing and over-permissioned access.

Surveys of CISOs back this up with numbers. In one recent global study, 98 percent of CISOs and senior technology leaders said they were concerned about giving third-party AI systems access to company data, even as most third-party risk programs still only apply full controls to their most critical suppliers. A separate CISO-focused report found 79 percent of respondents were concerned that growing AI tool use by suppliers and partners poses a cybersecurity risk to their own organization, while risk controls remain unevenly applied; 70 percent of firms cascade controls only to key suppliers, and just 15 percent extend them across the full supplier base. Identity governance is a particular sore spot: one recent CISO survey found 21 percent of organizations still rely on shared credentials or broad-permission service accounts to govern AI agent access, and only 31 percent of CISOs feel fully aligned with their C-suite and board on what level of AI risk is acceptable.

What solution providers are building toward

Vendors in the security space are already reorganizing product roadmaps around exactly the scenario McKinsey's report describes. Cloudsmith's guidance for 2026 argues that supply-chain security teams need to treat AI itself as a dependency to be governed: in 2026, an AI model is just another third-party dependency, and organizations need to shift from static software bills of materials toward agentic, "curation-first" governance that blocks risky components at ingestion rather than catching them in production.

Vendor risk platforms are moving the same direction. Compyl's research notes that third-party involvement in breaches has climbed to roughly 30 percent of incidents, and AI has widened the attack surface further because vendor AI features can route customer data through new models and sub-processors, effectively creating "fourth-party" dependencies that need to be assessed as part of standard vendor due diligence. Application security vendors are drawing a straight line from AI-generated code and agent credentials to unmanaged risk, warning that organizations that haven't inventoried these assets carry meaningfully higher exposure as regulatory pressure on AI-BOM and provenance disclosure increases.

The common thread: security vendors aren't treating AI-enabled procurement or distribution tools as a niche use case. They're treating every AI agent—whether it's optimizing warehouse capacity, negotiating with a supplier, or running category strategy—as a new identity and a new dependency that needs the same discovery, monitoring, and least-privilege treatment as any other piece of infrastructure.

What boards and CEOs are hearing

This conversation has already reached the boardroom, though not always at the pace CISOs would like. NACD's 2026 governance research found that more than 62 percent of directors now set aside dedicated agenda time for full-board AI discussions, and 77 percent have discussed the material and financial implications of cybersecurity incidents—a 25-point jump from 2022. A separate 2026 board survey found that 84 percent of public-company directors say their boards have broadened scenario planning over the past five years to include cyber events, supply chain disruption, and AI-related risks, and about a quarter have introduced new AI-enabled monitoring tools or dashboards to track it between meetings—yet half of directors still expect AI and technology regulation to demand the most compliance attention in 2026, and 41 percent call it the most underestimated compliance risk their board faces.

[RELATED: The Board Meeting Is Working. Why the Governance Underneath It Isn't]

CEOs, for their part, appear more focused on capability-building than on the risk side of the ledger. A 2026 governance survey found that CEOs' top AI priorities center on building internal expertise, strengthening organizational culture to support adoption, and identifying proven use cases and tools—an operational, deployment-first posture rather than a risk-first one. That gap between board-level risk appetite and CEO-level deployment enthusiasm is precisely the gap McKinsey's category-agent pitch will need to close to land safely: the efficiency case is being made in the C-suite, but the governance case is still being made almost entirely by security teams.

The takeaway for security leaders

McKinsey's report is, on its own terms, a supply chain and procurement story. Read through a cybersecurity lens, it's an early warning. Every category agent, sourcing recommendation engine, or 24/7 "virtual partner" McKinsey describes is a new machine identity with access to sensitive commercial data, a new integration point with external tools and models, and—per Forrester and others—a new third-party dependency that most organizations aren't yet inventorying, let alone governing.

The efficiency case for AI in distribution is strong and well-documented. The security case for treating every one of those agents as a first-class asset in the identity and supply-chain risk program is just as strong, and considerably less discussed in the boardroom right now. Closing that gap—AI-BOMs, least-agency access, continuous third-party monitoring extended to AI tooling itself—is the work CISOs will need to do in parallel with, not after, the operational rollout McKinsey is encouraging distributors to pursue.

Comments