What you'll learn
Why the economics of open weight models like GLM 5.2 — frontier-level performance at 5-6x lower cost — are about to pull enterprise AI adoption away from Anthropic and OpenAI, and what new supply chain risks come with that shift.
How AI licensing quietly breaks businesses: early Llama models banned military, surveillance, and even transportation use before Meta softened the language across versions, and most legal teams can't tell you whether they're allowed to use an OpenRAIL++ model.
Why an AI Bill of Materials isn't compliance theater but a machine-readable way to answer "where is this compromised data set running in my environment?" in minutes instead of the six to eight weeks a model approval currently takes.
Description
Daniel Bardenstein is the founder and CEO of Manifest Cyber, and before that he was chief of technology strategy at CISA and the cybersecurity lead for Operation Warp Speed. He also helped write the cross-sector Cybersecurity Performance Goals that now shape how the US government thinks about software supply chain risk. This conversation is about a claim he keeps making everywhere he goes: AI is a subset of software, AI has supply chains the same way software does, and the tools security teams already own get them most of the way to managing it.
The through-line is that third-party risk was already broken — SOC 2 PDFs, vendor questionnaires, legal CYA — and pouring AI into every product makes it worse, because now the third-party tech in your car, your MRI machine, or your HR system is non-deterministic and nobody agrees on who owns the trust decision. Bardenstein walks through the real failures: companies quietly fine-tuning DeepSeek to dodge compliance rules, the Lion 5B data set that forced CISOs into incident response over child abuse imagery baked into their models, AI IDEs shipping with actively exploited vulnerabilities that nobody scans. This is for security leaders whose CEO has mandated Claude Code everywhere and who are trying to figure out what's actually running, where it came from, and how to say yes faster than six weeks.
What we cover
"AI has supply chains in the same way that software does" — the core argument, and why AI security and software security shouldn't live on two separate dashboards.
"They will download the weights for Deep Seek. They will ever so slightly fine-tune them, and then they pretend that they have some new model" — how business units launder banned models past compliance.
"They've basically internalized child porn" — the Lion 5B story and what it forced CISOs to do about models trained on a poisoned data set.
"How you could use the model changed over each version" — Llama's shifting license terms and why AI licensing is a black box that can kill a commercialization path.
"Hi, I'm the problem, it's me" — shadow AI, one line of Python pulling a model off the internet, and AI-generated infrastructure floating on public IP space.
"We just need to worry about the rest of the org" — the overconfidence trap, and why a markdown file telling Claude to write secure code doesn't work.
"It's a lot of legal CYA" — why third-party cyber risk starts from a broken foundation before AI makes it non-deterministic.
"AI is a subset of software... you're 90% of the way there" — the optimistic close, and the case against buying an AI firewall, AI DLP, and AI SIEM on top of the 50 tools you already have.
Thank you to our Sponsors:
→ Hampton North is the premier US based cybersecurity search firm. Start building your security team with Hampton North.
→ Sysdig is the leader in AI-powered real-time cloud defense; stop watching and start defending.
The conversation
The market is about to swing back to open weight models, and it's just arithmetic
Bardenstein describes the last two years of AI adoption as a camel hump. Everyone started pre-ChatGPT racing to adopt open weight models off Hugging Face, worrying about pickle deserialization attacks. Then Claude Code and ChatGPT arrived and everyone forgot open weights — someone else was running the model, so why bother. Now the factors that made open weights attractive are landing at once, and the cost story is the forcing function.
The context Conor sets up is GLM 5.2: a 744-billion-parameter open weight model with frontier-level performance at 5-6x lower cost than the proprietary providers. Bardenstein sees the same thing happening across the industry — token maxing is proving overblown, with Uber burning through a full year's AI budget in a single quarter and CFOs questioning whether the ROI on Claude Code subscriptions beats just hiring people. When the cost advantage and the performance advantage both flip, open weights come back into play.
"Over the next 12 months, I think we're going to see a massive shift in investment to open white models."
He adds one more push toward open weights that most people missed: the business risk of running your whole enterprise off a model a third party — or a government — can switch off. The point for a security leader isn't to resist the shift. It's to recognize that when performance and cost equalize, the conversation collapses to cost, and the CISO's job becomes answering "cost at what risk" fast enough that the mitigations are worth the token savings.
The DeepSeek website and the DeepSeek weights are two completely different risks
Bardenstein got excited about GLM 5.2's benchmarks because Manifest works with air-gapped and classified environments where self-hosted AI matters. Then he read the fine print. Z.ai is a Chinese company, and if you use the out-of-the-box app or API, they store all the prompts and all the data you put in. Use the open weight model from Hugging Face and you've got a different risk profile entirely.
"There are gonna be a bunch of companies that rush to use GLM 5.2 and don't realize that they might unintentionally be siphoning off their data or prompts to a Chinese entity."
Conor draws the parallel to DeepSeek's launch: grab the weights and run them locally, or go to the website and use it as a ChatGPT alternative. Neither is risk-free, and they're different classes of risk. The mistake is treating "we're using DeepSeek" as a single decision when it's really two.
The relationship between models and data sets is where AI supply chain stops looking like software
This is Bardenstein's origin story for the whole field. A model doesn't live in a vacuum — it's trained on data sets, put into a container, packaged into an application, then into a car or a device. And the data set layer is where things get genuinely new. The Lion 5B example is his anchor: a public data set of 5 billion images used to train Stable Diffusion, one of the most widely used freely available image models at the time. Stanford researchers found a couple thousand images of child abuse material in it.
That turned into an incident response scenario for CISOs across the industry. Are we using this data set anywhere? Are we running Stable Diffusion? Have we fine-tuned anything off it? A model can perform beautifully at its assigned task while having internalized something that is a massive legal and business risk to your company.
"If you didn't build it yourself, whether it's software, an open source package, or a model, you gotta know who built it. You gotta know how you trust them, you gotta know where your data is going."
The map he draws: data sets feed model training, trained models get embedded into software, and the AI supply chain has to link into the software supply chain because models have to get put into software to be used. Which means the least sexy parts of the security program — inventory and third-party risk — are exactly the parts that fail first. Bardenstein says he's still hard-pressed to find a CISO who could quickly answer where a named compromised data set or model is running in their environment. Phone calls, emails, spreadsheets. Log4Shell all over again.
AI licensing is worse than open source licensing, and nobody owns it
Conor, who has built an open source licensing program, teases Bardenstein with the hope that AI has somehow solved this. It hasn't — it's gotten worse. Models can carry the familiar permissive-versus-copyleft distinctions, but ask a legal team whether they can use an OpenRAIL++ model and they don't know.
The Llama story is the sharp one. Companies trying to bring AI-enabled software to parts of the US government used early Llama models because they were open weight and could run in closed environments. But Llama's license changed with every version. Early Llama 3.1 explicitly banned use for military, defense, surveillance, transportation, and heavy manufacturing applications. Then Meta, not wanting to lose the business, softened that language across 3.2 and 3.3.
"This model might be legal if you're just gonna use it to summarize emails or read PDFs, but not if you're gonna do health, you know, cancer diagnostics or anything that could be construed as surveillance."
On ownership, Conor's hot take is that nobody cares until an M&A event, when opposing counsel suddenly wants the spreadsheet filled in. Bardenstein's answer is that it lands in one of two places — legal or GRC — usually funneled through some AI review board stitched together from security, legal, and privacy. And that board's approval process for a single open weight model can take six to eight weeks. In AI time, that's your competitors already shipping on GLM 5.2 while your legal team reads 20-page acceptable-use PDFs.
The markdown file that tells Claude to write secure code does not work
The shadow AI section is where Bardenstein quotes Taylor Swift on himself — he's the problem. He can run Claude Code locally, spin up models, build dashboards, and he's technical and security-savvy enough to be a good steward. Most people building this stuff aren't. One line of Python pulls a random model from the internet onto a machine, and the model then spins up test apps at machine speed. He's seen AI-generated shadow infrastructure sitting on public IP space that was never meant to be there.
Stu's point sharpens it: the people doing this often aren't traditional engineers. Ask a sales or HR person what a vulnerability is and it already sounds intimidating — but they can now produce the polished software product they used to wait on the engineering team for, and they have no context that it can land the business in hot water.
The trap Bardenstein wants CISOs to avoid is assuming engineers are immune. He's talked to Fortune 500 CISOs whose entire plan is a markdown file that says "write secure code, Claude, don't write any SQL injection vulnerabilities." It doesn't work, and he catches it in his own workflow — Claude picking an outdated framework version because the new one "seemed too new," then refusing to upgrade because the upgrade might break the app.
"It's non-deterministic. We need to remember that. And so just telling it not to bring in Vaughns or write insecure code, it's just guessing the next word."
Stu adds the human failure mode: if the first five pull requests look perfect, you stop reviewing the eighth as closely, and that's the one with pasta sauce everywhere. Bardenstein's summary is that we're too quick to trust and also lazy — the moment something looks like it'll do our job, we want it to.
You can require machine-readable artifacts without spending a dollar
When Stu asks for the business framing that actually opens a CFO's wallet, Bardenstein splits it. The expensive path: if you have the team, pen-test and vuln-scan every piece of third-party tech you buy. It's better than nothing, but it's outside-in — you can't see how good the software is under the hood
The cheap path costs political capital, not budget. Require your vendors to hand over a machine-readable artifact alongside the SOC 2. You're not asking for their source code; you're asking for a representation of what's in their supply chain — because it's now your supply chain too. That's something you can scan, inventory, and monitor. Modern tech all on the latest version is a good sign. OpenSSL and zlib from a decade ago is a flag for a broader problem.
"Storing them in a folder doesn't actually get you anywhere. Like you have to do something with them, to scan them, you have to monitor them."
This is where the AI Bill of Materials comes in — and Bardenstein insists on the caveat that an AIBOM is just an SBOM that describes AI. It's not a new concept; it's a structured, consistent JSON representation of a model, its supplier, the data sets it was trained on, its licensing, and how it's assembled into a larger system. The value is that it's machine-readable, so the model approval that takes six to eight weeks of reading web pages can be scanned and automated. And it answers the Lion 5B question fast: given a compromised data set, what models were trained on it, what containers hold those models, and what products hold those containers.
He's blunt about why model cards, data cards, and system cards don't replace it. They're text-heavy, inconsistent across vendors — Meta's model card looks nothing like NVIDIA's or Hugging Face's — not security-focused, and there's no guarantee they contain what you need. Bardenstein has read a fair number of Claude and GPT system cards; some run seventy pages, and he doesn't recommend it.
Show notes
Guests — Daniel Bardenstein, founder and CEO of Manifest Cyber; former chief of technology strategy at CISA; former cybersecurity lead for Operation Warp Speed; one of the architects of the cross-sector Cybersecurity Performance Goals.
Books mentioned — None named in the conversation.
Frameworks / models / tools named — SBOM (software bill of materials); AIBOM (AI bill of materials); CBOM (crypto bill of materials); SLSA; Cybersecurity Performance Goals (CPGs); GLM 5.2 (Z.ai); DeepSeek; Llama 3.1 / 3.2 / 3.3 (Meta); Stable Diffusion; Lion 5B data set; Mistral; Claude / Claude Code / Claude Opus (Anthropic); ChatGPT / GPT / Codex / ChatGPT desktop app (OpenAI); Hugging Face / Hugging Face Hub CLI; OpenRAIL++ license; MIT and Apache 2.0 licenses; npm; OpenSSL; zlib; React; MongoDB; model cards / data cards / system cards.
Other people / shows / resources referenced — Taylor Swift; Team PCP (npm supply chain attacks); Uber (AI budget report); Lockheed Martin / F-35 (supply chain example); Stanford researchers (Lion 5B / CSAM finding); US Department of Defense / Department of War.
Hosted by Conor Sherman and Stuart Mitchell.