Podcast

Alice in Supply Chains - Episode 20 | Recorded Live at Black Hat in Las Vegas!

August 19, 2026

Episode description:

On episode 20, Adrian and Alexandre discuss four recent stories shaping third-party and AI risk: SOC 2 commitments deferred by vendors, the lessons from Brazil’s PSTI security requirements, AI agents and security incidents involving Hugging Face, OpenAI and Anthropic, and a prompt injection case involving outside counsel in Brazil. The episode explores what these incidents mean for TPCRM, vendor assurance, regulatory compliance, AI governance, and third-party contracts.

Show notes:

Recording in person for the first time — from a scorching Las Vegas during Black Hat week — Adrian and Alexandre open with Adrian's BSides Las Vegas talk debunking the "60% of breached small businesses fail" myth.Story one covers the "trust me bro, I'll eventually get you a SOC 2" trend: contracts that let vendors start business now and promise a SOC 2 within a year. The guys argue this inverts the whole point — SOC 2 isn't a control, it's an assurance mechanism, so deferring it means hiring first and assessing later. With compliance-automation vendors promising push-button SOC 2s and the economic incentives that produced Delve unchanged, expect more rubber-stamp mills.

Story two heads to Brazil, where CMSW Solutions — the first PSTI (PIX payment infrastructure provider) publicly breached in last year's wave of nine-figure heists — passed the Central Bank's tough new requirements, then exited the PSTI business anyway. The lesson for TPCRM teams: "we meet the compliance requirements and no more" is a trap, because sometimes (moving hundreds of millions daily) the regulatory floor sits far below actual risk, and sometimes (a drywall contractor facing CMMC) far above it.

Story three was the talk of Black Hat: Hugging Face announced it was hacked by an AI agent, OpenAI raised its hand to claim the oopsie, and Anthropic then admitted its agents had escaped sandboxes and done the same. We discuss the uncomfortable questions: where's the CFAA energy that gets aimed at human researchers, and why do we tolerate two-nines availability and sloppy containment from vendors whose entire pitch is how dangerous their technology is? Practical advice: hold AI labs to a higher vendor standard, and consider running inference through hyperscalers for better infrastructure, IAM, and data residency guarantees.

The final story is one for the "wouldn't even occur to a sci-fi writer" file: outside counsel defending Brazilian cosmetics giant Natura embedded a prompt injection in a court filing, attempting to manipulate the judiciary's automated document processing. The judge found the firm litigated in bad faith, applied the maximum 10% misconduct fine, and referred the lawyers to the bar. The TPCRM takeaway: your third parties' AI use isn't just a data-leakage question anymore — review whether your contracts with outside counsel (and everyone else) cover willful acts like this.Links:

  1. Story 1: https://www.linkedin.com/posts/kelsey-waters_ive-now-seen-this-twice-enterprise-buyers-share-7483510195877240832-nZFg/
  2. Story 2: https://www.linkedin.com/posts/cmsw-tecnologiafinanceira-infraestruturafinanceira-share-7487486750743969794-_xQi/
  3. Story 3: https://kaynemcgladrey.com/blog/when-the-arsonist-sells-fire-insurance/
  4. Story 4: https://brazileconomy.com.br/empresas/2026/08/natura-e-condenada-pela-justica-por-litigancia-de-ma-fe-e-manipulacao-de-ia/
  5. Adrian’s BSides Las Vegas talk: https://youtu.be/K9tDYG4dMSY?t=609

Show Transcript

Watch or listen to full episodes in English

Recent Episodes