Back to full agenda Wed May 20 / 02:40 PM - 03:15 PM PST

Trust No Package: AI and the Evolution of Supply Chain Threats

AI is no longer just transforming software — it is transforming the risk profile of the entire software supply chain. As AI models, prompts, agents, and supporting infrastructure become first-class artifacts, they introduce new trust boundaries and attack surfaces that traditional security controls were never designed to assess. Natural language, agent behavior, and opaque AI components now directly influence execution, decision-making, and access to sensitive systems. This session explores the new risks posed by AI-driven supply chains, how attackers are exploiting these emerging trust models, and how AI itself can be used to help combat these threats. Drawing on concrete, real-world examples from Microsoft-operated distribution hubs and marketplaces, the talk examines how AI artifacts and AI agent ecosystems are being abused in ways that bypass conventional security assumptions and operate across multiple platforms simultaneously. From its unique vantage point protecting inbound dependencies, first-party software, public distribution hubs, and outbound marketplaces, Microsoft’s Trust & Security Services team is deploying AI-powered detection systems to identify emerging threats, assess publisher trust at scale, and correlate malicious activity across ecosystems. The session highlights how human expertise and AI-driven analysis work together to adapt security strategies, evolve policy, and raise the security bar in an AI-first world.

Tudor Dobrila Bio
Tudor Dobrila is a Principal Software Engineering Manager at Microsoft with over 11 years of experience in the security space. He previously led engineering teams within Microsoft Defender Antivirus, shipping security software to over one billion devices worldwide. Today, Tudor focuses on applying AI to protect the software supply chain across global distribution hubs and marketplaces. His work spans AI driven malware detection, publisher reputation, and large scale threat identification, combining advanced automation with human expertise to address emerging risks in an increasingly AI enabled threat landscape

Masterclass Technical deep-dive

More presentations from Tudor Dobrila: Beyond the Hype: The Real Business Impact of AI

20. Tudor Dobrila - Principal Engineering Manager from Microsoft HQ Redmond
Tudor Dobrila Principal Engineering Manager from Microsoft HQ Redmond
Back to full agenda