Mapping The Entire AI Supply Chain
A walk through the AI supply chain, from gallium to the grid to the frontier labs, by aggregating all 296 companies financial filings .
As a CEO I hated when we grew to the point we needed audited financials. The auditor records you on video answering yes or no as they validate the workings of the business model as it links in to the numbers. It forces the business to operate with a rigor which is the whole point of audited financials; backed by the criminal penalties of Sarbanes–Oxley.
On the flip side, I love being able to read public companies’ financial filings because they really do lay out their business fundamentals, the risks to their business, and what happened when those risks came true. We’re going to use that to paint a common operating picture of the American and Chinese AI supply chain.
Bottom Lines Up Front
Public and IPO’ing companies have to tell their investors about what threatens their business, and what actually hurt them. I mined the financial records of 296 filers across both the US and Chinese stock exchanges from gallium refiners to grid operators to frontier labs. They disclosed 5,885 risks and 578 realized “events” (meaning a risk actually happened to them). Many of these risks were the company disclosing the other companies that they depend on; which shows how the company is linked into the greater AI supply chain.
They say two things:
Damage was mostly self-administered. 94.5% of harm was caused by the company’s’ own conduct or their own governments’ policy. There was only $15 million in damage attributed to hostile actors.
The number of state-attribute attacks that degraded US AI supply chain is zero.
If we define arbitrary groupings, and write code that draws a map based on how companies document their dependencies, then it draws this:
What to see: the red sits upstream on physical things. The blue sits on tools, design and memory. Every path runs through one gold node in Taiwan. And the color of who controls those categories runs out downstream, where nobody has measured the concentration and where exactly one or 5,885 disclosed risks is about training-run integrity.
Caveat lector: this entire study counts what somebody was required, or chose, to write down. This is how the AI industry sees itself, not how others see it. The research data was current as of July 27, 2026.
Companies write their risks down, under pain of SOX criminal penalties
I downloaded the company’s annual financial reports and IPO prospectuses: American 10-Ks, foreign 20-Fs, Shanghai STAR Market and Hong Kong listing documents. And I ran it recursively so if a company referenced its supplier then I pulled its supplier filings too until I closed the loop. From each company I took two things, what it says threatened it, and what already hurt it. Only 103 damaging events described a dollar value of what the damage cost; but we’ll take it.
These corporate filings have a property that expert judgment does not: you get sued and might go to jail for being wrong. A company that poorly documents its own dependencies risks securities litigation, which makes each of these documents a careful statement by a motivated domain expert. The catch is the documents are narrowly scoped only to the one business. So the whole picture only exists if you assemble a few hundred of them.
Unfortunately three things are simply invisible to the method: private companies, classified programs, and the company’s unknown-unknown harms. We’ll talk more about this blindness in its own section near the end; the blindness is less than I thought.
The first surprise was when I saw the shape of the pile before even starting any analysis:
62% of the risks are about legal and economic exposure
8.6% about the equipment that goes into fabs
5.5% about raw materials
3.8% about facility, cooling, and the physical plant
1. Not 1%. One company had one risk about the integrity of model training runs.
I can think of three explanations and I can’t disprove any of them.
No AI company reports its model training is being attacked
None of them are obliged to say so (classified by the government??)
No securities lawyer reminded the company’s executives that they need to disclose those risks.
How to read it: each layer of the AI supply chain gets two bars, every disclosed risk item and the subset that touches the AI supply chain. Note that it’s graphed on a log scale so the legal risks didn’t dominate our ability to read the others.
What to see: legal and economic exposure is bigger than the other eighteen layers combined.
Upstream (where China already tried to squeeze the rest of the world)
I started at the top of the supply chain because that is where China has exerted export controls and I expected to see companies quantify the damage. According to the US Geological Survey, China accounted for 99% of world primary low-purity gallium production in 2024 and holds comparable market share across rare-earth minerals processing and permanent magnets.
When China put gallium and germanium under export licensing in August 2023, its gallium exports fell from 6,876 kilograms that July to 227 kilograms in October. Others followed and you can read about it elsewhere. The cost to the AI supply chain for gallium and germanium in 2025 was $71.8 million (or half of that if you allocate conservatively because the companies serve more industries than just AI).
The middle hardware layer (where everybody is already right)
The next stretch down the chain is the part the field already has right, so I will move through it quickly. Design tools are three firms, Synopsys, Cadence and Siemens EDA, at about 74% of the world market and about 78% of the China market on TrendForce’s 2024 numbers. Lithography is one firm, ASML, at roughly 90% of the market and all of extreme ultraviolet. ASML says it has never shipped an EUV system to China which the US Secretary of Commerce has publicly questioned. High-bandwidth memory (HBM) is effectively 100% from three allied suppliers. Advanced packaging is TSMC’s own platform sitting physically in Taiwan.
Then there is the fulcrum that is better demonstrated than quoting numbers for. NVIDIA’s and AMD’s GPUs are fabricated by TSMC in Taiwan. So are the custom TPUs and NPUs of Google, Amazon, Microsoft and Meta, with every major custom part now on the 3-nanometer node. In Taiwan. That’s the Silicon Shield.
Now the numbers. Across the industry, there were 76 items listed where the company stated it depends on a single supplier where there is no qualified alternative. There were 52 of those for raw materials. This is where company’s have no backup plan if the threat manifests.
How to read it: each bar counts the risk items where a company states it depends on a single supplier and they have no qualified alternative.
How many AIs does it take to change a light bulb?
I didn’t see this one coming. The grid and power firms filings documented 577 risks On 2019 data, the most recent published by the Department of Energy, roughly four in five new large power transformers (LPTs) were imported. Lead times grew from 50 weeks in 2021 to 128 weeks in Wood Mackenzie’s mid-2025 numbers.
Fortunately, this part of the AI supply chain can only be squished by our friends: Mexico, Canada, South Korea, Austria, and the European Union where we import LPTs from. The executive order restricting Chinese bulk-power equipment was suspended in January 2021, its implementing prohibition revoked that April, and the emergency behind it allowed to lapse.
To be exact about the risk here, a blocked transformer order does not affect a model training run already under way. It decides how much compute exists to run AI 2-3 years from now.
The open-weight model surprise
There are seven companies which list open-weight models as a risk to their business. One with regulatory risks, four where the efficiency of open-weight models threatens the services they provide to AI companies, one threatened by the cyber security implications, and one Chinese model provider who lists their own open-weight model as a threat to themselves. It’s ok to laugh.
This is despite Hugging Face’s Spring 2026 report putting Chinese models at the plurality of downloads over the past year. I’m watching to see if the open-weight risk paradigm inverts as more western companies integrate open-weight Chinese models into their businesses.
But what risks have actually impacted these companies?
We’ve done a cursory walk through the entire AI supply chain based on the risks the companies themselves identify. They have also identified where those things have gone wrong.
One of the most common threats companies (and governments) identify is having a single source of a critical supply. 11.7% of all of the AI industry’s documented risks are single-source risks. It has struck 29 times across the industry. And it has resulted in $0 in realized losses. Zero.
Cyber intrusion and intellectual-property theft is 10.4% of the industry’s fear map. And it has resulted in $15m in realized losses. And that’s dominated by two events. To help quantify how insignificant this is, Gartner reports worldwide AI spending $2.59T in 2026.
How to read it: one row per risk category. The dot is that category’s share of all disclosed fear, the bar is its share of all realized quantified loss. The yellow is a single Microsoft tax bill and I recolored to make it visible.
Then I coded every realized risk event twice, did the company’s own conduct cause the event or did another country cause the event. Inside the subset of events that somebody did deliberately, US policy accounts for $9.01 billion in losses across 93 events. The export controls runs about ten to one, $6.47 billion in losses by American and allied AI-industry companies against $0.64 billion in losses by Chinese companies.
And the hostile actors? AI industry companies disclosed 71 events but only two cost them money ($15m total).
How to read it: one asking whose conduct produced the loss, and one asking which government imposed it, in dollars on the left and in event counts on the right.
What to see: self-inflicted events plus own-government policy accounts for roughly 90% of the losses. Hostile action against the company is 13% of events but three hundredths of one percent of the money.
What the corporate filings cannot see (yet)
Everything above measures firms that file because they are public, or they have filed to make an initial public offering. Private companies, and those with still-confidential IPO filings, are invisible to this form of analysis. But the AI buildout is too capital-intensive for companies to stay private. SK hynix, the most concentrated single supplier node in the entire stack, priced its Nasdaq listing on July 9, 2026 when I was working on this project and disclosed risks. SK hynix names its dependence on a limited number of equipment makers in the Netherlands, the United States and Japan, names nation states among the parties that may penetrate its systems, and says it has already experienced cyberattacks.
The same need for capital is pulling Chinese chip designers onto the Shanghai and Hong Kong exchanges, and it is pulling the American Anthropic and OpenAI labs to file confidential draft IPO prospectus. Each IPO listing retroactively fills in gaps because as surfaces between 2.2 and 3.6 years of back-risks at once. This AI supply chain map gets more complete every quarter.
Best Arguments Against This
Measuring public company’s disclosures only measures what they disclosed. This will systematically miss classified harm, embarrassing harm, and harm nobody ever put a number on. The absence of Chinese-attributed damage could be a fact about my instrument rather than a fact about the world. That is the strongest counterargument. I mostly agree. This analysis identified 71 hostile events. But few documented losses and I wish I had a good explanation for it.
What Would Change My Mind
I went looking for where the AI industry could break and came out with an understanding of who has actually been breaking it. The biggest measured wounds came from export-controls. China’s export controls have cost the AI industry tens of millions of dollars against billions of self-imposed western cost. Then the question becomes are the national security advantages worth the cost? That’s a different article.
What I found was that American AI is not under siege. It is under management.
A note on method and AI use
I orchestrated AI agents for the research behind this piece. The hypotheses were 100% me. The data was 10.5 GB across ten datasets of which 29% are Chinese language filings by size. A local LLM was used for translation and data extraction. I vibe coded 22,955 lines of Python and shell scripts to deduplicate, acquire, extract, verify and chart all of it. This analysis exists because agents did the reading and I did the thinking. The conclusions were 100% me. The text is an amalgamation of AI-generated/Mike-edited and Mike-generated/AI-edited. For reference, it takes me more time to write up the conclusions than to conduct the research.







