Skip to content
All articles

Traceable agentic AI in the service of the supply chain

  • Supply chain
  • OSINT
  • Industry

On March 11, 2011, a major earthquake, quickly followed by a tsunami, struck northeastern Japan.

In the weeks that followed, automotive assembly lines slowed down or stopped, first in Japan, then in the United States and Europe. Toyota, whose production system then served as the model for the entire industry, counted more than 1,200 threatened part numbers and singled out 500 whose supply had to be secured as a priority. The company found at the time that a substantial share of its supplies came from plants whose existence the carmaker did not know of, because they were indirect suppliers, feeding its tier 1 suppliers from a distance of sometimes three or four contracts.

At the time, the most discussed case was that of Renesas Electronics, which supplied Toyota indirectly. The company’s microcontrollers entered the group’s vehicles through equipment suppliers such as Denso. Yet Renesas then produced about 40% of the world’s automotive microcontrollers according to the Congressional Research Service report on the event (May 2011), and its Naka plant, damaged by the earthquake, took several months to return to nominal capacity. As a result, it became clear that an entire industry rested on a site that almost no one had judged critical at the time.

Fifteen years later, nothing has really changed at the core: mapping your suppliers’ suppliers remains a difficult and costly exercise. The times, however, have changed. On one side, mastering your supply chain is becoming a survival criterion for a growing number of industries, caught between ever more complex regulations and a geopolitical instability that reshuffles logistics chains sometimes within days. On the other, progress in generative AI has brought down the barrier to entry of continuous investigation, and the diversity of open sources now makes accessible a wealth of data that used to be out of reach. That timing is the Cercle’s: putting agentic AI to work, in a structured and traceable way, to give you back, with full confidence, visibility into your supply chain.

The supply chain you see is the tip of the iceberg

Your direct suppliers, the ones you know and sign contracts with, form tier 1. Their own suppliers form tier 2, and so on down to raw materials. For a typical electronic or mechanical product, it is common for the chain to run five to eight tiers deep.

Except that the visibility you have into that chain follows the contracts, not the reality of the dependencies. Tier 1 you know: contracts, audits, quality reviews, daily exchanges. At tier 2, you depend on what your suppliers are willing to declare. Beyond that, there is usually nothing at all. In McKinsey’s survey on supply risk conducted in 2025, 95% of the executives surveyed report visibility into the risks of their tier 1 suppliers; only 42% still see beyond.

Diagram of the chain’s tiers: the reader’s company, a tier 1 known through contracts, a tier 2 partly known, a tier 3 made of unknown sites joined by assumed links.
Visibility follows the contracts: sharp at tier 1, declarative at tier 2, nonexistent beyond.

The opacity of this chain comes down to the following structural factors:

  1. Trade secrecy. The list of a supplier’s suppliers is an asset: disclosing it means making it possible to bypass them. Your direct supplier has good reasons not to give it to you, and in general no contract requires it beyond a few critical components.
  2. Cascading. A subcontractor facing a sudden influx of orders will generally turn to more subcontracting. That decision is sometimes taken without you, and all the more so as the supplier sits farther down the chain.
  3. Movement. A chain recomposes itself constantly: a new source is qualified, a line is shut down, a site is bought out. The map declared a year ago describes a chain that no longer exists. An annual audit can take the photo, but it does not “film.”

The apparent independence of chains is more complex than it seems

This permanent recomposition of the supply chain can have very unexpected consequences, sometimes painful for those unaware of it.

Seen from the contracts, your three tier 1 suppliers are three independent chains, so you logically conclude that the failure of one would be absorbed by the other two. That is the very principle of multi-sourcing. The problem is that this contractual view gives you only a partial picture of reality, which can be quite different seen from the ground.

What, in fact, prevents several suppliers from ending up relying on the same production site deeper in the chain? Truth be told, not much. And the common specialization of certain industrial players, a logical consequence of market maturity, even tends to bring out critical links that end up representing, on their own, a critical mass for a particular operation or supply.

Seen from the ground, chains therefore often converge two or three tiers down, on one and the same site: a foundry, a surface treatment plant, a resin producer, and so on.

Two views of the same network: on the left, three chains that appear independent; on the right, the same chains converge on a single site at tier 3.
Three suppliers, one chain: the diamond structure only shows at depth.

In fact, the reality of the chain often has a “diamond” structure: wide at tier 1, narrow at depth.

The experience of 2011 made it visible all at once at a carmaker sincerely convinced it had diversified its supply. And yet, one route in two ran through the same Japanese plant. Apparent diversification is the most common disguise of the single point of failure.

By the time you become aware of the disruption, it is already far too late

The main risk of this single point of failure is that you do not notice it immediately, even in a crisis. When a site at tier 3 or beyond stops because of a fire, a strike, a bankruptcy, or a climate disaster, you do not feel it the same day. Each link in the chain will first absorb the nascent shortage thanks to its work in progress and its buffer stock. Only once it runs dry will it abruptly stop delivering to the next echelon.

Commercial information then travels at the pace of the stockouts: your tier 1 supplier only warns you of the event’s impact when it realizes it can no longer deliver, that is, weeks or even months later.

Yet the event was often public from day one. The fire was covered in the local press, the bankruptcy recorded in the official registries, and the halt in activity can be read even on satellite images of the site.

The information existed, but collecting it remained out of reach: too many sources to process, too many languages to understand, too many links to untangle. This is precisely where agentic AI comes into its own: it follows every lead in parallel, monitors the press and the media in every language, and never sleeps.

Ten-week timeline: a tier 3 site stops in week zero, each tier absorbs on its stock then stops in turn, the client’s line stops in week eight, while the event was public from day one.
The disruption takes weeks to reach you, while the information was available from day one.

This lost window of action usually comes at a steep price. The McKinsey Global Institute estimated in August 2020, on a panel of 325 companies across 13 industries, that a supply disruption of a month or more occurs on average every 3.7 years, and that per decade those shocks erase, on average, the equivalent of 45% of one year’s EBITDA. The semiconductor shortage gave the scale: AlixPartners put it in September 2021 at 210 billion dollars of revenue and 7.7 million vehicles not produced for 2021 alone, for the automotive industry alone.

Arriving early changes the nature of the options available to you: the first weeks make it possible to secure volumes before the entire market rushes in, to qualify a fallback source, to decide which part numbers to protect. Those who arrive last will find themselves standing in line.

The disruption is not always an accident

Fukushima was an earthquake, unpredictable by nature. But climate disasters and conflicts are not the only possible causes of major disruptions to your supply chain.

The Nexperia affair, which made headlines in Europe in the fall of 2025, is a good example. There was no disaster at all: not one plant hit, not one machine stopped.

Nexperia, a Dutch component maker, produces entirely ordinary, low-value-added semiconductors, such as diodes and transistors worth a few cents. The automotive industry is their first outlet: in 2025, Nexperia held about 40% of the segment.

In 2019, Nexperia came under the control of China’s Wingtech group. On September 30, 2025, the Dutch government took control of the company, invoking a 1952 law that had never been used for technology, against a backdrop of American pressure and fears of technology transfers. On October 4, Beijing struck back: a ban on exporting the components Nexperia finishes in China. Yet about 70% of the chips Nexperia makes in Europe went precisely to China for final assembly, before heading back out to production lines worldwide. Within a few weeks, European carmakers were warning of production stoppages, and production rates were being cut as far away as Japan. De-escalation came only after the meeting of the American and Chinese presidents at the end of October: Beijing restored exemptions, The Hague suspended its order on November 19, and flows resumed in stages.

The episode teaches three things.

  1. A disruption can be decided. No site burned down: what moved was ownership, law, and export controls. Knowing where the plants are is no longer enough; you must know who owns each one and which jurisdictions it depends on.
  2. The bottleneck was not fabrication, but a step almost no buyer looks at: final assembly. You buy a module from your tier 1 supplier; the module contains a three-cent diode; the diode passes through a single site in China. The dependency was real, and invisible in the contracts.
  3. The signals had been there for years: the 2019 acquisition, the regulatory pressure building up around the shareholder. A change of ownership is a supply chain event in the same way a fire is, and it is monitored in the same way.

Mapping by hand works, and costs a decade

Toyota drew the lesson of 2011 by building RESCUE, a database covering about 650,000 supplier sites, and by asking its suppliers to hold two to six months of stock of critical chips. The result showed: during the 2021 shortage, Toyota held its volumes longer than its competitors.

So the method works. Its cost is the problem: a decade of effort, the bargaining weight of a buyer that size, and an update that never ends. The declarative route, questionnaires and supplier portals, for its part keeps hitting the same walls: partial response rates, data stale as soon as it is collected, and above all tier 2, which has no contract with you and therefore no obligation to answer you.

Rebuilding the chain from the bill of materials

We take the problem the other way around: do not ask for the chain, rebuild it. That is what the monitoring solution we are developing does.

The starting point is your bill of materials (BOM), the structured list of a product’s components. It says what must exist somewhere in the world: this microcontroller implies a foundry, this connector a mold maker, this alloy a surface treatment plant. From there, the solution cross-references what open sources already know: the local and trade press, company registries and customs data, certifications and regulatory publications, and satellite imagery, which reveals a site’s actual activity, its extensions, its shutdowns.

Artificial intelligence is what holds these scattered signals together: linking a site to a process, a process to a component, a component to your product. None of these sources is enough on its own; their cross-checking draws the chain. Every link in the graph carries its confidence level and its sources, and the graph updates at the pace of the sources, not at the pace of questionnaire campaigns.

Three-step diagram: the product’s bill of materials, the cross-referencing of open sources by a correlation engine, the rebuilt graph of the chain, where each link is confirmed or marked as a hypothesis.
From the bill of materials to the graph: every link carries its sources and its confidence level.

The same machinery that rebuilds the chain watches over it. An event is detected where it happens, at tier 3, in a regional newspaper or on an image, not where it ends up reaching you. Instead of learning of the disruption from your tier 1 supplier several weeks later, you have an alert within days, linked to the part numbers in your bill of materials that pass through the affected site.

What the solution does not claim to do: replace the supplier relationship, the audit, or the contract. It produces ranked, sourced hypotheses, which your teams confirm or dismiss. A verifiable hypothesis is worth more than a comfortable blind spot.

What regulation adds

Regulatory pressure pushes in the same direction. The French duty of vigilance law (2017), the German Supply Chain Due Diligence Act (LkSG, 2023), and the European corporate sustainability due diligence directive (CSDDD, adopted in 2024, with an implementation timetable still under discussion) all require buyers to know and monitor what happens beyond tier 1: working conditions, the environment, the origin of materials. You cannot monitor a chain you do not know.

Our mission: that the next failure of a tier 3 site should be, for you, a sourcing decision taken calmly weeks in advance, and not a discovery at the end of the line.