# Supply Chain Disruption Control — Problem Research

**Date:** 22 August 2026
**Purpose:** Understand the problem space deeply *before* designing an agent. What breaks, how badly, what companies already do about it, where the residual gap is, and which slice of that gap is actually agent-shaped.

> **Source-quality note:** roughly half the numbers below come from vendor reports, consultancies and trade press rather than peer-reviewed work. Vendor stats skew toward whatever the vendor sells. I've marked the softer ones as `[vendor]`. Treat directional claims as reliable, exact percentages as indicative.

---

## 1. Executive summary

Five findings that should drive whatever we build:

1. **The bottleneck is no longer detection — it is the 40 hours after detection.** Firms detect a disruption in ~8.7 hours on average but take ~40.9 hours to understand its financial and operational impact `[vendor]`. Sensing is close to commoditised (news feeds, weather, AIS, satellite, port data). *Interpretation and response* are not.

2. **Visibility collapses at Tier 2.** ~95% of leaders claim Tier 1 risk visibility; only ~42% have any visibility beyond it, and 43% of organisations have none at all `[vendor]`. Meanwhile >50% of incidents originate at Tier 2+, and 68% of high-tech production stoppages trace to Tier 2/Tier 3 failures `[vendor]`. **Risk lives exactly where the data doesn't.**

3. **Control towers largely failed at their actual job.** Only 22% of >$1B-revenue shippers think their control tower is highly effective at *driving action* `[vendor]`. The recurring failure mode: they were built as reporting projects, not decision-workflow projects. Alert volume rose; the decision process behind it stayed manual and slow. Alert fatigue is the dominant symptom.

4. **Everyone is shipping "agents", almost nobody is governing them.** Kinaxis (Maestro Agents, Oct 2025 + Agent Studio 2026), o9, Blue Yonder, SAP, Oracle all now ship supply chain agents. Gartner projects agents executing decisions autonomously in 50% of cross-functional SC solutions by 2030, up from 5% in 2025. But IDC found supply chain AI deployed by 88% of firms and *governed* by 12% — a ~7x rise in autonomous-at-scale operations in <24 months against a flat governance baseline. **Incumbents own the planning-suite agent layer. The unowned space is trust, evidence and governance around agent decisions — and the entire mid-market that owns no planning suite at all.**

5. **The mid-market is structurally unserved.** Mid-size manufacturers run direct-material sourcing and supplier risk on spreadsheets, email and SharePoint, with no dedicated risk function — a handful of people covering sourcing, onboarding, compliance and relationships across hundreds of suppliers. Spreadsheets remain the most-used risk tool in 2026 `[vendor]`. Enterprise SCRM platforms (Resilinc, Everstream, Interos, Z2Data) price and implement for the Fortune 500.

**Working thesis:** the highest-value agent is not another *sensing* agent. It is an agent that owns the **"signal → exposure → options → executed mitigation"** loop for a company that cannot afford a 12-person risk team — compressing the 40-hour impact-assessment window to minutes, and producing an auditable, evidence-backed recommendation rather than another alert.

---

## 2. Taxonomy: what "supply chain disruption" actually decomposes into

Distinct problems get lumped under one phrase. They have different data, different clocks, and different owners.

| # | Class | Clock (warning → impact) | Typical owner | Data available? |
|---|-------|--------------------------|---------------|-----------------|
| A | **Geopolitical / export control** (rare earths, Nexperia, sanctions) | Days → months | CPO / strategy | Public, but n-tier exposure unknown |
| B | **Tariff & trade policy** | Days → weeks | Trade compliance | Public, high churn |
| C | **Supplier failure** (financial distress, quality, capacity, fire) | Hours → weeks | Category buyer | Poor at Tier 2+ |
| D | **Cyber / IT** (JLR, ransomware on a supplier) | Zero warning | CISO + ops | Almost none pre-event |
| E | **Logistics & chokepoints** (Red Sea, Hormuz, Panama, port congestion, cargo theft) | Days → weeks | Logistics | Good (AIS, satellite, port) |
| F | **Capacity / allocation shocks** (DRAM 2026, HBM reallocation) | Weeks → quarters | Sourcing | Market signals, semi-public |
| G | **Demand-side volatility** | Weeks | Planning | Internal, good |
| H | **Climate & natural hazard** | Hours → weeks | Ops | Good, improving fast |
| I | **Labour** (strikes, shortages) | Days → months | HR / ops | Moderate |
| J | **Regulatory / ESG compliance** (CSDDD, UFLPA, forced labour) | Months | Compliance | Requires n-tier mapping |

An agent that tries to cover A–J is a dashboard. **Pick 2–3 adjacent classes.**

---

## 3. What is actually happening right now (2025 → Aug 2026)

Anchoring events, because these are what a buyer will have scar tissue from:

**Nexperia standoff (Oct 2025 → 2026).** Dutch government took control of the Chinese-owned chipmaker under the Goods Availability Act; China's MOFCOM restricted exports of Nexperia output from its China packaging site. On 10 Oct 2025 automakers and Tier 1s were told delivery could no longer be guaranteed; ACEA said stocks would last weeks. Nissan and Honda cut production, Bosch cut factory hours, Honda guided ~US$960m operating-profit hit for FY ending Mar 2026. The German VDA warned of elevated risk into Q1 2026.
→ **The lesson buyers took:** the part that stopped the line was a $0.20 discrete used in door locks, climate control and speedometers — not the expensive SoC anyone was tracking. *Criticality ≠ cost.*

**China rare earth / critical mineral export controls (Feb 2025 →).** Indium licensing Feb 2025; seven heavy REEs Apr 2025; five more plus processing technology and technical-expertise controls Oct 2025 (second wave suspended to Nov 2026). EU REE prices reported up to 6x higher (IEA). Dec 2025 Chinese exports of less-processed REEs 15.8% below the 2025 monthly average. Aerospace firms rationing yttrium for engine thermal coatings and flagging possible production pauses. S&P Global expects bottlenecks to persist through 2026.

**Jaguar Land Rover cyberattack (1 Sep 2025).** Five-week global production shutdown, plants on three continents, restart from 6 Oct. £196m in-quarter cost to JLR; Cyber Monitoring Centre modelled ~£1.9bn total UK economic loss across ~5,000 businesses. ~25% of suppliers had already begun layoffs with a further 20–25% expected. The UK export credit agency backstopped a £1.2bn loan largely to keep suppliers paid.
→ **Lesson:** a cyber incident at *one* node is a liquidity and continuity event for thousands of others. Almost no supplier had a model for "my customer goes dark for five weeks."

**Memory / DRAM shock (2025 → 2027+).** Samsung, SK Hynix and Micron (>95% of DRAM) reallocated capacity to HBM for AI. DRAM up ~80–90% QoQ from Q4'25 into Q1'26; some DDR5 SKUs 3.5–4x; DRAM projected >400% up from start-2024 to end-2026. OEMs receiving only 50–66% of ordered volumes. SK Hynix's CEO has suggested tightness beyond 2030.
→ **Lesson:** this is an *allocation* crisis, not a logistics one. No amount of tracking helps; the play is contracting, redesign and substitution.

**Maritime chokepoints (2024 →).** Red Sea still contested in 2026; most Asia–Europe tonnage still routing the Cape. Asia–Europe rates 25–40% above baseline, Asia–USEC 15–25%. A genuine Suez return would dump ~6% of global fleet capacity back into the market almost overnight — i.e. the *reopening* is itself a planning shock. Industry expectation: diversions persist to at least 2027. Separately, S&P Global's Q3 2026 outlook flags Strait of Hormuz closure effects on naphtha/petrochemicals, plastics precursors, aluminium and fertilisers.

**Tariffs.** 72% of trade professionals call US tariff volatility the most impactful regulatory change, up from 41% a year earlier. 82% of surveyed supply chain leaders had supply chains affected by new tariffs (39% higher supplier/material cost, 30% lower demand). Trade teams: 56% report increased workload, 49% higher stress. H2 2026 changes to how duty applies to full customs value break existing landed-cost formulas.

**Cyber, aggregate.** Supply chain attacks nearly doubled 2024→2025 (~$53.2bn global cost); 35.5% of 2024 breaches originated from third-party compromise; industrial ransomware +87% YoY in 2025.

**Pharma.** 44% of drugs in shortage at end-2025 had ≥1 key starting material made exclusively in a single country. 70–80% of APIs in US medicines originate abroad; India imports ~65–70% of KSM/bulk drug needs, up to ~90% dependence on China for some antibiotic APIs. >200 active US shortages persistently.

---

## 4. Severity ranking — which problem is most worth solving

Scored on: **(a)** frequency, **(b)** cost per event, **(c)** how badly current tooling handles it, **(d)** how tractable it is for an agent, **(e)** whether a buyer will pay.

### Rank 1 — Sub-tier (Tier 2/N) exposure blindness
*The single highest-leverage unsolved problem.*
- >50% of incidents originate at Tier 2+; 68% of high-tech stoppages trace to Tier 2/3 `[vendor]`.
- 43% of organisations have zero visibility past Tier 1; only 18% of manufacturers monitor compliance four or more tiers deep `[vendor]`.
- Root causes are *structural*, not lazy: ERPs model internal transactions and stop at the direct contract; sub-tier data is self-reported and often ~18 months stale; Tier 2/3 suppliers genuinely run on spreadsheets and email and have nothing to integrate; and Tier 1s treat their supplier list as commercially confidential.
- **Why it stays unsolved:** the last cause is *incentive*, not technology. Any solution must obtain sub-tier structure without asking a Tier 1 to surrender its sourcing IP.
- **Agent fit: high** — this is inference over messy, scattered, partially public evidence, exactly what an LLM agent is good at and what deterministic software is bad at.

### Rank 2 — The impact-assessment gap (detect → quantify → decide)
- ~8.7h to detect, ~40.9h to understand impact `[vendor]`; multi-day lag to informed response.
- Only 22% of large shippers call their control tower effective at driving action; 75% need 3–10 systems to make a supply chain decision; only 2 in 10 can see 75–100% of their chain in real time `[vendor]`.
- Alert fatigue is the named, repeated failure: visibility built ahead of response capacity produces problems faster than the organisation can absorb them.
- Procurement spends ~31% of its time on manual/paper process (Ivalua); managers expedite shortages instead of improving anything.
- **Agent fit: very high.** The work is: read the signal → traverse BOM/part/supplier/site graph → find affected SKUs, orders, customers, revenue → assemble options → draft the mitigation. It is bounded, repetitive, evidence-based, and today done by a human in 40 hours.

### Rank 3 — Response execution & alternate-source qualification
- Knowing the answer isn't the constraint; *executing* it is. In regulated/automotive contexts an alternate part needs AEC-Q + PPAP + OEM approval; any silicon/package/test change triggers requalification. Named bottlenecks: waiting on supplier response with no visibility into progress, late/inconsistent PPAP documents forcing rework.
- 78% of firms adopted dual sourcing for critical raw materials and 97% applied some mix of inventory, dual sourcing and regionalisation (McKinsey) — yet Nexperia still stopped lines. **Dual sourcing on paper ≠ a qualified, ordered, delivered alternate.**
- **Agent fit: high but slow-loop** — the agent can drive the paperwork, chase suppliers, pre-assemble qualification packages. The clock is weeks, not hours.

### Rank 4 — Tariff / trade-policy churn and landed-cost recalculation
- Highest-frequency, most quantifiable, most rule-shaped. 72% call it the top regulatory impact. Classification across growing catalogues, changing programs, multiple systems and suppliers is manual and breaking under update volume.
- **Agent fit: high, but crowded** — Thomson Reuters, Gaia Dynamics, Altana and others are already here, and it's partly deterministic rules work. Good wedge, weak moat.

### Rank 5 — Cyber / third-party continuity
- Highest cost per event (JLR ~£1.9bn economy-wide), fastest onset, near-zero warning. Attacks nearly doubled YoY.
- **Agent fit: moderate.** Prevention belongs to security vendors. The *unowned* piece is the **continuity response**: when a key node goes dark, what do I do for five weeks? Nobody sells that well.

### Rank 6 — Allocation / capacity shocks (DRAM-class)
- Enormous cost, but the levers are commercial and engineering (contracts, redesign, substitution), on a quarters-long clock. Poor fit for a fast agent loop; good fit for a design-for-supply advisory agent.

### Rank 7 — Logistics & chokepoint disruption
- Real and expensive, but **the most crowded and best-served**: project44, FourKites, Everstream, Xeneta, plus satellite/AIS feeds giving 10–14 days' warning on port congestion and up to 3 weeks on climate events `[vendor]`. Don't start here.

**Recommendation:** attack **Rank 2 as the product**, using **Rank 1 as the data moat**, with **Rank 3 as the expansion path**. Rank 4 is a viable faster-revenue wedge if we want one.

---

## 5. What companies do today — and why it isn't enough

| Measure | Adoption | Real limitation |
|---|---|---|
| Increased inventory buffers | Part of the 97% mix (McKinsey) | Direct margin hit; low-margin firms rationally refuse. Static buffers hedge the wrong SKUs. Toyota's semiconductor-crisis success came from *surgical* buffers on the highest-impact components — which requires exactly the criticality model most firms lack. |
| Dual / multi-sourcing | 78% for critical raw materials | Second source is often the same Tier 2, same fab, same region, same mine. Frequently unqualified. Nexperia showed both sources can share one chokepoint. |
| Regionalisation / reshoring | 43% plan to shift footprint to the US in 3 years (+25pp YoY) | Multi-year, capital-heavy, and moves rather than removes exposure. |
| SCRM platforms (Resilinc, Everstream, Interos, Z2Data) | Large enterprise only | Surface risk at *entity* level, not product/BOM level — flagged risk you can't verify or act on. Resilinc reviewers cite slow evolution and limited customisation; Interos shows churn/leadership concerns. Assessment-heavy models don't scale, leaving most of the chain unmonitored. |
| Control towers | Widespread in large enterprise | Only 22% effective at driving action `[vendor]`. Reporting project, not decision project. Alert fatigue. |
| Supplier questionnaires / audits | Near-universal | Point-in-time, self-reported, stale by ~18 months at sub-tier `[vendor]`. |
| Planning-suite AI agents (Kinaxis, o9, Blue Yonder, SAP, Oracle) | Rapid 2025–26 rollout | Require the suite. Deployed by 88%, governed by 12% (IDC). Most enterprises can't demonstrate EU AI Act high-risk compliance for them. |
| Spreadsheets + email | **Still the most-used risk tool in 2026** `[vendor]` | The actual incumbent we're competing with in the mid-market. |

**The structural pattern:** every layer above optimises *sensing* or *static structural hedging*. Almost nothing optimises **the decision and the execution in the 48 hours after a signal**, and nothing does it for a company without a risk team.

---

## 6. Where the gaps are — ten specific ones

1. **Entity-level risk, not part-level risk.** Platforms say "Supplier X is risky." Buyers need "Supplier X's Site 3 makes part 4471-B, which is in 3 SKUs, 1,200 open orders, ₹42Cr of Q4 revenue, and has no qualified alternate." Nobody bridges risk → BOM → revenue automatically.
2. **The 40-hour impact-assessment hole.** Detection is solved; quantification is manual and lives in 3–10 disconnected systems.
3. **Sub-tier structure is unknowable through direct integration.** Must be *inferred* — customs/bill-of-lading data, corporate registries, filings, certifications, job posts, satellite, trade press, supplier disclosures — and continuously re-verified.
4. **Alerts without playbooks.** Monitoring that doesn't produce a remediation outcome is reporting, not risk management. Everyone ships alerts; nobody ships the executed action.
5. **Dual-source theatre.** No system verifies that the "second source" is genuinely independent (different fab/site/mine/region) *and* currently qualified *and* has capacity.
6. **Cross-functional coordination is the real latency.** A disruption response spans procurement, planning, logistics, engineering, trade compliance, finance, sales. Each system is separate; the glue is email and Teams. This is where the days go.
7. **No institutional memory.** The same disruption class recurs and is re-solved from scratch. Nobody has "here's what we did last time, what it cost, whether it worked."
8. **Mid-market is unserved.** No risk function, no planning suite, hundreds of suppliers, spreadsheets. Enterprise SCRM is priced and implemented out of their reach.
9. **Governance vacuum around agents.** 88% deploy, 12% govern. Any agent that *acts* must ship with evidence trails, confidence bounds, approval thresholds and an audit log — or it will not clear procurement or the EU AI Act.
10. **Supplier-side blindness.** JLR's 5,000 affected suppliers had no way to model or finance a five-week customer outage. Downstream-facing continuity is almost entirely unaddressed.

---

## 7. Candidate agent designs

### Option A — **Exposure & Impact Agent** *(strongest fit; solves Gaps 1, 2, 6)*
On any signal (news, supplier notice, port event, export-control change), the agent:
1. Resolves the signal to concrete entities — legal entity, site, part numbers.
2. Traverses the client's own graph (ERP/PLM/BOM + open POs + customer orders) to compute exposure: which parts, SKUs, orders, customers, revenue, and days-of-cover remaining.
3. Ranks by revenue-at-risk × days-to-stockout.
4. Generates options with quantified trade-offs: expedite, substitute, reallocate inventory across sites, activate alternate, redesign.
5. Emits an evidence pack — every claim sourced and every number traceable.
6. Drafts the outbound actions (supplier emails, expedite requests, internal briefing) for human approval.
**Success metric: 40.9 hours → under 30 minutes.** That single number is the pitch.

### Option B — **Sub-tier Discovery Agent** *(the moat; Gap 3)*
Continuously infers the n-tier graph from public and semi-public evidence — customs/BoL records, corporate registries, certifications, filings, job listings, trade press, satellite — with a confidence score and citation per edge, re-verified on a schedule. Gets around the Tier 1 confidentiality problem by never asking. Slow to build, hard to copy, and it is what makes Option A accurate rather than plausible.

### Option C — **Mitigation Execution Agent** *(Gaps 4, 5; expansion)*
Owns the workflow after the decision: chases suppliers for commitments, tracks PPAP/qualification packages, escalates non-responses, assembles the qualification pack, keeps every stakeholder synced. Directly attacks the named PPAP bottleneck — "waiting on a supplier's response with no visibility into progress."

### Option D — **Tariff & Landed-Cost Agent** *(Gap 4; fastest revenue, weakest moat)*
Watches trade-policy changes, re-classifies affected SKUs, recomputes landed cost by origin scenario, flags contracts and orders needing repricing.

### Option E — **Continuity Agent for suppliers** *(Gap 10; contrarian, underserved)*
Sells *downstream*: if your major customer goes dark (JLR-style) or an allocation shock hits, model the cash and capacity impact and drive the response. Almost no competition. Harder buyer, thinner wallets.

**My recommendation: build A, backed by B, with C as the natural second act.** A is where the pain is measurable and the buyer already knows they're bleeding; B is why we'd still be defensible in two years.

---

## 8. Hard questions we have to answer before writing code

1. **Who is the buyer?** Mid-market manufacturer (unserved, faster sales, thin data) vs. enterprise (rich data, 9–18 month sales cycle, incumbent-defended)?
2. **Which vertical first?** Automotive/electronics (deepest pain, hardest qualification), pharma (regulated, single-source KSM concentration), industrial, or CPG/retail?
3. **How do we get the client's internal graph?** ERP integration (SAP/Oracle/NetSuite/Tally) is the real engineering cost — and without BOM + open orders, Option A degrades into another alert tool.
4. **Advisor or actor?** Human-in-the-loop recommendation vs. autonomous execution within thresholds. This determines the entire governance surface, and 88%-deployed/12%-governed says the market isn't ready for full autonomy.
5. **Where does external data come from?** Customs/BoL data (Panjiva, ImportGenius, Volza), registries, news, weather, AIS — several are paid, and the cost model matters at mid-market pricing.
6. **What's the demo?** Probably: replay Nexperia or the DRAM shock against a real BOM and show the exposure report the customer took two weeks to produce.
7. **Geography?** India-first (accessible manufacturers, Tally/SAP mix, export-exposed) vs. US/EU-first (bigger budgets, harder access)?

---

## 9. Sources

Risk landscape & rankings: [Xeneta – Biggest Supply Chain Risks of 2026](https://www.xeneta.com/blog/the-biggest-supply-chain-risks-of-2026-and-how-to-navigate-them) · [Thomson Reuters – 2026 supply chain challenge](https://tax.thomsonreuters.com/blog/2026s-supply-chain-challenge-confronting-complexity-and-disruption-in-global-trade-tri/) · [Z2Data – 22 Critical Supply Chain Risks 2026](https://www.z2data.com/insights/22-critical-supply-chain-risks-to-watch-for-in-2026/) · [NC State ERM – Third-Party & Supply Chain Risk](https://erm.ncsu.edu/resource-center/top-risk-focus-third-party-and-supply-chain-risk/) · [Risk Ledger – Top 10 Supply Chain Risks 2026](https://riskledger.com/resources/top-10-supply-chain-risks-2026) · [Supply Chain Dive – 2026 risks & trends](https://www.supplychaindive.com/news/supply-chain-risks-trends-outlook-2026/810852/) · [S&P Global – Q3 2026 Corporate Strategy Outlook](https://www.spglobal.com/market-intelligence/en/news-insights/research/2026/07/corporate-strategy-supply-chain-outlook-q3-2026) · [SupplyChainBrain – Why 2026 is testing global supply chains](https://www.supplychainbrain.com/articles/44330-why-2026-is-testing-global-supply-chains-like-never-before)

Sub-tier visibility: [Onspring – Tier 2/3 blind spot](https://onspring.com/resources/blog/tier-2-tier-3-supply-chain-risk-visibility/) · [JAGGAER – Why visibility breaks down beyond Tier 1](https://www.jaggaer.com/blog/why-supply-chain-visibility-breaks-down-beyond-tier-1-in-2026) · [D&B – Multi-tier visibility gap](https://www.dnb.co.uk/blog/supplier-risk/multi-tier-supply-chain-visibility-gap.html) · [Dualboot – Visibility starts at Tier 2](https://www.dualbootpartners.com/insights/supply-chain-visibility/) · [Sedex – Visibility beyond Tier 1](https://www.sedex.com/blog/supply-chain-visibility-beyond-tier-1/)

Why current tooling fails: [Altana – Why your SCRM plan will fail](https://altana.ai/resources/why-scrm-fails) · [SCMR – Why your SCRM plan will fail](https://www.scmr.com/article/why-your-supply-chain-risk-management-plan-will-fail) · [Fortress – Why cyber risk monitoring fails](https://www.fortressinfosec.com/blog/why-supply-chain-cyber-risk-monitoring-fails-and-how-ai-changes-the-equation) · [FourKites – Why control towers didn't deliver](https://www.fourkites.com/blogs/supply-chain-control-towers-whats-changing/) · [Locus – Why control towers don't actually control](https://locus.sh/blogs/why-supply-chain-control-towers-dont-actually-control-cto-architectural-authority-2026/) · [Siemens – Visibility alone is no longer enough](https://blogs.sw.siemens.com/digital-logistics/2025/12/10/the-supply-chain-control-tower-revolution-why-visibility-alone-is-no-longer-enough/) · [SupplyChainBrain – Avoiding control tower failures](https://www.supplychainbrain.com/articles/28114-how-to-avoid-supply-chain-control-tower-failures) · [Gartner Peer Insights – Everstream vs Resilinc](https://www.gartner.com/reviews/market/supplier-risk-management-solutions/compare/everstream-analytics-vs-resilinc)

Events: [Automotive Manufacturing Solutions – Nexperia standoff](https://www.automotivemanufacturingsolutions.com/analysis/nexperia-standoff-imperils-global-auto-production-within-weeks/1590908) · [Resilinc – What Nexperia means](https://resilinc.ai/blog/what-nexperia-crisis-means-for-global-semiconductor-supply-chain/) · [CNBC – Nexperia urgent plea](https://www.cnbc.com/2025/11/28/nexperia-crisis-dutch-chipmaker-issues-urgent-plea-to-its-china-unit.html) · [CSIS – Rare earth restrictions one year later](https://www.csis.org/analysis/rare-earth-export-restrictions-one-year-later) · [S&P Global – Rare earth bottlenecks persist in 2026](https://www.spglobal.com/energy/en/news-research/latest-news/metals/012726-rare-earth-supply-bottlenecks-set-to-persist-in-2026) · [European Parliament – China's rare-earth export restrictions](https://epthinktank.eu/2025/11/24/chinas-rare-earth-export-restrictions/) · [Cyber Monitoring Centre – JLR incident statement](https://cybermonitoringcentre.com/2025/10/22/cyber-monitoring-centre-statement-on-the-jaguar-land-rovercyber-incident-october-2025/) · [BleepingComputer – JLR cost](https://www.bleepingcomputer.com/news/security/jaguar-land-rover-cyberattack-cost-the-company-over-220-million/) · [Industrial Defender – What JLR taught manufacturers](https://www.industrialdefender.com/blog/what-the-jaguar-land-rover-cyberattack-taught-every-manufacturer) · [J.P. Morgan – AI-driven memory shortage](https://www.jpmorgan.com/insights/global-research/artificial-intelligence/dram-memory-shortage-from-ai) · [Avnet – 2026 memory & storage market](https://www.avnet.com/integrated/resources/article/2026-memory-shortage-ai-supercycle/) · [Zencargo – Red Sea reopening 2026](https://www.zencargo.com/resources/red-sea-reopening-2026/) · [GoFreight – Maritime disruption 2026](https://gofreight.com/blog/maritime-disruption)

Measures & effectiveness: [McKinsey – Tech and regionalization bolster supply chains](https://www.mckinsey.com/capabilities/operations/our-insights/tech-and-regionalization-bolster-supply-chains-but-complacency-looms) · [DC Velocity – McKinsey survey](https://www.dcvelocity.com/articles/59073-risk-and-resilience-are-the-top-topics-in-mckinsey-supply-chain-survey) · [SAGE – Balancing resilience and efficiency (lit review)](https://journals.sagepub.com/doi/10.1177/10591478241302735) · [IMD – Resilient and efficient?](https://www.imd.org/ibyimd/supply-chain/can-your-supply-chain-be-both-resilient-and-efficient/) · [SupplyChainBrain – The ROI of resilience](https://www.supplychainbrain.com/blogs/1-think-tank/post/38432-the-roi-of-resilience-how-to-be-lean-global-and-resilient-at-the-same-time)

Cost, response time & manual work: [Supply Chain 24/7 – Disruptions cost $16M/yr (Coupa)](https://www.supplychain247.com/article/procurement-disruptions-cost-16-million-supply-chain-coupa-report) · [Supply Chain 24/7 – Disruptions quietly hurting revenue](https://www.supplychain247.com/article/supply-chain-disruption-delays-revenue-loss-study) · [Conexiom – 20+ disruption cost statistics](https://conexiom.com/blog/the-cost-of-supply-chain-disruptions-20-statistics/) · [CIPS/Supply Management – Buyers spend a third of time on manual processes](https://www.cips.org/supply-management/news/2019/september/buyers-spend-third-of-time-on-manual-processes/) · [SCMR – Earliest disruption signal from orbit](https://www.scmr.com/article/space-observation-early-supply-chain-disruption)

Qualification & trade compliance: [Kiuey – 5 critical PPAP bottlenecks](https://kiuey.com/critical-bottlenecks-in-ppap/) · [IntellaQuest – PPAP challenges and OEM rejections](https://intellaquest.com/overcoming-common-ppap-challenges-that-lead-to-oem-rejections/) · [J2 – Automotive semiconductors, AEC-Q and lead times](https://j2sourcing.com/brief/automotive-semiconductors-aec-q-lead-times-ev-demand.html) · [Thomson Reuters – Tariff classification complexity](https://tax.thomsonreuters.com/blog/beyond-the-executive-order-maze-how-modern-trade-teams-navigate-tariff-classification-complexity-to-drive-strategic-value/) · [JAGGAER – US tariffs H2 2026](https://www.jaggaer.com/blog/us-tariffs-direct-procurement-2026)

Agentic AI landscape: [Gartner – Top supply chain technology trends 2026](https://www.gartner.com/en/newsroom/press-releases/2026-06-30-gartner-identifies-top-supply-chain-technology-trends-for-2026) · [Tellius – Agentic AI in supply chain 2026](https://www.tellius.com/resources/blog/agentic-ai-in-supply-chain-use-cases-platforms-and-whats-shipping-2026) · [Kinaxis – Maestro Agent Studio](https://investors.kinaxis.com/news-releases/news-release-details/2026/Kinaxis-Introduces-Maestro-Agent-Studio-Unlocking-Next-Level-Decision-Making-Through-Composable-AI-Agents/default.aspx) · [Blue Yonder – AI agents](https://blueyonder.com/why-blue-yonder/ai-and-machine-learning/ai-agents) · [TechTimes/IDC – SC AI deployed by 88%, governed by 12%](https://www.techtimes.com/articles/324392/20260813/supply-chain-ai-deployed-88-governed-12-idc-finds-trust-real-barrier.htm) · [Logistics Viewpoints – The autonomous supply chain is emerging](https://logisticsviewpoints.com/2026/06/09/the-autonomous-supply-chain-is-emerging-insights-from-blueyonder-icon-2026/)

Mid-market: [Supplios – Why mid-sized manufacturers still use spreadsheets](https://www.supplios.com/blog/why-manufacturers-use-spreadsheets-for-sourcing) · [Trust Your Supplier – Supplier risk for mid-market](https://trustyoursupplier.com/supplier-risk-management-mid-market) · [Z2Data – Top 7 SCRM tools 2026](https://www.z2data.com/insights/top-7-supply-chain-risk-management-software-tools-for-2026/)

Pharma & cyber: [Pharmacy Times – Drug shortages declining but vulnerabilities persist](https://www.pharmacytimes.com/view/drug-shortages-are-declining-but-persistent-supply-chain-vulnerabilities-continue-to-threaten-access) · [Brookings – USMCA and pharmaceutical supply chains](https://www.brookings.edu/articles/leveraging-the-usmca-to-strengthen-pharmaceutical-manufacturing-and-supply-chains-in-north-america/) · [SecurityScorecard – 2026 Supply Chain Cybersecurity Trends](https://securityscorecard.com/wp-content/uploads/2026/03/2026-Supply-Chain-Cybersecurity-Trends-Report.pdf)
