CampeloLabs
← Blog

AI for Supply Chain: The Founder Opportunity

Cicero Campelo

Cicero Campelo, CISSP
July 28, 2026 · 14 min read

Part of our guide to AI for startups.

A single founder tracing a live multi-tier chip supply chain map on a workbench while spreadsheets and paper purchase orders fall away behind them
Table of contents

A single advanced AI chip may be the most globally distributed object a company ever buys: its inputs cross borders dozens of times, the build runs for months, and the person who needs to know where it is right now is working from a spreadsheet and a phone. Y Combinator laid the problem out in a short call for founders to build supply chain 2.0 for chips: "A single advanced AI chip goes through about 1400 process steps of manufacturing, crosses a dozen countries, and takes 5 months to build." Then the sentence that should interest anyone hunting for a market: "This supply chain is managed with spreadsheets, SAP, and phone calls."

AI for supply chain is software that reads the unstructured half of the job (allocation letters, supplier emails, purchase orders, customs paperwork, quality reports) and turns it into a live model of who supplies what to whom, so a team sees what is about to break before a planner does. That gap, between the complexity of the object and the crudeness of the tools that track it, is where the whole opportunity sits. Chips are the sharpest version of the problem, and what is true here holds in milder form for autos, pharma, retail, and industrial manufacturing. This piece covers what the term actually points at, where visibility breaks, what an AI-native layer has to do to be worth buying, and the test for whether your version is a company or a feature the incumbent ships next quarter.

What AI for supply chain actually means

Supply chain software is not a new category. Manufacturers have run planning, procurement, and logistics systems for decades, and most large ones sit on some version of SAP. What is new is what software can finally do with the unstructured half of the job.

Most of what a supply chain runs on is language and documents. Allocation letters, purchase orders, supplier emails, customs paperwork, bills of materials, quality reports, engineering change notices, and a great many phone calls that never get written down anywhere. Legacy systems store the structured residue of all that: a part number, a quantity, a date. They do not read the rest, so the rest lives in a planner's head and in a spreadsheet parked next to their inbox.

AI for supply chain is the layer that reads the mess directly, keeps a live model of who supplies what to whom, and surfaces what is about to break before a person notices. Y Combinator names the three jobs it has to do in chips: real-time allocation tracking, multi-tier risk monitoring, and export compliance. That list is more useful than it looks, because none of the three is a reporting feature. Each is a question the current system of record structurally cannot answer.

It is the same shift we track across the AI for startups pillar and the same shape as AI ERP: the model stops being a feature bolted onto a system of record and becomes the thing that does the work.

Visibility stops at tier one

Here is the specific failure, and it is worth stating precisely because it is where the whole opportunity sits. Companies can see the suppliers they buy from, because those suppliers invoice them. They cannot see their suppliers' suppliers. Describing the 2021 shortage, Y Combinator put it this way: "Companies could see their direct suppliers, but had zero visibility into the second and third tiers."

This is not a chip-specific complaint. McKinsey's Supply Chain Risk Pulse 2025 found that 95 percent of respondents now have visibility into at least tier-one supplier risks, but that visibility extends into tier two or beyond for only 42 percent of them, and that creating deep multi-tier visibility has proved difficult. Roughly half the market can see one layer and no further, four years after the disruption that made everyone promise to fix it.

The cost of that blind spot is not theoretical. "In 2021, a $300 chip held up a $50,000 car, and $200 billion in vehicles did not get built," as the Y Combinator video puts it. The figure lines up with the contemporaneous forecast from AlixPartners, which in September 2021 estimated the shortage would cost the global auto industry $210 billion in lost revenue and 7.7 million units of lost production that year. A cheap part nobody was tracking stopped an expensive product nobody could build.

The scale of the thing is part of why. The Center for Strategic and International Studies notes an Accenture estimate that the inputs to a typical chip cross more than 70 international borders before the final product reaches a consumer, and separately that production runs more than 500 discrete stages over four to six months. No planner holds that in their head, and no purchase order system was built to describe it.

But the reason visibility stops at tier one is structural, and it is why this stayed unsolved through a decade of supply chain software. Your supplier's supplier is not your counterparty. They have no contract with you, no incentive to answer your questionnaire, and often a commercial reason to keep their sourcing quiet. So mapping tiers two and three is not a data-entry problem you can solve by adding a table to an existing system. It is an inference problem over messy outside evidence: customs and shipping records, certifications, regulatory filings, corporate registries, job postings, site visits, and the unread contents of your own inbox.

That is exactly the kind of work language models became good at, which is why the problem is newly winnable rather than newly important. It also means the asset you build is a proprietary graph rather than a feature list, which is the kind of thing that compounds. We go deeper on that in the data that makes an AI product defensible.

The bottleneck moved and the tooling did not follow

The 2021 story was about cheap automotive microcontrollers. The constraint today sits somewhere else entirely, and the tooling has not caught up.

Advanced packaging. The step that stitches logic dies and memory into a single AI accelerator has become the choke point. "TSMC advanced packaging is the single biggest bottleneck in AI compute right now, and Nvidia has locked up over 60% of it," Y Combinator says. Treat the exact share as an analyst estimate rather than a disclosed number, because allocations are not published, but the direction is well corroborated: DigiTimes reported Nvidia booking more than half of TSMC's CoWoS capacity for 2026 to 2027, and CNBC reported Nvidia snapping up packaging capacity as TSMC expands in the United States.

Memory. High bandwidth memory is in the same state. Y Combinator says it "is booked through 2026." SK hynix told investors as far back as October 2025 that its 2026 output was already sold out, and the company has since said it expects demand to outpace supply for around three years, according to The Korea Herald. When supply is allocated years ahead, the commercial question stops being price and becomes who holds an allocation, how firm it is, and what happens when it slips. Almost no software answers that.

Export controls. "Export controls change quarterly," Y Combinator says, and the underlying record supports the spirit of it. The Government Accountability Office documented that Commerce issued its advanced-semiconductor rule in 2022, revised it twice in 2023, updated technical specifications in 2024, and had to take specific steps to address industry compliance challenges. Entity list additions land several times a year. A compliance answer that was correct last quarter can be wrong this quarter, and the exposure runs down through packaging houses, distributors, and foreign affiliates you may not know you touch.

New fabs with no supply chain yet. At the same time, as the video notes, "the CHIPS Act is standing up new American fabs in Arizona, Texas, Ohio, and New York," each one needing a supply chain assembled nearly from scratch. TSMC's Arizona site is the furthest along: its first fab has been in high-volume production since late 2024, construction on the second fab structure was completed in 2025, and the company's finance chief told CNBC in July 2026 that it is accelerating the buildout to meet AI demand. Every one of those sites is a fresh network of local suppliers, qualifications, and logistics with no institutional memory behind it.

Four constraints, all moving, none of them well served. Y Combinator's summary of the tooling is blunt: almost none of what you would expect to exist actually does.

What AI for supply chain is actually used for

If you are building here, the three jobs are concrete. Each has a version that demos well and a version that survives contact with a procurement team.

  • Real-time allocation tracking. The demo version is a dashboard of purchase orders and promised dates. The real version tracks allocation as the negotiated, unstable thing it is: who committed what capacity, through which channel, how firm the commitment is, what it is contingent on, and what happened the last three times that supplier slipped. Most of that lives in email threads and call notes, not in the order system, which is precisely why a model has to read it.
  • Multi-tier risk monitoring. The demo version is a supplier list with risk scores. The real version maintains an inferred graph two and three tiers deep, ties each inferred link to the evidence behind it, and monitors that graph against the world: a fire at a substrate plant, a typhoon near a packaging site, an entity list addition, a customer's sole-source dependency they never noticed. Then it answers the only question that matters operationally, which parts of my build are exposed and what do I do this week.
  • Export compliance. The demo version screens your direct counterparties against a list. The real version tracks rule changes as they land, re-evaluates prior decisions when the rules move, follows exposure down through sub-tier parties and affiliates, and leaves an audit trail a regulator or an acquirer can follow. Compliance is a legal position, not a dashboard.

The common thread is that all three require reading and reasoning over evidence the system of record never captured. That is the technical wedge, and it is why the answer is a new product rather than a new report. If you want to see who is already circling this territory, the back-office and document-extraction companies in our YC AI for operations hub are attacking the same class of problem in adjacent functions.

The founder test: startup or SAP feature

The most useful line in the Y Combinator video is the one about defensibility: "You need to understand wafer allocation and packaging constraints at a deep level to build this, which is exactly why it's a startup opportunity and not a feature just inside SAP."

That generalizes past chips. When you are looking at a category an incumbent appears to own, run four questions.

  1. Does the buyer's pain sit where the incumbent has no data? A system of record knows what it processed. SAP knows your direct suppliers because you transacted with them, and knows nothing about tiers two and three because you never did. The pain is on the far side of the incumbent's data boundary, and no amount of feature work moves that boundary.
  2. Does building it require domain knowledge a product manager cannot acquire in a roadmap cycle? Wafer allocation, substrate qualification, and packaging constraints are years of context, not a spec. If your edge is knowledge rather than code, an incumbent cannot close it by scheduling a sprint.
  3. Does the product compound with use? An inferred supplier graph gets better with every customer, every confirmed link, and every disruption it calls correctly. A feature does not compound. If yours does not either, you are building a feature.
  4. Would winning force the incumbent to change its business model? Selling a system of record and selling a system of inference are different businesses with different failure modes, different pricing, and different liability. Incumbents ship features readily and change business models rarely.

The corollary is the same discipline that carries every vertical AI company: start absurdly narrow. Not "AI for supply chain" but one buyer with one unbearable version of the problem, which in this market might be a fabless company managing packaging allocation across two vendors, or a new fab standing up local suppliers from nothing. That is the practice of writing a narrow ideal customer profile before you chase the broad market, and it is exactly how vertical AI companies in the physical economy got their first wedge.

The trust layer, which is not optional here

I write this as a CISSP, and this category carries a heavier security and compliance load than most founders price in.

Start with what you are accumulating. A multi-tier supplier graph is a map of your customer's dependencies and single points of failure. Aggregated across customers, it is one of the more sensitive datasets in the industry: exactly what a competitor would pay for and what an adversary would target. Treat it that way from the first customer, with hard tenant isolation, a clear answer on whether one customer's data ever improves another's model, and a written retention policy. Do not discover the answer during a security review.

Then the compliance surface. Export control decisions carry real legal consequence, so a model output cannot be the decision. It can be the research, the monitoring, and the draft. What you owe the customer is traceability: which rule, which source, which date, which human approved it, and what changed when the rule was revised. Build the audit trail before you build the automation.

Finally, be honest about inference. A graph built from outside evidence contains wrong edges. A confidently asserted supplier relationship that does not exist can send a procurement team chasing a risk that is not there, and a missing edge lets a real one through. Ship confidence and evidence alongside every inferred link, make it cheap for a customer to confirm or reject one, and treat those corrections as the most valuable data you collect. A model that flags a likely link and shows its reasoning earns more trust than one that asserts a certainty and is wrong twice a quarter.

What to do this week

  • If you are evaluating this space as a founder, pick one buyer and one question they cannot answer today, then go ask five of them how they answer it now. The spreadsheet and the phone call they describe is your product spec.
  • Write down where the incumbent's data actually stops for your category. If your product lives inside that boundary, you are building a feature and should choose a different wedge.
  • If you run hardware procurement, list your top ten parts and try to name the tier-two supplier behind each. The ones you cannot name are your live exposure, not a research project for later.
  • Whatever you build, ship evidence and confidence with every inferred relationship from version one. Retrofitting trust into a system people already caught being wrong is much harder than building it in.
  • Put the data questions in writing before your first enterprise customer asks: tenant isolation, cross-customer model training, retention, and the export compliance audit trail.

Picking apart a market like this, deciding what AI can genuinely do, what it must not decide alone, and how to build the trust layer around it, is the same job as running a company on AI without losing control of it. That operating picture is what we teach in the AI Operating System for Startups.

Sources

  • Supply Chain 2.0 for Semiconductors (Y Combinator, April 2026), the call for founders this article distills, on the 1400 process steps, the spreadsheets-and-phone-calls status quo, the tier two and three blind spot, packaging and memory constraints, and why the opportunity is a startup rather than a feature inside SAP.
  • AlixPartners on the September 2021 forecast of $210 billion in lost auto revenue and 7.7 million units of lost production, and McKinsey's Supply Chain Risk Pulse 2025 on the finding that tier-one risk visibility reaches 95 percent of respondents while only 42 percent see into tier two or beyond.
  • On the current constraints: DigiTimes and CNBC on Nvidia's share of TSMC advanced packaging capacity, CNBC and The Korea Herald on SK hynix selling out its 2026 memory output, the Government Accountability Office on the pace of Commerce's advanced-semiconductor export rules and industry compliance challenges, and CNBC on TSMC accelerating its Arizona buildout.
  • Background on the structure of the chip supply chain: the Center for Strategic and International Studies, citing an Accenture estimate that a typical chip's inputs cross more than 70 international borders, and separately that production runs more than 500 discrete stages over four to six months. Fab status detail from TSMC Arizona.

Frequently asked questions

What is AI for supply chain?

AI for supply chain is software that reads the unstructured half of supply chain work directly (allocation letters, supplier emails, purchase orders, customs paperwork, bills of materials, and quality reports) and turns it into a live model of who supplies what to whom. Traditional planning and procurement systems store the structured residue of that work: a part number, a quantity, a date. An AI-native layer reads the documents and messages themselves, keeps the supplier map current, and flags what is about to break before a planner notices. In semiconductors the three jobs it has to do are real-time allocation tracking, multi-tier supplier risk monitoring, and export compliance.

Why is the semiconductor supply chain so hard to see into?

The semiconductor supply chain is hard to see into because it is long, global, and built from counterparties you have no contract with. The Center for Strategic and International Studies notes an Accenture estimate that the inputs to a typical chip cross more than 70 international borders before the final product reaches a consumer, and separately that production runs more than 500 discrete stages over four to six months. You can see the suppliers you buy from, since they invoice you. You cannot see their suppliers, because those firms owe you nothing and often treat their own sourcing as confidential. That is why a disruption two or three tiers down shows up as a surprise stockout rather than a forecast.

Can AI actually fix multi-tier supplier visibility?

AI can make multi-tier supplier visibility tractable in a way no earlier approach managed. Mapping tiers two and three is an inference problem over messy public and semi-public evidence: customs and shipping records, certifications, regulatory filings, job postings, supplier questionnaires, and the contents of your own inbox. That is exactly the kind of work language models became good at, and it is why the problem is newly winnable rather than newly important. The honest limit is that inference is not proof. A useful product shows its evidence for every inferred link and its confidence, so a human can confirm the relationships that matter before anyone reroutes an order.

Is supply chain software a real startup opportunity or a feature inside SAP?

Supply chain software is a real startup opportunity, not an SAP feature, whenever the buyer's pain sits outside the incumbent's data. A system of record knows about transactions it processed, so it knows your direct suppliers well and knows nothing about their suppliers. The pain lives in tiers two and three, in allocation that is negotiated rather than transacted, and in export rules that change faster than a roadmap cycle. Closing that gap means building an inference layer over outside evidence and understanding wafer allocation and packaging constraints deeply, which is a different product and a different business than selling a system of record. That is the argument for a startup, and it is the same argument in any category where the incumbent's data stops before the customer's problem does.

Build your AI Operating System

A practical course to grow with AI, build internal tools, and operate safely. v1.0 launches August 31, join the waitlist.