supply chain

A New Destination Is a New Custody Act

A freight destination is not just an address field. Changing it alters the authorised route, the intended consignee and the point at which custody passes to another party. When that decision lives only in an email, a phone call or an overwritten TMS field, a fraudulent redirection can look like routine administration.

Replace silent edits with signed events

We believe every destination change should create a new custody act tied to the lot: previous destination, new destination, reason, requesting organisation and person, timestamp, approval policy and a cryptographic reference to the preceding event. The old instruction remains visible. Revocations, refusals and corrections become additional events rather than rewritten history.

Strong authentication must come before signature. For sensitive loads, that means step-up or multi-factor authentication, explicit confirmation of what is being signed and dual approval when value, product or route justifies it. A valid login is not enough; the signer must also be authorised to redirect that specific lot.

Anchor proof, protect commercial data

With Sensefinity's blockchain layer, the signed document can remain access-controlled off-chain while its hash, version and timestamp are anchored in a tamper-resistant history. Authorised partners can verify that the instruction presented is the one that was signed and identify what came before it without publishing sensitive commercial details.

Blockchain cannot prove that a bad instruction was true or prevent a compromised credential. Its value is narrower and more useful: changes, sequence and conflicts become much harder to hide.

Connect authorised intent to physical movement

The signed act defines what should happen. Cargo telemetry shows what is happening. Sensefinity's Cargo Safety capabilities can detect unplanned stops and unauthorised access and support asset-level tracking. Comparing those signals with the latest authorised destination creates an actionable exception when a load leaves its approved route before a valid change exists.

Read the full Prova article

The full Prova analysis explains the event model, authentication and authorisation controls, blockchain anchoring, a seven-step operating workflow and how this approach aligns with the move toward authenticated, auditable freight data.

Read “A destination change is a custody act — and it should be signed” on Prova.

A destination change should never erase the past. It should add a signed, attributable and verifiable decision to the lot's custody history.

EPCIS in 2026: The State of Supply Chain Event Data

Supply chains have no shortage of data. They have a shortage of data that different companies can interpret in the same way.

That is the problem EPCIS was built to solve. GS1 describes EPCIS as its flagship standard for sharing the what, when, where, why and how of products and assets across organisations. EPCIS 2.0 extends that event model to sensor readings, certifications, JSON/JSON-LD, REST interfaces and GS1 Digital Link identifiers.[1]

This report assesses where the standard stands in 2026, what is driving implementation, and where projects still break down. It is a desk-research snapshot, not a vendor adoption survey. Our evidence comes from current GS1 specifications and public regulatory material.

The 2026 snapshot

Signal What the evidence says Industry implication Standard maturity EPCIS 2.0 was ratified in June 2022; its implementation guideline followed in March 2023 and the GS1 EPCIS Sandbox launched in February 2024.[1] The technical foundation is established. The main risk has moved from specification maturity to implementation discipline. Condition data EPCIS 2.0 can carry timestamped sensor data, including readings used in cold chains and industrial IoT.[1] Location events and temperature evidence can travel in one interoperable event stream. Certification data The standard supports certification details associated with products, organisations, locations, harvests and shipments.[1] Compliance evidence can be linked to the event where it matters rather than stored in an isolated document repository. API accessibility JSON/JSON-LD and REST capture/query interfaces are part of EPCIS 2.0.[1] Integration no longer has to start with XML-heavy, batch-only architecture. Regulatory pull The FDA Food Traceability Rule requires covered actors to retain Key Data Elements linked to Critical Tracking Events and provide requested information to FDA within 24 hours.[2] Regulated traceability is becoming an event-data problem, even where the law does not mandate EPCIS by name. DPP convergence The EU Digital Product Passport is being introduced progressively and will carry lifecycle, origin, material and environmental information for selected product groups.[11] Product master data and supply chain events will increasingly need a common identity layer.

Our finding: EPCIS covers five evidence layers, but governance remains outside the standard

We reviewed EPCIS 2.0 against five practical evidence layers required by modern cargo and product programmes.

Evidence layer EPCIS 2.0 coverage What still has to be designed Identity Native support through GS1 identifiers and Digital Link URI syntax.[1] Identifier ownership, granularity and partner onboarding. Business events Native event model for status, movement, transformation, aggregation and chain of custody.[1] A shared event vocabulary and rules for late or corrected events. Physical condition Native sensor-data support.[1] Device calibration, sampling frequency, alert thresholds and proof that a sensor remained attached to the cargo. Claims and certifications Native certification fields.[1] Who may issue a claim, how it expires and how it is revoked. Exchange JSON/JSON-LD and REST interfaces.[1] Access control, commercial permissions, retention and cross-company service levels.

The conclusion is useful because it separates a standards question from an operating-model question. EPCIS can express all five layers. It cannot decide which partner is trusted, how often a sensor should report, who pays for data retention or which event wins when two systems disagree.

Regulation is pushing companies toward event-level traceability

The strongest implementation pressure is no longer a generic promise of visibility. It is the need to reconstruct specific product histories quickly.

The FDA's Food Traceability Rule applies additional recordkeeping to foods on the Food Traceability List. Covered organisations must associate Key Data Elements with Critical Tracking Events and be able to provide the information to FDA within 24 hours or another agreed period.[2] GS1's own food-safety guidance maps GTIN, GLN and EPCIS event data to this need for product, location and movement records.[18]

The compliance date was originally January 20, 2026. FDA subsequently proposed a 30-month extension to July 20, 2028, and Congress directed the agency not to enforce the rule before that date.[2] That extension is preparation time, not a reason to postpone architecture. Partner identifiers, event semantics and exception workflows usually take longer than the API connection.

Europe is creating a second source of pressure. Under the Ecodesign for Sustainable Products Regulation, Digital Product Passports will be introduced through product-specific rules. The Commission lists batteries first, followed by product groups such as textiles, iron and steel, construction products and others.[8][11] A passport tells stakeholders what a product is and what must be known about it. EPCIS can supply the time-ordered operational evidence of what happened to it.

The adoption gap is not capture. It is continuity.

Most pilots can generate a shipping event. Far fewer can maintain a trustworthy history through repacking, consolidation, subcontracted transport and handover to another platform.

Four gaps appear repeatedly:

  1. Identity breaks at aggregation. A pallet identifier is recorded, but the link between item, case, pallet and container is incomplete.

  2. Condition data lacks business context. A temperature reading exists, but the system cannot say which shipment leg, custody holder or product lot it belongs to.

  3. Partners use different event meanings. "Received" may mean arrival at the gate, unloading, quality acceptance or ERP posting.

  4. Corrections are not governed. Event histories need a controlled way to handle duplicates, delayed data and amended records without erasing the audit trail.

EPCIS has the structures needed to address these problems. Implementers still need to agree on the operating rules.

A practical 90-day EPCIS readiness test

A company does not need a multi-year transformation programme to learn whether its data is ready. A useful first test follows one real shipment and asks five questions:

  • Can every tracked object and logistics unit be identified consistently?

  • Can the business record packing, shipping, receiving and transformation events using shared vocabulary?

  • Can sensor readings be tied to the correct object, place and time?

  • Can one external partner query only the events it is authorised to see?

  • Can the team reconstruct the shipment history without manually joining spreadsheets?

If any answer is no, the pilot has identified a concrete interoperability gap. That is more valuable than a polished dashboard built on ambiguous data.

Where Sensefinity fits

Sensefinity already supports EPCIS supply chain events and can combine them with location, temperature and humidity data. Our NB-IoT trackers create observations from the physical journey; EPCIS gives those observations a shared business context.

The result is not simply another track-and-trace screen. It is an event history that can be exchanged with customers, suppliers and compliance systems without forcing every participant into the same application.

What to watch next

During the next implementation cycle, three developments deserve attention:

  • convergence between EPCIS event histories and Digital Product Passport records;

  • practical use of sensor and certification fields beyond proof-of-concept projects;

  • partner governance, especially access rights, event correction and long-term availability.

The standard is ready enough. The differentiator in 2026 is whether companies can keep identity, condition and custody evidence connected after cargo leaves their own system.

Methodology and limitations

This report was prepared on September 5, 2026 from public GS1, FDA and EU sources. The readiness matrix is Sensefinity's analysis of features documented in EPCIS 2.0; it is not an adoption-rate survey. We found no authoritative global count of production EPCIS 2.0 deployments and have not invented one.

Sources

[1] https://www.gs1.org/standards/epcis — EPCIS & CBV | GS1 [2] https://www.fda.gov/food/food-safety-modernization-act-fsma/fsma-final-rule-requirements-additional-traceability-records-certain-foods — FSMA Food Traceability Rule | FDA [8] https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R1781 — Regulation (EU) 2024/1781 (ESPR) [11] https://single-market-economy.ec.europa.eu/single-market/digital-product-passport_en — Digital Product Passport | European Commission [18] https://gs1.org/public-policy/leveraging-GS1-standards-to-meet-key-food-safety-challenges — Leveraging GS1 standards for food safety | GS1

"The Worst I’ve Ever Seen": Cargo Theft Turns Violent in Pursuit of AI Hardware

A cargo investigator with 25 years of experience called it "the worst I’ve ever seen." The words refer to two alleged attacks on high-value technology shipments in California, reported by WIRED on August 12, 2026. In both cases, criminals appear to have targeted the security escort first. One escort vehicle was rear-ended; another was forced into a spin. Once the escorts were immobilised, the trucks continued away from their planned destinations and millions of dollars in data-centre equipment disappeared.

WIRED could not independently confirm every detail because the investigations were still active and identifying information was withheld. Two other cargo-security sources did, however, corroborate elements of the incidents. The reported method matters because it exposes a weakness in conventional transport security: if visibility depends on the vehicle, the driver or an escort, attackers only need to compromise one of them.

AI hardware has changed the economics of cargo theft

Servers, accelerators and other data-centre components concentrate enormous value in a small space. A few pallets can be worth millions and the goods can move quickly through grey markets. That combination attracts organised groups with the resources to conduct surveillance, obtain inside information, impersonate legitimate carriers and coordinate an attack.

Physical escorts remain useful, but these cases show their limits. An escort protects what it can see. It cannot continuously verify the identity of the driver, confirm that each pallet remains inside the trailer or detect that the cargo has been separated from the authorised vehicle.

The security model therefore has to follow the cargo itself.

Track the load, not only the truck

Sensefinity’s Internet of Cargo platform attaches visibility to the shipment through connected trackers and sensors placed on containers, pallets or high-value equipment. The telemetry remains independent of the truck’s onboard system and of the driver’s phone.

If an escort is forced to stop but the shipment keeps moving, the platform can still report the cargo’s position. If the tractor, trailer and pallets separate, cargo-level devices make that separation visible. This closes the blind spot that criminals exploit when they neutralise the people or systems around a load.

Detect the attack while it is happening

Prevention depends on recognising abnormal behaviour early enough to intervene. Sensefinity combines NB-IoT trackers and smart sensors with rules and alerts that can identify events such as:

  • departure from an authorised route;

  • an unscheduled stop or entry into a high-risk area;

  • unexpected motion after a vehicle should be stationary;

  • shock or impact consistent with rough handling or an attack;

  • opening or tampering outside an approved location;

  • separation between tracked cargo and its assigned vehicle.

A security team does not have to wait for a missed delivery or an end-of-shift phone call. It can receive the alert as the deviation happens, check the shipment and escalate to the carrier or law enforcement according to an agreed response plan.

No tracking system can guarantee that a violent attack will not occur. What it can do is remove the anonymity and time advantage on which cargo theft depends. Faster detection makes a theft harder to complete and improves the chance of recovery before the goods are broken up or resold.

Verify who had custody

The WIRED report also raises the possibility of driver involvement. That risk cannot be solved by location data alone. High-value transport needs a verifiable chain of custody: who collected the load, which vehicle was assigned, when custody changed and whether the route and handover matched the plan.

Sensefinity can record shipment events in a blockchain-backed logistics trail. This creates an auditable history that is harder to alter after an incident. Combined with authorised pickup identities and cargo-level sensor data, it helps operators detect a fictitious collection, an unauthorised handover or a route that no longer matches the shipment’s instructions.

Build security around response time

For high-value AI hardware, a useful security programme should define more than a tracker installation. It should specify:

  1. which assets are tracked at trailer, pallet and item level;

  2. the approved route, stops and handover points;

  3. alert thresholds for route deviation, opening, shock and separation;

  4. who receives each alert and how quickly they must respond;

  5. how location and custody evidence is shared with investigators.

Sensefinity brings those signals into one cargo-monitoring view. Operators can see where the shipment is, whether it has followed the authorised journey and whether anything happened to it in transit. The goal is practical: identify the first sign of interference, act before the cargo disappears and preserve reliable evidence if an incident still occurs.

The attacks described by WIRED show that guarding the vehicle is no longer enough. When criminals plan around the escort, security must stay with the cargo.

Sources

Sustainable Supply Chain Technology

sustainable_logistics

Improving Food Security Using IoT

1.3 billion tons of food spoils and is wasted every single year, that's about one-third of the total amount of food that is produced. To look at it another way, 1.3 billion tons of food could feed between 2 and 3 billion people, each year.

Current figures suggest that of the 7 billion people on this planet, 925 million are starving, so even if we can't produce more food sustainably, saving just half of the wasted food could solve world hunger.

Read more here: Sustainable Supply-Chains.

Sustainable Technology for the Supply Chain

safe food supply

Improving Food Security Using IoT

1.3 billion tons of food spoils and is wasted every single year, that's about one-third of the total amount of food that is produced. To look at it another way, 1.3 billion tons of food could feed between 2 and 3 billion people, each year.

Current figures suggest that of the 7 billion people on this planet, 925 million are starving, so even if we can't produce more food, saving just half of the wasted food could solve world hunger.

Learn how Sensefinity is leveraging technology to feed the world in the Well, that’s interesting blog.

The hottest application areas for IoT in manufacturing include Industrial Asset Management, Inventory and Warehouse Management and Supply Chain Management

The hottest application areas for IoT in manufacturing include Industrial Asset Management, Inventory and Warehouse Management and Supply Chain Management. In high tech manufacturing, Smart Products, and Industrial Asset Management are the hottest application areas according to Forrester.

Sensefinity NB-IoT Trackers, Sensors and Gateways service this market.

https://www.forbes.com/sites/louiscolumbus/2017/12/10/2017-roundup-of-internet-of-things-forecasts/#55fcfa121480