InfoRisk2025-05-28
RISK: Open Machine-Learning Models Create an Uncontrolled AI Supply Chain
Open machine-learning models can introduce malicious code, poisoned data, vulnerable frameworks or unclear provenance into enterprise AI systems.
Organizations should verify model sources, maintain dependency inventories and test downloaded models before integrating them into planning, sourcing or execution applications.
More details are available in the published research.
The Dataleo angle
Model provenance should be governed like supplier provenance: known source, controlled version, validation evidence and accountable owner.
