A model file is executable trust in another form
Downloading a model is closer to installing software than to opening a document.
Some model formats can carry code that runs when the file is loaded, and even where they cannot, you are trusting the behaviour of something you did not build and cannot inspect. It should go through the same questions as any other dependency: where did it come from, can you verify it is unmodified, and would you notice if it changed.
More on AI supply chain
- Dataset provenance matters for security and governanceWhere did this batch come from?
- Model version changes can be security changesOne plate swapped inside
- Third-party AI APIs extend the data boundaryThe fence moves with the call
- Evaluation data can leak into trainingIt has already seen the exam
- Fine-tuning credentials are production credentialsThe bench feeds the floor
- Open models shift responsibility toward the operatorThe engine comes with the engine room
