Fine-tuning credentials are production credentials

The keys used to train or update a model can change what that model does for everybody.

They tend to be treated as development credentials, because training feels like development work, and they sit in notebooks and scripts accordingly. Whoever holds them can alter the behaviour of a production system in a way that is difficult to detect afterwards. They deserve the protection given to deployment credentials, because functionally that is what they are.

More on AI supply chain