Fine-tuning credentials are production credentials
The keys used to train or update a model can change what that model does for everybody.
They tend to be treated as development credentials, because training feels like development work, and they sit in notebooks and scripts accordingly. Whoever holds them can alter the behaviour of a production system in a way that is difficult to detect afterwards. They deserve the protection given to deployment credentials, because functionally that is what they are.
More on AI supply chain
- A model file is executable trust in another formIt looks like data until you open it
- Dataset provenance matters for security and governanceWhere did this batch come from?
- Model version changes can be security changesOne plate swapped inside
- Third-party AI APIs extend the data boundaryThe fence moves with the call
- Evaluation data can leak into trainingIt has already seen the exam
- Open models shift responsibility toward the operatorThe engine comes with the engine room
