Model registries are release infrastructure
The place models are stored and promoted is a deployment system, and it decides what runs in production.
That makes it as privileged as an artefact repository: whoever can publish or re-tag there can change what your application does. It is frequently treated as a data science tool with correspondingly relaxed access, which is the same mistake organisations made with container registries.
More on AI supply chain
- A model file is executable trust in another formIt looks like data until you open it
- Dataset provenance matters for security and governanceWhere did this batch come from?
- Model version changes can be security changesOne plate swapped inside
- Third-party AI APIs extend the data boundaryThe fence moves with the call
- Evaluation data can leak into trainingIt has already seen the exam
- Fine-tuning credentials are production credentialsThe bench feeds the floor
