Model version changes can be security changes
When a provider updates a model underneath you, the behaviour of your application changes without anybody deploying anything.
Prompts that were reliable become less so. Guardrails tuned against one version behave differently against the next. Things that were refused may now be answered, and the reverse. Treating model versions as a dependency, pinned where possible and tested when changed, is the difference between a controlled update and finding out from a user.
More on AI supply chain
- A model file is executable trust in another formIt looks like data until you open it
- Dataset provenance matters for security and governanceWhere did this batch come from?
- Third-party AI APIs extend the data boundaryThe fence moves with the call
- Evaluation data can leak into trainingIt has already seen the exam
- Fine-tuning credentials are production credentialsThe bench feeds the floor
- Open models shift responsibility toward the operatorThe engine comes with the engine room
