Model version changes can be security changes

When a provider updates a model underneath you, the behaviour of your application changes without anybody deploying anything.

Prompts that were reliable become less so. Guardrails tuned against one version behave differently against the next. Things that were refused may now be answered, and the reverse. Treating model versions as a dependency, pinned where possible and tested when changed, is the difference between a controlled update and finding out from a user.

More on AI supply chain