The AI ecosystem inherits every classic software supply chain problem and adds a few of its own.
The vectors
- Untrusted weights. Model files can be crafted to execute code when loaded by vulnerable loaders.
- Plugin and connector sprawl. Third-party integrations frequently request broader permissions than their function requires.
- Package dependencies. Standard typosquatting and dependency confusion apply unchanged.
- Base image drift. Containers built months ago carry whatever vulnerabilities existed then.
Controls worth applying
- Download weights only from sources you can name, and verify published hashes.
- Run inference in a sandbox with no access to production credentials.
- Review plugin permissions the way you would review an OAuth scope request.
- Pin dependency versions and rebuild images on a schedule.
The mindset shift
A model is executable artefact. Teams that apply normal software review processes to it are rarely surprised. Teams that treat it as data usually are.
Comments (0)
Log in to join the discussion
Log InNo comments yet