Third-party model and dataset provenance
A model, dataset, or plugin is adopted from an external source without verifying provenance, licensing, or update history.
- medium
- supply-chain
- vendor-risk
- provenance
How it happens
A model, dataset, or plugin is adopted from an external source without verifying its training data, licensing, or update history.
Why it matters
An unverified model carries the same risk profile as unverified code — but is harder to inspect and easier to update silently underneath you.
Mitigating controls
The controls that address this risk, ranked by effectiveness.
Third-party model and vendor due diligence
Pre-procurement and ongoing due-diligence policy for the selection and contractual oversight of third-party AI models and datasets.
AI incident response and rollback
Defined containment, remediation, and rollback procedure for a detected AI system failure or harmful output.
Framework and clause references
| Framework | Clause | Title |
|---|---|---|
| EU AI Act | Chapter V | General-purpose AI model obligations |