Versatile AI Risk Assessment

AI threat catalogueSupply Chain and ProvenanceSupply Chain

Supply Chain – Models

Pre-trained AI models from external sources can be tampered with, carrying hidden malicious code or built-in backdoors. Anyone who adopts such a model imports the compromise straight into their own systems.

As of: July 2026 · Catalogue version 2026.07.17.3 · 4 mitigations · 15 verified sources

Description

Many organizations do not train AI models themselves but adopt pre-trained models from public platforms such as Hugging Face or from service providers. Attackers upload manipulated models there, swap out legitimate ones, or alter the model weights, the learned internal values of a model. Unsafe storage formats such as pickle open a particular attack path: merely loading such a model can execute hidden program code (a serialization attack). Built-in backdoors that only activate on specific inputs can even survive your own follow-up training. In normal operation the model appears unremarkable, so the manipulation is hard to detect without targeted checks.

Possible impact

A manipulated model can produce wrong or deliberately skewed results that the business then bases decisions on. Embedded malicious code additionally lets attackers take over systems and extract data. The organization risks operational disruption, breaches of documentation and cybersecurity duties under the EU AI Act, and a loss of trust if customers or business partners are affected by the compromise.

Example

Security researchers uploaded a well-known open-source language model in slightly altered form to a public model platform: it spread a specific piece of false information in response to certain questions while otherwise behaving completely normally. A company adopting this model without verification would hardly have noticed the manipulation.

Recommended mitigations (4)

Every mitigation states its control type, effect, implementation level and the reason for the classification.

Framework mappings

Verified locations in OWASP, NIST AI RMF, MITRE ATLAS, the EU AI Act and further frameworks. The mappings are taxonomic, not evidence of compliance.

OWASP LLM Top 10 LLM03:2025NIST AI RMF Section 2.12 · GOVERN 6.1 · MAP 4.1 · NISTAML.026 · NISTAML.051MITRE ATLAS AML.T0010EU AI Act Article 25(4) · Article 53(1)(a) · Article 55(1)(d)BSI R1 · R19BIML BIML-LLM model:4 · BIML78 alg:11 · BIML78 data:2

Verified references (15)

Every reference states the framework, the exact location and the publishing organisation.

More entries from the topic group Supply Chain and Provenance.

Assess this threat in your own system

The live demo contains all 52 threats of this catalogue, including the EU AI Act and GDPR assessment. The free single modules cover AI risk, the EU AI Act and GDPR. No sign-up; the assessment runs locally in your browser.

Cite this entry

For reports, policies or internal documents; the link leads directly to this entry.

“Supply Chain – Models”. Versatile AI Risk Assessment, AI threat catalogue, as of July 2026.
https://www.versatile-ai-risk-assessment.com/en/wissensbasis/threats/supply-chain-models/

← Back to the full catalogue