Boosted by baldur@toot.cafe ("Baldur Bjarnason"):
lrhodes@merveilles.town ("⁂ L. Rhodes") wrote:
"If a software dependency contains malicious code, we have mature practices for discovering it, tracking its provenance, and reducing its impact. AI models are different. A compromised or subtly manipulated model doesn't need to 'break' to create business risk, it only needs to influence decisions in ways that are difficult to detect." https://semgrep.dev/blog/2026/ai-supply-chain-problem/
And to demonstrate, one of the researchers prompted their way into a backdoor in an open weight model: https://www.theregister.com/ai-and-ml/2026/07/16/researcher-poisons-open-weight-ai-model-for-under-100/5273880