Blast Radius Index
78 / 100
6 of 9 assets compromised
Estimated Statutory Liability
$14.2M
GDPR / EU AI Act Article 79
Disclosure Deadline
72 Hours
SEC Item 1.05 & GDPR Art 33
Weight Tampering Likelihood
HIGH
Backdoor / trojan risk

Attack Propagation & Blast Radius Topology

Breach Origin
Compromised Node
Guarded / Safe
Consumer Pipeline

Propagation Vector Evidence 4 Compromised Steps

Regulatory & Legal Exposure AUDIT BENCHMARK

Jurisdiction / Rule Legal Doctrine Status

AI Model Supply Chain Architecture & Legal Responsibility

1. Upstream Model Hub Security Risks

Model registries like Hugging Face, GitHub, and OCI registries host serialized machine learning weights. Leaked organization tokens allow unauthorized actors to push poisoned checkpoint weights, trojanized fine-tunes, or exploit pickling deserialization to execute arbitrary code on downstream inferencing workers.

2. Emerging AI Supply Chain Litigation

Recent landmark lawsuits against frontier AI providers highlight expanding enterprise liability: failure to quarantine third-party models, unvetted downstream RAG pipeline ingestion, trade secret misappropriation, and statutory penalties under the EU AI Act for unmonitored high-risk foundational model distribution.

3. Zero-Trust Remediation Playbook

To eliminate model supply chain blast radius, teams must migrate immediately from arbitrary binary pickles to safetensors, enforce immutable cryptographic commit pinning, isolate GPU runtime workers in egress-restricted clusters, and implement short-lived STS tokens.

Enjoy this tool? Build your own with Super