Standard / soft law
Acquired AI models and components should be verified and scanned before use and loaded safely (NIST SP 800-218A PW.4.4, PW.6.1)
NIST SP 800-218A asks that any model or model component an organization takes from elsewhere (weights, datasets, reward models, adapters, configuration) be checked for integrity, origin and security, and scanned and tested for vulnerabilities and malicious content, before it is used (PW.4.4), and it points to serialization formats that leave less room for malicious content (PW.6.1). Detect third-party model artifacts loaded without a pinned revision, without a hash or signature check, or through loaders that can execute code (pickle, joblib, torch.load with weights_only=False, trust_remote_code=True).
nist-sp800-218a.pw-4-4-verify-acquired-models · NIST SP 800-218A, PW.4.4 (R1, R2) + PW.6.1 (C1): verify acquired AI models before use; secure model serialization · official source · jurisdictions: *