TwinEthosRequest access

Control

Third-party model artifacts loaded without integrity verification or with a loader that can execute code

Models, adapters, tokenizers, and other AI artifacts obtained from outside the organization are pinned to an immutable revision, verified by hash or signature and scanned before use, and loaded through formats and loaders that cannot execute code.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Family: An AI agent's authority, reach, inputs, and components are not bounded and accountable · control id cond.model-artifact-loaded-without-verification

Reach

1items this one guard addresses
0jurisdictions where binding law on it is in force
0more where it is enacted, not yet applying
1standards and frameworks on the same control

The guard to add

Pin model downloads to a commit, verify their hash or signature, scan them, and load only safe formats (safetensors, weights_only) without trust_remote_code.

Where the code downloads or loads a model (from_pretrained, hf_hub_download, snapshot_download, torch.load, joblib.load, keras.models.load_model, onnxruntime sessions), the call names an immutable revision (a 40-character commit hash), prefers safetensors (use_safetensors=True, safetensors.torch.load_file), and never enables code execution on load: no trust_remote_code=True for unreviewed repositories, torch.load(..., weights_only=True), keras load_model with safe_mode left on, and no pickle, dill, cloudpickle or joblib load of files that came from outside. Before first use, a helper compares the artifact's SHA-256 with a value committed in the repository (or verifies an OpenSSF model-signing / Sigstore signature), and CI or the ingest job runs a model scanner such as modelscan or picklescan on any pickle-based artifact. Artifacts that fail are rejected, not loaded with a warning.

Where it goes: 1 application source code, 5 dependencies, 8 model configuration, 11 CI/CD pipeline.

What reviewers look for: revision= set to a commit hash on every from_pretrained, hf_hub_download and snapshot_download; use_safetensors=True or safetensors loading; no trust_remote_code=True, weights_only=False, allow_pickle=True, or safe_mode=False; a hash or signature check between download and load; a modelscan or picklescan step for pickle-based artifacts.

Example (Hugging Face transformers), before:

model = AutoModelForCausalLM.from_pretrained('acme/support-7b', trust_remote_code=True)

After:

model = AutoModelForCausalLM.from_pretrained(
    'acme/support-7b',
    revision='3f1c2a9e8b7d6c5f4e3a2b1c0d9e8f7a6b5c4d3e',   # pinned, reviewed commit
    use_safetensors=True)                              # no pickle, no remote code

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

Standard / soft law (1)

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.