AI Model
Model weights, fine-tuning checkpoints, model cards, and the third-party models your organization consumes as a service all carry the same underlying question: can you trust what's actually running, and would you know if it changed?
Whether self-hosted or consumed through an API, models need provenance tracking, integrity monitoring, and — for anything you host yourself — protection against extraction and inversion that no traditional security control addresses.
Looking for help in this category?
Get matched with a vetted partner.
Tell us what you're trying to solve and we'll connect you with a vetted partner.
What AI Model covers
The subcategories, in practitioner terms.
Model inventory & AIBOM
A living registry of every model in use, self-hosted or consumed, with its provenance.
Model weight & integrity protection
Access controls and drift detection for self-hosted model artifacts.
Provider evaluation & version pinning
Structured evaluation of consumed-as-a-service models and controls against unannounced version changes.
Compliance mappingMaps to NIST IR 8596's model and algorithm concepts, the CSA AI Controls Matrix's Model Security and Governance/Risk/Compliance domains, ISO 42001 Annex A.6 and A.10, MITRE ATLAS techniques for model extraction and adversarial data crafting, and the OWASP LLM Top 10's supply-chain and data/model-poisoning risks.
Category structure adapted from the AI Defense Matrix by Lenny Zeltser and Sounil Yu, licensed CC BY-SA 4.0. For a broader view of the vendor landscape, see the AI Defense Matrix Catalog.
Not sure AI Model is your biggest gap? The assessment will tell you.
Take the free assessment →