Security teams evaluating open-source AI models often rely on unverified metadata tags to determine model lineage, leaving verification gaps. A recent report from Interconnects AI tracked 1,500 open models and found that 69% of derivatives stem from Alibaba’s Qwen family, with Chinese labs contributing 70%. Cisco’s newly launched AI Supply Chain Provenance Explorer addresses these gaps by fingerprinting nearly 900 open models using sophisticated similarity scores and weight-level analysis. This public tool allows users to verify model parentage, license restrictions, scan coverage, and provider details without needing a Cisco product or extensive local computation. The Explorer improves risk management by replacing self-reported tags with data-driven lineage, enabling security teams to assess vulnerabilities, malware scanning completeness, jurisdiction, and licensing obligations more accurately. It also supports compliance with the upcoming EU AI Act by providing transparent provenance data. Although the tool currently covers a subset of models on Hugging Face, it marks a significant advancement in securing open AI model supply chains and assisting organizations to adopt safer AI practices.
Back