Rolling the Cyber Dice With Open-Source and Open-Weight AI Models
CSO Online, Friday, October 2nd, 2026
Weighs the security risks of cheaper open-weight AI models, including hidden backdoors and data poisoning, and how to contain them.
Cost pressure is pushing organizations toward open-weight models whose training data and provenance cannot be inspected, creating risks such as embedded backdoors and data poisoning that traditional scanning cannot detect.
The author distinguishes true open-source models, which allow informed scrutiny, from downloadable open-weight artifacts, and notes that liability for failures lands on the CSO when there is no vendor contract.
Since weights may be unscannable, the recommended leverage is downstream - restricting what the model can do, requiring user approval for sensitive actions and allowing access only to vetted domains - and vendors should also be judged on how well they help map these emerging threats.