Back Issues/Search Home → Calendar → Archive → RSS → Subscribe → Current Issue → Popular →

All issues › Volume 342, Issue 5 › IT News › FOSS

Rolling the Cyber Dice With Open-Source and Open-Weight AI Models

CSO Online, Friday, October 2nd, 2026

Weighs the security risks of cheaper open-weight AI models, including hidden backdoors and data poisoning, and how to contain them.

Cost pressure is pushing organizations toward open-weight models whose training data and provenance cannot be inspected, creating risks such as embedded backdoors and data poisoning that traditional scanning cannot detect.

The author distinguishes true open-source models, which allow informed scrutiny, from downloadable open-weight artifacts, and notes that liability for failures lands on the CSO when there is no vendor contract.

Since weights may be unscannable, the recommended leverage is downstream - restricting what the model can do, requiring user approval for sensitive actions and allowing access only to vetted domains - and vendors should also be judged on how well they help map these emerging threats.

more →  ·  More from FOSS →