{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/control.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-assure-011.json",
  "source": "https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-011",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "control": {
    "id": "AIGE-CTL-ASSURE-011",
    "profile": "assurance-and-evidence",
    "url": "https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-011",
    "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-assure-011.json",
    "title": "Safe Model Formats and Digest-Pinned Third-Party Models",
    "version": "0.1",
    "status": "draft",
    "reviewerStatus": "open",
    "depth": "derived",
    "objective": "Model weights are stored in a format that cannot execute code on load (safetensors); every file in a code-executing format is scanned for code-executing imports before it reaches a registry and quarantined if it fails; third-party models are pulled by content digest, not by tag, re-hosted internally and recorded with their upstream source and digest in the registry entry.",
    "failureModes": [
      "A pickle file runs code when it is loaded: the Python documentation warns that the pickle module is not secure.",
      "A file in a code-executing format reaches a registry unscanned, or after a failed scan.",
      "A third-party model is pulled by name or tag, and the tag has since moved."
    ],
    "scope": "Every serialised model file admitted to an internal registry, and every third-party model or base model pulled from outside. Signature and provenance checks at load are AIGE-CTL-ASSURE-010.",
    "enforcementPoints": [
      "deploy"
    ],
    "verification": [],
    "evidence": [
      {
        "artefact": "Scan result for code-executing imports per serialised file, with the quarantine decision",
        "schemaId": "evidence-record",
        "schema": "https://aigovernanceengineer.com/schemas/evidence-record.v1.json",
        "layer": 2
      },
      {
        "artefact": "Upstream source and content digest of each third-party model, recorded in its registry entry",
        "schemaId": null,
        "schema": null,
        "layer": 2
      }
    ],
    "failureResponse": {
      "effect": "deny",
      "text": "A serialised file that fails the scan for code-executing imports is quarantined and does not reach the registry."
    },
    "layer": 2,
    "secondaryLayers": [],
    "patterns": [
      {
        "slug": "model-artefact-integrity",
        "title": "Model Artefact Integrity",
        "url": "https://aigovernanceengineer.com/patterns/model-artefact-integrity"
      }
    ],
    "seeds": [],
    "derivedFrom": [
      {
        "kind": "pattern",
        "ref": "model-artefact-integrity",
        "url": "https://aigovernanceengineer.com/patterns/model-artefact-integrity"
      },
      {
        "kind": "chapter",
        "ref": "governing-development",
        "url": "https://aigovernanceengineer.com/bok/governing-development"
      }
    ],
    "mappings": {
      "obligations": [
        {
          "id": "AIGE-OBL-EUAIA-ART15",
          "name": "EU AI Act Art. 15 accuracy, robustness and cybersecurity",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15"
        },
        {
          "id": "AIGE-OBL-ISO42001-A10",
          "name": "A.10 Third-party and customer relationships",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a10"
        },
        {
          "id": "AIGE-OBL-OWASP-LLM",
          "name": "Top 10 for LLM Applications 2026",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-llm"
        }
      ],
      "iso42001": [
        {
          "id": "A.10.3",
          "title": "Suppliers"
        }
      ],
      "nistAiRmf": [],
      "owasp": [
        {
          "id": "llm04-2026",
          "externalId": "LLM04:2026",
          "name": "Supply Chain",
          "url": "https://aigovernanceengineer.com/resources/threats#threat-llm04-2026"
        },
        {
          "id": "asi04",
          "externalId": "ASI04",
          "name": "Agentic Supply Chain Vulnerabilities",
          "url": "https://aigovernanceengineer.com/resources/threats#threat-asi04"
        }
      ],
      "atlas": [
        {
          "id": "aml-t0010",
          "externalId": "AML.T0010",
          "name": "AI Supply Chain Compromise",
          "url": "https://aigovernanceengineer.com/resources/threats#threat-aml-t0010"
        }
      ],
      "aiuc1": [],
      "csaAicm": [],
      "other": [
        {
          "framework": "MITRE ATLAS mitigation",
          "ref": "AML.M0016",
          "note": "Vulnerability Scanning"
        }
      ]
    },
    "references": [
      {
        "n": 20,
        "title": "Pattern: Model Artefact Integrity",
        "text": "Pattern: Model Artefact Integrity (AI Governance Engineering Body of Knowledge v0.5.0, chapter 05 pattern catalogue). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/patterns/model-artefact-integrity",
        "verified": "primary"
      },
      {
        "n": 7,
        "title": "Governing AI development",
        "text": "Governing AI development (AI Governance Engineering Body of Knowledge v0.5.0, chapter 14, section \"Reproducibility and linked versioning\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-development#reproducibility-and-linked-versioning",
        "verified": "primary"
      },
      {
        "n": 26,
        "title": "pickle: Python object serialization",
        "text": "pickle: Python object serialization (\"The pickle module is not secure. Only unpickle data you trust.\"). Python Software Foundation. 2026.",
        "url": "https://docs.python.org/3/library/pickle.html",
        "verified": "primary"
      },
      {
        "n": 27,
        "title": "Pickle Scanning",
        "text": "Pickle Scanning (arbitrary code execution when loading pickle files; the Hub's pickle-import scan \"is not 100% foolproof\"). Hugging Face Hub documentation. n.d. (accessed 2026-09-24).",
        "url": "https://huggingface.co/docs/hub/security-pickle",
        "verified": "primary"
      },
      {
        "n": 28,
        "title": "Safetensors",
        "text": "Safetensors (\"a new simple format for storing tensors safely (as opposed to pickle)\"). Hugging Face documentation. n.d. (accessed 2026-09-24).",
        "url": "https://huggingface.co/docs/safetensors/index",
        "verified": "primary"
      },
      {
        "n": 29,
        "title": "torch.load",
        "text": "torch.load (default weights_only=True; \"Never load data from an untrusted source\"). PyTorch documentation (2.14). n.d. (accessed 2026-09-24).",
        "url": "https://docs.pytorch.org/docs/stable/generated/torch.load.html",
        "verified": "primary"
      },
      {
        "n": 24,
        "title": "OWASP GenAI LLM Top 10 2026",
        "text": "OWASP GenAI LLM Top 10 2026 (LLM01:2026 Prompt Injection to LLM10:2026 Improper Output Handling; resource page dated 3 Aug 2026). OWASP GenAI Security Project. 2026-08-03.",
        "url": "https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/",
        "verified": "primary"
      },
      {
        "n": 8,
        "title": "OWASP Top 10 for Agentic Applications for 2026",
        "text": "OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents). OWASP GenAI Security Project. 2025-12-09.",
        "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
        "verified": "primary"
      },
      {
        "n": 25,
        "title": "MITRE ATLAS data, release v2026.09",
        "text": "MITRE ATLAS data, release v2026.09 (16 tactics, 120 techniques, 88 sub-techniques, 40 mitigations; technique names and technique-to-mitigation links read from dist/v6/ATLAS-2026.09.yaml). MITRE. 2026-09-15.",
        "url": "https://github.com/mitre-atlas/atlas-data/releases/tag/v2026.09",
        "verified": "primary"
      },
      {
        "n": 5,
        "title": "ISO/IEC 42001:2023, AI management systems",
        "text": "ISO/IEC 42001:2023, AI management systems (Annex A control ids and clause numbers cited by number and short title only; the text of the standard was not opened). ISO/IEC. 2023-12.",
        "url": "https://www.iso.org/standard/81230.html",
        "verified": "secondary"
      },
      {
        "n": 3,
        "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744",
        "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744 (the articles each control maps to, as chapters 14 and 18 restate them). Publications Office of the EU (EUR-Lex). 2026-07-27.",
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng",
        "verified": "primary"
      }
    ],
    "implementationNotes": [
      "Where a framework still loads pickle, keep its restrictions on: torch.load defaults to weights_only=True in its current documentation and warns \"Never load data from an untrusted source\".",
      "Do not rely on the scan alone: Hugging Face says of its own pickle-import scanner that it \"is not 100% foolproof\". Convert legacy checkpoints to safetensors, and verify the publisher's signature on a third-party model where one exists."
    ],
    "openQuestions": [
      "Verification procedure to be specified: the derivation adds no check its source material does not state; requires technical review.",
      "How should a legacy checkpoint that cannot be converted to safetensors be handled: blocked, or admitted after a scan with a named acceptor of the risk?"
    ],
    "observation": null,
    "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
    "examples": []
  }
}
