---
title: "Model signing"
description: "Signing a model's files at build: a manifest lists every file with its cryptographic digest and a detached signature covers the manifest, so any changed file fails verification."
canonical: https://aigovernanceengineer.com/glossary/model-signing
author: "Jorge García Aibar"
license: "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)"
doi: https://doi.org/10.5281/zenodo.22956197
version: "0.5.0"
updated: 2026-09-25
---

# Model signing

Signing a model's files at build: a manifest lists every file with its cryptographic digest and a detached signature covers the manifest, so any changed file fails verification. The OpenSSF Model Signing specification uses the Sigstore bundle format and supports keyless signing, private PKI, self-signed certificates or bare keys [1]. Serving verifies the signature before it loads a model.

- Developed in: [ch. 14, Reproducibility and linked versioning](https://aigovernanceengineer.com/bok/governing-development#reproducibility-and-linked-versioning); [ch. 05, Pattern: Model Artefact Integrity](https://aigovernanceengineer.com/patterns/model-artefact-integrity)
- Chapters: [ch. 05, Patterns](https://aigovernanceengineer.com/bok/patterns) · [ch. 14, Development](https://aigovernanceengineer.com/bok/governing-development) · [ch. 15, Deployment](https://aigovernanceengineer.com/bok/governing-deployment)
- Contrast with: [Build provenance (SLSA)](https://aigovernanceengineer.com/glossary/build-provenance-slsa)
- In the glossary chapter: https://aigovernanceengineer.com/bok/glossary#t-model-signing

## Sources

[1] "An Introduction to the OpenSSF Model Signing (OMS) Specification" (detached signature over a manifest of file hashes; Sigstore bundle format; PKI-agnostic: private PKI, self-signed certificates, bare keys, keyless Sigstore). OpenSSF. 2025-06-25. https://openssf.org/blog/2025/06/25/an-introduction-to-the-openssf-model-signing-oms-specification/ (verified: primary)
