Safetensors

A file format for storing a model's tensors safely, as opposed to Python pickle 1, whose loading can run arbitrary code and which the Python documentation calls not secure 2. Storing weights as safetensors, and scanning any remaining pickle files for code-executing imports before they reach a registry, closes a common supply-chain route into serving.

Developed in
ch. 14, Reproducibility and linked versioning
ch. 05, Pattern: Model Artefact Integrity
Chapters
ch. 05, Patterns · ch. 14, Development
Source
2 numbered references, listed below

Where it is used

The term is not used under this name in running prose; the sections listed under "Developed in" treat it.

Patterns that use this term

One pattern page uses the term.

Sources

  1. [1] Safetensors ("a new simple format for storing tensors safely (as opposed to pickle)"). Hugging Face documentation. n.d. (accessed 2026-09-25). https://huggingface.co/docs/safetensors/index (verified: primary)
  2. [2] pickle: Python object serialization ("The pickle module is not secure. Only unpickle data you trust."). Python Software Foundation. 2026. https://docs.python.org/3/library/pickle.html (verified: primary)

Definitions of legal terms paraphrase the cited text, which governs. Dated statements are as of .

Cite this term

García Aibar, J. (2026). Safetensors. In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0), Glossary. https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/glossary/safetensors. CC BY 4.0

BibTeX

@misc{aige2026safetensors,
  author  = {Jorge García Aibar},
  title   = {{Safetensors}},
  note    = {Glossary, AI Governance Engineering: The Thesis \& Body of Knowledge, version 0.5.0},
  year    = {2026},
  doi     = {10.5281/zenodo.22956197},
  url     = {https://aigovernanceengineer.com/glossary/safetensors}
}