The execution-vs-behavioral compromise distinction is probably the most important takeaway here. A scanner can tell you a model file looks safe, but it cannot tell you that the model learned a malicious behavior. That changes supply-chain security from “scan before deploy” into a combination of provenance, behavioral evaluation, and containment.
I’d also treat the ingestion boundary as a first-class security boundary, especially once agents can autonomously fetch packages, datasets, or models. In production AI work at IT Path Solutions, that means the artifact should be quarantined, content-pinned, isolated from credentials, and promoted internally before any workload can consume it.
The key architectural principle is that you shouldn't need to perfectly detect every poisoned artifact if a compromised artifact still can't reach sensitive credentials or perform high-impact actions. Provenance reduces uncertainty; least privilege limits the blast radius.