"If a software dependency contains malicious code, we have mature practices for discovering it, tracking its provenance, and reducing its impact. AI models are different. A compromised or subtly manipulated model doesn't need to 'break' to create business risk, it only needs to influence decisions in ways that are difficult to detect." https://semgrep.dev/blog/2026/ai-supply-chain-problem/
And to demonstrate, one of the researchers prompted their way into a backdoor in an open weight model: https://www.theregister.com/ai-and-ml/2026/07/16/researcher-poisons-open-weight-ai-model-for-under-100/5273880
This is kind of an incredible website:
Why your stuff stopped lasting, who profited, and what's still built right.
AI Companies Are Buying Tons of Old Books Because They're Free of AI Slop
https://www.404media.co/ai-companies-are-buying-tons-of-old-books-because-theyre-free-of-ai-slop/?utm_source=flipboard&utm_medium=activitypub
Posted into 404 Media @404-media-404media
#ShlaerMellor, #FunctionPointAnalysis, #punk, #environmentalist, #unionAdvocate, #anarchosocialist
"with a big old lie and a flag and a pie and a mom and a bible most folks are just liable to buy any line, any place, any time" - Frank Zappa