“Carefully vet the sources of data and suppliers, including their terms & conditions and privacy policies… ensure no changes in their security posture or T&Cs.”
The fake “OpenAI” repo (Slide 14) and PoisonGPT (Slide 15) both won by impersonating a trusted source. The T&Cs scenario (Slide 18) is a supplier quietly changing the deal. None survive actual vetting of who the supplier is and what their terms allow.
→ Maintain an approved-supplier list; pin to specific verified publishers, not names
→ Confirm the real identity behind a model/dataset, not just the display name
→ Re-review terms and privacy policies on a schedule — treat a T&Cs change as a security event
Pick any model in your stack and ask: who published it, how do we know, and what do their current terms permit? If you can't answer all three, it isn't vetted.
Ask your team how they decided to trust the AI vendor or open-source model you're currently using — and whether that decision was documented. Trusting something because it's popular is not a security evaluation.