AI Origin Labels Can Mislead: Why Your Model's Roots Matter

New research reveals AI models can carry hidden risks from parent models. How should organisations respond?

AI2Day Newsdesk2 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Share

Key points

  • Cisco research in 2025 found that AI models can inherit risks from upstream models built in other countries.
  • No global regulator requires full disclosure of an AI model's lineage or origins.
  • Security teams may still face risks they aimed to avoid by blocking specific AI brands.
  • As first reported by ThreatVectr, AI model labels often hide the true origin of the software's components.

What did Cisco's research discover?

Cisco's 2025 study found AI models can carry risks from parent models developed elsewhere, even if they appear homegrown. A model developed in the United States might still use code or data from a Chinese-origin model. The study highlights the complexity of AI supply chains, where many models are fine-tuned versions of existing ones. Fine-tuning means taking an existing model and training it further, which can pass on previous security issues or biases.

Should users be worried?

Yes, security teams may not avoid risks by blocking specific AI brands. AI models often carry inherited issues from their parent models. Governments and employers ban tools linked to certain countries, especially China, due to fears over data handling and security backdoors. These bans mostly target brand names, not model lineages, meaning a rebranded product could still harbor unwanted traits.

What should organisations do?

Organisations should ask vendors for model cards, which detail a model's training data and base models. Treat missing cards like missing ingredient lists. Steps include mapping AI tools against model cards, questioning vendors about geographic restrictions, limiting data shared with tools, and making lineage disclosure a procurement requirement. Currently, no regulator, including the US FTC or the UK's ICO, mandates full model lineage disclosure. It's up to organisations to ensure this transparency.

Common questions

What is a model card?

A model card is a document that explains where an AI model's data comes from, what base models are used, and any additional training it underwent. It helps understand the model's capabilities and risks.

Why doesn't the label show the model's full lineage?

AI model labels often only display the final developer. They don't detail the complex family tree of parent and grandparent models, which might be from different countries or contain inherited issues.

© 2026 AI2Day