
MCP Security, Version 2.0: From Threat Taxonomy to a Model You Can Actually Audit Against
September 25, 2026Introducing AIMM: The Artifact Integrity Maturity Model for AI/ML Supply Chain Trust and Provenance
A team pulls a fine-tuned model from a public hub and puts it into production. It carries no signature, and the pipeline has no verification gate to reject it. Months later, a vulnerability is disclosed in the parent model from which it was derived, and no one can quickly say which of their deployed models inherited it. When an auditor asks what evidence supported the deployment, the answer has to be reconstructed after the fact from ticket systems, logs, and chat threads.
These are not edge cases. They are what happens when high-consequence AI/ML artifacts move through a supply chain without a verifiable record of what happened to them.
Can you prove that the artifact you are about to deploy is the one you expect? Can you trace where it came from and how it changed? Can you tell whether it meets the policies that apply to that deployment?
Those are different assurance problems, and they require different controls.
CoSAI Workstream 1 has released the Artifact Integrity Maturity Model (AIMM), a risk-based framework for AI/ML supply chain trust and provenance. AIMM builds on CoSAI’s earlier paper, Signing ML Artifacts: Building towards tamper-proof ML metadata records. Where that first paper made the case for cryptographically signing model artifacts, AIMM answers the question that follows: how much signing, provenance, and attestation infrastructure does a given use case need, and where should an organization start?
AIMM provides a progressive path from basic artifact integrity to verifiable provenance and, where appropriate, structured attestations that can support policy evaluation and admission gating.
Key Takeaways
AIMM organizes AI/ML artifact assurance around three levels. Each level answers a deeper question about an artifact than the one before it. The right level depends on the risk and deployment context of the use case.
Higher levels build on lower-level capabilities, but progression for its own sake is not the objective. The goal when using AIMM is to match assurance to risk. A healthcare organization, for example, might apply Level 3 controls to clinical diagnostic models while using Level 1 for internal research.
Why a Maturity Model Matters
AI/ML artifacts increasingly move through distributed supply chains in which models, datasets, configurations, and process artifacts are created, transformed, and deployed across multiple teams, organizations, and environments. Without verifiable integrity and provenance, consumers may have no reliable way to establish whether an artifact changed, where it came from, or which processes produced it.
Regulatory and risk-management frameworks such as the EU AI Act and the NIST AI Risk Management Framework are also increasing the need to understand AI/ML dependencies and maintain evidence for audit, incident response, and accountable deployment.
Software supply chain security already provides useful patterns through SLSA, the in-toto Attestation Framework, and Software Bills of Materials (SBOMs). AIMM builds on those ideas while focusing on the realities of the AI/ML lifecycle, where artifacts may be trained, fine-tuned, quantized, distilled, and otherwise transformed across organizational boundaries. Rather than prescribing one standard or one level of control for everyone, AIMM defines three progressive levels of assurance based on the needs of a particular use case.
From Integrity to Policy: The Three Levels of AI Supply Chain Assurance
Level 1: Basic Artifact Integrity
“Is this model what it claims to be?”
Producers hash and sign an artifact at a well-defined release boundary; consumers recompute the hash and validate the signature before the artifact enters a pipeline or reaches production.
Level 1 establishes artifact integrity and producer authenticity. Any post-signing change causes integrity verification to fail, whether the cause is malicious tampering, substitution, or accidental corruption. It is intentionally lightweight, but it verifies a single point in time rather than recording how the artifact was produced.
Level 2: Provenance and Lineage
“Where did this model come from?”
Level 2 adds signed provenance claims and verifiable lineage relationships between artifacts and the transformations that produced them.
This allows consumers to trace relevant parent artifacts and derivation history across fine-tuning, quantization, distillation, or other transformations. That becomes especially valuable when an upstream vulnerability or issue is discovered and teams need to determine which downstream artifacts may be affected.
Level 3: Structured Attestations for Policy Automation
“Does this artifact meet specified policies?”
Level 3 extends the evidence model to structured attestations about model, data, process, and infrastructure properties. Those attestations can be evaluated by policy engines and used in admission-gating decisions before an artifact reaches a deployment target.
Level 3 is most relevant for regulated industries, high-stakes applications, complex multi-party supply chains, and environments that need governance at scale. AIMM is explicit that fully automated policy enforcement remains aspirational in many environments because domain-specific attestation schemas and supporting infrastructure are still maturing. Many organizations will begin with a hybrid approach that combines machine-evaluable evidence with human review.
What AIMM Adds
AIMM goes beyond basic signing to address practical problems that emerge in real AI/ML supply chains:
- Agentic workflows: how AI agents participate as first-class entities in signing, verification, delegation, and provenance rather than acting as invisible intermediaries. In TEE-enabled environments, runtime attestation can also extend the evidence chain into the agent’s execution environment through hardware-rooted measurements.
- Multi-party claims: how to reconcile assertions from multiple parties about the same artifact.
- Incremental adoption: how to strengthen controls over time without building the most sophisticated system first.
- Clear scope boundaries: what signing and attestation can establish, and what they cannot.
AIMM is explicit about its limits: signing and attestation can establish integrity, authenticity, provenance, and evidence for policy decisions, but they do not guarantee that an artifact is correct, safe, or fair. AIMM is one layer in a defense-in-depth strategy.
Where to Start
For organizations beginning with little or no signing and verification infrastructure, AIMM recommends a risk-based adoption path:
- Start with Level 1 on the highest-risk models or artifacts, such as models running in production, externally facing models, or artifacts subject to regulatory requirements.
- Prioritize externally sourced models. For unsigned external models, organizations can perform feasible integrity checks and establish an internal signed trust boundary at ingestion. This does not provide the same assurance as an end-to-end producer signature, but it creates a verifiable boundary from that point forward.
- Introduce Level 2 when models have meaningful derivation histories, such as fine-tuned, distilled, or multi-source artifacts, where lineage materially improves security and incident response.
- Consider Level 3 if there is both a clear policy requirement and sufficient attestation and policy infrastructure to justify the additional complexity.
Read the Full Paper
The complete AIMM paper includes implementation guidance for each maturity level, incremental adoption strategies, scope and boundary considerations, and ecosystem context.
CoSAI Workstream 1 will continue evolving AIMM through industry and community collaboration, including companion implementation guidance and reference tooling intended to lower adoption barriers.
AIMM was developed by CoSAI Workstream 1 with contributions from Intel, Cohere, Microsoft, Thomson Reuters, NVIDIA, PayPal, IBM, OpenAI, Red Hat, Wiz, and EQTY Lab and workstream leadership from Asmae Mhassni (Intel), Matt Maloney (Cohere), and Jay White (Microsoft).
If you are signing, tracing, verifying, or setting policy for AI/ML artifacts, we want your implementation experience. Help pressure-test AIMM against real-world supply chains, identify where existing mechanisms are sufficient or fall short, and contribute the patterns and tooling that can make verifiable AI/ML supply chains easier to adopt.
Join the CoSAI Open Project and help shape what comes next.





