What happened
On July 30, 2026, CISA published 'Open Source Software: Security Principles and Practices,' a new resource for federal agencies covering OSS selection, patching, contribution, and production practices. The document includes a dedicated section, 'Evaluating Open Source Artificial Intelligence Models,' which directs agencies to obtain sufficient transparency into all relevant AI system components — including training data — before treating an AI model as OSS for risk-management purposes, so that agencies can study, analyze, and remediate vulnerabilities. The guidance aligns with Executive Order 14144 and Executive Order 14306.
Why it matters
This is a genuine new CISA guidance document (not previously covered) that extends established OSS supply-chain risk-management principles specifically to open-weight/open-source AI models for the federal government, addressing a recognized gap in AI-specific transparency requirements needed to assess and remediate AI supply-chain risk.
Action needed
Federal agencies and organizations sourcing open-weight AI models should map their model-vetting processes to the new C4-Framework-based transparency and risk-tolerance criteria in the guidance.