Banning One AI Brand Isn't Enough: Your Model's Family Tree Still Matters

Cisco researchers say that where an AI model is built tells you far less than where it came from. Tracing a model's lineage reveals hidden dependencies and inherited behaviours that a country-of-origin label simply cannot.

ThreatVectr Newsdesk· 3 min read
Photoreal news-editorial image, 16:9, full frame edge to edge
Share

Key points

  • Cisco research published in 2025 found that country-of-origin labels on AI models can hide inherited risks from upstream, or parent, models built elsewhere.
  • A model developed in the United States may still carry code, training data, or behaviours derived from a Chinese-origin model.
  • No single regulator has yet issued binding rules on AI model-lineage disclosure, leaving organisations to audit supply chains themselves.
  • Security teams that block specific AI brands without checking the full model family tree may still run the flagged risks they were trying to avoid.

Blocking a named AI product feels decisive. It rarely is.

New research from Cisco, first covered by SecurityWeek, shows that the country listed on an AI model's label often says nothing useful about what the model is actually built from. An AI model is a piece of software trained on vast amounts of data to perform tasks like writing, summarising, or generating code. Many modern models are not built from scratch. They are fine-tuned, meaning a developer takes an existing model and trains it further on new data, the way a student learns a trade by apprenticing under someone else.

So what is the real risk here?

When you fine-tune a model, you inherit its underlying structure, and potentially its quirks, biases, and security weaknesses. Cisco's researchers found that this lineage, the chain of parent and grandparent models a product descends from, is almost never disclosed on the label that an organisation's procurement team actually sees.

That matters for two reasons.

First, governments and large employers are increasingly banning AI tools with ties to certain countries, particularly China, over concerns about data handling and potential backdoors (hidden access points built into software that let outsiders reach it without a password). Second, those bans often target brand names rather than model lineage. A product repackaged or fine-tuned in a different country can pass the check while still carrying the inherited behaviour of a model the organisation thought it had ruled out.

What kind of data is at risk?

The answer depends on what your organisation feeds the model. AI tools used in business settings frequently process staff names and email addresses, customer records, financial summaries, and internal documents. If an AI model relays that input to an unexpected upstream source, or behaves in ways inherited from an untested parent model, sensitive data could be exposed or misused without any obvious sign that something went wrong.

Cisco did not name specific products as compromised. The research is a structural warning about how the AI supply chain works, not a disclosure of a specific breach.

What should organisations actually do?

Before deploying any AI tool, ask the vendor for its full model card, a document that lists training data sources, base models used, and any fine-tuning steps applied. Many vendors publish these voluntarily. Treat a missing model card the same way you would treat a missing ingredient list.

Four practical steps worth taking now:

  1. Map your AI tools against publicly available model cards and check each product's listed base model.
  2. Ask vendors directly whether their product is fine-tuned from any model subject to your organisation's geographic restrictions.
  3. Restrict what data staff paste into AI tools until lineage is confirmed, especially anything containing personal or financial records.
  4. Raise the topic in procurement so that model-lineage disclosure becomes a contractual requirement for new AI purchases, not an afterthought.

No regulator, including the United States Federal Trade Commission (FTC), the UK's Information Commissioner's Office (ICO), or Australia's Office of the Australian Information Commissioner (OAIC), has yet issued rules forcing vendors to disclose full model lineage. Until they do, the audit sits with you.

© 2026 Threat Vectr