don-t-trust-the-label-license-laundering-in-ai-supply-chains-f4c5e5c2·1 events·first seen Aliases: Don't Trust the Label: License Laundering in AI Supply Chains
A new arXiv paper traces 232,270 dataset→model→application chains across Hugging Face and GitHub to measure license propagation fidelity in AI supply chains. The authors identify two forms of 'license laundering': unlicensed artifacts acquiring definitive labels downstream, and declared licenses being replaced during redistribution. Key findings include that 62.3% of chains pass through at least one artifact with no declared license, and every obligation-bearing license category (e.g., copyleft, attribution-required) falls below 7% end-to-end survival while permissive licenses reach 95.1% survival. The paper offers recommendations for practitioners, model publishers, rights holders, and platform operators.