Skip to content

Security for Local and Open-Weight Models

The security considerations of running models on your own hardware: safe formats, isolation, updates and access.

Editorial team 1 min read

Running open-weight models locally or on your own servers keeps data in-house, but shifts security responsibility to you.

Safe Model Files

Some model file formats can execute arbitrary code when loaded. Prefer safe formats such as safetensors or GGUF, download from verified publishers, and check hashes.

Serving Software

Local inference servers are software like any other. Keep them updated, and don't expose their APIs to networks without authentication — many default to no authentication at all.

Access Control

Put an authenticating gateway in front of model endpoints, with rate limits and logging.

Safety Behaviour

Open-weight models may have weaker safety training, or modified versions may have had it removed. Add your own input and output safeguards for user-facing applications.

Data Handling

Local models avoid sending data to providers, but prompts and outputs may still be logged locally. Apply retention and access policies.

Resource Protection

GPU servers are attractive to attackers for cryptocurrency mining and other misuse. Monitor usage.

Licences

Check model licences for restrictions on use.

More in AI security

All AI security guides →
AI security Guide · 1 min

Introduction to AI Security

What AI security covers — attacks on models, data and AI applications — and how it differs from traditional security.

AI security 1 min read 29 Jun 2025

AI security Guide · 1 min

The OWASP Top 10 for LLM Applications

An overview of the widely used list of the most critical security risks for applications built on language models.

AI security 1 min read 28 Jun 2025

AI security Guide · 1 min

Jailbreaks: How They Work and How to Defend

How people try to get models to bypass their safety training, common techniques, and layered defences.

AI security 1 min read 27 Jun 2025

AI security Guide · 1 min

Indirect Prompt Injection

How attackers hide instructions in web pages, emails and documents that AI systems read, and why it's so dangerous for agents.

AI security 1 min read 26 Jun 2025