Don't Trust the Label: License Laundering in AI Supply Chains
AI artifacts move through a multi-platform supply chain, spanning datasets and models on Hugging Face and applications on GitHub. While each artifact carries a license whose obligations should propagate through redistribution, no study has yet measured whether those obligations survive the chain or are stripped and replaced as artifacts move downstream. We trace 232,270 dataset$\rightarrow$model$\rightarrow$application chains and quantify two forms of license laundering: when artifacts with no declared license acquire definitive labels downstream, and when one declared license category replace
Lineage graph
Paper → model → repo connections mined from source citations (Tier-1 exact match).
Why these links exist
Every edge carries a method, confidence, and the source snippet that justified it — so bad links are debuggable.
- PossiblePossibly related (embedding) · 53%AI vendors have found someone to pay their infrastructure bills: You →
- PossiblePossibly related (embedding) · 53%AI firms' mass purchase and destruction of books for model training fuels copyright debate - A News →
- PossiblePossibly related (embedding) · 52%AI Reshapes the Entry-Level Pipeline Across Law, Finance, and Consulting - Tech Times →
- PossiblePossibly related (embedding) · 49%Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks - Microsoft →
- PossiblePossibly related (embedding) · 49%Artificial intelligence for supply chain advantage - Today's Medical Developments →
- LinkedLinked via arxiv author · 85%James Jewitt →
“Don't Trust the Label: License Laundering in AI Supply Chains”
- LinkedLinked via arxiv author · 85%Bohao Li →
“Don't Trust the Label: License Laundering in AI Supply Chains”
- LinkedLinked via arxiv author · 85%Gopi Krishnan Rajbahadur →
“Don't Trust the Label: License Laundering in AI Supply Chains”
