Is this matter about publicly available model or private model? For publicly available model like opus 4.6, bad actors can do whatever they want and Anthropic won't know. If this is only about private custom model, designating public model as supply chain risk doesn't make sense as others can use it.