Skip to main content
The model catalog is a curated source of security-reviewed, open-source AI models that data scientists can browse and download for use in their workloads. Like channels, the catalog is governed. The policies on a team’s perimeter determine which models that team can access.

Why the model catalog matters

AI and machine learning workloads increasingly depend on pre-trained models pulled from public sources. The model catalog gives your teams a vetted set of models to work from, with metadata such as licensing, publisher, and model size, and gives your organization control over which of those models can be used and by whom. This brings the same governed-access architecture you have for packages to the models your teams build on.

How the catalog works in the platform

Models in the catalog carry metadata that policies can act on. An administrator configures model access policies for a perimeter that determine which models the teams in that perimeter can see and download, based on conditions such as model name, publisher, license, country of origin, tags, parameters, expected VRAM usage, and purpose. Some models also require an administrator to accept the model’s license before anyone in the deployment can download them. The platform enforces access rather than leaving it to individual users. Models that a policy blocks are filtered out before they ever reach a user, and the same check applies when a model is downloaded. As with all data on the platform, model files are delivered directly into your data plane rather than passing through Anaconda-operated services. Each model also exposes an AI Bill of Materials in CycloneDX format through the platform API, so security teams can inventory the components of the models their organizations use.

Working with the model catalog

For browsing and downloading models, see Model catalog. For configuring which models a perimeter can access, see Model governance.