Foundation Model

A foundation model is a large AI model trained on broad, general data at scale, designed to be adapted to a wide range of downstream tasks through fine-tuning or prompting, forming the base layer of most current enterprise AI systems.

Why Foundation Models Are a Distinct Category

Traditional ML models are trained for a single task. Foundation models are trained once at massive scale, then adapted to many tasks. That shift changes the economics of AI, the risk profile, and the governance requirements.

A single foundation model underlies thousands of enterprise applications. A vulnerability, bias, or behavioral quirk in the foundation model propagates to every downstream system built on it. That concentration is what makes foundation models a governance category in their own right, separate from the applications built on top of them.

Foundation Models and GPAI

Under the EU AI Act, foundation models overlap heavily with general-purpose AI (GPAI) models. The specific legal definitions differ, but in practice most foundation models used commercially fall under GPAI obligations.

Foundation Models in AI Supply Chain

Because foundation models are usually provided by external companies, they represent one of the largest concentrations of AI supply chain risk in the enterprise environment. Model behavior, data handling, and training decisions are set by the provider, not the deployer. AI governance programs need explicit strategies for managing foundation model dependencies, including provider risk assessment, model behavior monitoring, and contingency planning for provider-side changes.

Related Terms

Full AI Visibility. Full Control. One Connected Platform.

Enterprise AI is expanding faster than most governance programs can track. Kovrr connects every AI signal across browser, endpoint, network, identity, and vendor systems into a single platform so security, governance, and risk teams work from the same evidence.