VFX facilities adopting generative and agentic AI need an orchestration layer that treats models and their surrounding code as production dependencies, according to Foundry’s director of AI research Adam Cherbetji. The opinion is relevant because many tools described as open source publish weights but not training code, training data or commercial-use permissions.
The proposed pattern represents models as nodes in a repeatable graph. Untrusted code is sandboxed by restricting which files it can write and which hosts it can reach, while automated dependency scanning examines models, nodes and packages. New releases can be age-gated so a compromised version has time to be detected before entering a facility image.
Licence metadata remains part of the technical control plane: a model may permit local execution but not commercial shots, redistribution or a required retention period. Frame provenance can begin with sidecar metadata and grow toward C2PA records as clients demand a more formal chain of custody.
This is a vendor-authored operating model, not an audited security profile. The article does not publish threat models, sandbox escape testing, reference hardware, performance overhead, licence automation accuracy or completed studio deployments using the full pattern.