Safe By Design AI

What this is, and whose it is

An independent, unofficial reference to IBM's Granite models as published by IBM. Not affiliated with, endorsed by, or reviewed by IBM.

Compiled by Kacey Kelley · info@safebydesign.ai.

Release 1.0, published 2026-09-22. That is when this reference was released; it is not the snapshot date below, which is a fact about the catalogue rather than about this document.

How to cite this

Kacey Kelley. Granite models: an independent reference. Release 1.0, 2026-09-22. Snapshot of 172 ibm-granite repositories; latest upstream modification 2026-09-18.

A machine-readable form is in CITATION.cff.

Corrections

Corrections and source updates to info@safebydesign.ai.

The configuration digests in evidence/claims.json identify the exact files analysed, and can reveal when upstream content has changed since. They do not validate the analysis: a digest that still matches says the file is the one that was read, not that it was read correctly.

And the execution claims — what ran, what was recorded, what is refused — rest on an implementation that is not published here. Those are classified on support.md by the strength of the artifact behind each one, and they are not independently checkable from this bundle. Saying otherwise would be the kind of overstatement these pages are otherwise careful about.

What it covers, and as of when

A snapshot of 172 repositories in the ibm-granite catalogue on the Hugging Face Hub. The latest upstream last-modified timestamp it represents is 2026-09-18 — the hub distinguishes that from createdAt, and this is the second, so it says when something in the catalogue last changed and not when anything was published. It is not "every Granite model" and stops being complete the moment another is added: a reference that claims the present tense is wrong on a schedule.

139 of the 172 rows carry the sha256 of the exact config.json these pages read, in evidence/claims.json. A reader who fetches one of those models today can tell whether their configuration matches the one analysed here; where the digests differ, this reference describes an older file. The other 33 publish no configuration, and say so rather than carrying a digest of the empty placeholder that stands in for one.

Every row is also pinned to the upstream commit it describes (upstream_revision in evidence/claims.json, and the revision column in models.md). The pins were checked against the Hub on 2026-09-22: every published configuration at its pinned commit matched its digest.

A configuration digest identifies a configuration. It is not a checkpoint identity and not a repository revision (the pin above is that). Two models can publish byte-identical configurations and different weights, which findings has a section about.

Where it comes from

The catalogue and the architecture analysis are generated from two public sources and nothing else: that catalogue, and every published config.json that is available — 139 of the 172. The other 33 publish none, and no geometry is inferred to fill the gap.

The support assessment is separate and is not. It additionally records what an independent, unpublished implementation did — which models it ran, which forwards it recorded, which configurations it refuses — and every row says which of those it rests on.

What is whose

The descriptions, the analysis and the implementation sketches are original work, licensed CC BY 4.0 — reuse and adapt them with attribution. The grant and its scope are in LICENSE.md.

The models, their names and their configurations are published by IBM and governed by their respective licences, which each model card states. Nothing here redistributes a model, a weight or a checkpoint; configuration values are quoted to describe what each model is. The three models not under Apache-2.0 — granite-speech-5.0-470m-turboctc-nc (CC-BY-NC-SA-4.0), granite-geospatial-wxc-downscaling (CDLA-Permissive-2.0) and granite-timeseries-patchtst-fm-r2 (OpenMDW-1.0) — have their configurations quoted descriptively only, under the terms of those licences.

IBM and Granite are trademarks of International Business Machines Corporation, acknowledged here; this reference claims no rights in either and is not affiliated with or endorsed by IBM.

No output quality was measured and no model is recommended. Every number here describes structure — depth, width, an activation, a rope base, which tensor carries a bias — or says what was checked and how. Where something was not checked, the page says so on its face rather than in aggregate somewhere else.

The implementation these pages were checked against is not published here, and is not the subject. Where a page says something was implemented, recorded or refused, that is a statement about what was done in software you cannot inspect — so those claims are classified rather than reproducible, and evidence/claims.json says which classification each one holds. The reference is to IBM's models; that implementation produced and internally tested the execution evidence summarised here.