ValueError: Object arrays cannot be loaded when allow_pickle=False
The .npy file contains Python objects, and np.load blocks those by default for security. Pass allow_pickle=True only if you trust where the file came from.
Updated
The error
ValueError: Object arrays cannot be loaded when allow_pickle=False
What it means
You called np.load on a .npy or .npz file that stores Python objects rather than plain numbers. Loading objects requires pickle, Python's object-serialisation format — and unpickling untrusted data can execute arbitrary code. NumPy therefore refuses by default (since version 1.16.3) and makes you opt in.
Why it happens
Plain numeric arrays save and load without pickle. An array acquires dtype=object when it holds strings, dicts, or ragged rows of different lengths:
np.save("data.npy", np.array([[1, 2], [3, 4, 5]], dtype=object))Whoever created the file saved objects, knowingly or not. Loading it now needs pickle, so NumPy asks for explicit permission.
How to fix it
1. If you created the file, or fully trust its source, allow pickle.
data = np.load("data.npy", allow_pickle=True)That is the entire fix for your own files. Do not do this for files downloaded from the internet or received from strangers — a malicious pickle runs code the moment it loads.
2. For dict-like saves, remember .npz items need .item().
d = np.load("results.npy", allow_pickle=True).item() # a saved dict comes back3. Better long-term: stop saving objects. If the array became object by accident — ragged rows are the usual cause — fix the data instead:
arr = np.array(rows)
print(arr.dtype) # object? your rows have unequal lengthsPad the rows to equal length, or store each array separately in an .npz:
np.savez("data.npz", images=images, labels=labels)4. For genuinely structured data, use a format built for it. JSON for nested records, Parquet for tables, safetensors for model weights. All of them load without executing code.
How to prevent it
Check arr.dtype before saving. If it prints object, understand why before writing the file. Prefer formats that cannot execute code for anything that leaves your machine, and treat allow_pickle=True on a downloaded file as the security decision it is.
Related errors
- Weights only load failed (torch.load) — PyTorch's version of the same security default
- ValueError: setting an array element with a sequence — how ragged object arrays get created
- git-lfs pointer files instead of weights