What matters in AI.

Subscribe

Learn / AI security

Definition · AI security

AI bill of materials

An AI bill of materials is a machine readable inventory of the datasets, base models, checkpoints and tooling a system depends on. It extends the software bill of materials to the parts of a system that are learned rather than written, so that provenance can be checked and affected systems found quickly.

Last reviewed

Key points

  • An AI bill of materials inventories the parts of a system that were learned rather than written, being the datasets, the base model, the checkpoint and the tooling, and records where each came from.
  • Its purpose is speed in an incident. When a dataset or a published checkpoint is found to be compromised, the inventory answers which deployed systems inherited it.
  • An AI bill of materials tells you what is in the system, not whether any of it is safe. NIST says vulnerabilities encoded into a model's weights may not be auditable the way open-source software is.
  • Governments now define one. The G7 Cybersecurity Working Group published minimum elements for an SBOM for AI in May 2026, grouped into seven clusters that reach from datasets and models to security controls.
  • The formats still disagree on what belongs in one. CycloneDX carries datasets as components inside an ML-BOM; SPDX describes them in a profile of their own.

An AI bill of materials lists the parts of a system that were learned rather than written: the training datasets, the base model, the fine-tuned checkpoint, the tokenizer, the frameworks that produced them, and where each came from. CycloneDX’s ML-BOM adds model architecture, training details and intended use; SPDX splits the same ground into an AI profile and a Dataset profile. Both inventory inputs and artifacts, down to individual weight files. Neither says what is in them.

CISA’s 2026 minimum elements, which replaced NTIA’s 2021 baseline for a software bill of materials, apply to an AI system because AI is software, but state that the document “does not introduce additional elements for SBOMs for AI systems”. A software component decomposes into supplier, version and dependency tree. Weights do not: NIST states that organizations and researchers “may not be able to audit and identify vulnerabilities encoded into a model’s weights in the same way it is often possible to audit open-source software”.

What an AI bill of materials is for

An AI bill of materials answers one question quickly: what is in this system, and where it came from. MITRE ATLAS files it as mitigation AML.M0023, which can “enable rapid response to reported vulnerabilities”, and maps it to data poisoning because an AI BOM “can help users identify untrustworthy model artifacts”. An inventory does not stop the attack; it bounds it. The May 2026 G7 minimum elements say as much: an SBOM for AI “by itself is not sufficient”, and only works connected to vulnerability scanning and security advisories. Regulators want the same record. Article 53(1)(d) of the EU AI Act obliges providers of general-purpose AI models to publish “a sufficiently detailed summary about the content used for training”, from 2 August 2025.

Where definitions disagree

Three answers are in circulation, and not the same shape. CycloneDX carries datasets as components inside the ML-BOM. SPDX gives them a profile of their own, so a dataset can be described independently of its models. The G7 minimum elements are not a format at all but seven clusters, reaching past inventory into security controls, certifications and operational performance. CycloneDX and SPDX carry fields a security team would not have asked for — SPDX names known bias and energy consumption — because they took on the job of the model card too. The G7 list links out to one instead.

Questions and answers

What is in an AI bill of materials?

An AI bill of materials records the parts of a system that were learned rather than written, alongside the software components an ordinary SBOM already covers. The G7 minimum elements of May 2026 group them into seven clusters, being metadata about the document itself, system level properties, models, dataset properties, infrastructure, security properties and key performance indicators. CycloneDX's guide names nine areas, among them model identifiers, model architecture, datasets, tokenizers and prompt templates, training and testing details, and environmental impacts. SPDX splits the same ground across an AI profile describing the model and a Dataset profile describing the data, with fields for hyperparameters, evaluation metrics, decision thresholds, known bias, collection process and sensitive personal information.

How is an AIBOM different from an SBOM?

An SBOM stops at the model, and the authors of the current baseline say so. CISA's 2026 minimum elements apply to an AI system on the reasoning that AI is software, but state that the document "does not introduce additional elements for SBOMs for AI systems", and name the missing supply chain data as what AI engineers commonly discuss under the titles of model cards or data cards. The structural reason is that a model has no supplier, version and dependency graph in the sense an SBOM component does. Its behaviour comes from a training dataset that may be a list of URLs, from hyperparameters, from a base checkpoint someone else produced, and from a fine-tuning run that is not reproducible. An AIBOM adds those as first-class entries. The G7's cybersecurity agencies published minimum elements for one in May 2026, under a work stream co-led by Italy and Germany, and are explicit that those elements are in addition to the general SBOM minimum elements rather than a replacement.

Is an AIBOM required by law?

Not by that name, and not as a format. The G7 minimum elements for an SBOM for AI state that they "are not mandatory; do not create requirements, standards, or legislation". The closest binding requirement is the EU AI Act, whose Article 53(1)(d) obliges providers of general-purpose AI models to publish "a sufficiently detailed summary about the content used for training" to an AI Office template, applying from 2 August 2025, with technical documentation obligations alongside it. That is a disclosure duty about training content rather than a mandate to emit SPDX or CycloneDX. An AIBOM is currently the most practical way to satisfy it in machine-readable form, not the thing the law names.

Does an AI bill of materials detect a poisoned model?

No. An AI bill of materials records what went into a model; it does not inspect what the model learned. Its value against poisoning is containment and speed: when a dataset or checkpoint is later found to be compromised, the inventory answers which deployed systems inherited it. The G7 agencies make the same point about the record as a whole, that an SBOM for AI by itself "is not sufficient for increasing cybersecurity along the supply chain" and has to be connected to cybersecurity tools such as vulnerability scanning and security advisories. Detection is a separate problem, and a hard one: NIST states that organizations and researchers "may not be able to audit and identify vulnerabilities encoded into a model's weights in the same way it is often possible to audit open-source software".

Sources

  1. Software Bill of Materials for AI - Minimum ElementsG7 Cybersecurity Working Group, 12 May 2026
  2. 2026 Minimum Elements for a Software Bill of Materials (SBOM)CISA, 29 Jul 2026
  3. CycloneDX Machine Learning Bill of MaterialsOWASP CycloneDX
  4. OWASP CycloneDX Authoritative Guide to AI/ML-BOMOWASP CycloneDX
  5. CycloneDX v1.6: Now an Ecma International StandardOWASP CycloneDX, 26 Jun 2024
  6. SPDX 3.0 Revolutionizes Software Management in Systems with Enhanced Functionality and Streamlined Use CasesLinux Foundation, 16 Apr 2024
  7. SPDX Specification 3.0.1: AI Profile, AIPackageSPDX
  8. SPDX Specification 3.0.1: Dataset Profile, DatasetPackageSPDX
  9. SPDX Specification 3.0.1: Software Profile, FileSPDX
  10. MITRE ATLAS, AML.M0023 AI Bill of Materials (collection 2026.08)MITRE
  11. Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations (NIST AI 100-2e2025)NIST, 24 Mar 2025
  12. Regulation (EU) 2024/1689 (EU AI Act), Article 53: Obligations for Providers of General-Purpose AI ModelsEuropean Union, 12 Jul 2024

Guides that use this term