Analysis

AI Bills of Materials

June 18, 2026 00:24 · 12 min read
AI Bills of Materials

Introduction to AI Bills of Materials

A policy paper published on Tuesday by the Institute for Security and Technology argues that software bills of materials (SBOMs) for artificial intelligence are necessary to reduce cyber risk and improve transparency. The paper provides a roadmap for lawmakers, federal agencies, and other organizations on how to proceed with implementing AI bills of materials (AIBOMs).

Background on SBOMs

SBOMs, commonly described as an inventory of software ingredients, emerged in the 2010s and have expanded beyond software to include hardware and AI. However, the paper argues that AIBOMs require foundational work before they can be widely implemented.

Allan Friedman, a co-author of the paper, expressed concerns about the potential for a 'fire, ready, aim' situation where everyone is doing things slightly differently. Friedman emphasized the need for a shared vision to have a coherent policy, common tools, and interoperable data.

The Need for a Shared Vision

The idea for the paper sprung from discussions with Hill aides and Pentagon staffers, and people like them are the target audience. A key premise is that AIBOM policy needs to explore the topic from two sides: supply and demand.

Solving the Chicken-and-Egg Issue

Friedman explained that solving the chicken-and-egg issue, where no one is providing the data and no one is asking for it, requires going from both supply and demand. On the supply side, an AIBOM should capture relevant details about the models and datasets used for training, fine-tuning, evaluation, validation, testing, retrieval, grounding, augmentation, or other model development or operational purposes.

On the demand side, the paper suggests that some form of forcing function or requirement is needed, such as an industry mandate or government regulations, to require organizations to understand what is in the products they manufacture and sell.

Industry and Government Roles

Friedman argued that government regulations or contracting conditions could play a role in shaping AIBOM policy. He also acknowledged the prior work of organizations like the Open Worldwide Application Security Project (OWASP) and Linux Foundation.

The paper is not meant to be the be-all, end-all, and Friedman emphasized that AIBOM will not solve all AI security issues. However, he believes that papers like the one published on Tuesday are just the beginning of the discussion on AIBOM policy.

Conclusion

As AI continues to evolve rapidly, the need for a shared vision and a coherent policy on AIBOMs is becoming increasingly important. The paper provides a starting point for discussions on how to proceed with implementing AIBOMs and reducing cyber risk in the AI industry.

The answer is, you have to go from both supply and demand. - Allan Friedman

The discussion on AIBOM policy is ongoing, and the paper provides a roadmap for lawmakers, federal agencies, and other organizations on how to proceed.


Source: CyberScoop

Source: CyberScoop

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free