Cybersecurity Policy Report, Guidance on Creating AI ‘Bill of Materials’ Offered by U.S., G7 Allies, (May 13, 2026)
A “bill of materials” that lists the ingredients contained in an AI (artificial intelligence) system would improve the cybersecurity of technologies that rely on AI components, according to guidance issued yesterday by the U.S. and its G7 (Group of Seven) allies.
“Accessing information on the supply chain of an artificial intelligence (AI) system, as well as its individual components and dependencies, is critical to strengthen cybersecurity of AI. Transparency and knowledge about AI system composition fosters vulnerability management and supports cybersecurity risk management,” the guidance says.
Software bills of materials (SBOMs) that list the components contained in a software package have become a useful cybersecurity tool, and AI SBOMs would similarly help identify potential vulnerabilities in an AI system, it notes.
“Drawing from the existing Software Bill of Materials (SBOM) concept, an SBOM for AI consists of a structured record, or inventory of details and supply chain relationships for the various components used in building an AI system. This structured record is divided into different clusters. Each cluster contains ‘elements’ or information that captures the distinctive features of AI system components,” it says.
The “minimum elements” that an AI SBOM should contain include the underlying AI model, the datasets used to train the model, whether the training data contains personally identifiable information, the system’s dependency on external software components, and a host of other technical data, the guidance recommends.
“Besides addressing single elements, the authors highlight that an SBOM for AI by itself is not sufficient for increasing cybersecurity along the supply chain. To ensure substantial protection of the AI supply chain, it is necessary to connect the SBOM for AI to cybersecurity tools, such as vulnerability scanning and management tools, security advisories and bulletins, and promoting development of adaptable and evolutionary tooling mechanisms,” the guidance says.
The guidance was produced by the Cybersecurity and Infrastructure Security Agency and cyber defense agencies from the G7 nations, which include Canada, France, Germany, Italy, Japan, and the United Kingdom.
News: InternationalLegislation DataSecurity AINews