AIBOM at Build

AIBOM at Build A data-flow diagram generated by Archify. 01 / Sources 02 / Build 03 / AIBOM 04 / Registry (Layer 02) 05 / Consumers Foundation model · + fine-tunes · 01 / Sources Foundation model + fine-tunes Datasets & prompts · corpus, templates · 01 / Sources Datasets & prompts corpus, templates Dependencies · libraries · 01 / Sources Dependencies libraries Build pipeline · instrumented · 02 / Build Build pipeline instrumented AIBOM artefact · provenance · 03 / AIBOM · CycloneDX / SPDX AIBOM artefact provenance CycloneDX / SPDX Registry entry · store · 04 / Registry (Layer 02) Registry entry store Vulnerability match · supply-chain risk · 05 / Consumers Vulnerability match supply-chain risk Regulator docs · transparency · 05 / Consumers Regulator docs transparency collect collect collect emit attach match document Legend primary data data store data flow

A bill of materials for AI

  • • Models, datasets, prompts and dependencies with their provenance and licences
  • • Emitted at build and labelled CycloneDX ML-BOM or the SPDX 3.0 AI profile
  • • Regenerated on each build so it never drifts from the deployed system

Stored with the registry entry

  • • Attached to the entry the transparency and eval layers read
  • • A changed corpus licence surfaces as a diff in the next build's AIBOM
  • • Supply-chain and provenance questions become queries

Why it matters

  • • If your build does not emit it, you cannot answer what is running
  • • The cost is toolchain integration and accurate provenance metadata