On this page

Pattern: AIBOM

An AI bill of materials emitted at build, recording models, datasets, weights and their provenance in a standard format beside the registry entry.

Layer 02 · Inventory & Transparency In the chapter 05 catalogue

Summary: Generate an AI bill of materials at build for each AI system, recording models, datasets, weights and their provenance in a standard format, and store it with the registry entry. The AIBOM is what the transparency and eval layers read to know what to document and what to test.

AIBOM at Build A data-flow diagram generated by Archify. 01 / Sources 02 / Build 03 / AIBOM 04 / Registry (Layer 02) 05 / Consumers Foundation model · + fine-tunes · 01 / Sources Foundation model + fine-tunes Datasets & prompts · corpus, templates · 01 / Sources Datasets & prompts corpus, templates Dependencies · libraries · 01 / Sources Dependencies libraries Build pipeline · instrumented · 02 / Build Build pipeline instrumented AIBOM artefact · provenance · 03 / AIBOM · CycloneDX / SPDX AIBOM artefact provenance CycloneDX / SPDX Registry entry · store · 04 / Registry (Layer 02) Registry entry store Vulnerability match · supply-chain risk · 05 / Consumers Vulnerability match supply-chain risk Regulator docs · transparency · 05 / Consumers Regulator docs transparency collect collect collect emit attach match document Legend primary data data store data flow
AIBOM at BuildThe build step emits an AI bill of materials that lands on the registry entry and feeds the vulnerability-matching and documentation consumers. If your build does not emit it, you cannot answer what is running. Generated from the Body of Knowledge.Open interactive diagram (opens in a new tab)

Objectives

Make the composition and provenance of an AI system machine-readable, so supply-chain risk and transparency obligations can be answered from an artefact, not reconstructed.

Target users

AI governance engineer, ML engineer, security engineer.

Impacted stakeholders

Model owners, downstream deployers, auditors, procurement.

Relevant principles

Instrument the build to produce its own proof; start from a named failure mode or harm.

Context

AI systems assembled from foundation models, fine-tunes, third-party datasets and libraries, where the classic SBOM captures software dependencies but not models or data.

Problem

Without a bill of materials for models and data, an organisation cannot answer which model version, from which provenance, trained on which data, is inside a given system, so it cannot assess supply-chain risk or produce transparency documentation on demand.

Solution

Emit an AIBOM at build in a standard format, CycloneDX ML-BOM or the SPDX 3.0 AI profile, for example with the OWASP AIBOM generator 1 (illustrative), covering models, datasets, weights, and their provenance and licences. Attach it to the registry entry and regenerate it on each build so it never drifts from the deployed system.

Consequences

Supply-chain and provenance questions become queries; transparency documents can be generated from the AIBOM. The cost is toolchain integration and keeping provenance metadata accurate.

Agent Registry; Model Card as Control Evidence; Machine-Readable Evidence (OSCAL).

Maps to: EU AI Act Art. 11, Art. 53 (GPAI documentation) · ISO/IEC 42001 · NIST AI RMF (Map) · CSA AICM · Layer 02 Inventory & Transparency.

Function labels follow the NIST AI RMF2. Mappings are illustrative, not a claim of conformity.

Sources

  1. [1] “Evolving AI Transparency: the AIBOM generator’s new home at OWASP” (CycloneDX output). OWASP GenAI Security Project. 2025-12-18. https://genai.owasp.org/2025/12/18/evolving-ai-transparency-the-journey-of-the-aibom-generator-and-its-new-home-at-owasp/ (verified: primary)
  2. [2] AI Risk Management Framework (AI RMF 1.0; Govern, Map, Measure, Manage). NIST. 2023-01-26. https://www.nist.gov/itl/ai-risk-management-framework (verified: primary)
Edit this page on GitHub
Cite this pattern

García Aibar, J. (2026). Pattern: AIBOM. In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0), chapter 05, Patterns. https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/patterns/aibom. CC BY 4.0

BibTeX

@misc{aige2026bok,
  author  = {Jorge García Aibar},
  title   = {{AI Governance Engineering: The Thesis \& Body of Knowledge}},
  chapter = {05. Patterns: AIBOM},
  year    = {2026},
  version = {0.5.0},
  doi     = {10.5281/zenodo.22956197},
  url     = {https://aigovernanceengineer.com/patterns/aibom},
  note    = {Version 0.5.0}
}
Share on LinkedIn