Brief IA

Materials List for AI: Towards Greater Transparency

💡 Use Cases·Tom Levy·

Materials List for AI: Towards Greater Transparency

Materials List for AI: Towards Greater Transparency
Key Takeaways
1AI systems can make erroneous decisions without clear explanations.
2The AI materials list aims to detail the data and components used.
3Inspired by software materials lists, it is still not widely adopted.
💡Why it mattersClarifying AI systems reduces ethical and regulatory risks for organizations.
Le brief IA que lisent les pros

Le brief IA que les pros lisent chaque soir

Les 7 actus IA du jour, décryptées en 5 min. Gratuit.

Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.

Choisis ton rythme

Gratuit · Pas de spam · Désabonnement en 1 clic

📄
Full Analysis

List of Materials for AI: Towards Greater Transparency

When an AI system makes a "bad decision," most organizations cannot truly explain why. They are not entirely sure about the data that trained it, where the error occurred, which version was running, or what third-party components were involved. This creates an ethical and regulatory blind spot that poses risks for technology leaders in institutions of all sizes, and it has sparked growing interest in a newer framework called AI bill of materials (AIBOM).

If you have ever seen a software bill of materials (SBOM), you already understand the concept. However, many organizations have yet to consider applying this framework and process to the AI systems they use. That is about to change: regulations are pushing for the implementation of AIBOMs, according to Arpita Soni, a senior member of the professional technology organization IEEE. “I see a lot of pressure on inventory, on BOM models due to the need for increased safeguards,” Soni states. “Organizations are moving more towards this model because they need to be part of compliance and audits.”

For some, the decision follows the executive order from former President Joe Biden on the use and development of AI in 2024, among other factors. Given the increase in regulatory mandates — and the general desire to mitigate risks — here’s why AIBOMs are on the rise and what institutions should consider when building and implementing them.

What is an AI Bill of Materials?

The National Institute of Standards and Technology describes AIBOMs as “facilitators for transparency and security in AI software,” highlighting their ability to “foster trust” and “facilitate innovation.” More specifically, an AIBOM is a “repository or inventory,” explains Soni, “that can be read by your machines, by your systems, and that includes components such as your datasets, your queries, your models, your specific configurations, version history, pipelines, and third-party dependencies.”

Katie Norton, head of software supply chain security research and DevSecOps at IDC, notes that for organizations already using SBOMs, AIBOMs are a logical next step: “While an SBOM provides visibility into application code, libraries, and dependencies, an AIBOM captures the components that define AI behavior.”

What Does an AI Bill of Materials Contain?

AIBOMs generally have similar components, although they may vary slightly depending on the size, needs, and systems of an institution.

Norton specifies that these structured, machine-readable inventories document several layers of the AI systems an organization uses and include components and questions to ask for each:

  • The data layer includes training and validation datasets, provenance, licensing, and sensitivity. This layer answers questions like: “Where do your training data come from? What are the licensing terms? Does it contain personally identifiable information?”

  • The model layer includes architecture, weights, hyperparameters, version, and lineage. It answers questions like: “What architecture? What version? What was the training configuration?”

  • The infrastructure and dependency layers include the frameworks and hardware necessary to run the model, answering the question: “What frameworks and libraries does the model use, and where does it run?”

  • The governance metadata layer includes intended use, known limitations, and risk mitigation measures. It answers questions like: “What should this model do? What are its limitations? What safeguards are in place?”

Norton emphasizes that AIBOMs are necessary in addition to SBOMs. “An SBOM alone is insufficient for AI systems because it only inventories the code,” she says. “AI systems are data-driven and often non-deterministic; their behavior emerges from the training data and model configuration rather than from explicitly written logic. Without an AIBOM, IT leaders lack visibility into the ‘cognitive layer’ of the system, making it difficult to audit decisions, reproduce results, or assess supply chain risks.”

Why is the AI Bill of Materials Gaining Popularity Now?

AI is not new, so why is the AIBOM just starting to gain wider adoption? Soni explains that due to the need for AI to be “ethical, transparent, and fair,” a framework is necessary to analyze these principles, and AIBOMs have begun to do just that — particularly important at a time when “blind spots” have become apparent and the need for regulatory compliance is growing.

Norton highlights three converging factors that create the need for AIBOMs now:

  • First, generative AI has made it trivial for developers to integrate open-source models into applications without anyone in security being aware. Organizations suddenly realized they had no idea what models were in production.

  • Second, regulators have caught up. The EU AI Act and the NIST AI Risk Management Framework now expect transparency regarding training data and model lineage — elements that SBOMs were never designed to capture.

  • Finally, “the tools are finally here. Standards like Software Package Data Exchange (SPDX) and CycloneDX now have AI-compatible profiles, so generating an AIBOM is no longer a custom engineering project. The risk has always been there; now we have the means to address it,” explains Norton.

As Gartner forecasts that SBOM adoption will rise from 56% among large organizations in 2025 to 85% by 2028, the adoption rate of AIBOMs remains to be determined.

Brief IA — L'actualité IA en français

L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.