Transparency for AI: Why We Need an SBOM for AI
Artificial intelligence is no longer a future topic – it’s embedded in everyday life. In industry, government services and digital products, AI systems are increasingly taking over critical tasks. At the same time, their technical foundations are becoming more complex. Many AI applications combine multiple models, data sources, software libraries and components whose origin and composition are hard to trace. This is exactly where the concept of an SBOM for AI comes in.
An SBOM – a Software Bill of Materials – is essentially an ingredients list for software. Applied to AI, it means: making transparent which models, data and technical dependencies are part of an AI system. At the G7 cybersecurity working meeting in May 2025 in Ottawa, this concept was presented as a joint proposal by the cybersecurity authorities. The goal: more transparency, more security and more trust in AI systems.
Key takeaways
An SBOM for AI creates transparency around the models, data and components of an AI system.
It strengthens security across the entire AI supply chain and supports audits and compliance.
The G7 initiative defines initial minimum elements and drives international standards.
ISO/IEC 42001 complements the SBOM for AI as a management framework for trustworthy AI.
What is an SBOM for AI?
Compared to classic software, an AI system is significantly harder to understand. Many applications rely on pre-trained models built from a wide variety of data sources. On top of that come complex training and fine-tuning processes, which are often only partially documented or not externally verifiable. All of this makes it difficult to assess the quality, security and trustworthiness of an AI system.
A traditional SBOM, as used in software development, is not enough. It maps dependencies between code components but does not reflect AI-specific aspects – for example, the impact of training data on model behaviour or the ongoing evolution of systems through retraining and updates.
That is why AI needs its own SBOM concept. An SBOM for AI should not only list technical components but also capture information about the entire AI lifecycle. Only then can central questions be answered:
Where does the data come from?
How was the model trained and fine-tuned?
Which risks arise from potential bias or security vulnerabilities?
Why does AI need its own SBOM?
AI can only be considered trustworthy if its origin and mode of operation are transparent. This is especially critical in regulated or safety-relevant environments. Operators need to know:
Which components are part of an AI system
How these components interact
Which risks arise from this combination
Supply-chain attacks are among the most serious threats to IT systems – and AI is no exception.
An SBOM for AI increases clarity and control. It enables organisations to:
Identify vulnerabilities more quickly
Detect known security issues in components
Take targeted countermeasures
Simplify audits and compliance checks
If auditors can immediately see which models, data sources and security measures are used in a system, they can assess and document risks far more efficiently.
There’s also a business upside: transparency improves the reusability of vetted components, reducing development effort and cost. At the same time, the SBOM supports license management and regulatory compliance. Across the AI lifecycle – from developers to operators to assessors – it provides tangible relief.
What should an SBOM for AI contain?
To be effective, an SBOM for AI must reflect the specific characteristics of AI systems. That means going beyond classic SBOM fields like component name, version and vendor.
The G7 cybersecurity group has proposed an initial set of “minimum elements” in Ottawa. These are intended as a basis for international standardisation and include:
Models Information on the AI models used, including origin, training method and intended purpose.
Training data Description of data sources, their quality, provenance and potential biases.
Learning processes Techniques, algorithms and data pipelines used for training, fine-tuning and ongoing optimisation.
Security and compliance attributes References to safeguards, documented assessments and applied security standards.
System behaviour Description of how the model processes data and how components are linked and orchestrated.
Performance metrics Test results, benchmarks and quality indicators for the model.
Licenses Legal and licensing information for all components used.
Technical infrastructure Details on required software, platforms and hardware to run the AI system.
These elements should be provided in a structured, machine-readable format. This is key to enabling automated checks and smooth integration into existing security, compliance and transparency processes.
Step by step to a certifiable ISMS
With the ISMS tool from fuentis, you implement current standards in an automated and efficient way. Our ready-to-use modules, guided workflows and expert support make building an ISMS straightforward – whether you’re starting from scratch or modernising existing structures.
Multi-Compliance ISMS A complete ISMS tool that guides you towards ISO 27001 certification and at the same time supports other frameworks such as BSI Grundschutz, TISAX® and NIS2.
Automated processes Automated ISMS workflows that lead you step by step through the certification process – even without prior experience.
Review questionnaires Simple, customisable questionnaires that help you determine protection needs quickly and transparently. Risk-based information security has never been easier.
Personal support Direct access to experienced consultants who guide you from initial gap analysis to audit preparation and beyond.
By combining structured management systems (e.g. ISO 27001, ISO/IEC 42001) with digital tooling, you can make AI and information security not only compliant, but also efficient and auditable.
Challenges and open questions
As promising as the SBOM for AI concept is, there are still major challenges when it comes to implementation.
One of the biggest hurdles is standardisation. While classic SBOMs already exist in established formats, the AI ecosystem lacks uniform data models, interfaces and tools. Existing artifacts such as Model Cards or System Cards are often not machine-readable, hard to automate and difficult to integrate into enterprise processes.
Legal questions are another sensitive area. In many cases, models, training data and pipelines involve confidential or proprietary information. Disclosing too many details can conflict with trade secrets or intellectual property. At the same time, regulators and users are rightly demanding more transparency and accountability. The goal must be a balanced compromise between openness and protection.
The dynamic nature of AI systems also adds complexity. Techniques such as model distillation, synthetic data, continuous learning or frequent retraining make it harder to keep a complete and up-to-date picture of a system. An SBOM for AI must therefore be:
kept current,
integrated with change and release management,
and maintained through automated processes and clear governance.
Without this, the SBOM risks becoming outdated and losing its value.
A key development in this context is ISO/IEC 42001. As the first international management system standard dedicated specifically to AI, it addresses many of these gaps. It defines requirements for how organisations manage the responsible, transparent and secure use of AI systems across their lifecycle – including topics such as algorithmic decision-making, data ethics and traceability.
ISO/IEC 42001 complements existing standards like ISO 27001 or ISO 9001 and provides a structured framework that can be closely linked with an SBOM for AI. Together, these approaches can make AI systems not only more transparent, but also auditable and sustainably governable.
Outlook: The G7 process as an enabler
The SBOM for AI concept was developed within the G7 cybersecurity working group, led by Germany’s BSI and the Italian cybersecurity authority. This international collaboration is deliberate: AI is global by nature – and so are its risks.
A central outcome of the Ottawa meeting was a shared understanding of the core information categories that an SBOM for AI should contain. The next step is to define a “minimum set of elements” – a standardised baseline that allows vendors, developers and auditors to document AI systems in a structured and comparable way.
The G7 process aims to:
align with existing SBOM frameworks,
intensify collaboration with tool vendors,
and open the dialogue with companies, authorities and researchers.
The objective is clear: turn the SBOM for AI from a concept into a practical tool – and in doing so, create a new level of transparency and security for AI systems.
Next step
Continue reading about KRITIS and resilience requirements for critical infrastructures – and learn how you can combine SBOM for AI, ISO/IEC 42001 and an ISMS to build a future-proof security and compliance strategy.

Srdan Manasijevic
CEO
Expert in information security, data protection and risk management with extensive experience advising enterprises and public-sector organizations. Specialized in ISO 27001, BSI and advanced risk methodologies.


