CISA, G7 Issue AI Software Bill of Materials Guidance to Boost Supply-Chain Transparency
A software bill of materials, or SBOM, serves as a system inventory and was originally used to track packages, versions and dependencies. Generative AI and machine learning also involve model provenance, training data, inference frameworks and GPU environments. Without transparent information, companies struggle to promptly identify vulnerabilities, sensitive data and third-party risks, making AI SBOMs an important foundation for procurement, governance and incident response.
On May 12, 2026, the U.S. Cybersecurity and Infrastructure Security Agency and the G7 Cybersecurity Working Group released Minimum Elements for an AI Software Bill of Materials. The guidance divides disclosures into seven categories: metadata, system properties, models, datasets, performance metrics, infrastructure and security properties. It is voluntary, creates no new legal obligations or funding commitments, and is designed to evolve alongside AI technology.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.