AI Governance Library

G7 Software Bill of Materials for AI: Minimum Elements

Drawing from the existing Software Bill of Materials (SBOM) concept, an SBOM for AI consists of a structured record, or inventory of details and supply chain relationships for the various components used in building an AI system.
G7 Software Bill of Materials for AI: Minimum Elements

⚡ Quick Summary

Jointly authored by the cybersecurity agencies of the G7 nations (BSI, ACN, ANSSI, CSE, CISA, NCSC, and NCO) alongside the European Commission, this guidance establishes a consensus baseline of minimum elements for an Artificial Intelligence Software Bill of Materials (SBOM for AI). Building upon traditional SBOM foundations, the document defines actionable transparency expectations across seven core clusters to track vulnerabilities, understand dependencies, and manage cybersecurity risks across the AI supply chain. While non-mandatory and not a formal standard, it serves as an authoritative international blueprint for both AI developers and deployers.

🧩 What's Covered

The guidance defines an SBOM for AI as a structured record capturing supply chain relationships and distinctive technical components of AI systems across seven foundational clusters:

  • Metadata Cluster: Captures essential provenance about the SBOM artifact itself, including author identity, document version, machine-processable data format and version, digital author signatures (referencing NIST, ISO/IEC 14888-4, or ENISA standards), tooling details, generation context lifecycle phase, timestamps (RFC 9557), and dependency relationships.
  • System Level Properties (SLP): Documents system-wide characteristics such as system name, composite sub-components (models, databases, utilities), producer identity, versioning, data flow mappings across endpoints and multi-agent protocols, data usage policies, input/output modality characteristics, and intended operational domains.
  • Models Cluster: Details model-specific metadata including unique software identifiers (CPE, PURL, SWHID, OmniBOR), cryptographic hash values and approved hash algorithms, architectural parameters, input/output modalities, training and alignment techniques (supervised learning, RLHF, DPO, PPO, GRPO), licensing, and external lineage links.
  • Datasets Properties (DP): Details training, fine-tuning, and evaluation data properties, covering dataset identification, cryptographic hashes, provenance and collection methodology (web scraping, commercial feeds, synthetic generation), statistical properties, dataset sensitivity classifications (PII, intellectual property, medical or classified data), data pipelines, and licensing.
  • Infrastructure Cluster: Catalogues underlying execution dependencies, splitting elements into infrastructure software (firmware, runtime environments, frameworks) and links to Hardware Bills of Materials (HBOM).
  • Security Properties (SP): Discloses technical security controls—including AI-specific mitigations such as prompt injection defenses and adversarial robustness—alongside compliance certifications, security contact policies (security.txt), and external vulnerability database references.
  • Key Performance Indicators (KPI): Tracks security benchmarks (such as empirical robustness against manipulation) and operational metrics (system uptime, latency, request throughput).

💡 Why it matters?

As complex AI architectures, large language models, and agentic workflows integrate into critical workflows, traditional software component inventories fail to capture non-code risks inherent to weights, training datasets, and post-training alignment techniques. This G7 publication aligns seven leading national cybersecurity agencies on a common vocabulary for AI supply chain transparency. Implementing these minimum elements enables procurement teams, enterprise defenders, and governance leads to systematically evaluate model lineage, detect data sensitivity exposures, and streamline automated vulnerability management across third-party AI assets.

❓ What's Missing

The document deliberately omits formal implementation schemas, specific file serialization formats, or mandatory legal enforcement mechanisms. Furthermore, while the working group discussed capturing system autonomy and agentic decision-making levels, they opted to exclude autonomous agency as a standalone element for now. The authors also acknowledge that an SBOM for AI provides transparency but does not secure systems on its own without integration into active vulnerability scanners and threat intelligence feeds.

👥 Best For

AI developers, cybersecurity architects, software supply chain security engineers, enterprise risk managers, procurement officers, and compliance professionals seeking to implement or evaluate AI asset transparency.

📄 Source Details

Published by the G7 Cybersecurity Working Group (Germany's BSI, Italy's ACN, France's ANSSI, Canada's CSE, US CISA, UK NCSC, Japan's NCO) in collaboration with the European Commission (February 2026, 24 pages).

📝 Thanks to

Special recognition to the G7 Presidencies of Canada (2025) and France (2026), and the work stream co-leads Italy (ACN) and Germany (BSI) for coordinating this joint inter-agency framework.

About the author
Jakub Szarmach

AI Governance Library

Curated Library of AI Governance Resources

AI Governance Library

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to AI Governance Library.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.