Think of an AI Bill of Materials (AI BOM) as an ingredient list for an artificial intelligence system. Whereas an SBOM inventories code libraries and dependencies, an AI BOM documents the models, datasets, training history, licensing, and operational metadata that define an AI system's behavior and risk profile. It's a newer idea, but the push to make it standard practice is accelerating fast.
Regulators in Europe and the US are increasingly requiring them for high-risk AI systems, either explicitly or as part of broader SBOMs. The G7 recently published minimum guidelines for what an AI BOM should contain, and industry groups like ISACA now recommend requesting one as standard due diligence when procuring AI technology. The urgency is real — the number of AI models on Hugging Face doubled to two million last year, and malicious models on the platform surged six-and-a-half times compared to the prior year. Some backdoored models even passed all security checks.
The problem is that actual adoption remains largely aspirational. Experts say that even foundational datasets often don't fully disclose their data sources, and many organizations simply don't track their AI components at the level of detail a thorough BOM would require. Early draft standards that tried to capture everything faced serious pushback from practitioners who found them unworkable.
With the EU AI Act going live in August and agentic AI systems becoming more prevalent in critical business infrastructure, 2026 could be the year AI BOMs move from buzzword to boardroom reality — but only if the industry commits to practical, adoptable standards rather than perfect ones.