C1 News AI & Innovation · May 18, 2026

Is 2026 the Year AI Bills of Materials Get Real?

AI Bills of Materials are gaining regulatory momentum, but real-world adoption is still lagging dangerously behind.

Reading level

Switch if this feels too hard or too easy.

Think of an AI Bill of Materials (AI BOM) as an ingredient list for an artificial intelligence system. Whereas an SBOM inventories code libraries and dependencies, an AI BOM documents the models, datasets, training history, licensing, and operational metadata that define an AI system's behavior and risk profile. It's a newer idea, but the push to make it standard practice is accelerating fast.

Regulators in Europe and the US are increasingly requiring them for high-risk AI systems, either explicitly or as part of broader SBOMs. The G7 recently published minimum guidelines for what an AI BOM should contain, and industry groups like ISACA now recommend requesting one as standard due diligence when procuring AI technology. The urgency is real — the number of AI models on Hugging Face doubled to two million last year, and malicious models on the platform surged six-and-a-half times compared to the prior year. Some backdoored models even passed all security checks.

The problem is that actual adoption remains largely aspirational. Experts say that even foundational datasets often don't fully disclose their data sources, and many organizations simply don't track their AI components at the level of detail a thorough BOM would require. Early draft standards that tried to capture everything faced serious pushback from practitioners who found them unworkable.

With the EU AI Act going live in August and agentic AI systems becoming more prevalent in critical business infrastructure, 2026 could be the year AI BOMs move from buzzword to boardroom reality — but only if the industry commits to practical, adoptable standards rather than perfect ones.

Get more from every article

Highlight any word or phrase for an explanation or translation, save vocabulary, and bookmark articles.

📚 Key vocabulary

due diligence (noun)
careful research and checks done before making a business decision to avoid risk
"Before signing the contract, the procurement team completed full due diligence on the vendor's security practices."
procure (verb)
to obtain or purchase something, especially for professional or organizational use
"The IT department is responsible for procuring software that meets the company's security standards."
prevalent (adj)
very common or widespread in a particular situation or environment
"Cloud-based tools have become prevalent in remote working environments over the past few years."
aspirational (adj)
describing a goal or idea that is desired but not yet achieved in practice
"The company's sustainability targets are still largely aspirational and lack a clear implementation plan."
surge (verb)
to increase suddenly and dramatically
"Demand for cybersecurity professionals has surged since the rise of large-scale data breaches."

✨ Useful phrases for this topic

"as part of broader due diligence"
Use this when explaining that a specific check or requirement sits within a larger process of risk assessment or verification.
"Reviewing a vendor's data handling practices should be done as part of broader due diligence before signing any agreement."
"goes live"
Use this to describe the moment a law, system, or product officially becomes active or enforceable.
"The new data privacy regulation goes live in January, so all teams need to be compliant before then."
"attack surface"
Use this in cybersecurity discussions to refer to all the points where an unauthorized user could try to enter or extract data from a system.
"Adopting more third-party integrations significantly expands your attack surface and requires additional monitoring."

Advanced sentence structures

Patterns from this article you can use in meetings, emails, and everyday English

Structure 1

In context

Regulators in Europe and the US are increasingly requiring them for high-risk AI systems, either explicitly or as part of broader SBOMs.

The skeleton

Frame: [Authority/group] are increasingly [verb]-ing [object] for [context], either [option A] or [option B].

What it does: Describes a growing trend by naming who is acting, what they demand, and two ways it appears.

Quick swap: "Employers are increasingly requiring proof of certification for remote roles, either at hiring or as part of annual reviews."

More examples

  • "Airlines are increasingly requiring passengers to verify their identity digitally, either at check-in or as part of the boarding process."
  • "Universities are increasingly requiring evidence of research experience for postgraduate applications, either through a portfolio or as part of a personal statement."
  • "City councils are increasingly requiring landlords to meet energy efficiency standards for rental properties, either immediately or as part of a phased compliance schedule."

Easy exercise

Arrange the words and add the missing structural elements to build a correct sentence.

  1. AI systems · high-risk · explicitly · standards bodies · increasingly requiring · documentation for · or as part of broader regulations
  2. job applicants · digital references · either at the offer stage · employers · increasingly requiring · or as part of onboarding
Show answers
  • "Standards bodies are increasingly requiring documentation for high-risk AI systems, either explicitly or as part of broader regulations."
  • "Employers are increasingly requiring digital references from job applicants, either at the offer stage or as part of onboarding."

Open exercise

Write your own sentence using this structure. You can write about anything — here are some ideas if you need them:

  • What governments or regulators are demanding from tech companies
  • What managers are starting to expect from employees in your field
  • What schools or universities now ask of students or parents

One possible answer: "Hospitals are increasingly requiring staff to complete cybersecurity training for patient data systems, either annually or as part of a new role induction."

Structure 2

In context

Whereas an SBOM inventories code libraries and dependencies, an AI BOM documents the models, datasets, training history, licensing, and operational metadata that define an AI system's behavior and risk profile.

The skeleton

Frame: Whereas [Subject A] [verb] [Object A], [Subject B] [verb] [Object B].

What it does: Contrasts two things directly by placing them in parallel clauses, highlighting how they differ.

Quick swap: "Whereas a CV lists your qualifications and experience, a cover letter explains your motivation and fit for the role."

More examples

  • "Whereas a budget forecast estimates future spending, an audit report examines what was actually spent and why."
  • "Whereas a news article summarises events for a general audience, an academic paper analyses causes and evidence for specialists."
  • "Whereas traditional advertising targets broad demographic groups, personalised marketing targets individual behaviour and preferences."

Easy exercise

Arrange the words and add the missing structural elements to build a correct sentence.

  1. tracks known software components · an AI BOM · an SBOM · captures data sources · whereas · and model behaviour
  2. a contract outlines agreed terms and obligations · whereas · a memorandum of understanding · states general intentions and shared goals
Show answers
  • "Whereas an SBOM tracks known software components, an AI BOM captures data sources and model behaviour."
  • "Whereas a contract outlines agreed terms and obligations, a memorandum of understanding states general intentions and shared goals."

Open exercise

Write your own sentence using this structure. You can write about anything — here are some ideas if you need them:

  • The difference between two tools or systems used in your industry
  • How two types of workplace communication differ in purpose
  • How two approaches to learning or training compare

One possible answer: "Whereas a project brief defines the scope and objectives of a task, a project report evaluates what was achieved and what went wrong."

💬 Discussion questions

1

If your company started using a new AI tool tomorrow, what information would you personally want to know about it before trusting it with sensitive data?

2

Some experts argue that a simple, imperfect AI BOM standard is better than waiting for a perfect one. Do you agree — or does an incomplete standard give companies a false sense of security?

3

How does your organization currently track the technology tools and software it uses? What would need to change to include AI systems in that process?