An AIBOM (AI bill of materials) is an inventory of what an AI system is made of: the models it uses and their versions, the datasets behind them where known, the tools, MCP servers and other agents it calls, its prompts and policies, and the software packages underneath. Like a software bill of materials, it lets someone outside the build team see what is inside, check it against known problems, and compare one release with the next.

What goes in an AIBOM

  • Models: provider, name, version and licence where available.
  • Data: datasets used for training, fine-tuning or retrieval, with their source.
  • Tools and connections: MCP servers, APIs and other agents the system can call.
  • Configuration: system prompts, guardrails and policies that shape behaviour.
  • Software: the packages and frameworks, often taken from an existing SBOM.

Two open standards can carry this data: CycloneDX, through its machine-learning bill of materials (ML-BOM), and SPDX 3.0, which adds AI and dataset profiles.

How it differs from an SBOM

An SBOM lists software components and their versions so vulnerabilities and licences can be tracked. An AIBOM keeps that and adds the parts that change an AI system's behaviour without changing its code: a model version, a dataset, a prompt, a tool connection or a policy. Two releases with identical SBOMs can behave differently if one of those changed, which is why AIBOMs are compared release to release.

Why it matters for compliance

The EU AI Act asks providers of high-risk AI systems to keep technical documentation (Annex IV) that describes how the system was built, including any pre-trained systems or third-party tools it relies on, and the data it was trained on. An AIBOM is a practical way to keep that description current. ISO/IEC 42001 likewise asks organizations to document the resources an AI system uses, including data and tooling. An inventory also exposes shadow AI: components nobody approved show up as soon as someone lists what is there.

How Praesidia approaches evidence for AI systems is described on AI audit evidence.

Common questions

Is an AIBOM the same as a model card?

No. A model card describes one model: its intended use, evaluation results and limitations. An AIBOM lists everything an AI system is assembled from, which can include several models, each with its own card.

Who should produce an AIBOM?

Whoever assembles the AI system, usually the team that ships it, with component details from model and tool providers. A buyer can ask a vendor for one in the same way they ask for an SBOM.