AI Bill of Materials (AI BOM)
AI Bill of Materials (AI BOM)
AI Bill of Materials (AI BOM) provides complete visibility into your AI model inventory, dependencies, data flows, and compliance requirements.
What is AI BOM?
AI BOM is a comprehensive inventory of:
- Models - LLMs, fine-tuned models, embeddings used
- Dependencies - Framework versions, libraries, data sources
- Risks - Vulnerabilities, licensing issues, compliance gaps
- Exports - Standard formats (CycloneDX, SPDX, SARIF, Markdown)
Key Information Captured
How AI BOM Works
Automated Discovery
GovernanceAI scans your codebase to automatically discover:
Example Detection:
AI BOM automatically detects:
- ✅ Model: GPT-4 Turbo
- ✅ Provider: OpenAI
- ✅ Framework: openai-python SDK
- ✅ Package versions
- ✅ Vulnerability: CVE-2024-1234 in openai==1.3.5
Risk Assessment
AI BOM categorizes risks:
Using AI BOM
View in Dashboard
- Inventories section
- Click AI BOM
- Browse discovered models and dependencies
- Filter by risk level, framework, provider
- View detailed information per model
Generate Reports
CycloneDX Example
Compliance Mapping
AI BOM maps your inventory against compliance frameworks:
SOC2 Type II Mapping
HIPAA Mapping
Data Flow Tracking
AI BOM tracks where sensitive data goes:
Automated Scanning
Schedule Scans
On-Demand Scan
Webhook Integration
Get notified when risks are detected:
Webhook payload:
Compliance Reports
Generate Compliance Report
Report Contents
Integration with CI/CD
GitHub Actions Example
Best Practices
✅ Do:
- Scan regularly (weekly minimum)
- Review dependencies quarterly
- Update vulnerable packages promptly
- Track data flows for sensitive data
- Export reports for compliance audits
- Set up webhooks for critical alerts
❌ Don’t:
- Hardcode API keys (use environment variables)
- Ignore vulnerability warnings
- Deploy models with unpatched vulnerabilities
- Share raw AI BOM data containing credentials
- Forget to update dependencies
Next Steps
- Running Scans - Scan your repositories
- Compliance Frameworks - Map to compliance standards
- API Reference - AI BOM API endpoints