> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.governanceaicore.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.governanceaicore.com/_mcp/server.

# AI Bill of Materials (AI BOM)

> Track AI model inventory, dependencies, and compliance requirements with AI BOM

# AI Bill of Materials (AI BOM)

AI Bill of Materials (AI BOM) provides complete visibility into your AI model inventory, dependencies, data flows, and compliance requirements.

## What is AI BOM?

AI BOM is a comprehensive inventory of:

* **Models** - LLMs, fine-tuned models, embeddings used
* **Dependencies** - Framework versions, libraries, data sources
* **Risks** - Vulnerabilities, licensing issues, compliance gaps
* **Exports** - Standard formats (CycloneDX, SPDX, SARIF, Markdown)

### Key Information Captured

```yaml
AI BOM:
  models:
    - name: GPT-4
      version: "1106"
      provider: OpenAI
      purpose: General chat
      data_flows: [customer_input, internal_docs]
      license: Proprietary
      risks: [API_limit_reached, high_cost]

  dependencies:
    - package: langchain
      version: "0.1.0"
      license: MIT
      vulnerabilities: []
    - package: openai-python
      version: "1.3.5"
      license: MIT
      vulnerabilities: [CVE-2024-1234]

  data_flows:
    - source: customer_input
      model: GPT-4
      destination: response
      compliance_requirements: [GDPR, CCPA]

  compliance:
    frameworks: [SOC2, HIPAA]
    status: 85% compliant
    gaps: [audit_logging_incomplete, no_data_retention_policy]
```

## How AI BOM Works

### Automated Discovery

GovernanceAI scans your codebase to automatically discover:

```
Git Repository
├─ .github/workflows/*.yml → GitHub Actions scanning LLMs
├─ requirements.txt → Python dependencies and versions
├─ package.json → Node.js packages
├─ Dockerfile → Container base images
├─ src/ → Code references to LLM calls
└─ docs/ → Model usage documentation
```

**Example Detection:**

```python
# Your code
from openai import OpenAI
client = OpenAI(api_key=os.getenv("OPENAI_API_KEY"))
response = client.chat.completions.create(
    model="gpt-4-turbo",
    messages=[{"role": "user", "content": "..."}]
)
```

**AI BOM automatically detects:**

* ✅ Model: GPT-4 Turbo
* ✅ Provider: OpenAI
* ✅ Framework: openai-python SDK
* ✅ Package versions
* ✅ Vulnerability: CVE-2024-1234 in openai==1.3.5

### Risk Assessment

AI BOM categorizes risks:

| Category    | Examples                                   | Severity |
| ----------- | ------------------------------------------ | -------- |
| Security    | Known vulnerabilities, outdated packages   | High     |
| Compliance  | GDPR data handling, audit logging          | High     |
| Operational | Rate limits, API costs, latency            | Medium   |
| Licensing   | GPL requirements, proprietary restrictions | Medium   |
| Data        | Sensitive data in prompts, retention       | High     |

## Using AI BOM

### View in Dashboard

* **Inventories** section
* Click **AI BOM**
* Browse discovered models and dependencies
* Filter by risk level, framework, provider
* View detailed information per model

### Generate Reports

```bash
# Export as CycloneDX (SBOM standard)
curl -H "Authorization: Bearer $API_KEY" \
  https://api.governanceai.com/v1/ai-bom/export \
  -d '{"format": "cyclonedx"}' \
  > sbom.xml

# Export as SPDX (License compliance)
curl -H "Authorization: Bearer $API_KEY" \
  https://api.governanceai.com/v1/ai-bom/export \
  -d '{"format": "spdx"}' \
  > sbom.spdx.json

# Export as SARIF (Security findings)
curl -H "Authorization: Bearer $API_KEY" \
  https://api.governanceai.com/v1/ai-bom/export \
  -d '{"format": "sarif"}' \
  > findings.sarif

# Export as Markdown (Human readable)
curl -H "Authorization: Bearer $API_KEY" \
  https://api.governanceai.com/v1/ai-bom/export \
  -d '{"format": "markdown"}' \
  > inventory.md
```

### CycloneDX Example

```xml
<?xml version="1.0" ?>
<bom xmlns="http://cyclonedx.org/schema/bom/1.3">
  <metadata>
    <component type="application">
      <name>My AI Application</name>
      <version>1.0.0</version>
    </component>
  </metadata>
  <components>
    <component type="library">
      <name>openai</name>
      <version>1.3.5</version>
      <purl>pkg:pypi/openai@1.3.5</purl>
      <vulnerabilities>
        <vulnerability ref="CVE-2024-1234">
          <rating>7.5</rating>
          <description>API key exposure in logs</description>
        </vulnerability>
      </vulnerabilities>
    </component>
  </components>
</bom>
```

## Compliance Mapping

AI BOM maps your inventory against compliance frameworks:

### SOC2 Type II Mapping

```
SOC2 Control: CC6.1 - Restrict logical access
├─ Requirement: Control who can access LLM APIs
├─ AI BOM Finding:
│  └─ openai SDK has hardcoded API key in config.py:45
├─ Status: VIOLATION
└─ Remediation: Move to environment variables

SOC2 Control: CC7.2 - Monitor system components
├─ Requirement: Log all LLM API calls
├─ AI BOM Finding:
│  └─ API call logging enabled ✓
├─ Status: COMPLIANT
└─ Evidence: 1.2M logged calls in past 30 days
```

### HIPAA Mapping

```
HIPAA Rule: Privacy Rule (45 CFR § 164.504)
├─ Requirement: Encryption of ePHI in transit and at rest
├─ AI BOM Finding:
│  └─ GPT-4 API uses TLS 1.2+ ✓
│  └─ Prompts may contain patient names/IDs ⚠
├─ Status: PARTIALLY COMPLIANT
└─ Action: Add PII masking guardrail
```

## Data Flow Tracking

AI BOM tracks where sensitive data goes:

```
User Input
  ├─ May contain: Name, Email, SSN
  │
  ├─ GPT-4 API Call
  │  └─ Data flows to OpenAI (USA)
  │  └─ Complies with: GDPR (standard contracts), CCPA
  │
  ├─ Embedding Model
  │  └─ Data flows to Pinecone (AWS)
  │  └─ Stored for vector search
  │
  └─ Logging System
     └─ Data flows to DataDog (EU)
     └─ Complies with: GDPR (sub-processor)
```

## Automated Scanning

### Schedule Scans

```bash
curl -X POST https://api.governanceai.com/v1/ai-bom/scans/schedule \
  -H "Authorization: Bearer $API_KEY" \
  -d '{
    "name": "Daily AI Inventory Scan",
    "schedule": "0 2 * * *",  # 2 AM daily
    "repositories": ["all"],
    "scan_options": {
      "include_dependencies": true,
      "check_vulnerabilities": true,
      "analyze_data_flows": true,
      "generate_report": true
    }
  }'
```

### On-Demand Scan

```bash
curl -X POST https://api.governanceai.com/v1/ai-bom/scans \
  -H "Authorization: Bearer $API_KEY" \
  -d '{
    "repositories": ["repo_1", "repo_2"],
    "priority": "high"
  }'
```

### Webhook Integration

Get notified when risks are detected:

```bash
# Configure webhook
curl -X POST https://api.governanceai.com/v1/webhooks \
  -H "Authorization: Bearer $API_KEY" \
  -d '{
    "event": "ai_bom.vulnerability_detected",
    "url": "https://your-domain.com/webhooks/ai-bom",
    "filters": {
      "severity": ["high", "critical"]
    }
  }'
```

Webhook payload:

```json
{
  "event": "ai_bom.vulnerability_detected",
  "timestamp": "2024-01-15T10:30:00Z",
  "vulnerability": {
    "cve": "CVE-2024-1234",
    "package": "openai",
    "version": "1.3.5",
    "severity": "high",
    "description": "API key exposure in debug logs",
    "remediation": "Upgrade to 1.3.6 or later"
  }
}
```

## Compliance Reports

### Generate Compliance Report

```bash
curl -X POST https://api.governanceai.com/v1/reports/compliance \
  -H "Authorization: Bearer $API_KEY" \
  -d '{
    "frameworks": ["SOC2", "HIPAA"],
    "format": "pdf",
    "period": "Q1"
  }' \
  > compliance_report_q1.pdf
```

### Report Contents

```
Compliance Report - Q1 2024
├─ Executive Summary
│  ├─ Overall compliance: 85%
│  ├─ Critical gaps: 3
│  └─ Trend: +5% from Q4
├─ Framework Details
│  ├─ SOC2: 92% compliant
│  │  └─ 1 control violation
│  ├─ HIPAA: 78% compliant
│  │  └─ 5 control violations
│  └─ GDPR: 89% compliant
│     └─ 2 control violations
├─ Finding Details
│  ├─ High: Unencrypted API keys in logs
│  ├─ Medium: Missing audit logging
│  └─ Low: Old package versions
└─ Recommendations
   ├─ Immediate: Rotate API keys
   ├─ This week: Enable audit logging
   └─ This month: Update dependencies
```

## Integration with CI/CD

### GitHub Actions Example

```yaml
name: AI BOM Scan

on: [push, pull_request]

jobs:
  ai-bom-scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v3

      - name: Scan with GovernanceAI
        run: |
          curl -X POST https://api.governanceai.com/v1/ai-bom/scans \
            -H "Authorization: Bearer ${{ secrets.GOVERNANCEAI_API_KEY }}" \
            -d '{
              "repository": "${{ github.repository }}",
              "ref": "${{ github.ref }}"
            }'

      - name: Check Results
        run: |
          # Fail if critical vulnerabilities found
          curl -H "Authorization: Bearer ${{ secrets.GOVERNANCEAI_API_KEY }}" \
            https://api.governanceai.com/v1/ai-bom/results/latest \
            | jq -e '.critical_vulnerabilities | length == 0'
```

## Best Practices

✅ **Do:**

* Scan regularly (weekly minimum)
* Review dependencies quarterly
* Update vulnerable packages promptly
* Track data flows for sensitive data
* Export reports for compliance audits
* Set up webhooks for critical alerts

❌ **Don't:**

* Hardcode API keys (use environment variables)
* Ignore vulnerability warnings
* Deploy models with unpatched vulnerabilities
* Share raw AI BOM data containing credentials
* Forget to update dependencies

## Next Steps

* **[Running Scans](/usage-guides/scans)** - Scan your repositories
* **[Compliance Frameworks](./04-compliance-frameworks.mdx)** - Map to compliance standards
* **[API Reference](/api)** - AI BOM API endpoints