> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.governanceaicore.com/core-concepts/ai-bom/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.governanceaicore.com/_mcp/server. # AI Bill of Materials (AI BOM) > Track AI model inventory, dependencies, and compliance requirements with AI BOM # AI Bill of Materials (AI BOM) AI Bill of Materials (AI BOM) provides complete visibility into your AI model inventory, dependencies, data flows, and compliance requirements. ## What is AI BOM? AI BOM is a comprehensive inventory of: * **Models** - LLMs, fine-tuned models, embeddings used * **Dependencies** - Framework versions, libraries, data sources * **Risks** - Vulnerabilities, licensing issues, compliance gaps * **Exports** - Standard formats (CycloneDX, SPDX, SARIF, Markdown) ### Key Information Captured ```yaml AI BOM: models: - name: GPT-4 version: "1106" provider: OpenAI purpose: General chat data_flows: [customer_input, internal_docs] license: Proprietary risks: [API_limit_reached, high_cost] dependencies: - package: langchain version: "0.1.0" license: MIT vulnerabilities: [] - package: openai-python version: "1.3.5" license: MIT vulnerabilities: [CVE-2024-1234] data_flows: - source: customer_input model: GPT-4 destination: response compliance_requirements: [GDPR, CCPA] compliance: frameworks: [SOC2, HIPAA] status: 85% compliant gaps: [audit_logging_incomplete, no_data_retention_policy] ``` ## How AI BOM Works ### Automated Discovery GovernanceAI scans your codebase to automatically discover: ``` Git Repository ├─ .github/workflows/*.yml → GitHub Actions scanning LLMs ├─ requirements.txt → Python dependencies and versions ├─ package.json → Node.js packages ├─ Dockerfile → Container base images ├─ src/ → Code references to LLM calls └─ docs/ → Model usage documentation ``` **Example Detection:** ```python # Your code from openai import OpenAI client = OpenAI(api_key=os.getenv("OPENAI_API_KEY")) response = client.chat.completions.create( model="gpt-4-turbo", messages=[{"role": "user", "content": "..."}] ) ``` **AI BOM automatically detects:** * ✅ Model: GPT-4 Turbo * ✅ Provider: OpenAI * ✅ Framework: openai-python SDK * ✅ Package versions * ✅ Vulnerability: CVE-2024-1234 in openai==1.3.5 ### Risk Assessment AI BOM categorizes risks: | Category | Examples | Severity | | ----------- | ------------------------------------------ | -------- | | Security | Known vulnerabilities, outdated packages | High | | Compliance | GDPR data handling, audit logging | High | | Operational | Rate limits, API costs, latency | Medium | | Licensing | GPL requirements, proprietary restrictions | Medium | | Data | Sensitive data in prompts, retention | High | ## Using AI BOM ### View in Dashboard * **Inventories** section * Click **AI BOM** * Browse discovered models and dependencies * Filter by risk level, framework, provider * View detailed information per model ### Generate Reports ```bash # Export as CycloneDX (SBOM standard) curl -H "Authorization: Bearer $API_KEY" \ https://api.governanceai.com/v1/ai-bom/export \ -d '{"format": "cyclonedx"}' \ > sbom.xml # Export as SPDX (License compliance) curl -H "Authorization: Bearer $API_KEY" \ https://api.governanceai.com/v1/ai-bom/export \ -d '{"format": "spdx"}' \ > sbom.spdx.json # Export as SARIF (Security findings) curl -H "Authorization: Bearer $API_KEY" \ https://api.governanceai.com/v1/ai-bom/export \ -d '{"format": "sarif"}' \ > findings.sarif # Export as Markdown (Human readable) curl -H "Authorization: Bearer $API_KEY" \ https://api.governanceai.com/v1/ai-bom/export \ -d '{"format": "markdown"}' \ > inventory.md ``` ### CycloneDX Example ```xml My AI Application 1.0.0 openai 1.3.5 pkg:pypi/openai@1.3.5 7.5 API key exposure in logs ``` ## Compliance Mapping AI BOM maps your inventory against compliance frameworks: ### SOC2 Type II Mapping ``` SOC2 Control: CC6.1 - Restrict logical access ├─ Requirement: Control who can access LLM APIs ├─ AI BOM Finding: │ └─ openai SDK has hardcoded API key in config.py:45 ├─ Status: VIOLATION └─ Remediation: Move to environment variables SOC2 Control: CC7.2 - Monitor system components ├─ Requirement: Log all LLM API calls ├─ AI BOM Finding: │ └─ API call logging enabled ✓ ├─ Status: COMPLIANT └─ Evidence: 1.2M logged calls in past 30 days ``` ### HIPAA Mapping ``` HIPAA Rule: Privacy Rule (45 CFR § 164.504) ├─ Requirement: Encryption of ePHI in transit and at rest ├─ AI BOM Finding: │ └─ GPT-4 API uses TLS 1.2+ ✓ │ └─ Prompts may contain patient names/IDs ⚠ ├─ Status: PARTIALLY COMPLIANT └─ Action: Add PII masking guardrail ``` ## Data Flow Tracking AI BOM tracks where sensitive data goes: ``` User Input ├─ May contain: Name, Email, SSN │ ├─ GPT-4 API Call │ └─ Data flows to OpenAI (USA) │ └─ Complies with: GDPR (standard contracts), CCPA │ ├─ Embedding Model │ └─ Data flows to Pinecone (AWS) │ └─ Stored for vector search │ └─ Logging System └─ Data flows to DataDog (EU) └─ Complies with: GDPR (sub-processor) ``` ## Automated Scanning ### Schedule Scans ```bash curl -X POST https://api.governanceai.com/v1/ai-bom/scans/schedule \ -H "Authorization: Bearer $API_KEY" \ -d '{ "name": "Daily AI Inventory Scan", "schedule": "0 2 * * *", # 2 AM daily "repositories": ["all"], "scan_options": { "include_dependencies": true, "check_vulnerabilities": true, "analyze_data_flows": true, "generate_report": true } }' ``` ### On-Demand Scan ```bash curl -X POST https://api.governanceai.com/v1/ai-bom/scans \ -H "Authorization: Bearer $API_KEY" \ -d '{ "repositories": ["repo_1", "repo_2"], "priority": "high" }' ``` ### Webhook Integration Get notified when risks are detected: ```bash # Configure webhook curl -X POST https://api.governanceai.com/v1/webhooks \ -H "Authorization: Bearer $API_KEY" \ -d '{ "event": "ai_bom.vulnerability_detected", "url": "https://your-domain.com/webhooks/ai-bom", "filters": { "severity": ["high", "critical"] } }' ``` Webhook payload: ```json { "event": "ai_bom.vulnerability_detected", "timestamp": "2024-01-15T10:30:00Z", "vulnerability": { "cve": "CVE-2024-1234", "package": "openai", "version": "1.3.5", "severity": "high", "description": "API key exposure in debug logs", "remediation": "Upgrade to 1.3.6 or later" } } ``` ## Compliance Reports ### Generate Compliance Report ```bash curl -X POST https://api.governanceai.com/v1/reports/compliance \ -H "Authorization: Bearer $API_KEY" \ -d '{ "frameworks": ["SOC2", "HIPAA"], "format": "pdf", "period": "Q1" }' \ > compliance_report_q1.pdf ``` ### Report Contents ``` Compliance Report - Q1 2024 ├─ Executive Summary │ ├─ Overall compliance: 85% │ ├─ Critical gaps: 3 │ └─ Trend: +5% from Q4 ├─ Framework Details │ ├─ SOC2: 92% compliant │ │ └─ 1 control violation │ ├─ HIPAA: 78% compliant │ │ └─ 5 control violations │ └─ GDPR: 89% compliant │ └─ 2 control violations ├─ Finding Details │ ├─ High: Unencrypted API keys in logs │ ├─ Medium: Missing audit logging │ └─ Low: Old package versions └─ Recommendations ├─ Immediate: Rotate API keys ├─ This week: Enable audit logging └─ This month: Update dependencies ``` ## Integration with CI/CD ### GitHub Actions Example ```yaml name: AI BOM Scan on: [push, pull_request] jobs: ai-bom-scan: runs-on: ubuntu-latest steps: - uses: actions/checkout@v3 - name: Scan with GovernanceAI run: | curl -X POST https://api.governanceai.com/v1/ai-bom/scans \ -H "Authorization: Bearer ${{ secrets.GOVERNANCEAI_API_KEY }}" \ -d '{ "repository": "${{ github.repository }}", "ref": "${{ github.ref }}" }' - name: Check Results run: | # Fail if critical vulnerabilities found curl -H "Authorization: Bearer ${{ secrets.GOVERNANCEAI_API_KEY }}" \ https://api.governanceai.com/v1/ai-bom/results/latest \ | jq -e '.critical_vulnerabilities | length == 0' ``` ## Best Practices ✅ **Do:** * Scan regularly (weekly minimum) * Review dependencies quarterly * Update vulnerable packages promptly * Track data flows for sensitive data * Export reports for compliance audits * Set up webhooks for critical alerts ❌ **Don't:** * Hardcode API keys (use environment variables) * Ignore vulnerability warnings * Deploy models with unpatched vulnerabilities * Share raw AI BOM data containing credentials * Forget to update dependencies ## Next Steps * **[Running Scans](/usage-guides/scans)** - Scan your repositories * **[Compliance Frameworks](./04-compliance-frameworks.mdx)** - Map to compliance standards * **[API Reference](/api)** - AI BOM API endpoints > Track AI model inventory, dependencies, and compliance requirements with AI BOM