

Guidance
This section will host practical guidance for creating, maintaining, and
operationalizing an AI Bill of Materials (AIBOM).
Workstreams
Prerequisites
The Prerequisites workstream team is assessing existing AI Bill of Materials (AI BOM) standards, particularly SBOM formats like CycloneDX 1.6 and SPDX 3.0, to determine how well they address AI-system requirements and where extensions may be needed. Over the past week, the team conducted a gap analysis of these standards and deepened its understanding of AI data lifecycle management, including model and data tracking. In the coming week, they plan to identify whether current specifications should be enhanced to represent AI assets such as dataset versioning, fine-tuning parameters, and key gap domains across architecture (model), data (provenance/integrity), and risk/governance.
Foundational Best Practices
The Foundational Best Practices workstream, is focused on creating a clear, actionable, and adoption-oriented foundation for AIBOM. Over the past week, the team completed the Table of Contents and mapped its alignment with other workstreams, finalized RACI-based roles and responsibilities, and defined the threat landscape and taxonomy. The upcoming week’s focus is on continuing development of the AIBOM Lifecycle by referencing established SBOM frameworks like CycloneDX. The roadmap aims for a version 0.1 release in November 2025, with progress currently on track for the end-of-month milestone.