PlatformPlatform architectureProduct tourProduct graphRisk intelligenceContinuous governanceEvidence & auditDeploymentIntegrationsExecutive view
BOM SuiteSBOMCBOMQBOMAIBOMHBOMBOM Governance
SolutionsSecurityComplianceSupply chain riskQuantum readinessAI governanceDigital trust
ComplianceCERT-InRBISEBI / CSCRFMeitYNISTEU CRAEU AI ActCERT-In SBOM guide
IndustriesBanking & Financial ServicesGovernment & Public SectorDefence & Critical InfrastructureHealthcareIndian enterprises
ResourcesResource centreSBOM resourcesCBOM resourcesQBOM resourcesAIBOM resourcesHBOM resourcesProgramme & regulationBlog
CompanyAboutSecurity & trustContact
Request a DemoTalk to an expert
Compliance3 min readReviewed September 20268 sources

AI procurement requirements for vendors and model providers

Most organisations buy more AI than they build. Procurement is where you can require suppliers to tell you what their systems contain and to keep telling you as those systems change.

Key takeaways
  • Commentary on CERT-In's guidelines notes an expectation that public-sector AI procurement includes an AIBOM.
  • The EU AI Act requires written agreements between high-risk AI providers and their component suppliers on the information needed for compliance.
  • US OMB M-25-22 sets AI contract terms on portability, data use and performance monitoring.
  • Specify format, required fields, update triggers and validation at intake, not just 'provide an AIBOM'.

Why procurement is the control point

An organisation cannot generate an accurate AIBOM for a vendor's model it cannot inspect. The supplier has to provide it. Several frameworks now point to contracts as the mechanism:

  • India: reporting on CERT-In's Version 2.0 guidelines notes that government, public-sector and essential-services organisations engaged in AI procurement are expected to include an AIBOM [1]. The guidelines define the minimum AIBOM elements [2].
  • EU: Article 25(4) of the AI Act requires high-risk AI providers and suppliers of AI tools, services, components or processes to agree in writing the information, technical access and assistance needed for compliance, with an exemption for free and open-source components [3].
  • US federal: OMB M-25-22 requires AI contracts to address vendor lock-in, data and model portability, and ongoing performance monitoring, and to prohibit use of non-public agency data to train publicly or commercially available AI without permission [4].
  • Banking: the RBI FREE-AI report recommends board-approved AI policies covering third-party vendor liabilities [5].

What to require

RequirementWhat to specify
FormatCycloneDX (ML-BOM) or SPDX 3.0 with AI and Dataset profiles, with a named minimum version
Required fieldsCERT-In Table 10 elements, or the G7 SBOM for AI clusters, plus your own additions
ScopeAll models, datasets, AI software, infrastructure and third-party AI services, including subcontracted ones
Update triggersNew AIBOM on retraining, model replacement, provider change or major dependency upgrade
IntegrityArtefact hashes; signatures where available
Security evidenceVulnerability status of AI software, model scan results, adversarial testing summary
Data useWhether your data is used to train the supplier's models, and on what terms
NotificationTime limits for notifying compromised components or material model changes

The G7 minimum elements, published in May 2026, group AIBOM content into seven clusters and are a useful, voluntary reference for the required-fields clause [6].

Sample clause language

The following is illustrative and should be adapted with legal advice.

  1. "The Supplier shall deliver, with each release of the AI System, an AI Bill of Materials in CycloneDX version 1.6 or later, or SPDX version 3.0 or later, containing at minimum the elements listed in Schedule X."
  2. "The Supplier shall deliver an updated AIBOM within [N] days of any retraining, replacement of a model, change of third-party AI service provider, or change to training datasets."
  3. "The AIBOM shall identify each third-party model, dataset and AI service used, including those used by subcontractors."
  4. "The Supplier shall notify the Customer within [N] hours of becoming aware that a component listed in the AIBOM is compromised or affected by a vulnerability."

Questions for model providers

  • Which base models, adapters and datasets does the product use, and under what licences?
  • How will we be told when the underlying hosted model version changes?
  • Is our data used to train or fine-tune any model?
  • What testing has been done against supply-chain and poisoning threats, such as those listed in OWASP LLM03 [7]?
  • For general-purpose AI models in the EU, can you provide the downstream information required under Article 53 [8]?

At intake

Validate every supplier AIBOM on receipt against schema and your required fields, and reject or flag incomplete deliveries (How to validate an AIBOM). Store each version so you can see what changed between deliveries (AIBOM management).

How IntelliXBOM helps

IntelliXBOM ingests supplier AIBOMs in CycloneDX and SPDX, validates them against the required-field policy in your contract, and keeps each delivery as a version with diffs. It correlates listed components with vulnerabilities and licences and records the results as timestamped evidence.

This article summarises public guidance and is not legal advice.

Frequently asked questions

What should an AI vendor provide in procurement?

At minimum, an AIBOM in CycloneDX or SPDX covering models, datasets, AI software and third-party AI services, with versions, licences and hashes. Contracts should also cover update triggers, data use and incident notification.

Does the EU AI Act require suppliers to share information?

Article 25(4) requires high-risk AI providers and suppliers of components used in those systems to agree in writing the information and assistance needed for compliance. Suppliers of free and open-source components are exempt.

Which fields should an AIBOM clause require?

Many organisations use CERT-In's Table 10 elements or the G7 SBOM for AI clusters as a baseline, then add their own requirements such as artefact hashes, owners and data-use disclosures.

Sources

  1. How Do CERT-In's AIBOM Guidelines Affect AI Procurement?MediaNamawww.medianama.com/2025/07/223-cert-in-ai-bill-of-materials-guidelines/
  2. Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf
  3. AI Act Article 25: Responsibilities Along the AI Value ChainEU AI Act Explorer (Future of Life Institute)artificialintelligenceact.eu/article/25/
  4. OMB M-25-22, Driving Efficient Acquisition of Artificial Intelligence in Government (3 April 2025)The White House, Office of Management and Budgetwww.whitehouse.gov/wp-content/uploads/2025/02/M-25-22-Driving-Efficient-Acquisition-of-Artificial-Intelligence-in-Government.pdf
  5. ERGO: RBI's FREE-AI Framework (28 August 2025)Khaitan & Cowww.khaitanco.com/sites/default/files/2025-08/Ergo%20-%20FREE%20AI%20Framework%20-%2028%20Augusut%202025.pdf
  6. Global Cyber Agencies Issue New SBOMs for AI GuidanceInfosecurity Magazinewww.infosecurity-magazine.com/news/new-sboms-for-ai-guidance-2026/
  7. LLM03:2025 Supply ChainOWASP Gen AI Security Projectgenai.owasp.org/llmrisk/llm032025-supply-chain/
  8. AI Act Article 53: Obligations for Providers of General-Purpose AI ModelsEU AI Act Explorer (Future of Life Institute)artificialintelligenceact.eu/article/53/

Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.

Related AIBOM guides

Across the BOM Suite

Put your AIBOM under governance.AI supply-chain transparency with continuous correlation and timestamped evidence.