PlatformPlatform architectureProduct tourProduct graphRisk intelligenceContinuous governanceEvidence & auditDeploymentIntegrationsExecutive view
BOM SuiteSBOMCBOMQBOMAIBOMHBOMBOM Governance
SolutionsSecurityComplianceSupply chain riskQuantum readinessAI governanceDigital trust
ComplianceCERT-InRBISEBI / CSCRFMeitYNISTEU CRAEU AI ActCERT-In SBOM guide
IndustriesBanking & Financial ServicesGovernment & Public SectorDefence & Critical InfrastructureHealthcareIndian enterprises
ResourcesResource centreSBOM resourcesCBOM resourcesQBOM resourcesAIBOM resourcesHBOM resourcesProgramme & regulationBlog
CompanyAboutSecurity & trustContact
Request a DemoTalk to an expert
Compliance4 min readReviewed September 202614 sources

AIBOM compliance: EU AI Act, CERT-In, NIST AI RMF, ISO/IEC 42001 and Indian guidance

Few rules use the word AIBOM, but many require the information an AIBOM holds. This overview maps the main frameworks to the inventory they expect and gives the dates that matter.

Key takeaways
  • CERT-In's Version 2.0 guidelines (9 July 2025) are the most explicit AIBOM guidance in India.
  • Under the AI Omnibus, EU high-risk AI rules apply from 2 December 2027 (Annex III) and 2 August 2028 (Annex I); GPAI obligations have applied since 2 August 2025.
  • NIST AI RMF and ISO/IEC 42001 are voluntary frameworks that expect an inventory of AI systems and their resources.
  • MeitY's AI Governance Guidelines (November 2025) and RBI's FREE-AI report (August 2025) point Indian organisations toward inventories, accountability and incident reporting.

One inventory, many frameworks

Regulators and standards bodies ask similar questions about AI systems: what models are in use, where they came from, what data trained them, how they perform, and who is accountable. An AIBOM answers these questions once, in a structured form, so the same record can support several frameworks. The table summarises the main ones as of September 2026.

FrameworkStatusWhat it expects that an AIBOM supports
CERT-In Technical Guidelines v2.0 (India)Guidelines, 9 July 2025Minimum AIBOM elements (Table 10)
EU AI Act, Regulation (EU) 2024/1689In force; phased applicationTechnical documentation, data governance, value-chain information
NIST AI RMF 1.0 and AI 600-1Voluntary, 2023 and 2024Inventory and mapping of AI systems and risks
ISO/IEC 42001:2023Certifiable management system standardDocumented AI resources, data and third-party relationships
MeitY India AI Governance GuidelinesGovernance framework, 5 November 2025Transparency, accountability, incident reporting
RBI FREE-AI committee reportCommittee recommendations, August 2025AI inventories covering models, use cases, dependencies and risks

CERT-In

CERT-In's Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0, define the AIBOM and list its minimum elements, including model name, version, type, developer, licensing, software dependencies, ML models and algorithms, performance metrics, data source and data-set information [1]. Commentary notes that government, public-sector and essential-services organisations are expected to include AIBOMs in AI procurement [2]. See CERT-In AIBOM requirements.

EU AI Act and the AI Omnibus

Providers of high-risk AI systems must prepare technical documentation before placing a system on the market and keep it up to date [3]. Annex IV requires, among other things, software versions, use of third-party pre-trained systems, and datasheets describing training data and its provenance [4]. Providers of general-purpose AI models must maintain technical documentation, give downstream providers information, and publish a summary of training content [5].

The AI Omnibus entered into force on 27 July 2026. It moved the application of high-risk rules to 2 December 2027 for Annex III systems and 2 August 2028 for high-risk AI in products covered by Annex I [6]. Obligations for general-purpose AI models have applied since 2 August 2025 [7]. See EU AI Act and AIBOM.

NIST AI RMF

NIST released AI RMF 1.0 on 26 January 2023, organised into four functions: Govern, Map, Measure and Manage. The Generative AI Profile, NIST AI 600-1, followed on 26 July 2024, and NIST states that AI RMF 1.0 is being revised [8]. The framework is voluntary. An AIBOM supplies the system inventory and dependency context that the Map function works from, and the change history that Manage relies on.

ISO/IEC 42001

ISO/IEC 42001:2023, published in December 2023, specifies requirements for an AI management system [9]. Its Annex A control objectives include "Resources for AI systems", "Data for AI systems" and "Third-party and customer relationships", which call for documenting the data, tooling and computing resources each system depends on and where training data came from [10]. An AIBOM is a natural record for these controls.

India: MeitY and RBI

MeitY released the India AI Governance Guidelines on 5 November 2025. They are not new legislation; they set out seven principles and recommendations to be applied through existing law where possible [11]. Summaries describe proposals for transparency reports, a national AI incidents database and graded accountability across the AI value chain [12].

The RBI's Framework for Responsible and Ethical Enablement of AI (FREE-AI) committee report, released on 13 August 2025, recommends that regulated entities adopt board-approved AI policies and that AI inventories be created covering models, use cases, dependencies and risks [13]. It contains 26 recommendations across six pillars [14]. See AIBOM for banks and AIBOM for Indian enterprises.

A practical sequence

  1. Build one AIBOM per AI system, using fields that satisfy the strictest framework you report against.
  2. Map each field to the control or article it supports.
  3. Keep version history, because most frameworks expect records to stay current.
  4. Produce evidence packages from the same inventory rather than rewriting documents per framework.

How IntelliXBOM helps

IntelliXBOM validates AIBOMs against required-field policies such as the CERT-In elements, maps the inventory to framework controls including the EU AI Act, NIST AI RMF and ISO/IEC 42001, and produces timestamped evidence. Version history and diffs show how the record changed over time.

This article summarises public guidance and is not legal advice.

Frequently asked questions

Does the EU AI Act require an AIBOM?

The Act does not use the term, but Annex IV technical documentation for high-risk systems covers software versions, third-party pre-trained components and training-data provenance. An AIBOM is a practical way to hold and maintain that information.

When do EU high-risk AI obligations apply after the AI Omnibus?

Following the AI Omnibus, which entered into force on 27 July 2026, the rules apply from 2 December 2027 for Annex III systems and from 2 August 2028 for high-risk AI in Annex I products.

Is ISO/IEC 42001 relevant to AIBOMs?

Yes. Its Annex A controls on AI resources, data and third-party relationships expect organisations to document what each AI system depends on, which is the content of an AIBOM.

Sources

  1. Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf
  2. How Do CERT-In's AIBOM Guidelines Affect AI Procurement?MediaNamawww.medianama.com/2025/07/223-cert-in-ai-bill-of-materials-guidelines/
  3. AI Act Article 11: Technical DocumentationEU AI Act Explorer (Future of Life Institute)artificialintelligenceact.eu/article/11/
  4. AI Act Annex IV: Technical DocumentationEU AI Act Explorer (Future of Life Institute)artificialintelligenceact.eu/annex/4/
  5. AI Act Article 53: Obligations for Providers of General-Purpose AI ModelsEU AI Act Explorer (Future of Life Institute)artificialintelligenceact.eu/article/53/
  6. AI Omnibus enters into force (27 July 2026)European Commissiondigital-strategy.ec.europa.eu/en/news/ai-omnibus-enters-force
  7. AI Act Article 113: Entry into Force and ApplicationEU AI Act Explorer (Future of Life Institute)artificialintelligenceact.eu/article/113/
  8. AI Risk Management Framework (AI RMF 1.0) and Generative AI Profile (NIST AI 600-1)NISTwww.nist.gov/itl/ai-risk-management-framework
  9. ISO/IEC 42001:2023 Information technology: Artificial intelligence: Management systemISOwww.iso.org/standard/42001
  10. ISO 42001 Controls: The 38 Annex A ControlsKonfirmitywww.konfirmity.com/blog/iso-42001-controls
  11. MeitY Unveils India AI Governance Guidelines (5 November 2025)Press Information Bureau, Government of Indiawww.pib.gov.in/PressReleasePage.aspx?PRID=2186639
  12. MeitY releases Guidelines on AI Governance: The Way Ahead and Roadmap for AI use in IndiaAZB & Partnerswww.azbpartners.com/bank/meity-releases-guidelines-on-ai-governance-the-way-ahead-and-roadmap-for-ai-use-in-india/
  13. ERGO: RBI's FREE-AI Framework (28 August 2025)Khaitan & Cowww.khaitanco.com/sites/default/files/2025-08/Ergo%20-%20FREE%20AI%20Framework%20-%2028%20Augusut%202025.pdf
  14. RBI FREE-AI Committee Report on Framework for Responsible and Ethical Enablement of Artificial IntelligenceKPMG Indiakpmg.com/in/en/insights/2025/08/rbi-free-ai-committee-report-on-framework-for-responsible-and-ethical-enablement-of-artificial-intelligence.html

Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.

Related AIBOM guides

Across the BOM Suite

Put your AIBOM under governance.AI supply-chain transparency with continuous correlation and timestamped evidence.