PlatformPlatform architectureProduct tourProduct graphRisk intelligenceContinuous governanceEvidence & auditDeploymentIntegrationsExecutive view
BOM SuiteSBOMCBOMQBOMAIBOMHBOMBOM Governance
SolutionsSecurityComplianceSupply chain riskQuantum readinessAI governanceDigital trust
ComplianceCERT-InRBISEBI / CSCRFMeitYNISTEU CRAEU AI ActCERT-In SBOM guide
IndustriesBanking & Financial ServicesGovernment & Public SectorDefence & Critical InfrastructureHealthcareIndian enterprises
ResourcesResource centreSBOM resourcesCBOM resourcesQBOM resourcesAIBOM resourcesHBOM resourcesProgramme & regulationBlog
CompanyAboutSecurity & trustContact
Request a DemoTalk to an expert
Industry3 min readReviewed September 202611 sources

AIBOM for government and the public sector

Governments buy more AI than they build, and they are accountable for decisions that affect citizens. An AIBOM gives a department a verifiable record of what each procured AI system contains.

Key takeaways
  • CERT-In's Version 2.0 guidelines target government, public-sector and essential-services organisations, and commentary notes an expectation of AIBOMs in AI procurement.
  • G7 cyber agencies, including CISA, published SBOM for AI minimum elements in May 2026.
  • US OMB memoranda M-25-21 and M-25-22 (April 2025) require annual public AI use-case inventories and set AI contract terms.
  • Under the EU AI Act, AI used to assess eligibility for public assistance benefits is high-risk.

Why the public sector needs AIBOMs

Public bodies use AI in benefits processing, document handling, citizen services and security operations, and most of it is procured. When a model turns out to be flawed, a department has to answer quickly which services use it, what data it was trained on, and which supplier is responsible. Contract documents rarely answer these questions. A structured AIBOM, delivered with the system and kept current, can.

India

CERT-In's Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025), are aimed at government, public-sector and essential-services organisations and define minimum AIBOM elements, including model name, version, type, developer, licensing, dependencies, performance metrics, data source and data-set information [1]. Reporting on the guidelines notes that organisations engaged in AI procurement are expected to include an AIBOM and to maintain AIBOMs for systems they use, procure and develop [2]. Legal commentary expects government departments to make BOM disclosure a requirement for suppliers across software, hardware and AI [3]. See CERT-In AIBOM requirements.

MeitY's India AI Governance Guidelines (5 November 2025) favour applying existing law and propose institutions and practices such as transparency reporting and an AI incidents database [4][5].

G7 and allied cyber agencies

In May 2026 the G7 Cybersecurity Working Group published Software Bill of Materials for AI: Minimum Elements, with contributions from agencies including Germany's BSI, France's ANSSI, Italy's ACN, Canada's CSE, the UK NCSC, Japan's NCO, the European Commission and US CISA [6][7]. It groups elements into seven clusters (metadata, system-level properties, models, dataset properties, key performance indicators, infrastructure and security properties) and describes them as not mandatory [7]. For public buyers, it is a ready-made baseline for procurement clauses.

United States

OMB memoranda M-25-21 and M-25-22, issued on 3 April 2025, replaced M-24-10. Agencies must inventory and publicly publish their AI use cases at least annually and apply minimum risk-management practices to high-impact AI [8]. M-25-22 covers acquisition: contracts should address vendor lock-in and data and model portability, and must prohibit use of non-public agency data to train publicly or commercially available AI without agency permission. It applies to solicitations issued 180 days or more after the memo [9].

European Union

Annex III of the AI Act lists as high-risk AI systems used by public authorities to evaluate eligibility for essential public assistance benefits and services, along with uses in law enforcement, migration and border control, and the administration of justice [10]. Following the AI Omnibus, Annex III rules apply from 2 December 2027 [11].

What a public-sector AIBOM programme looks like

StepAction
InventoryList every AI system in use, including AI features inside procured software and hosted services
ContractRequire suppliers to deliver an AIBOM in CycloneDX or SPDX, meeting CERT-In or G7 elements, with updates on change
IntakeValidate supplier AIBOMs on receipt against schema and required fields
LinkConnect each AI system to the public service and data it touches
MonitorCorrelate components with vulnerability advisories and track supplier updates
ReportProduce evidence for audits, inventories and oversight bodies from the same records

For clause wording, see AI procurement requirements. For intake checks, see How to validate an AIBOM.

Sovereignty and hosting

Government AIBOMs describe sensitive systems and sometimes classified environments. Keep the inventory within the department's own infrastructure where required, and make sure supplier AIBOMs can be received and processed in offline or air-gapped settings.

How IntelliXBOM helps

IntelliXBOM helps public bodies ingest supplier AIBOMs in CycloneDX and SPDX, validate them against CERT-In and other required-field policies, and link AI systems to the services they support. It correlates components with vulnerabilities and records timestamped evidence, and can be deployed on-premise or air-gapped.

This article summarises public guidance and is not legal advice.

Frequently asked questions

Do Indian government departments need AIBOMs?

CERT-In's Version 2.0 guidelines are aimed at government, public-sector and essential-services organisations and define minimum AIBOM elements. Reporting on the guidelines notes an expectation that AI procurement includes an AIBOM, so departments should build it into supplier requirements.

Are the G7 SBOM for AI minimum elements mandatory?

No. The G7 guidance published in May 2026 describes its clusters as not mandatory and open to refinement. Public buyers can adopt them as a contractual baseline.

What do US federal agencies have to publish about AI?

Under OMB M-25-21, agencies must inventory and publicly publish their AI use cases at least annually and report determinations for high-impact AI. M-25-22 sets expectations for AI contracts.

Sources

  1. Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf
  2. How Do CERT-In's AIBOM Guidelines Affect AI Procurement?MediaNamawww.medianama.com/2025/07/223-cert-in-ai-bill-of-materials-guidelines/
  3. CERT-In's New BOM Guidelines: What India's Software, AI, and Hardware Ecosystem Needs to KnowAZB & Partnerswww.azbpartners.com/bank/cert-ins-new-bom-guidelines-what-indias-software-ai-and-hardware-ecosystem-needs-to-know/
  4. MeitY Unveils India AI Governance Guidelines (5 November 2025)Press Information Bureau, Government of Indiawww.pib.gov.in/PressReleasePage.aspx?PRID=2186639
  5. MeitY releases Guidelines on AI Governance: The Way Ahead and Roadmap for AI use in IndiaAZB & Partnerswww.azbpartners.com/bank/meity-releases-guidelines-on-ai-governance-the-way-ahead-and-roadmap-for-ai-use-in-india/
  6. Software Bill of Materials (SBOM) for Artificial Intelligence: Minimum Elements (May 2026)BSI with G7 Cybersecurity Working Groupwww.bsi.bund.de/SharedDocs/Downloads/EN/BSI/KI/SBOM-for-AI_minimum-elements.html
  7. Global Cyber Agencies Issue New SBOMs for AI GuidanceInfosecurity Magazinewww.infosecurity-magazine.com/news/new-sboms-for-ai-guidance-2026/
  8. OMB Issues Revised Policies on AI Use and Procurement by Federal AgenciesHunton Andrews Kurthwww.hunton.com/privacy-and-cybersecurity-law-blog/omb-issues-revised-policies-on-ai-use-and-procurement-by-federal-agencies
  9. OMB M-25-22, Driving Efficient Acquisition of Artificial Intelligence in Government (3 April 2025)The White House, Office of Management and Budgetwww.whitehouse.gov/wp-content/uploads/2025/02/M-25-22-Driving-Efficient-Acquisition-of-Artificial-Intelligence-in-Government.pdf
  10. AI Act Annex III: High-Risk AI SystemsEU AI Act Explorer (Future of Life Institute)artificialintelligenceact.eu/annex/3/
  11. AI Omnibus enters into force (27 July 2026)European Commissiondigital-strategy.ec.europa.eu/en/news/ai-omnibus-enters-force

Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.

Related AIBOM guides

Across the BOM Suite

Put your AIBOM under governance.AI supply-chain transparency with continuous correlation and timestamped evidence.