PlatformPlatform architectureProduct tourProduct graphRisk intelligenceContinuous governanceEvidence & auditDeploymentIntegrationsExecutive view
BOM SuiteSBOMCBOMQBOMAIBOMHBOMBOM Governance
SolutionsSecurityComplianceSupply chain riskQuantum readinessAI governanceDigital trust
ComplianceCERT-InRBISEBI / CSCRFMeitYNISTEU CRAEU AI ActCERT-In SBOM guide
IndustriesBanking & Financial ServicesGovernment & Public SectorDefence & Critical InfrastructureHealthcareIndian enterprises
ResourcesResource centreSBOM resourcesCBOM resourcesQBOM resourcesAIBOM resourcesHBOM resourcesProgramme & regulationBlog
CompanyAboutSecurity & trustContact
Request a DemoTalk to an expert
Industry3 min readReviewed September 20269 sources

AIBOM for Indian enterprises: CERT-In, MeitY, RBI and DPDP

India has no single AI law, but several sources of guidance point in the same direction: know what your AI systems are made of, where their data came from, and who is accountable. An AIBOM brings those answers together.

Key takeaways
  • CERT-In's Version 2.0 guidelines (9 July 2025) are the main Indian source for AIBOM elements.
  • MeitY's AI Governance Guidelines (5 November 2025) are a governance framework, not new legislation.
  • RBI's FREE-AI report recommends AI inventories for regulated entities.
  • DPDP Rules notified on 14 November 2025 phase in over 18 months, so training data provenance matters.

The Indian landscape in brief

SourceDateAIBOM relevance
CERT-In Technical Guidelines v2.09 July 2025Defines AIBOM and minimum elements
RBI FREE-AI committee report13 August 2025Recommends AI inventories, board-approved AI policy, incident reporting
MeitY India AI Governance Guidelines5 November 2025Principles, accountability, transparency and incident database proposals
DPDP Rules, 2025Notified 14 November 202518-month phased compliance; affects personal data in training sets

CERT-In

CERT-In's guidelines define the AIBOM as "a comprehensive list of components used in building, training, and deploying AI models" and list minimum elements including model name, version, type, developer, licensing information, software dependencies, ML models and algorithms, performance metrics, data source and data-set information [1]. They are aimed at government, public-sector and essential-services organisations and at software exporters and service providers. Private companies supplying government projects should expect BOM disclosure requirements across software, hardware and AI [2]. Detail is in CERT-In AIBOM requirements.

MeitY

The India AI Governance Guidelines, released on 5 November 2025 under the IndiaAI Mission, are explicitly not new legislation. They rely on existing law where possible and set out seven guiding principles [3]. Summaries describe six governance pillars, proposed bodies including an AI Governance Group and an AI Safety Institute, industry transparency reports, a national AI incidents database, and graded accountability across the AI value chain [4]. Graded accountability depends on knowing who supplied which component, which an AIBOM records.

RBI and the financial sector

The RBI's FREE-AI committee report recommends board-approved AI policies covering lifecycle management and third-party vendor liabilities, and AI inventories and sector-wide repositories covering models, use cases, dependencies and risks [5]. See AIBOM for banks.

Personal data in training sets

The Digital Personal Data Protection Rules, 2025 were notified on 14 November 2025 with an 18-month phased compliance timeline [6]. Where personal data is used to train or fine-tune models, organisations need to know which datasets contain it and which models were trained on them. SPDX 3.0 dataset properties such as hasSensitivePersonalInformation and anonymizationMethodUsed give a structured place to record this [7].

Exporters and global customers

Indian IT services firms and product companies selling into Europe should also note that EU AI Act high-risk obligations apply from 2 December 2027 (Annex III) and 2 August 2028 (Annex I) following the AI Omnibus [8]. EU providers must document third-party pre-trained components they integrate, so they are likely to ask Indian suppliers for AIBOM-style information. See EU AI Act and AIBOM.

A 90-day starting plan

  1. Weeks 1 to 3: list AI systems in production, including hosted AI APIs and AI features in SaaS tools.
  2. Weeks 4 to 6: generate AIBOMs for the highest-impact systems, covering the CERT-In Table 10 elements.
  3. Weeks 7 to 9: identify datasets containing personal data and link them to models.
  4. Weeks 10 to 12: add AIBOM clauses to supplier contracts and set up validation at intake.

Securities-market entities

Entities regulated by SEBI already work under the Cybersecurity and Cyber Resilience Framework of August 2024, which brought SBOM expectations into the securities sector [9]. AI systems used in trading, surveillance or client servicing sit on the same software stack, so extending the existing SBOM process to cover models and datasets is usually the quickest route to an AIBOM.

How IntelliXBOM helps

IntelliXBOM validates AIBOMs against the CERT-In AIBOM elements and other required-field policies, keeps version history, and correlates models, datasets and frameworks with vulnerabilities, licences and business services. It maps the inventory to Indian and global framework controls with timestamped evidence, and can be self-hosted, including air-gapped.

This article summarises public guidance and is not legal advice.

Frequently asked questions

Is there an AI law in India?

India does not have a dedicated AI statute. MeitY's AI Governance Guidelines of November 2025 are a governance framework that relies on existing laws, while CERT-In and sectoral regulators such as the RBI have issued guidance relevant to AI systems.

Which Indian guidance defines AIBOM elements?

CERT-In's Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0, dated 9 July 2025, define the AIBOM and list its minimum elements in Table 10.

How does the DPDP Act affect AI models?

Where personal data is used to train or fine-tune models, organisations need to account for it under the DPDP framework. Recording which datasets contain personal data, and which models used them, makes that manageable.

Sources

  1. Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf
  2. CERT-In's New BOM Guidelines: What India's Software, AI, and Hardware Ecosystem Needs to KnowAZB & Partnerswww.azbpartners.com/bank/cert-ins-new-bom-guidelines-what-indias-software-ai-and-hardware-ecosystem-needs-to-know/
  3. MeitY Unveils India AI Governance Guidelines (5 November 2025)Press Information Bureau, Government of Indiawww.pib.gov.in/PressReleasePage.aspx?PRID=2186639
  4. MeitY releases Guidelines on AI Governance: The Way Ahead and Roadmap for AI use in IndiaAZB & Partnerswww.azbpartners.com/bank/meity-releases-guidelines-on-ai-governance-the-way-ahead-and-roadmap-for-ai-use-in-india/
  5. ERGO: RBI's FREE-AI Framework (28 August 2025)Khaitan & Cowww.khaitanco.com/sites/default/files/2025-08/Ergo%20-%20FREE%20AI%20Framework%20-%2028%20Augusut%202025.pdf
  6. Digital Personal Data Protection (DPDP) Rules, 2025 notified (14 November 2025)Press Information Bureau, Government of Indiawww.pib.gov.in/PressReleasePage.aspx?PRID=2190014&reg=3&lang=2
  7. SPDX 3.0.1 specification: Dataset profile, DatasetPackage classSPDX / Linux Foundationspdx.github.io/spdx-spec/v3.0.1/model/Dataset/Classes/DatasetPackage/
  8. AI Omnibus enters into force (27 July 2026)European Commissiondigital-strategy.ec.europa.eu/en/news/ai-omnibus-enters-force
  9. Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (August 2024)SEBIwww.sebi.gov.in/legal/circulars/aug-2024/cybersecurity-and-cyber-resilience-framework-cscrf-for-sebi-regulated-entities-res-_85964.html

Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.

Related AIBOM guides

Across the BOM Suite

Put your AIBOM under governance.AI supply-chain transparency with continuous correlation and timestamped evidence.