AIBOM generation: discovering models, datasets and AI services
Generating an AIBOM is mostly a discovery problem. Models, datasets and AI services are spread across code, registries, notebooks and API calls. This guide covers where to look and what to capture.
- Start from four sources: code and containers, model registries, data platforms and outbound API traffic.
- External model APIs are often missed because nothing is installed locally.
- Record provenance with hashes and pinned revisions, not model names alone.
- Automate generation in CI and registry workflows so AIBOMs update when models change.
What generation means for AI
For software, generating an SBOM usually means scanning a repository or container image. An AIBOM needs more. CERT-In's minimum elements include model developer, licensing, performance metrics, data source and data-set information [1], and none of these can be read from a dependency manifest. Generation therefore combines automated discovery with metadata pulled from the systems where models and data are managed.
Where to discover AI components
| Source | What you find | How to extract it |
|---|---|---|
| Source code and containers | ML frameworks, inference servers, model files, SDKs for hosted AI services | Software composition analysis; searches for model file types and AI SDK imports |
| Model registries | Registered models, versions, lineage to training runs | Registry APIs and metadata export |
| Model hubs | Licence, base model, datasets, evaluation results | Model card metadata |
| Data platforms | Training and evaluation datasets, owners, versions | Catalogue and lineage metadata |
| Network and API gateways | Calls to external model APIs | Egress logs, gateway configuration, secrets inventory |
Model registries
If teams use a registry, it is the most reliable source. The MLflow Model Registry, for example, tracks versions, supports aliases such as "champion", and links each registered version to the run, logged model or notebook that produced it [2]. That link is where lineage to training data and parameters begins.
Model hub metadata
Hugging Face model cards include YAML metadata such as license, datasets, base_model (for fine-tunes, adapters, quantised versions and merges) and model-index evaluation results [3]. The OWASP AIBOM Generator uses this metadata to produce CycloneDX 1.6 AIBOMs and scores how complete they are [4]. Treat hub metadata as a supplier claim to be checked, not as verified fact.
External AI services
Hosted model APIs are the component most often left out of AIBOMs, and they can change without notice. Look for AI provider SDKs in code, API keys in secrets managers, and outbound traffic to AI endpoints. For each service, record the provider, the model identifier and version requested, the data categories sent, and the owning application.
What to capture per component
- Models: name, version or revision, type, developer, licence, artefact hash, base model and adapters, performance metrics, intended use and limitations. CycloneDX represents these as a
machine-learning-modelcomponent with amodelCard[5]. - Datasets: source, version, licence, collection process, known bias and whether personal data is present. SPDX 3.0's
DatasetPackagehas properties for each of these [6]. - Software: frameworks, inference servers and their dependencies, generated as a normal SBOM.
- Infrastructure: accelerators, runtime environment and hosting, which the G7 minimum elements treat as a separate cluster [7].
Keeping generated AIBOMs accurate
- Generate at the point of change. Run generation when a model is registered, promoted or retrained, and when a service changes its AI provider configuration.
- Pin and hash. Replace references to "latest" with explicit revisions and record hashes of model files.
- Reconcile sources. Compare registry contents with what is actually deployed. Models in production but not in the registry are the ones to investigate first.
- Validate before publishing. Check each AIBOM against schema and policy (AIBOM validation).
Start small
Begin with the systems that make or support decisions about people, money or safety, and with every external model API. A complete AIBOM for ten important systems is more useful than a thin one for a hundred.
How IntelliXBOM helps
IntelliXBOM generates and ingests AIBOMs in CycloneDX and SPDX and correlates the models, datasets, frameworks and AI services they list with vulnerabilities, licences and business services. Required-field policies flag gaps such as missing hashes or dataset provenance, and version history shows what changed between generations.
Frequently asked questions
Can an AIBOM be generated automatically?
Partly. Frameworks, model files and registry metadata can be collected automatically, but fields such as intended use, data provenance and approval status usually need input from model owners.
How do I find AI services my organisation uses?
Search code for AI provider SDKs, check secrets managers for AI API keys, and review egress or API gateway logs for calls to AI endpoints. Procurement records help with AI features inside SaaS products.
How often should an AIBOM be regenerated?
Whenever a model is registered, promoted, retrained or replaced, and whenever a service changes the external model it calls. Scheduled regeneration catches changes that bypass these workflows.
Sources
- Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf
- MLflow Model RegistryMLflowmlflow.org/docs/latest/ml/model-registry/
- Model CardsHugging Face Hub documentationhuggingface.co/docs/hub/model-cards
- OWASP AIBOM GeneratorOWASP Gen AI Security Project (GitHub)github.com/GenAI-Security-Project/aibom-generator
- CycloneDX v1.6 JSON ReferenceOWASP CycloneDXcyclonedx.org/docs/1.6/json/
- SPDX 3.0.1 specification: Dataset profile, DatasetPackage classSPDX / Linux Foundationspdx.github.io/spdx-spec/v3.0.1/model/Dataset/Classes/DatasetPackage/
- Global Cyber Agencies Issue New SBOMs for AI GuidanceInfosecurity Magazinewww.infosecurity-magazine.com/news/new-sboms-for-ai-guidance-2026/
Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.