AIBOM tools: open-source options for generating, validating and securing AI BOMs
There is no single open-source tool that produces a complete AIBOM. There is a small, useful toolkit for generating, validating, signing and scanning the pieces. This is what each tool does, according to its own documentation.
- The OWASP AIBOM Generator produces CycloneDX 1.6 AIBOMs for Hugging Face models and scores their completeness.
- CycloneDX CLI validates CycloneDX documents up to v1.7 and can diff, merge, sign and verify them.
- SPDX 3 documents should be checked with both JSON Schema and SHACL; spdx3-validate does both.
- Model signing and model scanning tools cover integrity and serialisation risks that a BOM alone cannot.
What an AIBOM toolchain needs to do
An AIBOM is assembled from several sources: model metadata, dataset records, dependency manifests and deployment configuration. A practical toolchain therefore covers five jobs: generating the document, validating it against its specification, rendering it for human review, proving the integrity of the model artefacts it describes, and checking those artefacts for unsafe content. The tools below are open source and are described from their official repositories. Inclusion is not an endorsement, and each tool should be tested against your own models and policies.
Generation
OWASP AIBOM Generator
The OWASP Gen AI Security Project runs an AIBOM initiative whose stated aim is to operationalise the AI Bill of Materials through open tooling, completeness assessment and practitioner guidance [1]. Its main deliverable, the AIBOM Generator, takes a Hugging Face model ID and generates an AIBOM in CycloneDX 1.6 JSON. It pulls metadata from model cards, configuration and repository files, calculates a completeness score with recommendations, and offers both a web interface and a CLI. It is licensed under Apache 2.0 [2].
Its scope is the model as published on the Hub. It does not see how your organisation deploys the model, which applications call it, or what data you fine-tuned it on. Those facts have to come from your own systems.
Model registries and model cards
Much AIBOM content already exists in the tools data scientists use. Hugging Face model cards carry YAML metadata such as license, datasets, base_model and structured evaluation results in model-index [3]. The open-source MLflow Model Registry tracks model versions, aliases and tags, and links each registered version to the run or notebook that produced it [4]. Both are useful inputs for generation. See AIBOM generation.
Validation
CycloneDX CLI
The CycloneDX CLI, maintained by the CycloneDX project under Apache 2.0, includes validate for specification versions 1.0 to 1.7, along with diff, merge, convert, sign and verify [5]. Schema validation confirms that a document is well formed. It does not confirm that required AI fields are populated. That needs a policy check on top. See AIBOM validation.
SPDX 3 validation
The SPDX project recommends validating SPDX 3 JSON-LD documents in two ways: structurally against the published JSON Schema, and semantically against the SHACL model. It lists spdx3-validate, pyshacl, check-jsonschema and ajv as options [6]. spdx3-validate (MIT licence) performs both checks and handles external references across merged documents [7]. The SPDX tools-python library describes its SPDX 3.0 support as experimental: it can write and convert to 3.0 but not yet read it, and its authors advise against production use [8].
Human-readable output
mlbomdoc generates human-readable documentation from a CycloneDX ML-BOM, with console, JSON, Markdown and PDF output [9]. Reviewers and approvers often need this view, because few of them read JSON.
Integrity and artefact safety
A BOM that lists a model hash is only as trustworthy as the process that checks it. Sigstore's model_signing project, built with the OpenSSF, signs model artefacts using Sigstore, public keys or PKCS #11 devices so that verifiers can confirm a model has not been altered since signing [10]. Protect AI's ModelScan, licensed under Apache 2.0, scans Pickle, H5 and SavedModel files for embedded code before they are loaded [11]. Neither produces an AIBOM, but both produce evidence an AIBOM should reference.
Summary table
| Job | Tool | Formats | Licence |
|---|---|---|---|
| Generate from Hugging Face | OWASP AIBOM Generator | CycloneDX 1.6 | Apache 2.0 |
| Validate, diff, sign | CycloneDX CLI | CycloneDX 1.0 to 1.7 | Apache 2.0 |
| Validate | spdx3-validate | SPDX 3 | MIT |
| Render | mlbomdoc | CycloneDX ML-BOM | See repository |
| Sign models | model_signing | Model artefacts | Apache 2.0 |
| Scan models | ModelScan | Pickle, H5, SavedModel | Apache 2.0 |
What tools leave to you
None of these tools knows which business service depends on which model, who approved it, or whether a hosted API changed its model version last week. Those links come from your own registries and change records, and they are what turns a collection of files into an inventory. For choosing a platform to hold that inventory, see AIBOM platforms: evaluation criteria.
How IntelliXBOM helps
IntelliXBOM ingests CycloneDX and SPDX AIBOMs produced by open-source tools, validates them against required-field policies, and keeps version history and diffs. It correlates the models, datasets and frameworks they list with vulnerabilities, licences and business services, and records the result as timestamped evidence.
Frequently asked questions
Is there a free AIBOM generator?
Yes. The OWASP AIBOM Generator is open source under Apache 2.0 and generates CycloneDX 1.6 AIBOMs for models hosted on Hugging Face, with a completeness score. It covers the published model, not your deployment context.
How do I validate an SPDX 3.0 AI BOM?
The SPDX project recommends checking both the JSON Schema and the SHACL model. The spdx3-validate tool performs both checks in one run.
Do SBOM scanners produce AIBOMs?
Software composition tools can list the ML frameworks and libraries around a model, which covers part of an AIBOM. They do not usually capture model lineage, training data or evaluation metrics, so those fields need other sources.
Sources
- OWASP AIBOM initiativeOWASP Gen AI Security Projectgenai.owasp.org/owasp-aibom/
- OWASP AIBOM GeneratorOWASP Gen AI Security Project (GitHub)github.com/GenAI-Security-Project/aibom-generator
- Model CardsHugging Face Hub documentationhuggingface.co/docs/hub/model-cards
- MLflow Model RegistryMLflowmlflow.org/docs/latest/ml/model-registry/
- CycloneDX CLICycloneDX (GitHub)github.com/CycloneDX/cyclonedx-cli
- Validating SPDX 3 JSON-LD documentsSPDX spdx-3-model (GitHub)github.com/spdx/spdx-3-model/blob/develop/serialization/jsonld/validation.md
- spdx3-validateGitHub (JPEWdev)github.com/JPEWdev/spdx3-validate
- SPDX tools-pythonSPDX (GitHub)github.com/spdx/tools-python
- MLBOMDocGitHub (Anthony Harrison)github.com/anthonyharrison/mlbomdoc
- Model Transparency (model_signing)Sigstore (GitHub)github.com/sigstore/model-transparency
- ModelScan: protection against model serialisation attacksProtect AI (GitHub)github.com/protectai/modelscan
Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.