PlatformPlatform architectureProduct tourProduct graphRisk intelligenceContinuous governanceEvidence & auditDeploymentIntegrationsExecutive view
BOM SuiteSBOMCBOMQBOMAIBOMHBOMBOM Governance
SolutionsSecurityComplianceSupply chain riskQuantum readinessAI governanceDigital trust
ComplianceCERT-InRBISEBI / CSCRFMeitYNISTEU CRAEU AI ActCERT-In SBOM guide
IndustriesBanking & Financial ServicesGovernment & Public SectorDefence & Critical InfrastructureHealthcareIndian enterprises
ResourcesResource centreSBOM resourcesCBOM resourcesQBOM resourcesAIBOM resourcesHBOM resourcesProgramme & regulationBlog
CompanyAboutSecurity & trustContact
Request a DemoTalk to an expert
Compliance4 min readReviewed September 202612 sources

EU AI Act documentation duties and how an AIBOM supports them

The AI Act asks providers to document how their systems are built, what data trained them and which third-party components they rely on. An AIBOM does not replace that documentation, but it supplies much of its content and keeps it current.

Key takeaways
  • High-risk AI rules apply from 2 December 2027 (Annex III) and 2 August 2028 (Annex I) after the AI Omnibus, which entered into force on 27 July 2026.
  • Annex IV technical documentation covers software versions, third-party pre-trained components, training-data datasheets and lifecycle changes.
  • GPAI providers have had documentation, downstream information and training-summary duties since 2 August 2025.
  • Documentation for high-risk systems must be kept up to date and retained for ten years.

Key dates

DateWhat applies
2 February 2025Chapters I and II (general provisions and prohibited practices) [1]
2 August 2025Chapter V obligations for general-purpose AI models [1]
27 July 2026AI Omnibus enters into force [2]
2 December 2027High-risk rules for Annex III systems [2]
2 August 2028High-risk rules for AI in Annex I products, such as machinery, toys and lifts [2]

The Regulation itself is Regulation (EU) 2024/1689 [3]. The AI Omnibus also extended some SME measures to small mid-caps and simplified certain registration obligations [2].

High-risk AI: technical documentation

Article 11 requires the provider of a high-risk AI system to draw up technical documentation before the system is placed on the market or put into service, and to keep it up to date. Minimum contents are set out in Annex IV [4]. Annex IV items that an AIBOM directly supports include [5]:

  • "the versions of relevant software or firmware, and any requirements related to version updates";
  • "recourse to pre-trained systems or tools provided by third parties and how those were used, integrated or modified";
  • "datasheets describing the training methodologies and techniques and the training data sets used", including provenance, scope and main characteristics;
  • validation and testing data, and the metrics used to measure accuracy, robustness and compliance;
  • cybersecurity measures, and "relevant changes made by the provider to the system through its lifecycle".

Article 10 adds data-governance duties, including documenting data collection processes and the origin of data, and data-preparation operations such as labelling and cleaning [6]. Article 18 requires the documentation to be kept for ten years after the system is placed on the market or put into service [7].

The value chain

Article 25(4) requires the provider of a high-risk system and any third party supplying AI systems, tools, services, components or processes used in it to agree in writing the information, capabilities, technical access and assistance needed for compliance. Third parties supplying components under free and open-source licences are exempt from this requirement [8]. In practice, providers will ask suppliers for AIBOM-style information, and an AIBOM delivered under contract is a clear way to meet that request. See AI procurement requirements.

General-purpose AI models

Article 53 requires GPAI model providers to keep technical documentation, including training and testing processes (Annex XI); to give downstream providers information about capabilities and limitations (Annex XII); to maintain a copyright policy; and to publish a sufficiently detailed summary of training content [9]. The Commission published the voluntary GPAI Code of Practice on 10 July 2025, and its Transparency chapter includes a Model Documentation Form [10]. The template for the public training-content summary, released on 24 July 2025, asks for data sources, including large datasets and top domain names for scraped content [11].

For downstream providers, the Annex XII information they receive belongs in their own AIBOM as the record of the GPAI component they integrate.

Mapping AI Act duties to AIBOM content

AI Act dutyAIBOM content
Annex IV software versionsSoftware dependencies with versions
Annex IV third-party pre-trained systemsBase models, adapters and suppliers, with lineage
Annex IV and Article 10 data documentationDataset components with provenance, collection process and preprocessing
Annex IV metricsPerformance metrics per model version
Annex IV lifecycle changesAIBOM version history and diffs
Article 15 cybersecurity (poisoning, adversarial examples)Hashes, signatures, scan results, security properties
Article 53 and Annex XII downstream informationGPAI component record with capabilities and limitations

Article 15 specifically names data poisoning and model poisoning of pre-trained components as threats to address [12]; see AI supply-chain risks.

What an AIBOM does not cover

The technical documentation also includes the risk-management system, human-oversight measures, the EU declaration of conformity and post-market monitoring [5]. These are organisational records. An AIBOM supplies the component, data and change information they refer to.

How IntelliXBOM helps

IntelliXBOM keeps AIBOMs for each AI system with version history and diffs, which supports Annex IV's lifecycle-change requirement. It validates the fields your AI Act policy requires, correlates components with vulnerabilities, and maps the inventory to AI Act articles with timestamped evidence.

This article summarises public guidance and is not legal advice.

Frequently asked questions

Does the EU AI Act mention an AIBOM?

No. It requires technical documentation for high-risk systems and GPAI models, and much of that documentation, such as software versions, third-party pre-trained components and training-data provenance, is what an AIBOM records.

When do high-risk AI obligations apply after the AI Omnibus?

From 2 December 2027 for Annex III systems and 2 August 2028 for high-risk AI in Annex I products. The AI Omnibus entered into force on 27 July 2026.

How long must AI Act technical documentation be kept?

Article 18 requires providers of high-risk AI systems to keep technical documentation for ten years after the system is placed on the market or put into service.

Sources

  1. AI Act Article 113: Entry into Force and ApplicationEU AI Act Explorer (Future of Life Institute)artificialintelligenceact.eu/article/113/
  2. AI Omnibus enters into force (27 July 2026)European Commissiondigital-strategy.ec.europa.eu/en/news/ai-omnibus-enters-force
  3. Regulation (EU) 2024/1689 (Artificial Intelligence Act)EUR-Lexeur-lex.europa.eu/eli/reg/2024/1689/oj
  4. AI Act Article 11: Technical DocumentationEU AI Act Explorer (Future of Life Institute)artificialintelligenceact.eu/article/11/
  5. AI Act Annex IV: Technical DocumentationEU AI Act Explorer (Future of Life Institute)artificialintelligenceact.eu/annex/4/
  6. AI Act Article 10: Data and Data GovernanceEU AI Act Explorer (Future of Life Institute)artificialintelligenceact.eu/article/10/
  7. AI Act Article 18: Documentation KeepingEU AI Act Explorer (Future of Life Institute)artificialintelligenceact.eu/article/18/
  8. AI Act Article 25: Responsibilities Along the AI Value ChainEU AI Act Explorer (Future of Life Institute)artificialintelligenceact.eu/article/25/
  9. AI Act Article 53: Obligations for Providers of General-Purpose AI ModelsEU AI Act Explorer (Future of Life Institute)artificialintelligenceact.eu/article/53/
  10. The General-Purpose AI Code of Practice (10 July 2025)European Commissiondigital-strategy.ec.europa.eu/en/policies/contents-code-gpai
  11. European Commission Releases Mandatory Template for Public Disclosure of AI Training DataWilmerHalewww.wilmerhale.com/en/insights/blogs/wilmerhale-privacy-and-cybersecurity-law/european-commission-releases-mandatory-template-for-public-disclosure-of-ai-training-data
  12. AI Act Article 15: Accuracy, Robustness and CybersecurityEU AI Act Explorer (Future of Life Institute)artificialintelligenceact.eu/article/15/

Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.

Related AIBOM guides

Across the BOM Suite

Put your AIBOM under governance.AI supply-chain transparency with continuous correlation and timestamped evidence.