CERT-In - Technical Guidelines on SBOM, QBOM & CBOM, AIBOM & HBOM - Version 2.0
AI / PRIVACY / CYBER RELEVANCE
AI BOM is directly relevant to model/dependency provenance, training/data components, vulnerability management and AI supply-chain assurance.
AI: Very HighPrivacy: HighCybersecurity: Very High
READ FIRST
- AIBOM section
- inventory of AI models/components/data sources
- transparency and vulnerability management
PURVIEW
Addresses software- and component-transparency through bills of materials, including SBOM, QBOM, CBOM, AIBOM and HBOM concepts. Its relevance to AI regulation is substantial because AI systems increasingly depend on complex combinations of source code, packages, hardware, models, datasets and external components. An AIBOM-oriented approach can improve traceability of model and AI dependencies, while SBOM and related inventories support vulnerability management and incident response. For privacy and security, the document helps organisations know what components process or expose data, identify dependency risks and establish a defensible asset inventory for audits, patching and supply-chain assurance.
Classification and legal status. Technical guideline / supply-chain guidance; not a universal statute.