- What: CISA and G7 release guidance on AI software bill of materials
- Impact: Helps organizations improve transparency in AI systems and supply chains
CISA and the Group of Seven (G7) international partnersâGermany, Canada, France, Italy, Japan, the United Kingdom, and the European Unionâhave released joint guidance, Software Bill of Materials for AI â Minimum Elements , to help public and private sector stakeholders improve transparency in their artificial intelligence (AI) systems and supply chains. A software bill of materials (SBOM) acts as an âingredients listâ for software that better positions organizations to understand their supply chains and make risk-informed decisions about how to protect their critical systems. The guidance builds on CISAâs previous work with federal and international partners to establish a shared vision for a software bill of materials and provides recommendations on minimum elements that should be included in an SBOM for AI. Because AI systems are software systems, these recommendations should be considered in addition to the general minimum elements for an SBOM . While not exhaustive or mandatory, the supplemental minimal elements outlined in this guidance reflect the consensus of G7 experts and will expand over time to keep pace with the rapid advancement of AI technology. Please share your thoughts! We welcome your feedback. CISA Product Survey