Book an Appointment

Transparency for the AI supply chain

Why models, weights and training data belong in the bill of materials – and how CycloneDX ML-BOM and SPDX 3.0 make the AI supply chain documentable.

Last updated: July 2026 · Valeri Milke, ISO 27001 & ISO 42001 Lead Auditor

2established standard formats: CycloneDX ML-BOM and SPDX 3.0
~100malicious models identified on Hugging Face (JFrog, February 2024)
10OWASP Top 10: the AI supply chain as a dedicated risk (LLM03:2025 Supply Chain)
2027CRA main obligations (from 11 December)

AI systems consist of more than code: their behaviour is determined by models, model weights, training datasets and ML frameworks – artefacts that do not appear in a traditional software bill of materials (SBOM). At the same time, the AI supply chain is a real attack target, from tampered models on public model hubs to compromised framework dependencies. With CycloneDX ML-BOM and the AI and Dataset profiles of SPDX 3.0, two established standard formats now exist for inventorying these components in machine-readable form. In parallel, the Cyber Resilience Act and the AI Act are turning the documentation of components, datasets and pre-trained models into a regulatory obligation.

From specification to obligation

Five stages of the AI-SBOM — tap a milestone for details.

The Essentials at a Glance

Six topic blocks — tap to expand.

Format explorer: three routes to documented AI

CycloneDX ML-BOM, SPDX 3.0 and model cards side by side — tap a tab.

since 1.5 (06/2023)
  • The component types "machine-learning-model" and "data" place models and datasets on an equal footing with software libraries.
  • A "modelCard" object documents intended use, limitations, biases, training parameters, datasets used, performance metrics and ethical considerations.
  • First published as the international standard ECMA-424 in June 2024; the current 2nd edition (December 2025) corresponds to CycloneDX 1.7.
machine-learning-modeldatamodelCardECMA-424CycloneDX 1.7

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

Ecma International · 2025

ECMA-424: CycloneDX Bill of Materials Specification

International standardisation of CycloneDX; 1st edition June 2024, 2nd edition (December 2025) corresponds to CycloneDX 1.7 – ML-BOM capabilities since CycloneDX 1.5.

The Linux Foundation / SPDX Project · 2024

SPDX Specification v3.0.1

Defines the AI profile (AIPackage, energy consumption, safety risk assessment) and the Dataset profile (DatasetPackage) for AI components in SBOMs.

Mitchell et al., ACM Conference on Fairness, Accountability, and Transparency (FAT*) · 2019

Model Cards for Model Reporting

Original publication of the model card concept, which CycloneDX adopted as the machine-readable modelCard field.

OWASP GenAI Security Project · 2025

OWASP Top 10 for LLM Applications – LLM03:2025 Supply Chain

Describes supply chain risks from pre-trained models to LoRA adapters and explicitly recommends SBOM/AI-BOM inventories based on CycloneDX.

Amtsblatt der EU / EUR-Lex · 2024

Verordnung (EU) 2024/2847 (Cyber Resilience Act)

SBOM obligation in Annex I Part II No. 1; reporting obligations from 11 September 2026, main obligations from 11 December 2027.

Amtsblatt der EU / EUR-Lex · 2024

Verordnung (EU) 2024/1689 (AI Act)

Technical documentation for high-risk AI (Art. 11, Annex IV) and GPAI obligations including the training data summary (Art. 53, Annexes XI/XII), phased in from 2 August 2025/2 August 2026.

Do you know what is inside your AI systems?

If you would like to take a structured approach to building an AI-SBOM or meeting the documentation requirements of the CRA and the AI Act, feel free to contact us for a non-binding initial consultation.