{"id":36715,"date":"2026-05-12T22:10:19","date_gmt":"2026-05-12T22:10:19","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/36715\/"},"modified":"2026-05-12T22:10:19","modified_gmt":"2026-05-12T22:10:19","slug":"major-world-economies-spell-out-key-elements-of-ai-ingredients-list","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/36715\/","title":{"rendered":"Major world economies spell out key elements of AI \u2018ingredients list\u2019"},"content":{"rendered":"<p>A group of international government agencies released guidance Tuesday on what they believe any artificial intelligence \u201cingredients list\u201d tool should include to make AI more secure.<\/p>\n<p>The concept of such a list, known as a \u201csoftware bill of materials (SBOM),\u201d is to know everything that goes into a particular piece of software so that any supply chain risks are easier to identify. There\u2019s been a <a href=\"https:\/\/cyberscoop.com\/sbom-adoption-challenges-ai-coding-transparency\/\" rel=\"nofollow noopener\" target=\"_blank\">growing focus<\/a> from cyber experts on how they interact with AI.<\/p>\n<p>The guidance produced by agencies from the G7 group of nations, including the Cybersecurity and Infrastructure Security Agency, is aimed at setting minimum voluntary standards for what SBOMs for AI should look like. It builds on past efforts to produce other kinds of <a href=\"https:\/\/cyberscoop.com\/cisa-guide-seeks-a-unified-approach-to-software-ingredients-lists\/\" rel=\"nofollow noopener\" target=\"_blank\">SBOM guidance<\/a>.<\/p>\n<p>\u201cWhile not exhaustive or mandatory, the supplemental minimal elements outlined in this guidance reflect the consensus of G7 experts and will expand over time to keep pace with the rapid advancement of AI technology,\u201d CISA stated. (Some refer to SBOMs for AI as AIBOMs.)<\/p>\n<p>The elements include those that fall under the categories of information related to the SBOM for AI itself, on the AI system as a whole, for identifying the models used by the AI system, on datasets used during the whole life cycle of the model, on physical and virtual infrastructure needed for operation and support support of the AI system, on cybersecurity measures that apply to AI models and systems and on the AI system\u2019s key performance indicators.\u00a0<\/p>\n<p>A trio of industry professionals who have worked on the topic of AISBOMs told CyberScoop they welcomed the guidance, in each case praising it as a good step that could nonetheless be improved upon.<\/p>\n<p>\u201cPretty much every piece of software out there is now going to have AI incorporated into it, and when a hospital is buying an AI-enabled medical device, or the Department of War is buying an AI-enabled weapon system, or auto manufacturers are putting AI into cars, we need to be able to trust what AI is in those systems,\u201d said Daniel Bardenstein, CEO of Manifest Cyber. \u201cAnd the first step to trust is to identify what is this AI, where did it come from? How is it trained?\u201d<\/p>\n<p>\u201cThis is a strong, applaudable step towards getting everybody on the same page that this is the future of how we need to think about trusting AI,\u201d said Bardenstein, who has built and AIBOM generator and worked on the topic in the past with CISA and the OWASP Foundation.<\/p>\n<p>Dmitry Raidman, co-founder and chief technology officer at Cybeats \u2014 and someone who, like Bardenstein, has built his own AIBOM generator and worked on AIBOMs with CISA and OWASP \u2014 said the G7 guidance was \u201camazing\u201d because it covers 80 to 90% of what\u2019s needed.<\/p>\n<p>\u201cThere was no baseline, but it now will put out a clear baseline,\u201d he said.<\/p>\n<p>On the downside, Bardenstein said he had concerns with how easily organizations can implement the guidance, and Raidman said it doesn\u2019t adequately tackle the issue of runtime.<\/p>\n<p>Allan Friedman, sometimes called the \u201cgodfather of SBOMs,\u201d said the guidance was a good document, but probably mislabeled because it states that the elements it identifies are not mandatory.<\/p>\n<p>\u201cThis document is laying out sets of types of data that could be useful,\u201d said Friedman, who worked on SBOMs in multiple U.S. government roles who is senior technical adviser at the Institute for Security and Technology and technologist in residence at TPO Group. \u201cAnd so it is a great, great piece to advance AI transparency and AI system transparency, but it lists potential elements. These aren\u2019t the minimum elements.\u201d<\/p>\n<p>Friedman said the next steps could include mapping the guidance into what is being implemented today, and talking about aligning it with policies in the European Union and G7 governments to make sure there are minimal conflicts.<\/p>\n<p>\t\t\t\t\t<img decoding=\"async\" class=\"author-card__image\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/05\/1778623819_153_Tim-Starks-01.jpg\" alt=\"Tim Starks\"\/><\/p>\n<p>\t\t\tWritten by Tim Starks<br \/>\n\t\t\tTim Starks is senior reporter at CyberScoop. His previous stops include working at The Washington Post, POLITICO and Congressional Quarterly. An Evansville, Ind. native, he&#8217;s covered cybersecurity since 2003. Email Tim here: <a href=\"https:\/\/cyberscoop.com\/g7-cisa-ai-sbom-security-guidance\/mailto:tim.starks@cyberscoop.com\" rel=\"nofollow noopener\" target=\"_blank\">tim.starks@cyberscoop.com<\/a>.\t\t<\/p>\n","protected":false},"excerpt":{"rendered":"A group of international government agencies released guidance Tuesday on what they believe any artificial intelligence \u201cingredients list\u201d&hellip;\n","protected":false},"author":2,"featured_media":36716,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[24,25,111,22980,14461,22981,22982,22983,22984],"class_list":["post-36715","post","type-post","status-publish","format-standard","has-post-thumbnail","category-ai","tag-ai","tag-artificial-intelligence","tag-artificial-intelligence-ai","tag-cybeats","tag-cybersecurity-and-infrastructure-security-agency-cisa","tag-g7","tag-manifest-cyber","tag-owasp","tag-sbom"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/36715","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=36715"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/36715\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/36716"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=36715"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=36715"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=36715"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}