The G7 minimum elements make an important distinction: an AI SBOM describes the composition of the broader AI system — not just the model inside it.✨ For agentic systems, that distinction is especially relevant. The OWASP AIBOM Generator contributes one machine-readable part of that broader inventory by capturing detailed model information in CycloneDX format. The OWASP AIBOM Generator tackles a practical part of that larger problem: generating machine-readable, CycloneDX-based details about models that are part of a broader AI system inventory. At #HackerSummerCamp, Dmitry R. and I will show it in action: 🔹 OWASP AIBOM Generator — Arsenal 📅 August 8 | 14:00–15:00 📍 DEF CON 34 — AppSec Village™ Arsenal Come see us turn model metadata into something security and governance tooling can actually consume. OWASP GenAI Security Project OWASP GenAI Security Project - AIBOM Initiative Steve Wilson Scott Clinton Sandy Dunn John Sotiropoulos Keren Katz Emmanuel Guilherme Jason Ross Ron F. Del Rosario Sonu Kumar Talesh Seeparsan Bryan Nakayama Rock Lambros Idan Habler, PhD Kayla Underkoffler Evgeniy Kokuykin #DEFCON34 #AppSecVillage #OWASP #AIBOM #AISBOM #SBOM #AISupplyChain #AITransparency
OWASP AIBOM Generator: https://github.com/GenAI-Security-Project/aibom-generator
This is a great distinction, Helen - the AI system vs. the model is exactly where a lot of compliance efforts fall short. At Conformis we see the same gap when mapping EU AI Act obligations: teams document the model card but miss the datasets, tooling, and integration layer that the Act actually holds them accountable for. Machine-readable AIBOMs feel like the right foundation for that.
Great work. The distinction between an AI SBOM and the broader AI system is particularly important for agentic systems. One complementary thought is that inventory alone may not be sufficient for high-consequence AI. An AIBOM tells us what an AI system is composed of—models, components, dependencies, and supply-chain relationships. It strengthens transparency and governance. The next challenge is understanding what the AI is actually allowed to execute at runtime. For autonomous agents operating in cyber-physical and other safety-critical environments, we may eventually need to complement AI BOMs with Execution Assurance—continuous runtime verification that an AI-generated action remains admissible under the current execution context before it is executed. In that sense, trustworthy AI may require both: • Composition Assurance (What is the system made of?) • Execution Assurance (Should this action execute right now?) These two perspectives together could provide a stronger foundation for trustworthy autonomous systems.
The distinction between the AI system and the model is so important for agentic workflows.
Oh no! I'm presenting at the OS Community at the same time as your presentation! I loved your preso last year. Do you think you'll have time to chat at the event?
Thanks for sharing Helen Oakley. I will have to reconsider and stay in Vegas to attend.
G7 reference: https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/KI/SBOM-for-AI_minimum-elements.pdf