Agent Inventory Tool

Free browser tool

AI BOM Template and Component Guide

Use an AI BOM template to record models, datasets, dependencies, versions and provenance references without claiming completeness.

An AI BOM template records which model and data components belong to a defined AI system, how they are identified and what evidence supports the relationship. An AI bill of materials or AI BOM can complement an operational inventory, but does not establish business purpose, owner approval or live deployment status by itself.

Definition

An AI bill of materials (AI-BOM) is a structured record of components and relationships for a defined AI system. The term is used across formats and does not mean every AI-BOM has the same schema. Define the system boundary first, then record what is known about models, datasets, software dependencies, tools and relevant configuration revisions. Keep the accountable business-system inventory linked to the component record: one explains the service and owner; the other helps trace dependencies.

CycloneDX describes an ML-BOM for model, compositional-asset and lifecycle information. SPDX 3.0.1 defines an AI Profile for AI application and model artifacts, while its Dataset Profile separately describes dataset information. These are different machine-readable models; a generic spreadsheet is not automatically compliant with either.

AI-BOM vs SBOM

A software bill of materials (SBOM) records software components and their relationships. An AI-BOM or ML-BOM may add model identifiers, datasets, training or evaluation references, prompt/configuration versions, and other AI-specific information when the chosen format supports it. Scope varies by implementation. Preserve links between the records rather than assuming one replaces the other: a software library change, model revision or data-source change can affect the same deployed AI workflow.

NIST AI RMF 1.0 MAP 4.1–4.2 discusses mapping risks and internal controls for AI-system components, including third-party software and data. That is risk-management guidance, not a BOM schema or a claim that a component list is complete. NIST marks AI RMF 1.0 voluntary and says it is being revised.

Fields

For a practical, manually maintained component map, begin with:

Choose one format and version before exchanging machine-readable files. Consult the CycloneDX ML-BOM overview and authoritative guide, or the SPDX 3.0.1 AI Profile and Dataset Profile. Check the selected release's schema and profile rules before claiming conformance.

Example

The following is a hypothetical CRM summarisation workflow, not a discovered system or a generated BOM:

ComponentIllustrative recordRelationship / evidence to verify
Business systemcrm-summary-prod, productionOwned by sales operations; confirm system boundary and intended use
Model serviceProvider model alias; immutable revision unknownProcesses draft requests; obtain provider/version evidence if available
RuntimeOrchestration package, version not verifiedConnects the model to the CRM reader; check the deployed lockfile
Data sourceCRM customer notes, confidential categoryRead-only access is claimed; verify effective permission and approved data scope
Prompt/configurationSummary instruction revision not verifiedOwner keeps a controlled revision reference; do not copy customer text into this record

If the CRM connector later gains write permission, record the changed component/configuration and review the system's permitted actions. Do not infer a model's training data, provider controls, evaluation result or regulatory category from an inventory row.

Tools

Collect component data from authorised package manifests, model/deployment records, data-owner documentation and change tickets, then have the relevant owners verify the entries. Mark each source and observation date; a manifest describes recorded dependencies, not necessarily every runtime behavior. Select a BOM tool only after checking support for the exact format/version and whether it preserves required relationships and provenance.

The Agent Inventory Tool on this site is a manual starter inventory. It does not discover dependencies, create CycloneDX or SPDX documents, validate a BOM schema, or certify AI-BOM completeness. Its CSV is not a standards-conformant AI-BOM. The public ISO/IEC 42001 overview describes an AI management-system standard, but licensed normative clauses were not available in the reviewed sources, so this page makes no Annex A mapping. The EU AI Act reference in the content plan is not interpreted here; an inventory does not decide legal classification or registration duties.

Continue with the AI agent inventory builder, the AI inventory template, or the AI agent inventory template.

Sources: CycloneDX ML-BOM; CycloneDX authoritative guide to AI/ML-BOM; SPDX 3.0.1 AI Profile; SPDX 3.0.1 Dataset Profile; NIST AI RMF 1.0; NIST AI RMF status; ISO/IEC 42001 public overview; EU AI Act official text.

Distinguish component records from a complete inventory

An AI BOM vs SBOM question is about scope and representation. A software bill of materials focuses on software components; an AI/ML bill of materials can also describe machine-learning models, datasets and provenance. CycloneDX documents an ML-BOM model and supports it in versions 1.5 and higher. A CycloneDX ML BOM should be generated or maintained with a compatible implementation and checked against intended scope; this manual guide does not generate a standards-conformant file.

Teams searching for an AI SBOM tool should compare supported formats, component identifiers, model and dataset relationships, provenance, signing and change capture. Do not treat a generic SBOM export as proof that training data, model lineage or runtime configuration are included. Record what the source represents and which components remain unknown.

For an AI BOM template, start with a stable system ID, model name and version, provider or repository reference, dataset identifiers where available, framework dependencies, collection date and source. Link these records to the deployment and owner in an AI agent inventory. Keep license, security, privacy and model-risk decisions in their proper review processes. Sources: CycloneDX Machine Learning Bill of Materials and the CycloneDX AI/ML-BOM guide. Updated 2026-10-08. Sources are linked on this page.

Primary sources and review

Published by Agent Inventory Tool. Updated . Sources are linked on this page. Outputs do not certify compliance.