What happened
On Oct 8 Insignary announced GA of Clarity AIR, a source-code-level scanner that fingerprints open-source code against its ecosystem database even when modified/regenerated by AI assistants, classifies how much of a codebase an AI actually wrote (line-by-line confidence), inventories models/APIs/frameworks into an AI Bill of Materials, and exports human-review-confirmed audit-ready SBOMs — on customer-owned infrastructure.
Why it matters
Manifests/SBOMs miss undeclared dependencies and AI-generated code — an unmanaged supply-chain and compliance risk for CISOs; adds a genuinely new AI-BOM and AI-code-detection capability as SBOM verification becomes mandatory (OMB M-26-05, FDA 524B, Canada Bill C-8).
Applicability
AppSec and compliance teams that must verify SBOM accuracy and quantify AI-written code; evaluate alongside existing SCA/SBOM governance (Clarity suite) for source vs binary-level coverage.