Definition
A declared inventory of the models, data, code, and AI-generated components inside a software product — an extension of the familiar software bill of materials (SBOM) to the AI era. It exposes undeclared open-source dependencies and AI-written code that ordinary SBOMs miss. Think of it as an ingredient label for what is actually running in your AI stack.
Why it matters
Undeclared open-source and AI-generated code is both a security and a license/compliance risk; an AI-BOM gives CISOs and auditors visibility into what is really deployed.