Utilizing SBOM for Transparent AI Risk Communication
Value chains for AI systems are becoming increasingly complex and can consists of multiple actors that contribute services, tools, data, models and code. An efficient risk management along this value chain requires all actors to communicate potential risk sources and recommendations for mitigation. The Software Bill of Materials (SBOM) is a method from cybersecurity, that enables organizations to communicate information like licences, security vulnerabilities and dependencies of software components. SBOM raises increasing interest in the AI community to share information about AI components, like data and models. In this paper we discuss the suitability of SBOM for AI risk management along a value chain and show the potential but also gaps in current approaches.
- Published in:
Proceedings of the AAAI Symposium Series - Type:
Article - Authors:
- Year:
2025
Citation information
: Utilizing SBOM for Transparent AI Risk Communication, Proceedings of the AAAI Symposium Series, 2025, 7, 1, 185--189, November, Association for the Advancement of Artificial Intelligence (AAAI), Helmer.etal.2025a,
@Article{Helmer.etal.2025a,
author={Helmer, Lennard; Fink, Lisa; Poretschkin, Maximilian},
title={Utilizing SBOM for Transparent AI Risk Communication},
journal={Proceedings of the AAAI Symposium Series},
volume={7},
number={1},
pages={185--189},
month={November},
publisher={Association for the Advancement of Artificial Intelligence (AAAI)},
year={2025},
abstract={Value chains for AI systems are becoming increasingly complex and can consists of multiple actors that contribute services, tools, data, models and code. An efficient risk management along this value chain requires all actors to communicate potential risk sources and recommendations for mitigation. The Software Bill of Materials (SBOM) is a method from cybersecurity, that enables organizations to...}}