{"data":{"id":"bb036895-319a-4fe2-bf95-5ca4d4b44a05","title":"CISA’s AI SBOM guidance pushes software supply-chain oversight into new territory","summary":"CISA and G7 cyber agencies released guidance on minimum elements for AI software bills of materials (SBOMs, documents listing all components and dependencies in software), helping security leaders assess AI system risks before deployment. Unlike traditional SBOMs that only track code, AI SBOMs must document models, training data, prompts, infrastructure, and other AI-specific elements because AI systems' behavior depends on data and models as much as code. The guidance gives organizations a framework to ask vendors for transparency during procurement, though it shows what vendors claim exists rather than proving the systems are trustworthy.","solution":"N/A -- no mitigation discussed in source.","labels":["policy","security"],"sourceUrl":"https://www.csoonline.com/article/4170694/cisas-ai-sbom-guidance-pushes-software-supply-chain-oversight-into-new-territory.html","publishedAt":"2026-05-13T10:42:33.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"info","attackType":[],"issueType":"news","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":[],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-05-13T10:42:33.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity"],"aiComponentTargeted":null,"llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}