Building an Open AIBOM Standard in the Wild
By: Gopi Krishnan Rajbahadur , Keheliya Gallaba , Elyas Rashno and more
Potential Business Impact:
Helps track AI parts for safer, clearer systems.
Modern software engineering increasingly relies on open, community-driven standards, yet how such standards are created in fast-evolving domains like AI-powered systems remains underexplored. This paper presents a detailed experience report on the development of the AI Bill of Materials AIBOM specification, an extension of the ISO/IEC 5962:2021 Software Package Data Exchange (SPDX) software bill of materials (SBOM) standard, which captures AI components such as datasets and iterative training artifacts. Framed through the lens of Action Research (AR), we document a global, multi-stakeholder effort involving over 90 contributors and structured AR cycles. The resulting specification was validated through four complementary approaches: alignment with major regulations and ethical standards (e.g., EU AI Act and IEEE 7000 standards), systematic mapping to six industry use cases, semi-structured practitioner interviews, and an industrial case study. Beyond delivering a validated artefact, our paper documents the process of building the AIBOM specification in the wild, and reflects on how it aligns with the AR cycle, and distills lessons that can inform future standardization efforts in the software engineering community.
Similar Papers
Implementing AI Bill of Materials (AI BOM) with SPDX 3.0: A Comprehensive Guide to Creating AI and Dataset Bill of Materials
Software Engineering
Lists all parts used to build AI safely.
TAIBOM: Bringing Trustworthiness to AI-Enabled Systems
Software Engineering
Makes AI systems safer and more trustworthy.
Wild SBOMs: a Large-scale Dataset of Software Bills of Materials from Public Code
Software Engineering
Helps software builders track code parts safely.