2026-09-25 –, 106 (Capacity 45)
Software Bill of Materials (SBOM) has become a foundational requirement for software supply chain security. But modern applications increasingly embed machine learning models, datasets, feature stores, prompts, vector databases, and training pipeline artifacts that traditional SBOMs were never designed to describe.
This talk explores extending SBOM concepts into an AI Bill of Materials (AI-BOM) that captures machine learning artifacts across the lifecycle.
We will examine:
* Why SBOM alone is insufficient for ML systems
* What additional metadata is required for AI systems
* Mapping ML artifacts into CycloneDX/SPDX extensions
* Provenance, reproducibility, and compliance challenges
* Security risks in models, datasets, and prompt supply chains
* How AI-BOM supports governance, auditability, and responsible AI
The session includes a practical architecture walkthrough and a focused demo showing how AI-BOM artifacts can be generated and integrated into existing DevSecOps workflows.
Ayushi is an Associate Software Engineer at Red Hat, specializing in AI, python, and open source. With over 2 years of experience, she has worked on rule writing, log analysis, and proactive issue resolution. She is a mentor and public speaker, frequently sharing insights on open source, AI advancements, and career growth in tech. Passionate about scalable automation and AI-driven support systems, she strives to bridge the gap between engineering efficiency and real-world problem-solving.