Feature · AI bill of materials

Capture the provenance behind every AI system with an AI bill of materials

SentinelAI generates a content-hashed AI Bill of Materials that captures the model, dataset, and framework provenance behind each AI system, flags license conflicts, and exports to CycloneDX, SPDX, and PDF.

What this area covers

The AI Bill of Materials brings supply-chain governance to AI by recording the components behind each system. It captures model, dataset, and framework provenance with content hashing, checks for license conflicts, and produces standard exports so provenance is auditable and shareable.

Related product areas

  • Model registry

    Maintain a governed inventory for AI models and use-case context with lifecycle state, ownership, risk posture, and supporting evidence.

  • Dataset governance

    Bring datasets, lineage, approvals, taxonomy-backed controls, catalog integrations, and quality gates into the AI governance workflow.

  • Vendor AI governance

    Register third-party AI vendors, structure due diligence, and connect external AI dependencies to internal governance records.

  • Compliance workflows

    Operationalize evidence collection, control tracking, remediation, and framework mapping across AI systems.

  • Reports and certificates

    Prepare executive reporting, audit-ready evidence views, and governance certificate workflows without overstating outcomes.

Core capabilities

Built to support production governance work

Content-hashed provenance

Generate a content-hashed AI Bill of Materials so the recorded provenance is verifiable and tamper-evident.

Model, dataset, and framework capture

Capture the model, dataset, and framework provenance behind each AI system so the full component picture is documented.

License conflict flagging

Flag license conflicts across components so incompatible terms are caught before they create downstream exposure.

Standard exports

Export the bill of materials to CycloneDX, SPDX, and PDF so provenance can be shared in established supply-chain formats.

Supply-chain governance context

Keep the bill of materials connected to the governed system record so provenance supports review, reporting, and audit.

Target users

  • AI governance teams documenting supply-chain provenance
  • Security teams managing software and model supply-chain risk
  • Compliance officers verifying component and license records
  • ML and platform teams accountable for system composition

Governance value

  • Documents the components behind each AI system for supply-chain governance
  • Makes provenance verifiable through content hashing
  • Catches incompatible terms early through license-conflict flagging
  • Shares provenance in standard CycloneDX, SPDX, and PDF formats
  • Connects component records to governance review and audit

How teams use it

A practical operating flow for this feature family

Step 1

Capture components

Record the model, dataset, and framework provenance behind each AI system with content hashing.

Step 2

Check licenses

Flag license conflicts across the captured components.

Step 3

Export and share

Export the bill of materials to CycloneDX, SPDX, and PDF for review and audit.

Continue exploring

Explore how SentinelAI connects adjacent governance workflows