AI Supply Chain in Practice: Generate Your First AI Bill of Materials | Oakley & Raidman | S2 E3

AI Supply Chain in Practice: Generate Your First AI Bill of Materials | Oakley & Raidman | S2 E3

🎙 Eva Benn 👥 101K 📅 August 3, 2026 ⏱ 37 min 👁 15K 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

AI Bill of MaterialsSBOMsupply chainCycloneDXHugging Face

Summary

The video is an episode of ‘Security Mondays’ hosted by Eva Benn, featuring Helen Oakley and Dmitry Raidman, co-leads of the OWASP AI SBOM Initiative. They discuss the growing risk of AI supply chain attacks, referencing recent incidents like the Axios npm compromise and the Miasma campaign. The core of the episode is a practical demonstration of generating an AI Bill of Materials (AIBOM) using the open-source AIBOM Generator for a Hugging Face model. The hosts explain the difference between SBOM and AIBOM, emphasizing that AIBOM extends beyond software components to include models, datasets, prompts, and other AI-specific elements. They highlight the importance of understanding use cases and risk appetite when assessing AI components. The demonstration shows how to generate an AIBOM, interpret its completeness score, and integrate it into CI/CD pipelines using CycloneDX format. The discussion also covers limitations, such as the inability to fully assess model integrity and the need for additional tools for vulnerability analysis. The episode concludes with advice on operationalizing AI supply chain security, starting with inventory and using standards like NTIA minimum elements and G7 guidelines.

182 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides high practical value by offering a step-by-step demonstration of generating an AIBOM, which is directly actionable for security professionals. The argumentation is solid, grounded in the experts’ extensive experience and involvement in standards development. They effectively use analogies (e.g., food ingredients) to explain complex concepts and support their claims with real-world attack examples. The discussion is well-structured, moving from general concepts to specific implementation details, and addresses potential counterarguments by acknowledging limitations and unknowns.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate; the content is based on expert opinion and industry practices rather than peer-reviewed research. The sources cited include the OWASP AIBOM Generator, the AIBOM Generator GitHub repository, the OWASP AI SBOM Initiative, the White House executive order, and CISA alerts, which are authoritative and relevant. The title accurately reflects the content, focusing on practical AIBOM generation. The video does not delve into academic literature but provides a credible overview of current best practices and standards.

172 words

Title / Content Match

The title accurately reflects the content, which focuses on generating an AI Bill of Materials in practice, with a clear demonstration and expert discussion.

Quality & Reliability

8/10

The video features two recognized experts in AI supply chain security, co-leads of the OWASP AI SBOM initiative, and provides a practical demonstration of an open-source tool. The information is consistent with known industry practices and standards (CycloneDX, NTIA minimum elements). However, the discussion is largely based on expert opinion and practical experience rather than peer-reviewed research, and some claims (e.g., attack statistics) are not independently verified.

Chapters

Cited Sources

  • OWASP AIBOM Generator — Tool demonstrated in the video for generating AIBOMs from Hugging Face models.
  • AIBOM Generator on GitHub — Open-source repository for the AIBOM Generator, allowing local deployment and CI/CD integration.
  • OWASP AI SBOM Initiative — Initiative co-led by the guests, providing resources and playbooks for AI SBOMs.
  • White House executive order, June 2, 2026 — Referenced as a recent policy driver for AI supply chain security.
  • CISA alert on the Axios compromise — Referenced as an example of a recent supply chain attack.

Concurring Sources

  • CISA SBOM Resources — CISA provides official guidance on SBOMs, aligning with the video's emphasis on supply chain transparency.
  • OWASP CycloneDX — The standard used for AIBOM output, supporting the technical details discussed.

External References

Contribution & Novelties

The video provides a practical, hands-on introduction to generating AI Bills of Materials, which is a relatively new and evolving area. It offers a clear demonstration of an open-source tool and explains how to interpret the results, filling a gap for practitioners. The discussion also highlights the distinction between SBOM and AIBOM and the importance of considering the broader AI ecosystem (models, datasets, prompts, etc.).

Pour aller plus loin :

  • CycloneDX — The standard used for the AIBOM output, relevant for understanding the format and its capabilities.
  • NTIA SBOM Minimum Elements — Foundational document for SBOM requirements, referenced in the video.
  • OWASP AI Security and Privacy Guide — Related OWASP resource for AI security, providing broader context.

117 words

Radar Profile

The radar profile shows high scores in information quantity, quality, and reliability, with a slightly lower technical depth. This indicates the video is informative and credible, but may not delve into advanced technical details, making it suitable for a broad security audience.

Reliability 8/10