AI/ML SBOMs
Unlike packages, ML artifacts do not have SBOMs to help with transparency and dataset evaluation. This is changing. The US Army has been looking at implementing an AI Bill of Materials. You can read more about it at https://www.afcea.org/signal-media/cyber-edge/us-army-considering-ai-bill-materials.
Note
Security non-profit organization OWASP has recently updated its SBOM CycloneDX standard, introducing an ML BOM extension in CycloneXC 1.5 to cover models and datasets. See https://cyclonedx.org/capabilities/mlbom/ for more information.
These positive developments are still at an early stage but will undoubtedly accelerate to support increasing demand. We expect that the not-so-distant future models and datasets will have their BOMs and vulnerabilities publicly maintained like CVEs are maintained for software components. We recommend that as vendors start supporting AI/ML BOMs, organizations should embrace them and use them as well.