Black Hat 2026: Why AI Software Bills of Materials Are Essential to AI Trust
SC Media, Wednesday, August 5th, 2026
AI SBOMs are needed as a practical control, not a compliance nicety, after the Hugging Face-OpenAI incident.
AvePoint's Dana Simberkoff argues the Hugging Face-OpenAI incident exposed the need for more ubiquitous AI software bills of materials.
SBOMs became standard after Log4Shell and a 2021 executive order, but AI changes the inventory problem: an AI system is a full stack of models, datasets, prompts, retrieval sources, APIs, plugins, identities, permissions, and agentic workflows that can act with limited human review.
The 2026 State of AI Report found 88.4% of organizations had at least one agent-related security incident in the past year, and 21.1% do not know whether employees use unsanctioned tools to build agents.
AI SBOMs must be living, machine-readable inventories refreshed through CI/CD and MLOps pipelines, not assembled after an incident.