Every procurement clause you write today either accounts for AI risk or it does not. When CERT-In updated its Technical Guidelines to include the Artificial Intelligence Bill of Materials, or AIBOM, alongside SBOM, CBOM, QBOM and HBOM, the document carried no penalty clause and no mandatory deadline. It read like guidance, and for now, it is guidance.
India’s cybersecurity ecosystem has seen this pattern before, on the exact same document family. SBOM followed the same arc: recommendation first, informal adoption by forward-leaning organisations second, quiet inclusion in RFPs and vendor contracts third.
AIBOM under CERT-In guidelines stands at that same starting point today. This post explains why the voluntary label will not hold for long, and what to write into procurement contracts now.
What CERT-In says about AIBOM
CERT-In’s Version 2.0 guidelines dedicate a section to AIBOM, defining it as a structured inventory of the models, datasets and dependencies that make up an AI system. The advice is specific enough to act on immediately, not vague enough to defer.
1. Section 9 minimum elements
The guidance advises AI developers and integrators to document datasets, algorithms, model performance metrics and known vulnerabilities, then automate that documentation within development pipelines. It also recommends integrating AIBOM data with vulnerability databases and CERT-In alerts so risks surface in real time.
2. Voluntary status, and what it means
Legal analysis of the update describes the framework as voluntary but detailed, representing government intent likely to influence contractual standards and procurement procedures even without legal force. Voluntary does not mean optional in the way a nice-to-have feature is optional. It means the requirement has not yet reached the statute books while everything around it moves to assume it exists.
The SBOM precedent: how voluntary became contractual
SBOM’s own history is the clearest evidence available for what happens next with AIBOM. The mechanism that forced adoption was never the law itself.
From executive order to procurement checkbox
The 2021 Executive Order on Improving the Nation’s Cybersecurity mandated SBOMs for US federal software procurement, and the National Telecommunications and Information Administration followed with minimum elements vendors had to meet.
Within a few years, SBOM requests moved from a government-only requirement to a standard line item in enterprise vendor questionnaires across sectors with no direct exposure to the original order.
A 2026 policy memorandum later rescinded the earlier form-based attestation model in favour of a risk-based approach, empowering agencies to demand a current SBOM from any vendor at will.
What changed vendor behaviour was not the mandate
It was buyer behaviour. Once a handful of large, security-conscious customers started asking for an SBOM as a condition of doing business, every vendor selling into that market had to have one ready, mandate or no mandate. CERT-In’s AIBOM guidance is positioned to trigger the same dynamic across India’s AI vendor landscape.
Why AIBOM will follow the same path
The signals pointing toward AIBOM becoming a practical requirement are already visible in how India’s regulators treat the rest of the same CERT-In document.
Regulatory signalling from SEBI and RBI
SEBI’s Cybersecurity and Cyber-Resilience Framework already references SBOM expectations for regulated entities, and RBI’s advisories point regulated entities back to CERT-In’s technical guidelines as the operative standard. Neither regulator has issued AI-specific mandates yet, but both already treat CERT-In’s guidance as the practical baseline for their sectors, and AIBOM sits inside that same document.
AI-specific risk procurement cannot ignore
AI procurement carries questions a generic security questionnaire was never built to answer, including where training data came from and whether a model has been evaluated for bias. These are precisely the questions an AIBOM is designed to answer, and precisely the questions current vendor contracts in India largely do not ask.
Building AIBOM procurement clauses now
A workable clause does not need to wait for a mandate. It needs to define what a vendor must produce and how often.
What to ask AI vendors for today
Ask vendors to provide, on a defined schedule:
- Model identity and provenance, including version and licensing terms
- Dataset sources, including collection method and known limitations
- Update triggers, meaning what changes require a fresh AIBOM
- Format commitment, ideally a machine-readable structure such as CycloneDX
Contract language that ages well
The clause that survives a future mandate is the one that does not assume voluntary status forever. Write the AIBOM into the delivery schedule as a standing artefact, updated on every material change, rather than something provided only on request.
What AIBOM ready looks like operationally
Most of the underlying discipline already exists inside vendors who build AI responsibly. The gap is in structuring and sharing it.
Documentation vendors should already have
Any vendor fine-tuning AI systems for enterprise customers should already track model versions, training data sources and evaluation results as a matter of engineering discipline, since Section 9’s minimum elements largely mirror sound model governance practice.
Where automation fits
Manually assembling an AIBOM for every AI system in a portfolio does not scale as models get retrained on a rolling basis. Automated discovery and continuous AIBOM generation, integrated with existing SBOM and CBOM platforms, keeps the artefact current without adding manual overhead.
Conclusion
CERT-In’s AIBOM guidance carries no penalty clause today, but the SBOM precedent shows how quickly that changes once large buyers start asking for it as a condition of doing business. Procurement teams that write AIBOM into vendor contracts now will not be scrambling when SEBI, RBI or their own customers start asking the same question CERT-In has already answered.
CyberNX extends its SBOM and CBOM management capability to support AI system inventories, helping regulated entities build AIBOM readiness into existing compliance workflows. Have questions about preparing your procurement contracts for AIBOM? Talk to our team and learn about our AIBOM solutions.
AIBOM under CERT-In Guidelines FAQs
Is AIBOM mandatory in India?
Not currently. CERT-In’s Technical Guidelines are voluntary, though SEBI and RBI already point to CERT-In’s guidelines as the operative reference for related BOM categories.
What happens if a vendor cannot provide an AIBOM?
Nothing under law today. In practice, it signals gaps in a vendor’s own model governance, which is exactly the risk an enterprise buyer is trying to assess.
How is AIBOM different from a security questionnaire?
A questionnaire is a point-in-time, self-reported answer set. An AIBOM is a structured inventory that can be validated against actual model artefacts and tracked over time.



