The Missing Layer: Why Your CBOM Doesn't Know About Your AI Agents
Two supply chain transparency programmes are running in parallel right now, and neither one sees the other.
On one track: the Cryptography Bill of Materials, or CBOM. Standardised in CycloneDX v1.6, expanded in v1.7, and made a federal requirement in the US by executive order in June 2026. A CBOM inventories every cryptographic asset in a system: algorithms, keys, certificates, protocols, libraries. It exists because you cannot migrate to post-quantum cryptography if you don’t know where your current cryptography lives.
On the other track: the SBOM for AI, sometimes called AIBOM. The G7 Cybersecurity Working Group published minimum elements in May 2026, built around seven clusters: metadata, models, dataset properties, system-level properties, KPIs, security properties, and infrastructure. CISA updated its SBOM minimum elements in July 2026 to explicitly call out AI as requiring additional elements. OWASP ships an open-source AIBOM generator. The EU Cyber Resilience Act and the EU AI Act both push toward this. An AIBOM inventories the models, training data, frameworks, and dependencies that make up an AI system.
Both programmes are necessary. Both are gaining regulatory traction. Both are producing real tooling. And both are blind to the same thing: the cryptographic assets that AI agents carry.
That blind spot is the subject of this post.
[Read More . . .]