G7 AIのためのソフトウェア部品表(SBOM for AI) 必須要素 (2026.05.12)
こんにちは、丸山満彦です。
G7が、AIのためのソフトウェア部品表(SBOM for AI) 最少要素を公表しています...
2025年6月にG7サイバーセキュリティ作業部会が公表したAI向けSBOMに関する共通ビジョンに基づき、AI向けSBOMに含めるべき最低限の要素について、有用かつ実践的な提言を行うために、イタリア(ACN)とドイツ(BSI)が共同で主導する「人工知能:AI向けSBOM」という作業部会のもと、G7議長国であるカナダ(2025年)およびフランス(2026年)からの支援を受けてこの文書はできているということです。
この文書は、
- AIのためのソフトウェア部品表(SBOM)に何が合理的に期待されるかについて、
- AIサプライチェーンにおける透明性とサイバーセキュリティを向上させるために、
官民のステークホルダーに向けた実践的な指針を提供するものということのようです...
クラスターとして7つを挙げていますね...
| 1 Metadata | 1 メタデータ |
| 2 System Level Properties (SLP) | 2 システムレベルプロパティ(SLP |
| 3 Models | 3 モデル |
| 4 Datasets Properties (DP) | 4 データセットプロパティ(DP) |
| 5 Infrastructure | 5 インフラストラクチャ |
| 6 Security Properties (SP) | 6 セキュリティプロパティ(SP) |
| 7 Key Performance Indicators (KPI) | 7 主要業績評価指標(KPI) |
● BSI
・2026.05.12 BSI veröffentlicht G7-Richtlinie zu Software Bill of Materials for AI
| BSI veröffentlicht G7-Richtlinie zu Software Bill of Materials for AI | BSI、AI向けソフトウェア部品表(SBOM for AI)に関するG7ガイドラインを公表 |
| Nachdem im Juni 2025 bereits eine gemeinsame Vision zum Nutzen und der Notwendigkeit einer Stückliste für KI (SBOM for AI) veröffentlicht wurde, erreichen die Cybersicherheitsbehörden der G7-Staaten und die EU-Kommission einen Meilenstein. Unter der Federführung des BSI und der italienischen Cybersicherheitsbehörde ACN fand ein regelmäßiger Austausch zwischen allen Behörden statt. | 2025年6月にAI向けソフトウェア部品表(SBOM for AI)の有用性と必要性に関する共同ビジョンがすでに公表されていたが、G7諸国のサイバーセキュリティ当局とEU委員会は新たな節目を迎えた。BSIとイタリアのサイバーセキュリティ機関ACNの主導の下、すべての当局間で定期的な意見交換が行われた。 |
| Das Ergebnis: Eine G7-Richtlinie zu Software Bill of Materials (SBOM) for AI. Diese bietet Empfehlungen für Minimalanforderungen an eine SBOM for AI und wurde gemeinsam von den KI-Expertinnen und Experten der G7 Cybersicherheitsbehörden und der EU-Kommission erarbeitet. Die sieben übergeordneten Informationskategorien (Cluster) enthalten jeweils mehrere Elemente, die durch anschauliche Beispiele für einen praxistauglichen Einsatz hinterlegt werden. | その結果、AI向けソフトウェア部品表(SBOM)に関するG7ガイドラインが策定された。これはAI向けSBOMの最低要件に関する推奨事項を提示するものであり、G7サイバーセキュリティ当局およびEU委員会のAI専門家によって共同で作成された。7つの上位情報カテゴリ(クラスター)にはそれぞれ複数の要素が含まれており、実用的な活用例が具体的に示されている。 |
| BSI-Präsidentin Claudia Plattner: "Transparenz über die KI-Lieferkette, die eingesetzten Komponenten und Abhängigkeiten bildet die Grundlage für robuste KI-Cybersicherheit. Sie ermöglicht Nachvollziehbarkeit der Systeme, unterstützt das effiziente Management identifizierter Schwachstellen und stärkt das Cyberrisikomanagement der Organisation." | BSIのクラウディア・プラットナー会長は次のように述べている。「AIのサプライチェーン、使用されるコンポーネント、および依存関係に関する透明性は、強固なAIサイバーセキュリティの基盤となる。これによりシステムの追跡可能性が確保され、特定された脆弱性の効率的な管理が支援され、組織のサイバーリスク管理が強化される。」 |
| Das kann eine SBOM for AI leisten: Sie schafft Transparenz, um mit den richtigen Tools die Cybersicherheit eines KI Systems effektiv umzusetzen. Eine SBOM soll, erweitert auf KI-Systeme, künftig z.B. Informationen über das verwendete KI-Modell sowie Art, Quelle und mögliche Biases in den Trainingsdaten enthalten. Ziel ist, den gesamten Lebenszyklus der KI-Anwendung zu betrachten und transparent zu machen. | SBOM for AIが果たす役割は、適切なツールを用いてAIシステムのサイバーセキュリティを効果的に実現するための透明性を生み出すことだ。AIシステムに拡張されたSBOMは、将来的には、使用されているAIモデルに関する情報や、トレーニングデータの種類、ソース、および潜在的なバイアスなどを含むことになる。その目的は、AIアプリケーションのライフサイクル全体を俯瞰し、透明性を確保することにある。 |
| Künstliche Intelligenz, wie etwa agentische oder generative KI, entwickelt sich schnell, umfangreich und permanent, weshalb das Dokument Anpassungen und Änderungen in der Zukunft offen lässt. | エージェント型や生成型AIなどの人工知能は、急速かつ広範に、そして絶えず進化しているため、この文書は将来的な調整や変更の可能性を残している。 |
・[PDF] Software Bill of Materials (SBOM) for Artificial Intelligence - Minimum Elements
目次...
| Exective Summary | エグゼクティブサマリー |
| 1. Introduction | 1. 序論 |
| 2. Clusters and Cluster Elements | 2. クラスターとクラスター要素 |
| 2.1 Metadata Cluster Elements | 2.1 メタデータ・クラスター要素 |
| 2.2 System Level Properties (SLP) Cluster Elements | 2.2 システムレベルプロパティ(SLP)クラスター要素 |
| 2.3 Models Cluster Elements | 2.3 モデル・クラスター要素 |
| 2.4 Datasets Properties (DP) Cluster Elements | 2.4 データセットプロパティ(DP)クラスター要素 |
| 2.5 Infrastructure Cluster Elements | 2.5 インフラストラクチャ・クラスタ要素 |
| 2.6 Security Properties (SP) Cluster Elements | 2.6 セキュリティプロパティ(SP)クラスター要素 |
| 2.7 Key Performance Indicators (KPI) Cluster Elements | 2.7 主要業績評価指標(KPI)クラスター要素 |
| 3. Discussion | 3. 考察 |
| 4. Conclusion | 4. 結論 |
| References | 参考文献 |
エグゼクティブサマリー...
| EXECUTIVE SUMMARY | エグゼクティブサマリー |
| Accessing information on the supply chain of an artificial intelligence (AI) system, as well as its individual components and dependencies, is critical to strengthen cybersecurity of AI. Transparency and knowledge about AI system composition fosters vulnerability management and supports cybersecurity risk management. | 人工知能(AI)システムのサプライチェーン、およびその個々の構成要素や依存関係に関する情報にアクセスすることは、AIのサイバーセキュリティを強化するために極めて重要である。AIシステムの構成に関する透明性と知識は、脆弱性管理を促進し、サイバーセキュリティリスクマネジメントを支援する。 |
| This document provides actionable guidelines for public and private sector stakeholders on what is reasonable to expect in a Software Bill of Materials (SBOM) for AI, and to improve transparency and cybersecurity along the AI supply chain. It builds on the shared vision of SBOM for AI published by the G7 Cybersecurity Working Group in June 2025 and provides useful practical recommendations on which minimum elements SBOMs for AI should include. As such, this document is meant to cover a minimum set of elements identified and agreed on by experts within the G7 Cybersecurity Working Group. These minimum elements are not mandatory; do not create requirements, standards, or legislation; and are open to further refinements to keep pace with technological development and evolution of legal or policy frameworks within G7 members. Additionally, in some jurisdictions, certain elements proposed in this document may already be, or may be expected to be, addressed through legal requirements and obligations, or through existing or forthcoming standards. | 本文書は、AI向けソフトウェア部品表(SBOM)に何が合理的に期待されるかについて、またAIサプライチェーンにおける透明性とサイバーセキュリティを向上させるために、官民のステークホルダーに向けた実践的な指針を提供するものである。これは、2025年6月にG7サイバーセキュリティ作業部会が公表したAI向けSBOMに関する共通ビジョンに基づき、AI向けSBOMに含めるべき最低限の要素について、有用かつ実践的な提言を行うものである。 したがって、本ドキュメントは、G7サイバーセキュリティ作業部会内の専門家によって識別され合意された、最低限の要素セットを網羅することを意図している。これらの最低限の要素は義務的なものではなく、要件、標準、または法規制を創設するものではない。また、技術の発展やG7加盟国における法的・政策的フレームワークの進化に対応するため、さらなる改良の余地を残している。 さらに、一部の法域においては、本文書で提案されている特定の要素が、法的要件や義務、あるいは既存または今後策定される標準を通じて、すでに扱われているか、あるいは扱われることが予想される場合がある。 |
| This document is jointly published by Germany’s Federal Office for Information Security (BSI), Italy’s National Cybersecurity Agency (ACN), France’s National Cybersecurity Agency (ANSSI), Canada’s Communications Security Establishment (CSE), the US Cybersecurity and Infrastructure Security Agency (CISA), UK’s National Cyber Security Centre (NCSC) and Japan’s National Cybersecurity Office (NCO), in collaboration with the EU Commission. | 本文書は、ドイツ連邦情報セキュリティ局(BSI)、イタリア国家サイバーセキュリティ庁(ACN)、フランス国家サイバーセキュリティ庁(ANSSI)、カナダ通信セキュリティ局(CSE)、米国サイバーセキュリティ・インフラセキュリティ庁(CISA)、 英国の国家サイバーセキュリティセンター(NCSC)、および日本の国家サイバーセキュリティ事務局(NCO)が、EU委員会と協力して共同で発行するものである。 |
| This document has been written thanks to the support provided by the G7 Presidencies of Canada (2025) and France (2026), under the work stream “Artificial Intelligence: SBOM for AI” co-led by Italy (ACN) and Germany (BSI). | 本文書は、イタリア(ACN)とドイツ(BSI)が共同で主導する「人工知能:AI向けSBOM」という作業部会のもと、G7議長国であるカナダ(2025年)およびフランス(2026年)からの支援を受けて作成された。 |
● US. CISA
・2026.05.12 Software Bill of Materials for AI - Minimum Elements
| Software Bill of Materials for AI - Minimum Elements | AI向けソフトウェア部品表(SBOM)-必須要素 |
| CISA and the Group of Seven (G7) international partners—Germany, Canada, France, Italy, Japan, the United Kingdom, and the European Union—have released joint guidance, Software Bill of Materials for AI – Minimum Elements, to help public and private sector stakeholders improve transparency in their artificial intelligence (AI) systems and supply chains. | CISAおよびG7(ドイツ、カナダ、フランス、イタリア、日本、英国、欧州連合)の国際パートナーは、官民のステークホルダーが人工知能(AI)システムおよびサプライチェーンの透明性を向上させることを支援するため、共同ガイダンス『AI向けソフトウェア部品表(SBOM)-必須要素』を発表した。 |
| A software bill of materials (SBOM) acts as an “ingredients list” for software that better positions organizations to understand their supply chains and make risk-informed decisions about how to protect their critical systems. The guidance builds on CISA’s previous work with federal and international partners to establish a shared vision for a software bill of materials and provides recommendations on minimum elements that should be included in an SBOM for AI. Because AI systems are software systems, these recommendations should be considered in addition to the general minimum elements for an SBOM. | ソフトウェア部品表(SBOM)は、ソフトウェアの「成分表」としての役割を果たし、組織が自社のサプライチェーンを理解し、重要なシステムを保護する方法についてリスクに基づいた意思決定を行うための基盤となる。本ガイダンスは、ソフトウェア部品表に関する共通のビジョンを確立するためにCISAが連邦政府および国際的なパートナーとこれまで行ってきた取り組みを基に作成されたものであり、AI向けSBOMに含めるべき最低限の要素に関する推奨事項を提示している。AIシステムはソフトウェアシステムであるため、これらの推奨事項は、SBOMの一般的な必須要素に加えて考慮されるべきである。 |
| While not exhaustive or mandatory, the supplemental minimal elements outlined in this guidance reflect the consensus of G7 experts and will expand over time to keep pace with the rapid advancement of AI technology. | 本ガイダンスで概説された補足的な必須要素は、網羅的でも強制的でもないが、G7の専門家による合意を反映したものであり、AI技術の急速な進歩に対応するため、今後順次拡充されていく予定である。 |
・[PDF] A shared G7 Vision on Software Bill of Materials for Artificial Intelligence
| Jointly drafted by BSI and CAN | BSIとCANによる共同作成 |
| A Shared G7 Vision on Software Bill of Materials for AI | AI向けソフトウェア部品表(SBOM)に関するG7の共通ビジョン |
| Transparency and Cybersecurity along the AI Supply Chain | AIサプライチェーンにおける透明性とサイバーセキュリティ |
| This paper has been written under the work stream “Smarter Together: Artificial Intelligence” of the G7 Cybersecurity Working Group. It serves as food for thought and does not intend to contradict work conducted in existing G7 groups such as the Hiroshima AI Process. In some jurisdictions a number of elements of SBOMs for AI proposed in this paper may be expected to be covered, for example, through legal requirements and obligations or existing or forthcoming standards. Due to the ongoing evolution of legal and policy frameworks within the G7 members, this paper is open for further evolution. | 本報告書は、G7サイバーセキュリティ作業部会の「Smarter Together: Artificial Intelligence」という作業ストリームの下で作成されたものである。本報告書は考察の材料となるものであり、広島AIプロセスなどの既存のG7グループで行われている取り組みと矛盾する意図はない。一部の法域においては、本報告書で提案されているAI向けSBOMの要素の一部が、例えば法的要件や義務、あるいは既存または今後策定される規格などを通じて、すでに網羅されていると予想される。G7加盟国における法的・政策的枠組みは現在も進化し続けているため、本報告書の内容は今後も変更される可能性がある。 |
| 1. Introduction | 1. はじめに |
| Organizations, institutions and the general public all around the world are using AI systems for multiple purposes. Developing such systems is highly complex: it requires a vast amount of resources (e.g., energy, data), infrastructure (esp. GPUs), and human expertise. Many AI systems often rely on existing base models - either commercial or open source - and are adapted according to their application purpose. | 世界中の組織、機関、そして一般市民が、様々な目的でAIシステムを利用しています。こうしたシステムの開発は極めて複雑であり、膨大なリソース(エネルギー、データなど)、インフラ(特にGPU)、そして人的専門知識を必要とします。多くのAIシステムは、商用またはオープンソースの既存のベースモデルに依存し、その用途に応じて適応されています。 |
| Like most modern software systems, AI systems are complex. Complexity often leads to a lack of insights into how exactly an AI system works and which components and elements an AI system is based on. | 現代のほとんどのソフトウェアシステムと同様に、AIシステムは複雑です。この複雑さゆえに、AIシステムが具体的にどのように機能しているのか、またどのようなコンポーネントや要素に基づいているのかについての理解が不足しがちです。 |
| As a result, key cybersecurity issues, such as potential weak points, vulnerabilities, manipulations or compromises, are difficult to detect. Indeed, aspects such as how an AI system has been trained, including the data used and the underlying base model, are key to ensure trustworthiness, security and safety of AI systems, whereas we note that safety and security of AI systems are related as described for example in G7 Leaders’ Statement on the Hiroshima AI Process. | その結果、潜在的な弱点、脆弱性、改ざん、または侵害といった重要なサイバーセキュリティ上の問題を検出することが困難になる。実際、使用されたデータや基盤となるベースモデルを含め、AIシステムがどのように学習されたかといった側面は、AIシステムの信頼性、セキュリティ、および安全性を確保する上で鍵となる。一方で、例えば「広島AIプロセスに関するG7首脳声明」で述べられているように、AIシステムの安全性とセキュリティは相互に関連していることに留意する必要がある。 |
| The G7 Cybersecurity Working Group suggests introducing a common concept for Software Bill of Materials for AI (SBOM for AI).[1] An SBOM for AI consists of a structured record of details and supply chain relationships for the various components used in building an AI system. The goal of an SBOM for AI is to contribute to fostering security of AI systems through AI supply chain transparency and traceability of its components and dependencies. | G7サイバーセキュリティ作業部会は、AI向けソフトウェア部品表(SBOM for AI)に関する共通概念の導入を提案している[1]。AI向けSBOMは、AIシステムの構築に使用される様々なコンポーネントの詳細およびサプライチェーン上の関係性を構造化して記録したものである。AI向けSBOMの目的は、AIサプライチェーンの透明性およびコンポーネントと依存関係のトレーサビリティを通じて、AIシステムのセキュリティ向上に寄与することにある。 |
| This paper presents a shared vision and a first high-level summary of the SBOM for AI concept, including its benefits for cybersecurity, its properties, and an initial proposal for its example minimum elements. While SBOMs for AI are not explicitly a cybersecurity tool, if designed and used correctly in conjunction with appropriate tools (e.g., vulnerability management software), they could foster the transparent inventory needed to help secure the supply chain. The paper concludes with an outlook on necessary next steps to further proceed with the technical implementation of an SBOM for AI framework. | 本稿では、AI用SBOMの概念に関する共通のビジョンと、その概要を初めて高レベルで提示する。これには、サイバーセキュリティへの利点、その特性、および最小構成要素の初期提案が含まれる。AI用SBOMは、厳密にはサイバーセキュリティツールではないが、適切なツール(例:脆弱性管理ソフトウェア)と組み合わせて正しく設計・使用されれば、サプライチェーンのセキュリティ確保に役立つ透明性のあるインベントリの構築を促進し得る。本論文は、AI向けSBOMフレームワークの技術的実装をさらに進めるために必要な今後のステップに関する展望をもって締めくくられる。 |
| 2. Improving cybersecurity through transparency along the AI supply chain | 2. AIサプライチェーンにおける透明性を通じたサイバーセキュリティの向上 |
| One of the key challenges of securing an AI system is the vulnerability of its supply chain to both traditional and novel attack vectors. The depth and complexity of AI supply chains, coupled with the evolving and dynamic AI lifecycle, represents a considerable attack surface. Successful cyber attacks often aim at compromising a product before it reaches the consumer/end-user, including also AI components. The goal of so-called supply chain attacks is often to gather/steal sensitive information, pre-positioning and more generally to cause damage, either in the relationships between the stakeholders and/or financially, e.g., by tampering or poisoning data, causing unproductivity, misinformation or pursuing own interests. | AIシステムのセキュリティ確保における主要な課題の一つは、そのサプライチェーンが従来型および新規の攻撃ベクトルに対して脆弱である点である。AIサプライチェーンの深さと複雑さは、進化し続ける動的なAIライフサイクルと相まって、相当な攻撃対象領域を形成している。成功するサイバー攻撃は、AIコンポーネントを含め、製品が消費者やエンドユーザーに届く前に侵害することを狙うことが多い。いわゆるサプライチェーン攻撃の目的は、機密情報の収集・窃取、事前配置、そしてより一般的には、データの改ざんや汚染、生産性の低下、誤情報の拡散、あるいは自己利益の追求などを通じて、ステークホルダー間の関係や財務面に損害を与えることにある。 |
| Against this backdrop, improved cybersecurity along the AI supply chain can be achieved by increasing transparency, specifically with regard to accessing information on the creation process of the final AI system, as well as its individual components and dependencies. While for traditional software products the Software Bill of Materials (SBOM) concept may support mitigation to the above mentioned cybersecurity attacks, there is no internationally established and practically applicable common practice for systems using AI yet. In conjunction with other security tools, an SBOM for AI can increase transparency along the supply chain and thus contribute to cybersecurity. | こうした背景において、AIサプライチェーン全体でのサイバーセキュリティの向上は、透明性を高めることで実現可能です。具体的には、最終的なAIシステム、およびその個々のコンポーネントや依存関係に関する作成プロセスへの情報アクセスに関して透明性を高めることが重要です。従来のソフトウェア製品においては、ソフトウェア部品表(SBOM)の概念が前述のサイバーセキュリティ攻撃への対策として有効ですが、AIを利用するシステムについては、国際的に確立され、実用的な共通の慣行はまだ存在しません。他のセキュリティツールと組み合わせて活用することで、AI向けSBOMはサプライチェーン全体の透明性を高め、サイバーセキュリティの向上に寄与する。 |
| An SBOM for AI may bring transparency and knowledge about AI system composition. It fosters vulnerability management and patching by minimizing the response time required to check if known vulnerabilities are deployed within the AI system components, supporting risk management. | AI向けSBOMは、AIシステムの構成に関する透明性と知見をもたらす可能性があります。これにより、既知の脆弱性がAIシステムのコンポーネント内に実装されているかどうかを確認するために必要な対応時間を最小限に抑え、脆弱性管理とパッチ適用を促進し、リスク管理を支援します。 |
| Moreover, an SBOM for AI allows both AI model tracking, addressing issues related to performance while speeding up the entire security compliance verification process, simplifying auditing and keeping track of already existing compliance attestations. Furthermore, the usage of already proven components can reduce costs during the development phase of an AI system. As part of existing Secure by Design paradigms, a persistent use of an SBOM for AI can have positive effects on expensive and time consuming reworkings, such as model retraining, or damage repair. An SBOM for AI also facilitates license management. Most importantly, an SBOM for AI strengthens the autonomy and awareness of AI systems stakeholders by enabling them to make a carefully considered decision whether an AI system, an individual component or indeed a supplier is suitable for a particular purpose or not. | さらに、AI向けSBOMはAIモデルの追跡を可能にし、パフォーマンスに関連する問題に対処すると同時に、セキュリティコンプライアンス検証プロセス全体を迅速化し、監査を簡素化し、既存のコンプライアンス証明を追跡します。さらに、実績のあるコンポーネントを使用することで、AIシステムの開発段階におけるコストを削減できます。既存の「Secure by Design(設計段階からのセキュリティ確保)」パラダイムの一環として、AI向けSBOMを継続的に活用することは、モデルの再学習や障害修復といった、費用と時間を要する手直し作業に対してプラスの効果をもたらします。また、AI向けSBOMはライセンス管理も容易にします。最も重要な点として、AI向けSBOMは、AIシステム、個々のコンポーネント、あるいはサプライヤーが特定の目的に適しているかどうかを、ステークホルダーが慎重に検討した上で判断できるようにすることで、ステークホルダーの自律性と認識を強化します。 |
| 3. Software Bill of Materials for AI | 3. AI向けソフトウェア部品表(SBOM) |
| Properties | 特性 |
| To allow an SBOM for AI to be effective, it needs to ensure that the three following properties are satisfied: | AI向けSBOMが効果を発揮するためには、以下の3つの特性が満たされている必要があります: |
| • being able to capture the static and dynamic aspects of AI systems (e.g., datasets used for training, testing and validation during the lifecycle of the system or learning outcomes) that distinguish them from traditional software systems; | • 従来のソフトウェアシステムとは異なる、AIシステムの静的および動的な側面(例:システムのライフサイクルにおけるトレーニング、テスト、検証に使用されるデータセット、あるいは学習成果)を捕捉できること; |
| • being able to be easily processed automatically and tool generated in a machine-readable format; | • 機械可読形式で、容易に自動処理およびツール生成が可能であること; |
| • being able to leverage structured data formats as much as possible, to ensure that the relevant information is available transparently upon demand to all the stakeholders. | • 構造化データ形式を可能な限り活用し、関連情報がすべてのステークホルダーの要求に応じて透明性を持って利用可能であることを確保できること。 |
| Furthermore, it is equally important to clearly define the information set that an SBOM for AI should include, defined as its “minimum elements”. | さらに、AI用SBOMが含めるべき情報セットを「最小構成要素」として明確に定義することも同様に重要です。 |
| Example minimum elements | 最小要素の例 |
| An SBOM for AI should be composed of a set of minimum elements to capture the distinctive features of an AI system, ensuring compatibility and providing an adequate level of transparency for all the stakeholders. It should automatically build upon information captured by each of the AI components, providing an understanding of the flow between the AI elements of the system. While some transparency mechanisms exist, this effort aims to highlight a core set of data fields that are machine-generatable and machineprocessable. It is important to highlight that these minimum elements represent recommendations to a reasonable extent and should be decided accordingly to the specific context of use. Here below is an exemplary set of high-level minimum elements for a G7 SBOM for AI framework, which may extend the information used for traditional software bill of materials (e.g., supplier name, component version)[2], listed as clusters that can embed more detailed information on: | AI用SBOMは、AIシステムの特徴を捉え、互換性を確保し、すべてのステークホルダーに対して適切なレベルの透明性を提供するために、一連の最小要素で構成されるべきである。それは、各AIコンポーネントによって捕捉された情報を自動的に統合し、システム内のAI要素間の流れを理解できるようにするものである。いくつかの透明性確保の仕組みは存在するものの、本取り組みは、機械生成および機械処理が可能なデータフィールドの中核となるセットを明確にすることを目的としている。これらの最小構成要素は、あくまで合理的な範囲での推奨事項であり、具体的な使用状況に応じて決定されるべきである点を強調しておくことが重要である。以下に、G7 AI用SBOMフレームワークにおける高レベルの最小構成要素の例を示す。これらは、従来のソフトウェア部品表(SBOM)で使用される情報(例:サプライヤー名、コンポーネントのバージョン)[2]を拡張するものであり、より詳細な情報を埋め込むことができるクラスターとして列挙されている: |
| • Models used by the AI system, including basic information to identify the model, describe how the model was created, and spell out how the model is intended to be used. | • AIシステムで使用されるモデル。これには、モデルを特定するための基本情報、モデルの作成方法の説明、およびモデルの使用目的の明示が含まれます。 |
| • Learning, including the description of the training techniques and pipelines and information about training datasets in, e.g., datasheets for datasets. | • 学習。これには、トレーニング手法やパイプラインの説明、およびデータセットのデータシートなどに記載されたトレーニングデータセットに関する情報が含まれます。 |
| • Datasets used during the whole lifecycle of the model, including basic information that documents the identity, creation, use, and provenance of data. | • モデルのライフサイクル全体で使用されるデータセット。これには、データの識別情報、作成、使用、および来歴を記録した基本情報が含まれます。 |
| • Safety and security characteristics, such as a link or reference to the safeguards or guardrail implementations, safety alignment, compliance attestations and cybersecurity best practices adopted during the AI lifecycle. | • 安全性およびセキュリティ特性。これには、AIライフサイクル中に採用されたセーフガードやガードレールの実装、安全性の整合性、コンプライアンスの証明、およびサイバーセキュリティのベストプラクティスへのリンクや参照が含まれます。 |
| • System level characteristics, such as a link or reference to a description of the flow between the AI elements and how the model consumes input data. | • システムレベルの特性。これには、AI要素間のフローや、モデルが入力データをどのように処理するかについての説明へのリンクや参照が含まれる。 |
| • Key Performance Indicators of an AI system, including model benchmark evaluation results. | • AIシステムの主要業績評価指標(KPI)。これには、モデルのベンチマーク評価結果が含まれる。 |
| • Licensing information about the components of an AI system. | • AIシステムの構成要素に関するライセンス情報。 |
| • Infrastructure used by the AI system, including the software components specifically required to deliver an AI system. | • Iシステムが使用するインフラ。これには、AIシステムを提供するために特に必要なソフトウェアコンポーネントが含まれる。 |
| The list is open for further expansion of the clusters in the future to keep pace with the rapid development of technology. | このリストは、技術の急速な発展に対応するため、将来的にクラスターをさらに拡張できるよう設計されている。 |
| To increase trustworthiness and to avoid giving a false sense of security, an SBOM for AI should be verifiable as a whole. This implies not only the verification of its individual components - e.g., via cryptographic hashes or digital signatures from the corresponding manufacturers - but also of the entire SBOM for AI. In order to achieve this goal, a viable SBOM for AI should at least be digitally signed by its manufacturer. While individual components are signed within the SBOM for AI, the signature of the entire SBOM for AI has to be verifiable from the outside. | 信頼性を高め、誤った安心感を与えないようにするため、AI向けのSBOMは全体として検証可能でなければならない。これは、個々のコンポーネント(例:対応するメーカーによる暗号ハッシュやデジタル署名を通じて)の検証だけでなく、AI用SBOM全体の検証も意味する。この目標を達成するためには、実用的なAI用SBOMは少なくともそのメーカーによってデジタル署名されている必要がある。AI用SBOM内の個々のコンポーネントには署名があるものの、AI用SBOM全体の署名は外部から検証可能でなければならない。 |
| 4. The way forward | 4. 今後の展望 |
| Challenges | 課題 |
| An SBOM for AI should include the unique features that distinguish an AI system, in addition to traditional software components. Before introducing an SBOM for AI, tools like system cards and model cards have been proposed both by private companies and by AI regulation as tools to offer increased transparency into AI models. Despite their effectiveness in some contexts, today these tools suffer from lack of harmonized and machine-readable formats, automation and interoperability with other tools. Data management is also an important consideration. SBOMs are not assumed to be publicly available today by regulation or market expectation, and intellectual property protection assumptions should hold for an SBOM for AI. Capturing the dynamic features of the AI model through adequate file formats and fields represents a challenge for building an SBOM for AI. At the same time, an SBOM for AI needs to be able to provide traceability of training pipelines and datasets, especially in the case of proprietary closed models, synthetic data and pre-training information, where a very large number of diverse data corpuses and sophisticated data processing pipelines are used for creating base models. Furthermore, it is critical to keep an SBOM for AI current with the speed at which AI technology develops, adding new information and relevant fields when needed, such as the case of model distillation, an emerging and meaningful technique that should be captured within an SBOM for AI. Indeed, this could easily lead to longer bills and redundant information, hence automation and harmonization of the format is essential for creating a meaningful and effective SBOM for AI. Moreover, it is essential to develop a framework to effectively track AI vulnerabilities and weaknesses, given the still largely experimental results in the field of AI model red teaming. | AI用SBOMには、従来のソフトウェアコンポーネントに加え、AIシステムを特徴づける独自の要素を含めるべきである。AI用SBOMが導入される以前、AIモデルに対する透明性を高めるツールとして、民間企業やAI規制の双方から、システムカードやモデルカードのようなツールが提案されてきた。一部の状況では有効であるものの、現在のこれらのツールは、統一された機械可読形式の欠如、自動化の不足、および他のツールとの相互運用性の問題を抱えている。データ管理も重要な考慮事項である。現在の規制や市場の期待において、SBOMが一般に公開されることは想定されておらず、AI向けSBOMにおいても知的財産保護の前提が維持されるべきである。適切なファイル形式やフィールドを通じてAIモデルの動的な特徴を捕捉することは、AI向けSBOMを構築する上での課題となっている。同時に、AI用SBOMは、トレーニングパイプラインやデータセットのトレーサビリティを提供できる必要があります。特に、独自のクローズドモデル、合成データ、および事前学習情報の場合、ベースモデルの作成には非常に多くの多様なデータコーパスと高度なデータ処理パイプラインが使用されるため、その重要性は高まります。さらに、AI技術の発展速度に合わせてAI用SBOMを最新の状態に保ち、必要に応じて新しい情報や関連フィールドを追加することが極めて重要である。例えば、AI用SBOM内に捕捉すべき新興かつ有意義な技術であるモデル蒸留(モデルディスティレーション)の場合がこれに該当する。実際、これによりSBOMが冗長化したり不要な情報が含まれたりする恐れがあるため、有意義かつ効果的なAI用SBOMを作成するには、フォーマットの自動化と標準化が不可欠である。さらに、AIモデルに対するレッドチーム攻撃の分野では依然として実験的な結果が大半を占めていることを踏まえ、AIの脆弱性や弱点を効果的に追跡するためのフレームワークを構築することが不可欠である。 |
| Future G7 work | 今後のG7の取り組み |
| This paper presented a shared G7 vision on SBOM for AI to increase transparency and cybersecurity along the full supply chain of AI systems and models. A trustworthy SBOM for AI: | 本稿では、AIシステムおよびモデルのサプライチェーン全体における透明性とサイバーセキュリティを向上させるための、AI向けSBOMに関するG7の共通ビジョンを提示した。信頼性の高いAI向けSBOMは: |
| • allows all the stakeholders involved in the AI supply chain to benefit from the improved transparency and knowledge of the system components; | • AIサプライチェーンに関わるすべてのステークホルダーが、システムコンポーネントに関する透明性と知識の向上から恩恵を受けられるようにする; |
| • reduces risks, improves insight and traceability of the core components of an AI system, including security guardrails, vulnerability management and compliance attestations; | • リスクを低減し、セキュリティガードレール、脆弱性管理、コンプライアンス証明を含むAIシステムのコアコンポーネントに関する洞察とトレーサビリティを向上させる; |
| • can foster interoperability with or be integrated in already established safety, transparency and cybersecurity frameworks for traditional software, such as SBOM or security advisories and bulletins. | • 従来のソフトウェア向けの既存の安全性、透明性、サイバーセキュリティフレームワーク(SBOMやセキュリティアドバイザリ、セキュリティ情報など)との相互運用性を促進したり、それらに統合されたりすることが可能である。 |
| To fully harness the benefits and address the challenges of SBOM for AI, the next steps for the G7 Cybersecurity Working Group – Smarter Together: Artificial Intelligence will be to focus on providing a shared technical vision tackling these challenges, starting with a status quo analysis of existing frameworks to be carried out in the second half of 2025. This will be followed by further work on technical recommendations and guidelines, paving the way for the definition of a common G7 framework fostering adoption of SBOM for AI by public and private sector operators. | AI向けSBOMのメリットを最大限に活用し、その課題に対処するため、「G7サイバーセキュリティ作業部会 – Smarter Together: Artificial Intelligence」の次のステップは、これらの課題に取り組む共通の技術的ビジョンの提供に焦点を当てることとなります。その第一歩として、2025年後半に既存のフレームワークに関する現状分析を実施する予定です。これに続き、技術的な提言やガイドラインに関するさらなる作業が行われ、官民の事業者がAI向けSBOMを採用することを促進する共通のG7フレームワークの定義に向けた道筋が整えられることになる。 |
| References | 参考文献 |
| Allen D. Householder, Vijay S. Sarvepalli, Jeff Havrilla, Matt Churilla, Lena Pons, Shing-hon Lau, Nathan M. VanHoudnos, Andrew Kompanek, and Lauren McIlvenny: Lessons Learned in Coordinated Disclosure for Artificial Intelligence and Machine Learning Systems. 2024. | Allen D. Householder、Vijay S. Sarvepalli、Jeff Havrilla、Matt Churilla、Lena Pons、Shing-hon Lau、Nathan M. VanHoudnos、Andrew Kompanek、Lauren McIlvenny:人工知能および機械学習システムにおける協調的開示から得られた教訓。2024年。 |
| Federal Office for Information Security (BSI): Transparency of AI Systems, White Paper. 2024. | 連邦情報セキュリティ局(BSI):AIシステムの透明性、ホワイトペーパー。2024年。 |
| Federal Office for Information Security (BSI): Technical Guideline TR-03183: Cyber Resilience Requirements for Manufacturers and Products - Part 2: Software Bill of Materials (SBOM). 2024. | 連邦情報セキュリティ局(BSI):技術ガイドライン TR-03183:製造業者および製品に対するサイバーレジリエンス要件 - 第2部:ソフトウェア部品表(SBOM)。2024年。 |
| French National Cybersecurity Authority (ANSSI): Building trust in AI through a cyber risk-based approach. Joint high-level risk analysis on AI. Version 1.0, 2025. | フランス国家サイバーセキュリティ庁(ANSSI):サイバーリスクベースのアプローチを通じたAIへの信頼構築。AIに関する共同ハイレベルリスク分析。バージョン 1.0、2025年。 |
| Ministry of Economy, Trade and Industries (METI) of Japan: Revised Guide Formulated on Specific Methods for Managing Software Vulnerability Utilizing “Software Bill of Materials (SBOM),” a List of Software Components, as a Preparatory Guide for Cyberattacks. | 日本経済産業省(METI):サイバー攻撃への備えとして、ソフトウェア構成要素の一覧である「ソフトウェア部品表(SBOM)」を活用したソフトウェア脆弱性管理の具体的な方法に関する改訂ガイド。 |
| National Cyber Security Center (NCSC): Guidelines for secure AI system development. 2023. | 国立サイバーセキュリティセンター(NCSC):安全なAIシステム開発のためのガイドライン。2023年。 |
| The United States Department of Commerce: The Minimum Elements For a Software Bill of Materials (SBOM), 2021. | 米国商務省:ソフトウェア部品表(SBOM)の必須要素、2021年。 |
| [1] The term SBOM for AI follows the already established concept of Software Bill of Material (SBOM) in the field of traditional software management. | [1] AIにおけるSBOMという用語は、従来のソフトウェア管理分野で既に確立されているソフトウェア部品表(SBOM)の概念に従っている。 |
| [2] As an example we can consider the information included in the US Department of Commerce NTIA document found in reference. | [2] 例として、参考文献にある米国商務省NTIAの文書に含まれる情報を挙げることができる。 |
● まるちゃんの情報セキュリティ気まぐれ日記
・2026.05.08 Five Eyes エージェンティックAIの慎重な導入 (2026.05.01)
・2025.08.13 G7 人工知能のためのソフトウェア部品表に関する G7 の共通ビジョン (2025.06.12)
SBOM...
・2026.04.29 米国 NIST DevSecOps Practice (2026.03.24)
・2026.02.02 IPA AIインシデントレスポンス・アプローチ (2025.01.09)
・2026.01.08 欧州 ENISA パブコメ SBOMの現状分析 - 実装ガイドに向けて案 (2025.12.17)
・2025.11.27 欧州委員会 SBOMの最新状況に関する調査 (2025.12.19まで)
・2025.09.18 ドイツ 情報セキュリティ庁 BSI TR-03183: 製造事業者および製品に対するサイバーレジリエンス要件 第2部:ソフトウェア部品表 (SBOM), 第3部:脆弱性報告および通知 (2025.09)
・2025.09.08 米国他主要国 サイバーセキュリティのためのソフトウェア部品表(SBOM)に関する共通ビジョン
・2025.08.25 米国 CISA パブコメ 2025 年ソフトウェア部品表(SBOM)の最小要素
・2025.08.13 G7 人工知能のためのソフトウェア部品表に関する G7 の共通ビジョン (2025.06.12)
・2025.03.14 シンガポール オープンソースソフトウェアとサードパーティ依存のSBOMとリアルタイム脆弱性監視に関するアドバイザリー (2025.02.20)
・2024.11.25 欧州 サイバーレジリエンス法、官報に掲載 (2024.11.20)
・2024.11.12 インド政府 CERT-In SBOM技術ガイド 第1版 (2024.10.03)
・2024.11.09 ドイツ 連邦セキュリティ室 (BSI) 意見募集 TR-03183: 製造者及び製品に対するサイバーレジリエンス要件(一般要求事項、SBOM、脆弱性報告)
・2024.09.01 経済産業省 ソフトウェア管理に向けたSBOM(Software Bill of Materials)の導入に関する手引ver2.0 (2024.08.29)
・2024.01.08 米国 NSA SBOM管理のための推奨事項 (Ver. 1.1)
・2023.11.12 米国 NSA CISA ソフトウェアサプライチェーンの確保: ソフトウェア部品表の開示に関する推奨事項
・2023.10.13 米国 CISA FBI NSA DOT 運用技術 (OT) および産業制御システム (ICS) におけるオープンソースソフトウェアのセキュリティ向上
・2023.09.18 米国 CISA オープンソース・ソフトウェア・セキュリティ・ロードマップ
・2023.09.01 NIST SP 800-204D(初期公開ドラフト)DevSecOps CI/CDパイプラインにソフトウェアサプライチェーンセキュリティを統合するための戦略
・2023.08.30 日本ネットワークセキュリティ協会 (JNSA) 「日本におけるソフトウェアサプライチェーンとSBOMのこれから」「ゼロトラストと標準化」
・2023.08.15 ドイツ SBOMの要件...技術ガイドライン TR-03183:製造業者および製品に対するサイバーレジリエンス要件 (2023.08.04)
・2023.08.01 経済産業省 ソフトウェア管理に向けたSBOM(Software Bill of Materials)の導入に関する手引
・2023.07.09 米国 NSA CISA 継続的インテグレーション/継続的デリバリー(CI/CD)環境の防御に関する共同ガイダンス (2023.06.28)
・2023.07.03 OWASP SBOMガイダンス CycloneDX v1.5 (2023.06.23)
・2023.04.25 米国 CISA SBOM関連の二文書
・2022.11.17 CISA ステークホルダー別脆弱性分類 (SSVC) ガイド
・2021.05.13 米国 国家のサイバーセキュリティ向上に関する大統領令
« 金融庁 「コーポレートガバナンス・コードの改訂に関する有識者会議」(令和7年度第3回)議事録 (2026.05.22) | Main | 米国 一般調達局 FPKI統合テスト環境(CITE)参加ガイド (2026.04.21) »


Comments