Overview
Severity: MEDIUM | Affected: NIST | Category: policy
The U.S. National Institute of Standards and Technology (NIST) has released the final version of its AI Risk Management Framework 2.0, which now includes mandatory secure supply chain standards for AI systems used in critical infrastructure. Under the new guidelines, developers and operators must provide a detailed AI Bill of Materials (AIBOM) that documents the provenance of training data, pre-trained models, and key software libraries. This AIBOM must be auditable and track changes throughout the model's lifecycle. The framework aims to mitigate risks like data poisoning, model theft, and the use of vulnerable components in AI systems deployed in sectors such as finance, energy, and healthcare. Compliance will be required for all new federal government contracts involving AI by Q4 2027, setting a new de facto standard for the industry.