AI supply-chain assurance for the AI industry using cryptographically signed bills of materials
Bringing trustworthiness to AI systems — a bill of materials for the whole AI supply chain.
The Challenge
AI is the pre-eminent “complex system”: a modern AI product is far more than a single model, encompassing training data, parameter sets, frameworks, toolchains and interacting software components drawn from a long, opaque supply chain. Developers, auditors, regulators and buyers currently have no reliable way to answer basic questions — what AI system is being used, what are its components and their origin, what data was it trained on, is its integrity assured, and under what licence is it supplied? Without the ability to label, version and attest AI systems there is no foundation for any higher-level trust, safety or compliance claim.
The Solution
TAIBOM (Trustable AI Bill of Materials) extends Software Bill of Materials (SBOM) principles into the AI domain. NQM led the collaborative R&D consortium (with BAE Systems, BSI, Copper Horse, TechWorks and the University of Oxford, and in collaboration with the US CISA) to deliver a trust-enabled AIBOM data model: structured dependency modelling for AI components, cryptographic signing to secure integrity propagation, integrity verification, dataset provenance tracking, and a trust attestation process for verifying component provenance across heterogeneous AI pipelines. NQM’s trusted-data expertise — signed claims, attestation and distributed trust reasoning — underpins the framework, and TAIBOM feeds directly into NQM products (Synapse builds on TAIBOM for AI assurance).
Outcomes
TAIBOM was Phase 2 of NQM’s trustworthy-AI programme, building on the Phase 1 feasibility study T-CHAIN. It was formally announced at the TechWorks AI launch event at Bletchley Park in April 2024, with support from the Minister for AI. The framework supports and aligns with key regulations such as the EU AI Act and US Executive Order 14028.
The outputs delivered include the open TAIBOM specifications, schemas and SDK published at taibom.org; the research paper “TAIBOM: Bringing Trustworthiness to AI-Enabled Systems” (arXiv:2510.02169) co-authored with the University of Oxford; and, following the project phase, a standalone TAIBOM working group under TechWorks with an industry review phase inviting organisations to review, test and contribute use-cases toward a globally recognised standard.

Features
Trust-enabled AIBOM data model with structured dependency modelling for AI components (data, code, models, configurations).
Cryptographic signing and integrity verification, so a system can attest it is what it says it is.
Dataset provenance tracking from training data through to model outputs.
Trust attestation process for verifying component provenance across heterogeneous AI pipelines.
A "lingua franca" for combining AI security descriptors, aligned with the EU AI Act and US EO 14028.
Goes beyond SBOM by handling AI-specific artefacts (training data, weights, retraining cycles) with cryptographically backed descriptions and subjective-claim validation.
Benefits
"TAIBOM: Bringing Trustworthiness to AI-Enabled Systems" (arXiv:2510.02169), authored by Vadim Safronov (Oxford), Anthony McCaigue (NQM), Nicholas Allott (NQM) and Andrew Martin (Oxford).
Transitioned from funded project into a standalone TechWorks working group; industry review phase launched, inviting organisations to review, test and contribute use-cases toward a recognised standard.
Developed in collaboration with the US CISA, signalling international relevance.
Making AI systems more transparent, traceable and trustworthy (framework capability; large-scale adoption metrics are projections at this stage).
NQM's Synapse builds on TAIBOM for AI assurance and TrustNetZ for device/network security.
Volt features used
AI as first-order elements — fast
secure monitoring and telemetry
open standards and open source, by commitment
data-centric security
interoperable core
embedded supply chain and provenance
confidence scoring and continuous assurance — trust as a graded, computed measure
Working with
News

Assuring Systems Integrity for Software and AI: From SBOM to TAIBOM
AI systems, from training to deployment is the focus of the Techworks organisation workshop session today held at Kellogg college Oxford University. The event is opened by Gareth Richards, TechWorks. Nick Allott, NquiringMinds, speaks first and presents on SBOM/TAIBOM – what are they all about with case studies, and discusses tools and technologies for creation.

TAIBOM Trusted AI Bill of Materials
NquiringMinds is developing new secure AI technology to solve the issue of trust and continuous assurance in complex AI systems. TAIBOM is funded by UKRI Technology Missions Fund, and was recently announced by Secretary of State (SoS) for Science, Innovation and Technology, Michelle Donelan,. This program is designed to accelerate the UK’s adoption of trustworthy.

Setting the Standard for Trustable AI: UK-Funded TAIBOM Project Launches Industry Review Phase
The Trustable AI Bill of Materials (TAIBOM), a UK government-seeded initiative, is rapidly emerging as a leading standard for building trust in artificial intelligence systems. As AI technologies are increasingly deployed in critical, sensitive, and high-risk contexts, TAIBOM delivers a structured, transparent way to document and manage AI systems across their full supply chain—from training.

NquiringMinds Collaborates with Leading Organizations to Establish a Trusted AI Bill of Materials
A group of prominent organisations have joined forces to develop the TAIBOM (Trusted AI Bill of Materials) collaborative project, aimed at creating processes and mechanisms to ensure the transparency and trustworthiness of AI systems as they become increasingly prevalent in our daily lives. The TAIBOM project was formally announced today at the TechWorks AI launch.
