Organizations are deploying artificial intelligence (AI) far faster than they can document its underlying components. Frameworks for recording a model’s provenance exist, covering training data, licensing, and modification history, but there is no unified standard required for edge and defense procurement.
The result is a set of conditions that accumulate during normal operations: documentation practices remain optional and uneven, disclosure across the vendor to-government boundary is not mandatory, and the resulting gaps in visibility widen when no immediate crisis forces them into view.
This paper from Latent.AI describes the components of the AI software supply chain, the points at which visibility is lost, and the national security exposure that accumulates when those components are deployed without a documented provenance record.
It surveys the standards and tooling that address parts of the problem and describes where their coverage stops short, and it outlines the elements a standardized AI Bill of Materials (AIBOM) would need to capture to close the gap.
