Do You Know What's Inside Your District's AI Tools? Meet the AI Bill of Materials
AI is already in your classrooms and your back office.
But if a board member asked what data trained those tools, or whose components are running underneath them, could you answer?
Most districts could not. A recent EdTech Magazine explainer by Alexandra Frost calls this "an ethical and regulatory blind spot that creates risk for tech leaders in districts of all sizes" and lays out the tool built to close it: the AI Bill of Materials, or AIBOM.
What an AI Bill of Materials actually is
Think of it as an ingredient list for an AI system.
Arpita Soni, a senior member of IEEE, describes an AIBOM in the article as a machine-readable "repository or inventory" covering a system's data sets, prompts, models, configurations, version history, pipelines and third-party dependencies.
The National Institute of Standards and Technology (NIST) describes AIBOMs as "enablers for AI software transparency and security" that can "foster trust" and "facilitate innovation."
The four layers
Katie Norton, research director for cloud security at IDC, breaks an AIBOM into four layers:
Data. The training and validation data sets, where they came from, how they are licensed and how sensitive they are, including whether they contain personally identifiable information.
Model. The architecture, weights, hyperparameters, version and lineage. In plain terms: what kind of model it is, which version you are running and how it was trained.
Infrastructure and dependencies. The frameworks, libraries and hardware the model needs in order to run.
Governance metadata. What the model is intended for, its known limitations and the safeguards in place.
Why a software inventory is not enough
Many IT teams already know the Software Bill of Materials (SBOM), which lists an application's code, libraries and dependencies. The article is clear that an AIBOM is needed in addition to an SBOM, not instead of one.
Norton explains why: an SBOM "only inventories code," while AI systems are data-driven and often nondeterministic. Their behavior comes from training data and model configuration, not from logic someone wrote out line by line.
Without an AIBOM, she says, IT leaders lack visibility into the "cognitive layer" of the system. That makes it hard to audit decisions, reproduce results or assess supply chain risk.
Why this is picking up now
Norton points to three forces arriving at once:
Generative AI made it easy. Developers can drop open-source models into applications without anyone in security knowing. In her words, organizations "suddenly realized they had no idea what models were running in production."
Regulation is catching up. The EU Artificial Intelligence Act and NIST's AI Risk Management Framework now expect transparency around training data and model lineage, which SBOMs were never designed to provide. The article also cites former President Joe Biden's executive order on AI as part of that push.
The tooling exists. Two established standards, Software Package Data Exchange (SPDX) and CycloneDX, now have AI-aware profiles, so nobody has to build a format from scratch.
Soni sees the same pressure from the compliance side: organizations are leaning toward this model "because they need to be part of compliance and audits." Her broader point is that if AI must be "ethical, transparent and fair," you need a framework for checking that it is.
What this looks like on the ground
The article stays at the framework level and does not profile a specific district, so here is the everyday version.
A district adopts a tool that drafts parent communications, flags students for intervention or screens job applicants. A parent, an auditor or a board member asks how it reached a decision. With an AIBOM in hand, you can say what data the tool learned from, which model version is running, what it depends on and what its maker says it should not be used for. Without one, the honest answer is "we'd have to ask the vendor."
What leaders should actually do
The source article explains the concept and stops there. These next steps are our take on how a district can put it to work, ordered from fastest to slowest.
Ask the question this week. On your next vendor call, ask: "Can you provide an AI Bill of Materials for this product?" The answer tells you a lot, even if it is no.
List the AI you already have. Start a simple inventory of every tool in the district that uses AI, including features quietly added to software you bought years ago.
Use the four layers as your checklist. For each tool, ask about data, model, dependencies and governance. Pay particular attention to whether student or staff personal information was used in training.
Write it into procurement. Add AI transparency language to RFPs and renewals, and ask for documentation in a standard format such as SPDX or CycloneDX.
Keep your SBOM practice. The AIBOM sits beside it. You need both.
Get this in your inbox every week
If this was useful, The YOSS Advantage delivers more like it every week. It is our newsletter for K-12 leaders covering AI, EdTech and the policy shifts that land on your desk, written to be read in a few minutes. Join your peers and subscribe here: https://subscribe.learnyoss.com/
Source & credit
This post summarizes and builds on "What Is an AI Bill of Materials?" by Alexandra Frost, a Cincinnati-based freelance journalist and former high school teacher, published in EdTech Magazine on September 9, 2026. The definitions, the four-layer structure, the comparison with SBOMs, the three drivers of adoption and all quotations from Arpita Soni (IEEE) and Katie Norton (IDC) come from her reporting. The "What this looks like on the ground" example and the "What leaders should actually do" steps are YOSS's own additions. Thank you to Alexandra Frost and EdTech Magazine for a clear explainer on a topic district leaders will be hearing much more about.



