powering productive workplaces
Front page
InterviewTrust & Risk2h · 12:38 BST · 4 min read

Why Traditional SBOMs Are No Longer Enough in the AI Age

Kristian McCann speaks with Devashri Datta, Senior Security Architect at NVIDIA and independent researcher, about why AI is exposing new software supply chain risks, how this can hurt operations, and how organizations can rethink governance before those risks become vulnerabilities

The rapid adoption of AI across the enterprise has transformed how organizations build software, automate workflows, and improve productivity. But as AI becomes increasingly embedded in everyday business operations, it is also exposing security gaps that many organizations are unaware of. Traditional methods for understanding software components and managing supply chain risk are no longer equipped to deal with systems that can interpret information, make decisions, and act independently.

In this episode of UC Today, Kristian McCann is joined by Devashri Datta, Senior Security Architect at NVIDIA, who spoke to us in a personal capacity as an independent researcher specializing in AI supply chain security and open source governance. Drawing on her research, Datta explains why enterprises need to rethink how they approach software transparency and governance as AI becomes more deeply integrated into critical business systems.

Why Traditional SBOMs Fall Short in the AI Era

Datta begins by explaining the original purpose of an Software Bill of Materials (SBOM), describing it as the software equivalent of an ingredients label on food packaging. It identifies the components that make up an application, including third-party libraries, dependencies, licenses, and versions, giving organizations greater visibility into what their software contains.

Over the past two decades, SBOMs have become increasingly sophisticated. Machine-readable standards such as SPDX, vulnerability extensions like CycloneDX, and a new VEX (Vulnerability Exploitability eXchange) have all improved the way organizations identify and prioritize software vulnerabilities. However, according to Datta, those improvements were designed for traditional software rather than AI-powered systems.

"We are moving from an era that says we execute systems to code," she explains.

"Now we are moving from systems to code to an AI system that interprets intent and takes actions."

That distinction fundamentally changes what organizations need to monitor. Instead of tracking only software components, AI introduces entirely new elements, including model weights, training data, retrieval-augmented generation (RAG) pipelines, fine-tuning layers, and integrations with multiple external tools. Traditional SBOMs were never designed to capture this information, leaving significant blind spots in software governance.

Datta also highlights that AI introduces risks that simply do not exist in conventional applications. Prompt injection, data poisoning, hidden instructions embedded within documents, and tool misuse all create attack vectors that cannot be identified simply by scanning software packages. Security teams must now think beyond code vulnerabilities and consider whether an AI system itself can be manipulated into performing harmful actions.

Building Governance Around AI Behavior Rather Than Code

Those risks become even more significant as AI assistants gain access to enterprise collaboration and productivity platforms.

Datta points to widely used tools such as Microsoft Copilot, Cursor, Claude, Gemini, and Codex, explaining that these platforms increasingly interact with emails, Teams or Slack conversations, documentation, Jira tickets, GitHub repositories, PDFs, and internal knowledge bases. Rather than acting as passive assistants, they are beginning to execute tasks and make decisions on behalf of employees.

As those capabilities expand, organizations face new challenges around data leakage, unauthorized workflow execution, and what Datta describes as "access creep," where AI systems gradually accumulate permissions across multiple business applications. Without clear governance, an AI assistant could eventually gain access to sensitive financial systems, payroll platforms, or confidential corporate information that extends well beyond its original purpose.

To address these challenges, Datta argues that governance itself must evolve:

"If AI is operating at machine speed, governance cannot run at human speed."

Her proposed solution builds upon existing SBOM standards rather than replacing them. She introduces several complementary concepts, including AIVEX, an extension designed to record AI-specific behavioral risks such as prompt injection and tool misuse, alongside TMBOM, or Threat Modeling Bill of Materials, which continuously evaluates operational risks rather than relying solely on design-stage threat modeling.

Rather than producing multiple disconnected security reports, Datta envisions combining SBOMs, threat models, AI risk assessments, safety evaluations, and organizational policies into a single intelligence layer capable of delivering clear approval decisions and complete audit trails. This approach, she argues, would simplify compliance while giving customers, auditors, and internal security teams greater confidence in how AI-enabled software is assessed.

AI Governance Must Become a Continuous Process

Although governments and standards bodies have begun responding with frameworks such as the NIST AI Risk Management Framework and the EU AI Act, Datta believes implementation remains the industry's biggest challenge. Many organizations are racing to deploy AI tools, but far fewer are investing in the governance needed to manage them safely.

She argues that security must become part of every stage of AI adoption, from permission management and identity controls to continuous monitoring of AI behavior. Employees also need training that goes beyond learning how to use AI products, focusing instead on how to use them securely and responsibly within enterprise environments.

Perhaps her most important message is that human oversight cannot disappear, regardless of how capable AI becomes. Organizations should continue validating AI-generated actions, monitoring access privileges, and assigning clear accountability for decisions made by intelligent systems.

As Datta concludes, enterprises should stop viewing AI as just another automation tool. Instead, they should begin treating it as they would another employee, one that requires oversight, governance, and clearly defined responsibilities. As AI continues to reshape software development and business operations, that shift in thinking may prove just as important as the technology itself.

rate this story
helps rank stories across uc today
The discussion0 takes · attributed & checked

Does this reflect your experience?

opening the room…
Read nextordered by techtelligence · every pick explained
picked for this story

OpenAI Expands Daybreak With GPT-5.6-Cyber as Autonomous Threats Grow

11 Aug 2026
picked for this storyGeopolitical Tensions Are Reshaping European Tech Decisions, Study Finds6 Aug 2026picked for this storyWorkday Eyes AI Agent Issues With New Research Team20 Aug 2026