Section 2.2 of the AIBOM guidelines applies them "especially in" Government, Public Sector, Essential Services Organizations and the software export and services industry, so the list is indicative; 9.4.1.1 reaches organizations involved in AI-driven development and services. 9.4.1.3 states that "Government, public sector, and essential services organizations must ensure that an AIBOM is maintained for all AI systems being used, procured, and developed".
9.4.1.5 points to formats "such as Software Package Data eXchange (SPDX) or CycloneDX", so a vendor's AIBOM is a starting point; our gap list marks each element present, absent or vendor-supplied (see also AI vendor risk).
CERT-In's Blueprint for Reducing Exposure and Defending against AI-Assisted Vulnerabilities Exploitation in Digital Infrastructure, Version 1.0, 25.05.2026, has a row "Inventory and Visibility of AI Systems" with the objective "Maintain visibility into AI systems, integrations, APIs, and third-party AI dependencies", and a measure, "Define operational boundaries and permissions". It sets no minimum elements.