AI Bill of Materials Generator
Build an AI bill of materials from your models, datasets, embeddings and services, with licence conflicts, missing provenance and single points of failure flagged.
Last reviewed by the Radiatus Cloud team
Securing AI in production?
We build guardrails, governance & compliance for AI systems.
An AI system has a supply chain and almost nobody has written it down
A production AI feature typically depends on a base model, a fine-tuning dataset, an embedding model, a vector store, a reranker, a set of prompts and two or three hosted APIs. Each has a licence, a provider, a version and a failure mode, and the combination is rarely recorded anywhere. When a question arrives, about a licence, a model deprecation, a provider outage or where a piece of data came from, the answer has to be assembled by asking people, and the answer differs depending on who is asked.
Licence conflicts appear in combination, not in components
Each component can be individually acceptable while the combination is not. A base model whose licence prohibits use in training another model, combined with a distillation step, is a conflict that exists only when both are present. Non-commercial datasets are the most common source of this, because they are widely used in research and the restriction is easy to miss when the download succeeded without a click-through. Listing components together is what makes the conflicts visible.
Version pinning is the difference between reproducible and not
A component recorded as "the provider's latest model" is not recorded. Hosted models change under a stable name, and a system whose behaviour shifted last week cannot be investigated if nobody knows what it was running before. Pinning versions where the provider allows it, and recording the date where it does not, is what makes a regression traceable to a cause rather than to a guess.
Related tools
- AI Prompt Leakage Analyzer — Paste a system prompt and a hostile user input to see whether the prompt holds secrets and whether the input carries injection patterns. Local, instant.
- LLM Data Exposure Checker — Check if text contains data likely to be memorized or exposed by LLMs.
- AI Usage Policy Generator — Generate an acceptable use policy for AI tools in your company.
- Model Hallucination Estimator — Estimate risk of hallucinations based on task type and temperature.
Frequently Asked Questions
What belongs in an AI bill of materials?
Base and fine-tuned models, training and evaluation datasets, embedding models, vector stores, rerankers, guardrail services, prompts and any hosted API in the path. Each with its version, licence, provider and what it costs you if it disappears.
Why do licences need checking in combination?
Because a conflict can exist only when two components are present together, such as a base model prohibiting use in training another model alongside a distillation step. Each component alone is fine.
What is wrong with using the latest model version?
It means the system cannot be reproduced or investigated. Hosted models change under a stable name, so a behaviour shift last week has no traceable cause if nobody recorded what was running before.
Does this replace a software bill of materials?
No. It covers the AI-specific components a conventional SBOM does not model well, particularly datasets and model weights, and sits alongside rather than instead of one.
Is anything transmitted?
No. The inventory is assembled in your browser and nothing leaves it, which matters because a component list is a useful map for anyone attacking the system.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
List your AI components to build the bill of materials.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
AI Prompt Leakage Analyzer
AI SecurityPaste a system prompt and a hostile user input to see whether the prompt holds secrets and whether the input carries injection patterns. Local, instant.
LLM Data Exposure Checker
AI SecurityCheck if text contains data likely to be memorized or exposed by LLMs.
AI Usage Policy Generator
AI SecurityGenerate an acceptable use policy for AI tools in your company.