Google Cloud has open-sourced k8s-aibom, a Kubernetes controller built to detect and document AI workloads running in cloud environments, including inference, training, agentic systems, evaluations, and retrieval-augmented generation deployments. The tool is designed to surface shadow AI activity and generate namespace-scoped AI bills of materials for auditors and security teams without modifying workloads, using a single unprivileged action in its own namespace rather than sidecars, eBPF, or root-level DaemonSet agents.
The controller outputs artifacts aligned with the CycloneDX ML-BOM standard, part of a broader software supply chain transparency ecosystem that also includes formats such as SBOM, VEX, and related attestations. Google said the project supports AI governance, compliance, and change detection efforts tied to frameworks including the EU AI Act, NIST AI RMF, and ISO/IEC 42001, extending bill-of-materials practices into machine learning environments.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
Google Cloud open-sourced k8s-aibom, a Kubernetes controller that identifies AI workloads and generates namespace-scoped AI bills of materials using the CycloneDX ML-BOM standard. The tool is positioned for AI transparency, compliance, and change detection in cloud environments.
CycloneDX published documentation describing Machine Learning Bill of Materials (ML-BOM) as one of several software supply chain transparency artifact types and related standards. The reference is descriptive and does not report a security incident or exploitation event.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.