Modern software engineering increasingly relies on open, community-driven standards, yet how such standards are created in fast-evolving domains like AI-powered systems remains underexplored. This paper presents a detailed experience report on the development of the AI Bill of Materials AIBOM specification, an extension of the ISO/IEC 5962:2021 Software Package Data Exchange (SPDX) software bill of materials (SBOM) standard, which captures AI components such as datasets and iterative training artifacts. Framed through the lens of Action Research (AR), we document a global, multi-stakeholder effort involving over 90 contributors and structured AR cycles. The resulting specification was validated through four complementary approaches: alignment with major regulations and ethical standards (e.g., EU AI Act and IEEE 7000 standards), systematic mapping to six industry use cases, semi-structured practitioner interviews, and an industrial case study. Beyond delivering a validated artefact, our paper documents the process of building the AIBOM specification in the wild, and reflects on how it aligns with the AR cycle, and distills lessons that can inform future standardization efforts in the software engineering community.
翻译:现代软件工程日益依赖开放、社区驱动的标准,然而在人工智能赋能系统等快速发展的领域中,此类标准如何建立仍缺乏深入研究。本文详细介绍了人工智能物料清单(AIBOM)规范的开发经验,该规范是ISO/IEC 5962:2021软件包数据交换(SPDX)软件物料清单(SBOM)标准的扩展,用于记录数据集和迭代训练工件等人工智能组件。通过行动研究(AR)的视角,我们记录了由90多位贡献者参与的全球多利益相关方努力以及结构化的AR周期。最终形成的规范通过四种互补方法进行了验证:与主要法规和伦理标准(如欧盟《人工智能法案》和IEEE 7000系列标准)的对齐、对六个行业用例的系统映射、半结构化从业者访谈以及一项工业案例研究。除了提供经过验证的成果外,本文还记录了在实践中构建AIBOM规范的过程,反思了其如何与AR周期相契合,并提炼出可为软件工程领域未来标准化工作提供参考的经验教训。