Why does shipping AI-written code leave no record of which model wrote it?
κΈ°ν
AI assistants now author a significant and growing fraction of production code, but no artifact format records which model, version, or prompt produced a given function. When a vulnerability is traced to a pattern that a specific model generation reliably introduces, there is no way to query a codebase or package registry to find every function that shares the same origin. Software Bills of Materials standardized by SPDX and CycloneDX capture library dependencies, not authorship provenance of source code. The 2026 Cloudsmith supply-chain survey found 29 percent of respondents identify AI-generated package risk as their top open-source security concern, and three quarters of organizations treat SBOMs as static compliance artifacts rather than active governance instruments. The EU AI Act and the US Executive Order on AI both reference software supply-chain integrity but neither specifies w
μ μ€μνκ°
AI authorship provenance is the SBOM gap that will define the next decade of software supply-chain audits and incident response.
κΈ°ν νκ° λ°©μ
κΈ°ν μ μλ μΈ‘μ κ°μ΄ μλ μ μ£Όκ΄μ νκ°μ λλ€. μΌλ§λ λΆνΈνμ§, μΌλ§λ μμ£Ό λ°μνλμ§, νμ¬ ν΄κ²°μ± μ΄ μΌλ§λ λΆμ‘±νμ§λ₯Ό λ°μν©λλ€. μ μκ° λμμλ‘ λ§λ€ κ°μΉκ° λ λλ€κ³ μκ°ν©λλ€.
λ°μνμ λ μΌλ§λ ν° λΆνΈμ μ΄λνλμ§.
μ€μ λ‘ μΌλ§λ μμ£Ό μ νκ² λλμ§.
νμ¬ μ΄λ₯Ό ν΄κ²°ν λ§ν λκ΅¬κ° μΌλ§λ λΆμ‘±νμ§.
ν΄κ²°ν κ°μΉ μλ λ λ§μ λ¬Έμ λ€
μ°λ¦¬κ° κ°μ₯ λ§μ΄ μμ‘΄νλ μννΈμ¨μ΄κ° μ κ°μ₯ μ¬μ©νκΈ° λΆνΈν κΉ?
Techλ΄κ° μμ±ν λ°μ΄ν°λ₯Ό μ λλ μ ν μμ νμ§ λͺ»ν κΉμ?
Techλ΄ λ°μ΄ν°κ° μ€μ λ‘ μμ λμμμ μ¦λͺ νλ μμμ¦μ μ λ°μ μ μλκ°?
Techμ€ν μ€μΈ κ²μ΄ SBOMμ μ μΈλ λ΄μ©κ³Ό μΌμΉνλμ§ μ μ μλ μ΄μ λ 무μμΈκ°?
TechC2PA μΆμ² 체μΈμ μ μ½ν μΈ κ° μμ λ―Έλμ΄μ μ¬λΌκ°λ μκ° λμ΄μ§λκ°?
TechWhy can I not trace a production failure that crossed a message queue?