Why transparency must be the foundation of trust in tech-driven global order

Members of the G7 Cybersecurity Working Group at the 52nd G7 summit in Évian-les-Bains, France. Courtesy photo.

As Big Tech joined G7 leaders in Evian on 16 June to discuss ‘trusted partners’ schemes granting access to frontier AI models, one thing was clear: in the age of AI, security is fundamentally about trust. In tech-driven international relations, security requires understanding, securing, and trusting the technological systems and supply chains on which public services, infrastructure, and enterprises – and therefore economic and national security – increasingly depend.

However, the task of securing and trusting technological supply chains can appear almost impossible. Supply chains remain globalised, strategic dependencies persist, and no government can fully control or monitor every layer of the technologies on which its economy and society rely.

Trust is about transparency

Yet we have to start somewhere. Improving transparency is a baseline strategic choice. It does not solve every vulnerability, but it allows governments, companies, and users to better understand where risks are located, how dependencies are structured, and how vulnerabilities can spread across the supply chain. This is why transparency has become a strategic priority for making technological supply chains more secure and trustworthy.

Without visibility into technological supply chains, governments and companies cannot properly assess risk. They cannot know which components are embedded in a system, where dependencies lie, or how vulnerabilities may spread. AI systems are complex, fast-moving, and built on multiple layers of software, data, models, and infrastructure, making this challenge ever more urgent.

Achieving transparency is not an administrative or technical exercise. It is the basis of the trust necessary to navigate geopolitical turmoil. Nor can transparency happen overnight or be effortlessly integrated into developers’ plans. It needs guidance to harmonise efforts and bring private and public stakeholders from different national jurisdictions on the same page on which steps are needed to actually build transparency. So, how can international partners cooperate to achieve greater transparency, improve trust, and, as a result, strengthen security? 

Transparency is about cooperation 

The G7 offers a good case study and a model for international cooperation in the digital age. Created as a platform for cooperation among major economies, the G7 has always operated at the intersection of economic stability, strategic coordination, and shared values. Today, amidst an intense phase of geo-technological competition, that intersection increasingly includes economic security: the ability of states and societies to protect critical capabilities, reduce excessive dependencies, and ensure that innovation remains a source of resilience rather than vulnerability.

This is why the G7 Cybersecurity Working Group is focusing on AI and cybersecurity, looking specifically at enhancing transparency in AI supply chains as the foundation of greater cybersecurity. 

G7 SBOM for AI 

Among the most concrete and significant results achieved by the working group has been the adoption by all G7 partners, plus the European Commission, of the guideline on minimum elements for Software Bill of Materials (SBOM) for Artificial Intelligence, published on 12 May 2026.

The document, which stems from the ‘shared vision’ report released by the working group the previous year, was finalised after months of negotiations among G7 experts, led by Italy’s National Cybersecurity Agency (ACN) and Germany’s Federal Office for Information Security (BSI). It is the first initiative of its kind on transparency of AI systems and provides a common baseline for what an AI Software Bill of Materials should include.

An SBOM can be understood as an inventory of what is inside a software product. Applied to AI, it helps developers, deployers, and public authorities identify components, map dependencies, detect vulnerabilities, and respond more quickly when weaknesses emerge. In practice, it gives organisations better visibility across the AI supply chain. It also gives governments a powerful instrument to increase trust and thus the security of AI technologies. Such an initiative could not be more timely.  

Addressing AI-powered threats

As Anthropic’s Mythos has shown, generative AI can increase the speed and scale of cyber threats. It can shorten the time between vulnerability discovery and exploitation, reducing the window available to defenders to patch and respond. It reduces costs and barriers to entry for malicious actors by compressing the time required to weaponise flaws, allowing even less sophisticated threat actors to execute advanced cyberattacks. 

On the defence side, it has increased the urgency of finding new instruments and approaches to cope with AI-powered cyber threats. Yet governments cannot secure what they cannot see, companies cannot manage risks they cannot map, and users cannot trust systems whose components and dependencies remain opaque.

The G7 SBOM for AI responds to this problem by translating transparency into a practical cybersecurity tool. It shows how trusted partners can work together to strengthen the security and trustworthiness of AI supply chains while supporting innovation. The G7 Cybersecurity Working Group has institutionalised a mechanism of collaboration based on consensus. This allowed countries with different strategic cultures and priorities to converge towards a shared goal of more transparency. 

Reshaping transnational AI governance 

Our approach to creating the SBOM for AI – inclusive, community-driven, solution-oriented, merging technical and policy expertise – can also be exported beyond the G7 framework. By defining minimum elements for AI SBOMs, the G7 Cybersecurity Working Group has made a contribution to the broader global governance of emerging technologies. Other countries, organisations, and standard-setting bodies, including the AI Safety Summit, the Pax Silica, the OECD, or regional groupings such as the EU, can build on and adapt this work method to improve their transparency, accountability, and resilience objectives across AI ecosystems.

The SBOM is much more than simply a list of technical clusters and minimum elements. Rather than slowing technological development, it helps create the conditions for AI systems to be developed, deployed, and adopted with greater confidence. Transparent supply chains make innovation more trustworthy, and trustworthy innovation is more likely to be sustainable. It creates a bridge of trust between jurisdictions at a time when countries seek to increase strategic autonomy, technological independence, and digital sovereignty. 

This will matter beyond AI. Quantum technologies, telecommunications services, and cloud infrastructure all prompt similar supply chain concerns. As innovation accelerates, governments united by security concerns need shared approaches to understanding systems and risks travelling across supply chains. 

A new agenda for tech trust-building

We often associate security with secrecy or confidentiality. In the tech race, transparency matters. 

The G7 Cybersecurity Working Group, from being the new kid on the (crowded) block of cyber initiatives, has taken a significant step to strengthen the security of its highly technological industrial, economic, and financial ecosystems. It has pioneered an ambitious model of international security cooperation, with trust at its core.

The opinions, findings, and conclusions or recommendations expressed in this article are those of the authors and do not necessarily reflect the views of either the Italian National Cybersecurity Agency or the G7 Cybersecurity Working Group partners.