Organizations are rapidly integrating artificial intelligence and machine learning into core application stacks, which in turn changes the definition of a software component. A secure supply chain is no longer just about open source packages and container layers; it now includes AI models that drive modern intelligent applications.
At the same time, security and operations teams face growing regulatory pressure. Under the EU Cyber Resilience Act (CRA) security reporting requirements, which became effective September 11, 2026, software vendors selling to EU nations must report actively exploited vulnerabilities or severe incidents within 24 hours of discovery. Meeting such aggressive deadlines demands robust processes, proactive planning, and automated governance. To maintain release velocity without compromising security, organizations must operationalize SBOM data across teams and build dedicated security controls into their AI components.
We are excited to announce Anchore Enterprise v6.2, designed to extend your SBOM visibility directly into AI/ML components while giving DevSecOps teams finer operational control over policy enforcement, export capabilities, local analysis, and AI agent integration.
Bringing AI Artifacts and Models into the SBOM Lifecycle
As developers embed Large Language Models (LLMs) and specialized AI capabilities into their applications, security teams face a critical blind spot. AI model files, often multi-gigabyte binaries or serialized weight files like GGUF or Docker Models, frequently bypass traditional security scanners that were built to analyze software code (e.g., Java, Python, or C++), static configuration files, and standard dependency trees. Large Language Models (LLMs) introduce fundamentally different file architectures, data volumes, and embedded logic that traditional scanners are equipped neither to inspect nor to parse. Without visibility into these artifacts, organizations risk shipping unvetted models, untracked licenses, or outdated model versions into production.
Anchore Enterprise v6.2 makes AI models first-class citizens in your Software Bill of Materials (SBOM).
- AI “Model” Artifact Detection (GGUF & Docker Models): Anchore Enterprise now natively inspects container images for AI/ML model artifacts, including GGUF files and Docker Model structures.
- Reporting AI Models as Packages: Discovered AI models are indexed and reported directly alongside standard software packages in your central SBOM catalog. This lets teams track model provenance, inventory AI deployments across environments, and apply consistent supply chain governance via Anchore’s policy engine to both traditional software and AI workloads.
AI-Ready Security Operations with Model Context Protocol (MCP) Support
As AI agents become an integral part of security operations, they need reliable, structured access to software supply chain data. The Anchore Enterprise MCP Server acts as a native interface between AI agents and Anchore Enterprise (v5.27+), powering agentic workflows that automatically aggregate security data across tools and route it downstream to Security Information and Event Management (SIEM) systems.
- Direct Agent Integration: Gives AI tools and agents direct, secure access to your vulnerability findings, policy evaluation results, and SBOM catalog without the need for brittle API custom integration scripts.
- Curated Tools & Response Management: Features specialized tools tailored for security workflows like triage, policy checks, and risk reporting, handling pagination and payload optimization so agents receive consistent, actionable data.
- Simple, Minimal Deployment: Ships as a lightweight container image that deploys optionally alongside your Anchore Enterprise instance.
Expanded App/Version Policy & VEX Governance
Enhanced policy evaluations respond to changing security contexts and external risk annotations.
- Outcome Change Notifications for App/Version Policies: Stay ahead of pipeline shifts. Anchore Enterprise now triggers automated notifications whenever a policy outcome changes at the application version level, ensuring security teams are alerted immediately when a previously compliant artifact becomes non-compliant due to new security metadata or policy updates.
- Policy Support for VEX Annotations: Incorporate Vulnerability Exploitability eXchange (VEX) data directly into policy evaluations. Policies can now automatically factor in VEX status (e.g., not_affected or fixed), allowing teams to suppress false positives and prevent unnecessary build breaks when a vulnerability isn’t exploitable in an application version context.
Filter Packages by Vulnerability Severity
Managing thousands of packages across multiple assets in an application version requires granular filtering to focus on what matters most. Security teams can now instantly filter packages within an application version by associated vulnerability severity (e.g., Critical, High, Medium). This accelerates targeted remediation efforts by pinpointing exactly which packages introduce critical or high severity vulnerabilities across your inventory.
Local SBOM Generation for Streamlined Workflows
Developers and CI/CD pipelines can now generate and output SBOMs locally during image scanning workflows (file system scan support was provided in Anchore Enterprise v6.1). This enables faster shift-left feedback loops, allowing developers to inspect component inventories and compliance status locally before pushing artifacts to central registries.
Continuous Visibility from Code to AI Models
Anchore Enterprise v6.2 release continues to reinforce our mission: providing a unified, SBOM-powered platform that simplifies compliance, eliminates security friction, and scales across modern software architectures.
- AI Supply Chain Security: Gain complete visibility into AI model artifacts alongside open-source dependencies.
- AI Operations Ready: Empower AI agents with trusted, deterministic supply chain data via the new Anchore MCP Server interface.
- Proactive Governance: Automate policy enforcement with native VEX integration and real-time policy outcome alerts.
- Operational Efficiency: Enable shift-left workflows with local SBOM generation and enriched, exportable asset intelligence.
Try out our new Anchore MCP. For additional information, please visit our release documents or contact our team for an in-depth demo.
The EU CRA demands a shift from static security reports to continuous Live Telemetry. Learn how to operationalize compliance, enforce deterministic policy gates, and automate your path to an audit-ready software supply chain.