apr-2026 → jul-2026

How nature of change is determined. For each requirement present in both releases, we compare the normalised wording of the previous and current versions and measure how much of it changed. We then classify the result into four categories:These categories drive the Nature column in the tables below. On this transition, the publisher's own change summary covers requirements and their underlying control activities jointly, while the Nature column below grades the requirement text only — so the labels are a working approximation rather than a calibrated reading.
release_type
incremental
requirements
identical 46 · editorial 1 · clarification 2 · substantive 2 · added 2 · removed 0
control bullets
prev 178 → cur 186 · matched 168 · added 7 · removed 10 · merges 0 · match rate 94.4%

Overview: website change summary

AIUC-1 for coding agents: Secrets management, secure defaults in code, execution-level safeguards broadened to coding agents Technical guidance for auditors: Public documentation on AIUC-1 audit scoping and annual re-certification Clarifications to existing requirements: Clearer rules for which controls apply to which agent types, and removal of duplicative controls

Per-principle change distribution

per-principle distribution

Requirement-level changes and control composition

A. Data & Privacy

IDTitleNatureDist.Shoulds/MaysSite narrative
A005Prevent cross-customer data exposuresubstantive0.2982/1 → 2/1 (Δ +0s/+0m)revision Broadened the requirement to cover cross-customer data exposure generally, not only when combining customer data from multiple sources
clarification Generalized typical evidence to logical isolation appropriate to the architecture rather than specific app-ID patterns
A006Prevent PII leakageclarification0.0592/1 → 1/1 (Δ -1s/+0m)revision Retired the core control requiring authentication and authorization for PII access; DLP system integration renumbered to A006.2 as a supplemental control

C. Safety

IDTitleNatureDist.Shoulds/MaysSite narrative
C001Define AI risk taxonomyeditorial0.0074/0 → 4/0 (Δ +0s/+0m)
C005Prevent agent-specific high risk outputsclarification0.0892/2 → 2/2 (Δ +0s/+0m)clarification Renamed from customer-defined to agent-specific high-risk outputs to reflect that the risk taxonomy is defined per agent

E. Accountability

IDTitleNatureDist.Shoulds/MaysSite narrative
E009Monitor third-party accesssubstantive0.3332/0 → 2/1 (Δ +0s/+1m)revision Expanded the requirement to cover monitoring and logging of third-party API connections, sessions, and data access
addition Added new supplemental control for alerting on anomalous third-party access

Per-bullet detail (indicative on consolidation releases)

A001 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayDocumenting processes for handling end-user data subject rights. For example, handling requests for opt-in/opt-out rights, access, portabil…Documenting processes for handling end-user data subject rights. For example, handling requests for opt-in/opt-out rights, access, portabil…
matchhigh r=1.00 shouldImplementing technical controls to enforce data retention and deletion policies. For example, automating data deletion based on retention s…Implementing technical controls to enforce data retention and deletion policies. For example, automating data deletion based on retention s…
matchhigh r=1.00 shouldDefining and communicating input data usage policies. Including specifying how customer data is used for inference and model training, esta…Defining and communicating input data usage policies. Including specifying how customer data is used for inference and model training, esta…
A002 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayImplementing technical controls to enforce AI output opt-in/opt-out and deletion policies. For example, automating customer preference enfo…Implementing technical controls to enforce AI output opt-in/opt-out and deletion policies. For example, automating customer preference enfo…
matchhigh r=1.00 shouldDisclosing opt-in/opt-out and deletion policies for AI outputs. For example, documenting how customers can opt out of output storage or reu…Disclosing opt-in/opt-out and deletion policies for AI outputs. For example, documenting how customers can opt out of output storage or reu…
matchhigh r=1.00 shouldEstablishing output ownership and usage rights policies. For example, specifying customer ownership of AI-generated outputs versus AI input…Establishing output ownership and usage rights policies. For example, specifying customer ownership of AI-generated outputs versus AI input…
A003 — matched 3 · added 0 · removed 1 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayEnabling agent access and governance through permission-ready architecture. For example, exposing per-agent permission scopes mappable to e…Enabling agent access and governance through permission-ready architecture. For example, exposing per-agent permission scopes mappable to e…
matchhigh r=1.00 mayEnabling agent identity management. For example, assigning each agent a unique, cryptographically verifiable identity; supporting standard…Enabling agent identity management. For example, assigning each agent a unique, cryptographically verifiable identity; supporting standard…
matchhigh r=1.00 shouldConfiguring data access limits to reduce data and privacy exposure. For example, limiting data access to task-relevant information based on…Configuring data access limits to reduce data and privacy exposure. For example, limiting data access to task-relevant information based on…
removedmayDeploying monitoring mechanisms. Including ensuring AI systems only perform necessary inference and logging deviations from defined operati…
A004 — matched 4 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayEstablishing output monitoring for high-risk IP scenarios. For example, logging AI responses that accessed confidential data sources, imple…Establishing output monitoring for high-risk IP scenarios. For example, logging AI responses that accessed confidential data sources, imple…
matchhigh r=1.00 mayImplementing technical controls to detect proprietary information in outputs.Implementing technical controls to detect proprietary information in outputs.
matchhigh r=1.00 mayLeveraging foundation model provider protections. For example, using providers with zero data retention policies, requiring contractual com…Leveraging foundation model provider protections. For example, using providers with zero data retention policies, requiring contractual com…
matchhigh r=1.00 shouldProviding user guidance on protecting confidential information. For example, instructing employees not to input trade secrets, proprietary…Providing user guidance on protecting confidential information. For example, instructing employees not to input trade secrets, proprietary…
A005 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayImplementing specific privacy-enhancing technologies (PETs) to reduce competitive exposure.Implementing specific privacy-enhancing technologies (PETs) to reduce competitive exposure.
matchhigh r=1.00 shouldImplementing customer data isolation controls. For example, enforcing strict logical and physical separation of customer data, applying ten…Implementing customer data isolation controls. For example, enforcing strict logical and physical separation of customer data, applying ten…
matchhigh r=1.00 shouldEstablishing explicit consent and disclosure for combined data usage. For example, informing customers when their data will be combined wit…Establishing explicit consent and disclosure for combined data usage. For example, informing customers when their data will be combined wit…
A006 — matched 2 · added 0 · removed 1 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayIntegrating with existing data loss prevention (DLP) systems to monitor and block outputs containing personal data in violation of policy.Integrating with existing data loss prevention (DLP) systems to monitor and block outputs containing personal data in violation of policy.
matchhigh r=1.00 shouldImplementing safeguards to prevent personal data leakage through AI system outputs and logs. For example, filtering prompts and outputs for…Implementing safeguards to prevent personal data leakage through AI system outputs and logs. For example, filtering prompts and outputs for…
removedshouldRequiring authentication and authorization for PII access. For example, role-based access controls for PII-containing systems, multi-factor…
A007 — matched 4 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayImplementing restrictions in AI acceptable use policy.Implementing restrictions in AI acceptable use policy.
matchhigh r=1.00 mayImplementing user guidance and guardrails to reduce IP risk. For example, usage policies that explain prohibited content types, user warnin…Implementing user guidance and guardrails to reduce IP risk. For example, usage policies that explain prohibited content types, user warnin…
matchhigh r=1.00 mayEstablishing supplementary content filtering mechanisms where provider protections have gaps or limitations. For example, detecting copyrig…Establishing supplementary content filtering mechanisms where provider protections have gaps or limitations. For example, detecting copyrig…
matchhigh r=1.00 shouldDocumenting foundation model provider IP protections which may serve as primary infringement safeguards. For example, indemnification claus…Documenting foundation model provider IP protections which may serve as primary infringement safeguards. For example, indemnification claus…
B001 — matched 5 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayAligning adversarial testing with broader security testing programs. For example, integrating AI-specific test cases into broader penetrati…Aligning adversarial testing with broader security testing programs. For example, integrating AI-specific test cases into broader penetrati…
matchhigh r=1.00 shouldEstablishing improvement processes based on findings. For example, assigning owners and remediation timelines based on test severity, track…Establishing improvement processes based on findings. For example, assigning owners and remediation timelines based on test severity, track…
matchhigh r=1.00 shouldMaintaining secure testing documentation. For example, recording test cases, methods, outcomes, and system behaviors with restricted access…Maintaining secure testing documentation. For example, recording test cases, methods, outcomes, and system behaviors with restricted access…
matchhigh r=1.00 shouldConducting comprehensive adversarial testing at least quarterly. For example, performing structured red-teaming, prompt injection assessmen…Conducting comprehensive adversarial testing at least quarterly. For example, performing structured red-teaming, prompt injection assessmen…
matchhigh r=1.00 shouldEstablishing a taxonomy for adversarial risks. For example, drawing on NIST's AI 100-2e2023 attack classifications and aligning these to sy…Establishing a taxonomy for adversarial risks. For example, drawing on NIST's AI 100-2e2023 attack classifications and aligning these to sy…
B002 — matched 5 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayIntegrating adversarial input detection into existing security operations tooling. For example, forwarding flagged inputs to SIEM platforms…Integrating adversarial input detection into existing security operations tooling. For example, forwarding flagged inputs to SIEM platforms…
matchhigh r=1.00 mayImplementing adversarial input detection prior to AI model processing where feasible. For example, using pre-processing filters to flag lik…Implementing adversarial input detection prior to AI model processing where feasible. For example, using pre-processing filters to flag lik…
matchhigh r=1.00 shouldMaintaining detection effectiveness through quarterly reviews. For example, updating detection rules based on emerging adversarial techniqu…Maintaining detection effectiveness through quarterly reviews. For example, updating detection rules based on emerging adversarial techniqu…
matchhigh r=1.00 shouldImplementing incident logging and response procedures. For example, logging suspected adversarial attacks with relevant context, escalating…Implementing incident logging and response procedures. For example, logging suspected adversarial attacks with relevant context, escalating…
matchhigh r=1.00 shouldEstablishing detection and alerting. For example, implementing monitoring for prompt injection patterns, jailbreak techniques, adversarial…Establishing detection and alerting. For example, implementing monitoring for prompt injection patterns, jailbreak techniques, adversarial…
B003 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayEstablishing approval processes. For example, requiring designated review for public content referencing AI capabilities in e.g. publicatio…Establishing approval processes. For example, requiring designated review for public content referencing AI capabilities in e.g. publicatio…
matchhigh r=1.00 shouldControlling organizational information to balance transparency with security. For example, limiting disclosure of AI team details, developm…Controlling organizational information to balance transparency with security. For example, limiting disclosure of AI team details, developm…
matchhigh r=1.00 shouldDocumenting limitations on technical information release. For example, limiting public disclosure of model architectures, algorithms, train…Documenting limitations on technical information release. For example, limiting public disclosure of model architectures, algorithms, train…
B004 — matched 4 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldMaintaining endpoint security through remediation. For example, tracking identified vulnerabilities, implementing protective measures based…Maintaining endpoint security through remediation. For example, tracking identified vulnerabilities, implementing protective measures based…
matchhigh r=1.00 shouldConducting simulated external attack testing of AI endpoints. For example, performing automated attack simulations, testing endpoint protec…Conducting simulated external attack testing of AI endpoints. For example, performing automated attack simulations, testing endpoint protec…
matchhigh r=1.00 shouldImplementing rate limiting and query restrictions. For example, establishing per-user quotas to prevent model extraction, blocking excessiv…Implementing rate limiting and query restrictions. For example, establishing per-user quotas to prevent model extraction, blocking excessiv…
matchhigh r=1.00 shouldImplementing systems distinguishing between high-volume legitimate usage and adversarial behavior. For example, using behavioral analytics…Implementing systems distinguishing between high-volume legitimate usage and adversarial behavior. For example, using behavioral analytics…
B005 — matched 5 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayPeriodically evaluating filter performance and adjusting thresholds accordingly. For example, accuracy, latency, false positives/negatives.Periodically evaluating filter performance and adjusting thresholds accordingly. For example, accuracy, latency, false positives/negatives.
matchhigh r=1.00 mayLogging flagged prompts for analysis and refinement of filters, while ensuring compliance with privacy obligations.Logging flagged prompts for analysis and refinement of filters, while ensuring compliance with privacy obligations.
matchhigh r=1.00 mayProviding feedback to users when inputs are blocked.Providing feedback to users when inputs are blocked.
matchhigh r=1.00 mayDocumenting the moderation logic and rationale. For example, explaining chosen moderation tools, threshold justifications, and decision cri…Documenting the moderation logic and rationale. For example, explaining chosen moderation tools, threshold justifications, and decision cri…
matchhigh r=1.00 shouldIntegrating automated moderation tools to filter inputs before they reach the foundation model. For example, integrating third-party modera…Integrating automated moderation tools to filter inputs before they reach the foundation model. For example, integrating third-party modera…
B006 — matched 2 · added 1 · removed 1 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldDeploying monitoring and alerting for agent actions that exceed security boundaries. For example, logging all agent service interactions, a…Deploying monitoring and alerting for agent actions that exceed security boundaries. For example, logging all agent service interactions, a…
matchhigh r=1.00 shouldImplementing technical restrictions that limit agent capabilities to authorized scope. For example, restricting agent access to approved ba…Implementing technical restrictions that limit agent capabilities to authorized scope. For example, restricting agent access to approved ba…
removedmayImplementing additional safeguards to contain runtime risk. For example, applying sandboxed execution environments with restricted filesyst…
addedmayImplementing additional safeguards to contain runtime risk. For example, enabling sandboxed execution environments with configurable filesy…
B007 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldConducting access reviews and updates at least quarterly. For example, validating access assignments, updating based on policy or role chan…Conducting access reviews and updates at least quarterly. For example, validating access assignments, updating based on policy or role chan…
matchhigh r=1.00 shouldRestricting administrative and configuration privileges to authorized personnel. For example, limiting ability to alter system behavior, to…Restricting administrative and configuration privileges to authorized personnel. For example, limiting ability to alter system behavior, to…
matchhigh r=1.00 shouldImplementing system-level access controls tailored to AI systems. For example, using role-based or attribute-based access to restrict acces…Implementing system-level access controls tailored to AI systems. For example, using role-based or attribute-based access to restrict acces…
B008 — matched 5 · added 0 · removed 1 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayVerifying model integrity before and during deployment. For example, using cryptographic checksums or signed artifacts to detect tampering,…Verifying model integrity before and during deployment. For example, using cryptographic checksums or signed artifacts to detect tampering,…
matchhigh r=1.00 maySecuring model hosting environments. For example, using up-to-date and minimal container images, scanning for known vulnerabilities in depe…Securing model hosting environments. For example, using up-to-date and minimal container images, scanning for known vulnerabilities in depe…
matchhigh r=1.00 mayEnforcing data integrity across agentic interfaces. For example, implementing cryptographic message signing for agent-to-agent communicatio…Enforcing data integrity across agentic interfaces. For example, implementing cryptographic message signing for agent-to-agent communicatio…
matchhigh r=1.00 shouldSecuring data in transit across model API endpoints and agentic interfaces. For example, enforcing TLS for all model API endpoint traffic,…Securing data in transit across model API endpoints and agentic interfaces. For example, enforcing TLS for all model API endpoint traffic,…
matchhigh r=1.00 shouldEnforcing caller authentication across API endpoints and agentic interfaces. For example, applying scoped API tokens or signed requests for…Enforcing caller authentication across API endpoints and agentic interfaces. For example, applying scoped API tokens or signed requests for…
removedshouldImplementing AI system access protection. For example, restricting access to production AI systems based on job function and operational ne…
B009 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayLimiting the fidelity of model outputs in certain use cases. For example, applying output rounding, threshold bands, or obfuscation techniq…Limiting the fidelity of model outputs in certain use cases. For example, applying output rounding, threshold bands, or obfuscation techniq…
matchhigh r=1.00 mayProviding user-facing notices or documentation about output limitations.Providing user-facing notices or documentation about output limitations.
matchhigh r=1.00 shouldReducing or limiting the number of results shown in outputs to relevant only to balance security and utility. For example, character limits…Reducing or limiting the number of results shown in outputs to relevant only to balance security and utility. For example, character limits…
C001 — matched 4 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldMaintaining taxonomy currency with documented change management. For example, updating based on emerging threats or incidents.Maintaining taxonomy currency with documented change management. For example, updating based on emerging threats or incidents.
matchhigh r=1.00 shouldEstablishing severity grading appropriate to organizational context and risk tolerance. For example, implementing consistent scoring method…Establishing severity grading appropriate to organizational context and risk tolerance. For example, implementing consistent scoring method…
matchhigh r=1.00 shouldAligning risk taxonomy with external frameworks and standards.Aligning risk taxonomy with external frameworks and standards.
matchhigh r=1.00 shouldDefining risk categories with severity levels and examples based on industry and deployment context. For example, classifying harmful outpu…Defining risk categories with severity levels and examples based on industry and deployment context. For example, classifying harmful outpu…
C002 — matched 5 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayImplementing pre-deployment vulnerability scanning of AI artifacts and dependencies. For example, scanning AI models and ML libraries for s…Implementing pre-deployment vulnerability scanning of AI artifacts and dependencies. For example, scanning AI models and ML libraries for s…
matchhigh r=1.00 mayIntegrating AI system testing into established software development lifecycle (SDLC) gates. For example, including threat modelling and ris…Integrating AI system testing into established software development lifecycle (SDLC) gates. For example, including threat modelling and ris…
matchhigh r=1.00 shouldObtaining approval sign-offs from designated accountable. For example, documented rationale for approval decisions and maintained records f…Obtaining approval sign-offs from designated accountable. For example, documented rationale for approval decisions and maintained records f…
matchhigh r=1.00 shouldCompleting risk assessments of identified issues before system deployment. For example, potential impact analysis, mitigation strategies, a…Completing risk assessments of identified issues before system deployment. For example, potential impact analysis, mitigation strategies, a…
matchhigh r=1.00 shouldConducting pre-deployment testing with documented results and identified issues. For example, structured hallucination testing, adversarial…Conducting pre-deployment testing with documented results and identified issues. For example, structured hallucination testing, adversarial…
C003 — matched 4 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayEvaluating harm mitigation controls using performance metrics.Evaluating harm mitigation controls using performance metrics.
matchhigh r=1.00 mayImplementing bias detection and mitigation controls. For example, monitoring for discriminatory patterns, implementing fairness checks in o…Implementing bias detection and mitigation controls. For example, monitoring for discriminatory patterns, implementing fairness checks in o…
matchhigh r=1.00 shouldImplementing guardrails for advice generation. For example, restricting high-risk recommendations in sensitive domains, requiring disclaime…Implementing guardrails for advice generation. For example, restricting high-risk recommendations in sensitive domains, requiring disclaime…
matchhigh r=1.00 shouldImplementing content filtering for harmful output types. For example, detecting and blocking distressed responses, angry language, offensiv…Implementing content filtering for harmful output types. For example, detecting and blocking distressed responses, angry language, offensiv…
C004 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayProviding user guidance on system capabilities and limitations. For example, communicating what the AI system can and cannot do, intended u…Providing user guidance on system capabilities and limitations. For example, communicating what the AI system can and cannot do, intended u…
matchhigh r=1.00 shouldTracking out-of-scope violations and updating boundaries. For example, logging boundary violations, adjusting restrictions based on misuse…Tracking out-of-scope violations and updating boundaries. For example, logging boundary violations, adjusting restrictions based on misuse…
matchhigh r=1.00 shouldDetecting and blocking out-of-scope requests. For example, detecting conversations outside intended use cases, blocking prohibited topics,…Detecting and blocking out-of-scope requests. For example, detecting conversations outside intended use cases, blocking prohibited topics,…
C005 — matched 4 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayImplementing automated real-time interventions. For example, blocking or modifying outputs based on severity.Implementing automated real-time interventions. For example, blocking or modifying outputs based on severity.
matchhigh r=1.00 mayEstablishing escalation procedures for flagged high-risk content. For example, defining when human review is required and establishing appr…Establishing escalation procedures for flagged high-risk content. For example, defining when human review is required and establishing appr…
matchhigh r=1.00 shouldImplementing response actions for detected risks. For example, blocking high-severity outputs, flagging medium-risk content for review, log…Implementing response actions for detected risks. For example, blocking high-severity outputs, flagging medium-risk content for review, log…
matchhigh r=1.00 shouldImplementing detection and blocking mechanisms aligned with organizational risk taxonomy. For example, deploying filtering based on defined…Implementing detection and blocking mechanisms aligned with organizational risk taxonomy. For example, deploying filtering based on defined…
C006 — matched 2 · added 1 · removed 1 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayDetecting advanced output-based attack patterns. For example, identifying prompt injection attempts, model subversion techniques, payloads…Detecting advanced output-based attack patterns. For example, identifying prompt injection attempts, model subversion techniques, payloads…
matchhigh r=1.00 shouldEstablishing output sanitization and validation procedures before presenting content to users. For example, encoding or stripping potential…Establishing output sanitization and validation procedures before presenting content to users. For example, encoding or stripping potential…
removedshouldImplementing security labeling and content handling based on trust level. For example, marking untrusted or third-party content, distinguis…
addedshouldImplementing content handling and security labelling based on trust level. For example, marking untrusted or third-party content, distingui…
C007 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayEstablishing human review workflows for flagged high-risk outputs. For example, assigning reviewers, defining escalation procedures for com…Establishing human review workflows for flagged high-risk outputs. For example, assigning reviewers, defining escalation procedures for com…
matchhigh r=1.00 shouldImplementing automated detection mechanisms for high-risk outputs. For example, using content filtering, risk scoring, or classification mo…Implementing automated detection mechanisms for high-risk outputs. For example, using content filtering, risk scoring, or classification mo…
matchhigh r=1.00 shouldDefining high-risk output criteria drawing on risk taxonomy.Defining high-risk output criteria drawing on risk taxonomy.
C008 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayIntegrating AI output monitoring with existing security tools. For example, forwarding alerts and flagged outputs to SIEM platforms, applyi…Integrating AI output monitoring with existing security tools. For example, forwarding alerts and flagged outputs to SIEM platforms, applyi…
matchhigh r=1.00 mayMaintaining documentation. For example, recording identified scenarios with clear examples, updating risk taxonomy based on monitoring find…Maintaining documentation. For example, recording identified scenarios with clear examples, updating risk taxonomy based on monitoring find…
matchhigh r=1.00 shouldEstablishing ongoing monitoring of AI outputs across risk categories. For example, conducting regular evaluations prioritized by risk sever…Establishing ongoing monitoring of AI outputs across risk categories. For example, conducting regular evaluations prioritized by risk sever…
C009 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayReviewing user feedback and intervention logs at regular intervals, analyzing findings using structured methodologies (e.g., categorizing b…Reviewing user feedback and intervention logs at regular intervals, analyzing findings using structured methodologies (e.g., categorizing b…
matchhigh r=1.00 shouldEnsuring accessibility of feedback and intervention mechanisms. For example, adhering to WCAG 2.1 standards for color contrast, screen read…Ensuring accessibility of feedback and intervention mechanisms. For example, adhering to WCAG 2.1 standards for color contrast, screen read…
matchhigh r=1.00 shouldEnabling user intervention capabilities. For example, providing mechanisms for users to pause, stop, or redirect system behavior, implement…Enabling user intervention capabilities. For example, providing mechanisms for users to pause, stop, or redirect system behavior, implement…
C010 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldMaintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti…Maintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti…
matchhigh r=1.00 shouldConducting regular testing. Including performing assessments of harmful outputs at least every quarter, defining testing scope and methodol…Conducting regular testing. Including performing assessments of harmful outputs at least every quarter, defining testing scope and methodol…
matchhigh r=1.00 shouldAppointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m…Appointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m…
C011 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldMaintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti…Maintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti…
matchhigh r=1.00 shouldConducting regular testing. Including defining testing scope and methodologies based on risk taxonomy and performing assessments of out-of-…Conducting regular testing. Including defining testing scope and methodologies based on risk taxonomy and performing assessments of out-of-…
matchhigh r=1.00 shouldAppointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m…Appointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m…
C012 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldMaintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti…Maintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti…
matchhigh r=1.00 shouldConducting regular testing. Including defining testing scope and methodologies based on risk taxonomy and performing assessments of high-ri…Conducting regular testing. Including defining testing scope and methodologies based on risk taxonomy and performing assessments of high-ri…
matchhigh r=1.00 shouldAppointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m…Appointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m…
D001 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayMaintaining uncertainty communication. For example, displaying confidence levels, providing appropriate disclaimers for generated informati…Maintaining uncertainty communication. For example, displaying confidence levels, providing appropriate disclaimers for generated informati…
matchhigh r=1.00 shouldEstablishing information source validation. For example, requiring citations for factual claims, implementing source reliability checks.Establishing information source validation. For example, requiring citations for factual claims, implementing source reliability checks.
matchhigh r=1.00 shouldImplementing factual accuracy controls. For example, deploying available fact-checking mechanisms, flagging uncertain or low-confidence res…Implementing factual accuracy controls. For example, deploying available fact-checking mechanisms, flagging uncertain or low-confidence res…
D002 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldMaintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti…Maintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti…
matchhigh r=1.00 shouldConducting regular testing. Including defining testing scope and methodologies based on risk taxonomy and performing assessments at least e…Conducting regular testing. Including defining testing scope and methodologies based on risk taxonomy and performing assessments at least e…
matchhigh r=1.00 shouldAppointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m…Appointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m…
D003 — matched 5 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayReviewing patterns of AI tool usage. For example, identifying anomalies, updating tool permissions, and retiring unused or high-risk functi…Reviewing patterns of AI tool usage. For example, identifying anomalies, updating tool permissions, and retiring unused or high-risk functi…
matchhigh r=1.00 mayRequiring human approval for sensitive tool operations. For example, requiring human confirmation before executing high-risk actions, multi…Requiring human approval for sensitive tool operations. For example, requiring human confirmation before executing high-risk actions, multi…
matchhigh r=1.00 shouldEstablishing execution monitoring and logging. For example, tracking all tool calls, monitoring for unauthorized access attempts or scope v…Establishing execution monitoring and logging. For example, tracking all tool calls, monitoring for unauthorized access attempts or scope v…
matchhigh r=1.00 shouldEnforcing rate limits and transaction caps for autonomous tool use.Enforcing rate limits and transaction caps for autonomous tool use.
matchhigh r=1.00 shouldImplementing tool call validation and authorization. For example, restricting tool calls to approved functions and MCP servers, validating…Implementing tool call validation and authorization. For example, restricting tool calls to approved functions and MCP servers, validating…
D004 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldMaintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti…Maintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti…
matchhigh r=1.00 shouldConducting regular testing. Including defining testing scope and methodologies based on risk taxonomy and performing assessments of tool ca…Conducting regular testing. Including defining testing scope and methodologies based on risk taxonomy and performing assessments of tool ca…
matchhigh r=1.00 shouldAppointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m…Appointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m…
E001 — matched 4 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldEstablishing evidence collection requirements with guidance on preserving evidence for potential legal review. For example, system logs, us…Establishing evidence collection requirements with guidance on preserving evidence for potential legal review. For example, system logs, us…
matchhigh r=1.00 shouldImplementing security remediation measures. For example, system freeze capabilities, vulnerability fixes, access control updates, and coord…Implementing security remediation measures. For example, system freeze capabilities, vulnerability fixes, access control updates, and coord…
matchhigh r=1.00 shouldDefining breach notification procedures. For example, customer communications, regulatory reporting requirements, and vendor notifications…Defining breach notification procedures. For example, customer communications, regulatory reporting requirements, and vendor notifications…
matchhigh r=1.00 shouldAssigning a breach response lead from existing staff. For example, IT manager, security officer, or designated executive with authority to…Assigning a breach response lead from existing staff. For example, IT manager, security officer, or designated executive with authority to…
E002 — matched 4 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayCoordinating external support engagement. For example, legal counsel consultation, PR support, and insurance claim procedures.Coordinating external support engagement. For example, legal counsel consultation, PR support, and insurance claim procedures.
matchhigh r=1.00 mayDefining harmful output categories with reference to risk taxonomy. For example, discriminatory content, offensive material, inappropriate…Defining harmful output categories with reference to risk taxonomy. For example, discriminatory content, offensive material, inappropriate…
matchhigh r=1.00 shouldEstablishing immediate mitigation steps with designated staff responsibilities. For example, system freeze capabilities, output suppression…Establishing immediate mitigation steps with designated staff responsibilities. For example, system freeze capabilities, output suppression…
matchhigh r=1.00 shouldImplementing customer communication protocols. For example, disclosure procedures, explanation of corrective actions, and follow-up commitm…Implementing customer communication protocols. For example, disclosure procedures, explanation of corrective actions, and follow-up commitm…
E003 — matched 3 · added 1 · removed 1 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayCoordinating potential external support. For example, legal consultation for significant claims, financial review when needed, and insuranc…Coordinating potential external support. For example, legal consultation for significant claims, financial review when needed, and insuranc…
matchhigh r=1.00 mayDefining hallucination incident types.Defining hallucination incident types.
matchmid r=0.73 shouldImplementing remediation measures. For example, system freeze capabilities, model adjustments, output validation improvements, customer not…Establishing immediate mitigation steps with designated staff responsibilities. For example, system freeze capabilities, model adjustments,…
removedshouldEstablishing compensation assessment procedures. For example, loss evaluation methods, settlement approaches, and payment authorization lev…
addedshouldImplementing customer communication protocols. For example, disclosure procedures, explanation of corrective actions, and follow-up commitm…
E004 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayImplementing code signing and verification processes for AI models, libraries, and deployment artefacts to ensure only digitally signed com…Implementing code signing and verification processes for AI models, libraries, and deployment artefacts to ensure only digitally signed com…
matchhigh r=1.00 shouldAssigning an accountable lead as approver for each of these changes. Can follow a RACI structure to formalize roles of those consulted and…Assigning an accountable lead as approver for each of these changes. Can follow a RACI structure to formalize roles of those consulted and…
matchhigh r=1.00 shouldDefining AI system changes requiring approval including model selection, material changes to the meta prompt, adding / removing guardrails,…Defining AI system changes requiring approval including model selection, material changes to the meta prompt, adding / removing guardrails,…
E005 — matched 0 · added 1 · removed 3 · merges 0
KindDetailPrevCur
removedshouldConducting deployment risk assessments. For example, evaluating data sensitivity, regulatory compliance requirements, IP protection needs,…
removedshouldDocumenting decision criteria and rationale. For example, establishing clear selection factors, maintaining records of deployment choices w…
removedshouldReviewing deployment decisions when requirements change. For example, reassessing choices when data sensitivity, regulations, or threat lan…
addedshouldDocumenting data storage security. For example, assessments around cloud vs. on-premises processing.
E006 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldMaintaining assessment records with sufficient detail for audit purposes and retaining due diligence evidence before vendor approval.Maintaining assessment records with sufficient detail for audit purposes and retaining due diligence evidence before vendor approval.
matchhigh r=1.00 shouldConducting documented assessments. For example, scoring results, verification activities such as certifications reviewed and references con…Conducting documented assessments. For example, scoring results, verification activities such as certifications reviewed and references con…
matchhigh r=1.00 shouldDefining assessment criteria for foundational or upstream AI models. For example, data handling and ownership practices, PII controls, secu…Defining assessment criteria for foundational or upstream AI models. For example, data handling and ownership practices, PII controls, secu…
E007 — matched 1 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldDocumenting formal review and approval decisions for changes defined in E004: Assign accountability.Documenting formal review and approval decisions for changes defined in E004: Assign accountability.
E008 — matched 4 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayCollecting and implementing external feedback on AI systems. For example, system risks, new threat patterns, new mitigation strategies.Collecting and implementing external feedback on AI systems. For example, system risks, new threat patterns, new mitigation strategies.
matchhigh r=1.00 shouldDocumenting and tracking remediation of any risks identified.Documenting and tracking remediation of any risks identified.
matchhigh r=1.00 shouldMaintaining a centralized repository of decision records and internal review of these record. For example, supporting evidence reviewed, re…Maintaining a centralized repository of decision records and internal review of these record. For example, supporting evidence reviewed, re…
matchhigh r=1.00 shouldReviewing decision processes every quarter including AI system changes, foundational model selection, security assessment.Reviewing decision processes every quarter including AI system changes, foundational model selection, security assessment.
E009 — matched 2 · added 1 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldCapturing access metadata. For example, user identification, authentication timestamps, accessed resources, session duration, origin IP add…Capturing access metadata. For example, user identification, authentication timestamps, accessed resources, session duration, origin IP add…
matchhigh r=1.00 shouldConfiguring logging for third-party interactions. For example, capturing API connections, user access sessions, data exchanges, and service…Configuring logging for third-party interactions. For example, capturing API connections, user access sessions, data exchanges, and service…
addedmayGenerating alerts on anomalous third-party access patterns against defined detection rules. For example, alerting on unexpected call volume…
E010 — matched 6 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayConducting regular effectiveness reviews. For example, quarterly analysis of violation trends, tool performance assessment, policy updates…Conducting regular effectiveness reviews. For example, quarterly analysis of violation trends, tool performance assessment, policy updates…
matchhigh r=1.00 mayMaintaining logging and tracking systems. For example, incident creation, violation tracking with case assignment and resolution documentat…Maintaining logging and tracking systems. For example, incident creation, violation tracking with case assignment and resolution documentat…
matchhigh r=1.00 mayReal-time monitoring, blocking, or alerting capabilities.Real-time monitoring, blocking, or alerting capabilities.
matchhigh r=1.00 shouldImplementing user feedback when policy is breached. For example, showing alerts or error messages when inputs violate acceptable use.Implementing user feedback when policy is breached. For example, showing alerts or error messages when inputs violate acceptable use.
matchhigh r=1.00 shouldImplementing detection and monitoring tools. For example, prompt analysis, output filtering, usage pattern anomalies, and suspicious access…Implementing detection and monitoring tools. For example, prompt analysis, output filtering, usage pattern anomalies, and suspicious access…
matchhigh r=1.00 shouldDefining prohibited AI usage for end-users. For example, jailbreak attempts, malicious prompt injection, unauthorized data extraction, gene…Defining prohibited AI usage for end-users. For example, jailbreak attempts, malicious prompt injection, unauthorized data extraction, gene…
E011 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayImplementing transfer compliance procedures. For example, assessing data transfer requirements for AI training data and inference processin…Implementing transfer compliance procedures. For example, assessing data transfer requirements for AI training data and inference processin…
matchhigh r=1.00 shouldReviewing and updating documentation regularly.Reviewing and updating documentation regularly.
matchhigh r=1.00 shouldMaintaining AI infrastructure location documentation. For example, geographic locations of foundation model processing locations and infere…Maintaining AI infrastructure location documentation. For example, geographic locations of foundation model processing locations and infere…
E012 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldReviewing the repository every 6 months and when additional requirements may be triggered. For example, regulations change or business oper…Reviewing the repository every 6 months and when additional requirements may be triggered. For example, regulations change or business oper…
matchhigh r=1.00 shouldDocumenting compliance procedures and strategies appropriate for company size and operations.Documenting compliance procedures and strategies appropriate for company size and operations.
matchhigh r=1.00 shouldIdentifying relevant regulations. For example, data protection laws. For example, GDPR, CCPA, sector-specific requirements, emerging AI sta…Identifying relevant regulations. For example, data protection laws. For example, GDPR, CCPA, sector-specific requirements, emerging AI sta…
E013 — matched 5 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayDocumenting communication procedures with regulatory authorities and stakeholders. For example, establishing protocols for regulatory repor…Documenting communication procedures with regulatory authorities and stakeholders. For example, establishing protocols for regulatory repor…
matchhigh r=1.00 mayEstablishing data management and record-keeping systems. For example, documenting data governance procedures, maintaining technical documen…Establishing data management and record-keeping systems. For example, documenting data governance procedures, maintaining technical documen…
matchhigh r=1.00 shouldImplementing defect tracking, continuous improvement, and post-market monitoring. For example, maintaining issue tracking systems, conducti…Implementing defect tracking, continuous improvement, and post-market monitoring. For example, maintaining issue tracking systems, conducti…
matchhigh r=1.00 shouldEstablishing change management, approval processes, and documentation standards. For example, defining review and approval requirements for…Establishing change management, approval processes, and documentation standards. For example, defining review and approval requirements for…
matchhigh r=1.00 shouldDefining quality objectives, metrics, and risk management approach for AI systems. For example, establishing performance targets, safety th…Defining quality objectives, metrics, and risk management approach for AI systems. For example, establishing performance targets, safety th…
E014 — matched 0 · added 1 · removed 0 · merges 0
KindDetailPrevCur
addedmayThis requirement was merged into E017 at the Q1, 2026 standard update. See aiuc-1.com/changelog for more information.
E015 — matched 4 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayImplementing technical controls to ensure logs are tamper-evident and independently verifiable. For example, ensuring that captured records…Implementing technical controls to ensure logs are tamper-evident and independently verifiable. For example, ensuring that captured records…
matchhigh r=1.00 mayCapturing full execution chains of agentic workflows to support investigation of agent-specific incidents. For example, logging agent prove…Capturing full execution chains of agentic workflows to support investigation of agent-specific incidents. For example, logging agent prove…
matchhigh r=1.00 shouldImplementing log storage with appropriate retention periods, access controls, and data sanitation to support auditing and incident response.Implementing log storage with appropriate retention periods, access controls, and data sanitation to support auditing and incident response.
matchhigh r=1.00 shouldCapturing system activity details to support incident investigation and behavior explanation. For example, logging inputs, processing steps…Capturing system activity details to support incident investigation and behavior explanation. For example, logging inputs, processing steps…
E016 — matched 5 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldEstablishing reactive disclosure capabilities when users ask if they are interacting with AI.Establishing reactive disclosure capabilities when users ask if they are interacting with AI.
matchhigh r=1.00 shouldDisclosing when autonomous AI agents or systems are performing actions. For example, notifying users when AI systems are making decisions,…Disclosing when autonomous AI agents or systems are performing actions. For example, notifying users when AI systems are making decisions,…
matchhigh r=1.00 shouldLabelling AI-generated media and documents in a machine-readable and detectable format. For example, marking AI-generated images, videos, a…Labelling AI-generated media and documents in a machine-readable and detectable format. For example, marking AI-generated images, videos, a…
matchhigh r=1.00 shouldImplementing AI disclosure for voice-based interactions. For example, providing audio notifications at the beginning of voice calls or inte…Implementing AI disclosure for voice-based interactions. For example, providing audio notifications at the beginning of voice calls or inte…
matchhigh r=1.00 shouldImplementing AI disclosure for text-based interactions. For example, displaying clear notices when users interact with AI chatbots, virtual…Implementing AI disclosure for text-based interactions. For example, displaying clear notices when users interact with AI chatbots, virtual…
E017 — matched 3 · added 1 · removed 1 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayDocumenting sharing procedures including approval workflows, version control, and distribution tracking. For example, establishing approval…Documenting sharing procedures including approval workflows, version control, and distribution tracking. For example, establishing approval…
matchhigh r=1.00 mayDefining policies for sharing transparency documentation with external stakeholders. For example, establishing when reports are shared, spe…Defining policies for sharing transparency documentation with external stakeholders. For example, establishing when reports are shared, spe…
matchhigh r=1.00 shouldCreating transparency documentation for major AI systems. For example, documenting system characteristics, data provenance, and model behav…Creating transparency documentation for major AI systems. For example, documenting system characteristics, data provenance, and model behav…
removedshouldEstablishing a transparency policy defining documentation requirements for major AI systems. For example, specifying required documentation…
addedmayDocumenting platform-level and deployer-level security responsibilities for AI systems. For example, delineating which security obligations…
F001 — matched 2 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayImplementing malicious use detection and blocking. For example, deploying available content filtering to detect requests for malicious code…Implementing malicious use detection and blocking. For example, deploying available content filtering to detect requests for malicious code…
matchhigh r=1.00 shouldResults of testing from foundation model developer on offensive cyber capabilities and mitigations.Results of testing from foundation model developer on offensive cyber capabilities and mitigations.
F002 — matched 2 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayEstablishing catastrophic misuse monitoring. For example, monitoring AI system interactions for patterns indicating weapons development or…Establishing catastrophic misuse monitoring. For example, monitoring AI system interactions for patterns indicating weapons development or…
matchhigh r=1.00 shouldResults of testing from foundation model developer on CBRN capabilities and mitigations.Results of testing from foundation model developer on CBRN capabilities and mitigations.
Generated by AIUC1explorer v0.1.0.dev0 — per-release change analysis of the AIUC-1 standard.
AIUC-1 (c) 2025-2026 Caliber Labs PBC, DBA Artificial Intelligence Underwriting Company (AIUC).
AIUC1explorer analysis and publication (c) 2025-2026 Cabahu Pty Ltd DBA axigetik.