Sources: apr-2026: website · commit 2948ae0 | jul-2026: website · commit d407401
AIUC-1 for coding agents: Secrets management, secure defaults in code, execution-level safeguards broadened to coding agents Technical guidance for auditors: Public documentation on AIUC-1 audit scoping and annual re-certification Clarifications to existing requirements: Clearer rules for which controls apply to which agent types, and removal of duplicative controls
| ID | Title | Nature | Dist. | Shoulds/Mays | Site narrative |
|---|---|---|---|---|---|
A005 | Prevent cross-customer data exposure | substantive | 0.298 | 2/1 → 2/1 (Δ +0s/+0m) | revision Broadened the requirement to cover cross-customer data exposure generally, not only when combining customer data from multiple sources clarification Generalized typical evidence to logical isolation appropriate to the architecture rather than specific app-ID patterns |
A006 | Prevent PII leakage | clarification | 0.059 | 2/1 → 1/1 (Δ -1s/+0m) | revision Retired the core control requiring authentication and authorization for PII access; DLP system integration renumbered to A006.2 as a supplemental control |
| ID | Title | Nature | Dist. | Shoulds/Mays | Site narrative |
|---|---|---|---|---|---|
C001 | Define AI risk taxonomy | editorial | 0.007 | 4/0 → 4/0 (Δ +0s/+0m) | |
C005 | Prevent agent-specific high risk outputs | clarification | 0.089 | 2/2 → 2/2 (Δ +0s/+0m) | clarification Renamed from customer-defined to agent-specific high-risk outputs to reflect that the risk taxonomy is defined per agent |
| ID | Title | Nature | Dist. | Shoulds/Mays | Site narrative |
|---|---|---|---|---|---|
E009 | Monitor third-party access | substantive | 0.333 | 2/0 → 2/1 (Δ +0s/+1m) | revision Expanded the requirement to cover monitoring and logging of third-party API connections, sessions, and data access addition Added new supplemental control for alerting on anomalous third-party access |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Documenting processes for handling end-user data subject rights. For example, handling requests for opt-in/opt-out rights, access, portabil… | Documenting processes for handling end-user data subject rights. For example, handling requests for opt-in/opt-out rights, access, portabil… |
| match | high r=1.00 should | Implementing technical controls to enforce data retention and deletion policies. For example, automating data deletion based on retention s… | Implementing technical controls to enforce data retention and deletion policies. For example, automating data deletion based on retention s… |
| match | high r=1.00 should | Defining and communicating input data usage policies. Including specifying how customer data is used for inference and model training, esta… | Defining and communicating input data usage policies. Including specifying how customer data is used for inference and model training, esta… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Implementing technical controls to enforce AI output opt-in/opt-out and deletion policies. For example, automating customer preference enfo… | Implementing technical controls to enforce AI output opt-in/opt-out and deletion policies. For example, automating customer preference enfo… |
| match | high r=1.00 should | Disclosing opt-in/opt-out and deletion policies for AI outputs. For example, documenting how customers can opt out of output storage or reu… | Disclosing opt-in/opt-out and deletion policies for AI outputs. For example, documenting how customers can opt out of output storage or reu… |
| match | high r=1.00 should | Establishing output ownership and usage rights policies. For example, specifying customer ownership of AI-generated outputs versus AI input… | Establishing output ownership and usage rights policies. For example, specifying customer ownership of AI-generated outputs versus AI input… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Enabling agent access and governance through permission-ready architecture. For example, exposing per-agent permission scopes mappable to e… | Enabling agent access and governance through permission-ready architecture. For example, exposing per-agent permission scopes mappable to e… |
| match | high r=1.00 may | Enabling agent identity management. For example, assigning each agent a unique, cryptographically verifiable identity; supporting standard… | Enabling agent identity management. For example, assigning each agent a unique, cryptographically verifiable identity; supporting standard… |
| match | high r=1.00 should | Configuring data access limits to reduce data and privacy exposure. For example, limiting data access to task-relevant information based on… | Configuring data access limits to reduce data and privacy exposure. For example, limiting data access to task-relevant information based on… |
| removed | may | Deploying monitoring mechanisms. Including ensuring AI systems only perform necessary inference and logging deviations from defined operati… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Establishing output monitoring for high-risk IP scenarios. For example, logging AI responses that accessed confidential data sources, imple… | Establishing output monitoring for high-risk IP scenarios. For example, logging AI responses that accessed confidential data sources, imple… |
| match | high r=1.00 may | Implementing technical controls to detect proprietary information in outputs. | Implementing technical controls to detect proprietary information in outputs. |
| match | high r=1.00 may | Leveraging foundation model provider protections. For example, using providers with zero data retention policies, requiring contractual com… | Leveraging foundation model provider protections. For example, using providers with zero data retention policies, requiring contractual com… |
| match | high r=1.00 should | Providing user guidance on protecting confidential information. For example, instructing employees not to input trade secrets, proprietary… | Providing user guidance on protecting confidential information. For example, instructing employees not to input trade secrets, proprietary… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Implementing specific privacy-enhancing technologies (PETs) to reduce competitive exposure. | Implementing specific privacy-enhancing technologies (PETs) to reduce competitive exposure. |
| match | high r=1.00 should | Implementing customer data isolation controls. For example, enforcing strict logical and physical separation of customer data, applying ten… | Implementing customer data isolation controls. For example, enforcing strict logical and physical separation of customer data, applying ten… |
| match | high r=1.00 should | Establishing explicit consent and disclosure for combined data usage. For example, informing customers when their data will be combined wit… | Establishing explicit consent and disclosure for combined data usage. For example, informing customers when their data will be combined wit… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Integrating with existing data loss prevention (DLP) systems to monitor and block outputs containing personal data in violation of policy. | Integrating with existing data loss prevention (DLP) systems to monitor and block outputs containing personal data in violation of policy. |
| match | high r=1.00 should | Implementing safeguards to prevent personal data leakage through AI system outputs and logs. For example, filtering prompts and outputs for… | Implementing safeguards to prevent personal data leakage through AI system outputs and logs. For example, filtering prompts and outputs for… |
| removed | should | Requiring authentication and authorization for PII access. For example, role-based access controls for PII-containing systems, multi-factor… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Implementing restrictions in AI acceptable use policy. | Implementing restrictions in AI acceptable use policy. |
| match | high r=1.00 may | Implementing user guidance and guardrails to reduce IP risk. For example, usage policies that explain prohibited content types, user warnin… | Implementing user guidance and guardrails to reduce IP risk. For example, usage policies that explain prohibited content types, user warnin… |
| match | high r=1.00 may | Establishing supplementary content filtering mechanisms where provider protections have gaps or limitations. For example, detecting copyrig… | Establishing supplementary content filtering mechanisms where provider protections have gaps or limitations. For example, detecting copyrig… |
| match | high r=1.00 should | Documenting foundation model provider IP protections which may serve as primary infringement safeguards. For example, indemnification claus… | Documenting foundation model provider IP protections which may serve as primary infringement safeguards. For example, indemnification claus… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Aligning adversarial testing with broader security testing programs. For example, integrating AI-specific test cases into broader penetrati… | Aligning adversarial testing with broader security testing programs. For example, integrating AI-specific test cases into broader penetrati… |
| match | high r=1.00 should | Establishing improvement processes based on findings. For example, assigning owners and remediation timelines based on test severity, track… | Establishing improvement processes based on findings. For example, assigning owners and remediation timelines based on test severity, track… |
| match | high r=1.00 should | Maintaining secure testing documentation. For example, recording test cases, methods, outcomes, and system behaviors with restricted access… | Maintaining secure testing documentation. For example, recording test cases, methods, outcomes, and system behaviors with restricted access… |
| match | high r=1.00 should | Conducting comprehensive adversarial testing at least quarterly. For example, performing structured red-teaming, prompt injection assessmen… | Conducting comprehensive adversarial testing at least quarterly. For example, performing structured red-teaming, prompt injection assessmen… |
| match | high r=1.00 should | Establishing a taxonomy for adversarial risks. For example, drawing on NIST's AI 100-2e2023 attack classifications and aligning these to sy… | Establishing a taxonomy for adversarial risks. For example, drawing on NIST's AI 100-2e2023 attack classifications and aligning these to sy… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Integrating adversarial input detection into existing security operations tooling. For example, forwarding flagged inputs to SIEM platforms… | Integrating adversarial input detection into existing security operations tooling. For example, forwarding flagged inputs to SIEM platforms… |
| match | high r=1.00 may | Implementing adversarial input detection prior to AI model processing where feasible. For example, using pre-processing filters to flag lik… | Implementing adversarial input detection prior to AI model processing where feasible. For example, using pre-processing filters to flag lik… |
| match | high r=1.00 should | Maintaining detection effectiveness through quarterly reviews. For example, updating detection rules based on emerging adversarial techniqu… | Maintaining detection effectiveness through quarterly reviews. For example, updating detection rules based on emerging adversarial techniqu… |
| match | high r=1.00 should | Implementing incident logging and response procedures. For example, logging suspected adversarial attacks with relevant context, escalating… | Implementing incident logging and response procedures. For example, logging suspected adversarial attacks with relevant context, escalating… |
| match | high r=1.00 should | Establishing detection and alerting. For example, implementing monitoring for prompt injection patterns, jailbreak techniques, adversarial… | Establishing detection and alerting. For example, implementing monitoring for prompt injection patterns, jailbreak techniques, adversarial… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Establishing approval processes. For example, requiring designated review for public content referencing AI capabilities in e.g. publicatio… | Establishing approval processes. For example, requiring designated review for public content referencing AI capabilities in e.g. publicatio… |
| match | high r=1.00 should | Controlling organizational information to balance transparency with security. For example, limiting disclosure of AI team details, developm… | Controlling organizational information to balance transparency with security. For example, limiting disclosure of AI team details, developm… |
| match | high r=1.00 should | Documenting limitations on technical information release. For example, limiting public disclosure of model architectures, algorithms, train… | Documenting limitations on technical information release. For example, limiting public disclosure of model architectures, algorithms, train… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Maintaining endpoint security through remediation. For example, tracking identified vulnerabilities, implementing protective measures based… | Maintaining endpoint security through remediation. For example, tracking identified vulnerabilities, implementing protective measures based… |
| match | high r=1.00 should | Conducting simulated external attack testing of AI endpoints. For example, performing automated attack simulations, testing endpoint protec… | Conducting simulated external attack testing of AI endpoints. For example, performing automated attack simulations, testing endpoint protec… |
| match | high r=1.00 should | Implementing rate limiting and query restrictions. For example, establishing per-user quotas to prevent model extraction, blocking excessiv… | Implementing rate limiting and query restrictions. For example, establishing per-user quotas to prevent model extraction, blocking excessiv… |
| match | high r=1.00 should | Implementing systems distinguishing between high-volume legitimate usage and adversarial behavior. For example, using behavioral analytics… | Implementing systems distinguishing between high-volume legitimate usage and adversarial behavior. For example, using behavioral analytics… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Periodically evaluating filter performance and adjusting thresholds accordingly. For example, accuracy, latency, false positives/negatives. | Periodically evaluating filter performance and adjusting thresholds accordingly. For example, accuracy, latency, false positives/negatives. |
| match | high r=1.00 may | Logging flagged prompts for analysis and refinement of filters, while ensuring compliance with privacy obligations. | Logging flagged prompts for analysis and refinement of filters, while ensuring compliance with privacy obligations. |
| match | high r=1.00 may | Providing feedback to users when inputs are blocked. | Providing feedback to users when inputs are blocked. |
| match | high r=1.00 may | Documenting the moderation logic and rationale. For example, explaining chosen moderation tools, threshold justifications, and decision cri… | Documenting the moderation logic and rationale. For example, explaining chosen moderation tools, threshold justifications, and decision cri… |
| match | high r=1.00 should | Integrating automated moderation tools to filter inputs before they reach the foundation model. For example, integrating third-party modera… | Integrating automated moderation tools to filter inputs before they reach the foundation model. For example, integrating third-party modera… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Deploying monitoring and alerting for agent actions that exceed security boundaries. For example, logging all agent service interactions, a… | Deploying monitoring and alerting for agent actions that exceed security boundaries. For example, logging all agent service interactions, a… |
| match | high r=1.00 should | Implementing technical restrictions that limit agent capabilities to authorized scope. For example, restricting agent access to approved ba… | Implementing technical restrictions that limit agent capabilities to authorized scope. For example, restricting agent access to approved ba… |
| removed | may | Implementing additional safeguards to contain runtime risk. For example, applying sandboxed execution environments with restricted filesyst… | |
| added | may | Implementing additional safeguards to contain runtime risk. For example, enabling sandboxed execution environments with configurable filesy… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Conducting access reviews and updates at least quarterly. For example, validating access assignments, updating based on policy or role chan… | Conducting access reviews and updates at least quarterly. For example, validating access assignments, updating based on policy or role chan… |
| match | high r=1.00 should | Restricting administrative and configuration privileges to authorized personnel. For example, limiting ability to alter system behavior, to… | Restricting administrative and configuration privileges to authorized personnel. For example, limiting ability to alter system behavior, to… |
| match | high r=1.00 should | Implementing system-level access controls tailored to AI systems. For example, using role-based or attribute-based access to restrict acces… | Implementing system-level access controls tailored to AI systems. For example, using role-based or attribute-based access to restrict acces… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Verifying model integrity before and during deployment. For example, using cryptographic checksums or signed artifacts to detect tampering,… | Verifying model integrity before and during deployment. For example, using cryptographic checksums or signed artifacts to detect tampering,… |
| match | high r=1.00 may | Securing model hosting environments. For example, using up-to-date and minimal container images, scanning for known vulnerabilities in depe… | Securing model hosting environments. For example, using up-to-date and minimal container images, scanning for known vulnerabilities in depe… |
| match | high r=1.00 may | Enforcing data integrity across agentic interfaces. For example, implementing cryptographic message signing for agent-to-agent communicatio… | Enforcing data integrity across agentic interfaces. For example, implementing cryptographic message signing for agent-to-agent communicatio… |
| match | high r=1.00 should | Securing data in transit across model API endpoints and agentic interfaces. For example, enforcing TLS for all model API endpoint traffic,… | Securing data in transit across model API endpoints and agentic interfaces. For example, enforcing TLS for all model API endpoint traffic,… |
| match | high r=1.00 should | Enforcing caller authentication across API endpoints and agentic interfaces. For example, applying scoped API tokens or signed requests for… | Enforcing caller authentication across API endpoints and agentic interfaces. For example, applying scoped API tokens or signed requests for… |
| removed | should | Implementing AI system access protection. For example, restricting access to production AI systems based on job function and operational ne… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Limiting the fidelity of model outputs in certain use cases. For example, applying output rounding, threshold bands, or obfuscation techniq… | Limiting the fidelity of model outputs in certain use cases. For example, applying output rounding, threshold bands, or obfuscation techniq… |
| match | high r=1.00 may | Providing user-facing notices or documentation about output limitations. | Providing user-facing notices or documentation about output limitations. |
| match | high r=1.00 should | Reducing or limiting the number of results shown in outputs to relevant only to balance security and utility. For example, character limits… | Reducing or limiting the number of results shown in outputs to relevant only to balance security and utility. For example, character limits… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Maintaining taxonomy currency with documented change management. For example, updating based on emerging threats or incidents. | Maintaining taxonomy currency with documented change management. For example, updating based on emerging threats or incidents. |
| match | high r=1.00 should | Establishing severity grading appropriate to organizational context and risk tolerance. For example, implementing consistent scoring method… | Establishing severity grading appropriate to organizational context and risk tolerance. For example, implementing consistent scoring method… |
| match | high r=1.00 should | Aligning risk taxonomy with external frameworks and standards. | Aligning risk taxonomy with external frameworks and standards. |
| match | high r=1.00 should | Defining risk categories with severity levels and examples based on industry and deployment context. For example, classifying harmful outpu… | Defining risk categories with severity levels and examples based on industry and deployment context. For example, classifying harmful outpu… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Implementing pre-deployment vulnerability scanning of AI artifacts and dependencies. For example, scanning AI models and ML libraries for s… | Implementing pre-deployment vulnerability scanning of AI artifacts and dependencies. For example, scanning AI models and ML libraries for s… |
| match | high r=1.00 may | Integrating AI system testing into established software development lifecycle (SDLC) gates. For example, including threat modelling and ris… | Integrating AI system testing into established software development lifecycle (SDLC) gates. For example, including threat modelling and ris… |
| match | high r=1.00 should | Obtaining approval sign-offs from designated accountable. For example, documented rationale for approval decisions and maintained records f… | Obtaining approval sign-offs from designated accountable. For example, documented rationale for approval decisions and maintained records f… |
| match | high r=1.00 should | Completing risk assessments of identified issues before system deployment. For example, potential impact analysis, mitigation strategies, a… | Completing risk assessments of identified issues before system deployment. For example, potential impact analysis, mitigation strategies, a… |
| match | high r=1.00 should | Conducting pre-deployment testing with documented results and identified issues. For example, structured hallucination testing, adversarial… | Conducting pre-deployment testing with documented results and identified issues. For example, structured hallucination testing, adversarial… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Evaluating harm mitigation controls using performance metrics. | Evaluating harm mitigation controls using performance metrics. |
| match | high r=1.00 may | Implementing bias detection and mitigation controls. For example, monitoring for discriminatory patterns, implementing fairness checks in o… | Implementing bias detection and mitigation controls. For example, monitoring for discriminatory patterns, implementing fairness checks in o… |
| match | high r=1.00 should | Implementing guardrails for advice generation. For example, restricting high-risk recommendations in sensitive domains, requiring disclaime… | Implementing guardrails for advice generation. For example, restricting high-risk recommendations in sensitive domains, requiring disclaime… |
| match | high r=1.00 should | Implementing content filtering for harmful output types. For example, detecting and blocking distressed responses, angry language, offensiv… | Implementing content filtering for harmful output types. For example, detecting and blocking distressed responses, angry language, offensiv… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Providing user guidance on system capabilities and limitations. For example, communicating what the AI system can and cannot do, intended u… | Providing user guidance on system capabilities and limitations. For example, communicating what the AI system can and cannot do, intended u… |
| match | high r=1.00 should | Tracking out-of-scope violations and updating boundaries. For example, logging boundary violations, adjusting restrictions based on misuse… | Tracking out-of-scope violations and updating boundaries. For example, logging boundary violations, adjusting restrictions based on misuse… |
| match | high r=1.00 should | Detecting and blocking out-of-scope requests. For example, detecting conversations outside intended use cases, blocking prohibited topics,… | Detecting and blocking out-of-scope requests. For example, detecting conversations outside intended use cases, blocking prohibited topics,… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Implementing automated real-time interventions. For example, blocking or modifying outputs based on severity. | Implementing automated real-time interventions. For example, blocking or modifying outputs based on severity. |
| match | high r=1.00 may | Establishing escalation procedures for flagged high-risk content. For example, defining when human review is required and establishing appr… | Establishing escalation procedures for flagged high-risk content. For example, defining when human review is required and establishing appr… |
| match | high r=1.00 should | Implementing response actions for detected risks. For example, blocking high-severity outputs, flagging medium-risk content for review, log… | Implementing response actions for detected risks. For example, blocking high-severity outputs, flagging medium-risk content for review, log… |
| match | high r=1.00 should | Implementing detection and blocking mechanisms aligned with organizational risk taxonomy. For example, deploying filtering based on defined… | Implementing detection and blocking mechanisms aligned with organizational risk taxonomy. For example, deploying filtering based on defined… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Detecting advanced output-based attack patterns. For example, identifying prompt injection attempts, model subversion techniques, payloads… | Detecting advanced output-based attack patterns. For example, identifying prompt injection attempts, model subversion techniques, payloads… |
| match | high r=1.00 should | Establishing output sanitization and validation procedures before presenting content to users. For example, encoding or stripping potential… | Establishing output sanitization and validation procedures before presenting content to users. For example, encoding or stripping potential… |
| removed | should | Implementing security labeling and content handling based on trust level. For example, marking untrusted or third-party content, distinguis… | |
| added | should | Implementing content handling and security labelling based on trust level. For example, marking untrusted or third-party content, distingui… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Establishing human review workflows for flagged high-risk outputs. For example, assigning reviewers, defining escalation procedures for com… | Establishing human review workflows for flagged high-risk outputs. For example, assigning reviewers, defining escalation procedures for com… |
| match | high r=1.00 should | Implementing automated detection mechanisms for high-risk outputs. For example, using content filtering, risk scoring, or classification mo… | Implementing automated detection mechanisms for high-risk outputs. For example, using content filtering, risk scoring, or classification mo… |
| match | high r=1.00 should | Defining high-risk output criteria drawing on risk taxonomy. | Defining high-risk output criteria drawing on risk taxonomy. |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Integrating AI output monitoring with existing security tools. For example, forwarding alerts and flagged outputs to SIEM platforms, applyi… | Integrating AI output monitoring with existing security tools. For example, forwarding alerts and flagged outputs to SIEM platforms, applyi… |
| match | high r=1.00 may | Maintaining documentation. For example, recording identified scenarios with clear examples, updating risk taxonomy based on monitoring find… | Maintaining documentation. For example, recording identified scenarios with clear examples, updating risk taxonomy based on monitoring find… |
| match | high r=1.00 should | Establishing ongoing monitoring of AI outputs across risk categories. For example, conducting regular evaluations prioritized by risk sever… | Establishing ongoing monitoring of AI outputs across risk categories. For example, conducting regular evaluations prioritized by risk sever… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Reviewing user feedback and intervention logs at regular intervals, analyzing findings using structured methodologies (e.g., categorizing b… | Reviewing user feedback and intervention logs at regular intervals, analyzing findings using structured methodologies (e.g., categorizing b… |
| match | high r=1.00 should | Ensuring accessibility of feedback and intervention mechanisms. For example, adhering to WCAG 2.1 standards for color contrast, screen read… | Ensuring accessibility of feedback and intervention mechanisms. For example, adhering to WCAG 2.1 standards for color contrast, screen read… |
| match | high r=1.00 should | Enabling user intervention capabilities. For example, providing mechanisms for users to pause, stop, or redirect system behavior, implement… | Enabling user intervention capabilities. For example, providing mechanisms for users to pause, stop, or redirect system behavior, implement… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Maintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti… | Maintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti… |
| match | high r=1.00 should | Conducting regular testing. Including performing assessments of harmful outputs at least every quarter, defining testing scope and methodol… | Conducting regular testing. Including performing assessments of harmful outputs at least every quarter, defining testing scope and methodol… |
| match | high r=1.00 should | Appointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m… | Appointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Maintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti… | Maintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti… |
| match | high r=1.00 should | Conducting regular testing. Including defining testing scope and methodologies based on risk taxonomy and performing assessments of out-of-… | Conducting regular testing. Including defining testing scope and methodologies based on risk taxonomy and performing assessments of out-of-… |
| match | high r=1.00 should | Appointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m… | Appointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Maintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti… | Maintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti… |
| match | high r=1.00 should | Conducting regular testing. Including defining testing scope and methodologies based on risk taxonomy and performing assessments of high-ri… | Conducting regular testing. Including defining testing scope and methodologies based on risk taxonomy and performing assessments of high-ri… |
| match | high r=1.00 should | Appointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m… | Appointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Maintaining uncertainty communication. For example, displaying confidence levels, providing appropriate disclaimers for generated informati… | Maintaining uncertainty communication. For example, displaying confidence levels, providing appropriate disclaimers for generated informati… |
| match | high r=1.00 should | Establishing information source validation. For example, requiring citations for factual claims, implementing source reliability checks. | Establishing information source validation. For example, requiring citations for factual claims, implementing source reliability checks. |
| match | high r=1.00 should | Implementing factual accuracy controls. For example, deploying available fact-checking mechanisms, flagging uncertain or low-confidence res… | Implementing factual accuracy controls. For example, deploying available fact-checking mechanisms, flagging uncertain or low-confidence res… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Maintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti… | Maintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti… |
| match | high r=1.00 should | Conducting regular testing. Including defining testing scope and methodologies based on risk taxonomy and performing assessments at least e… | Conducting regular testing. Including defining testing scope and methodologies based on risk taxonomy and performing assessments at least e… |
| match | high r=1.00 should | Appointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m… | Appointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Reviewing patterns of AI tool usage. For example, identifying anomalies, updating tool permissions, and retiring unused or high-risk functi… | Reviewing patterns of AI tool usage. For example, identifying anomalies, updating tool permissions, and retiring unused or high-risk functi… |
| match | high r=1.00 may | Requiring human approval for sensitive tool operations. For example, requiring human confirmation before executing high-risk actions, multi… | Requiring human approval for sensitive tool operations. For example, requiring human confirmation before executing high-risk actions, multi… |
| match | high r=1.00 should | Establishing execution monitoring and logging. For example, tracking all tool calls, monitoring for unauthorized access attempts or scope v… | Establishing execution monitoring and logging. For example, tracking all tool calls, monitoring for unauthorized access attempts or scope v… |
| match | high r=1.00 should | Enforcing rate limits and transaction caps for autonomous tool use. | Enforcing rate limits and transaction caps for autonomous tool use. |
| match | high r=1.00 should | Implementing tool call validation and authorization. For example, restricting tool calls to approved functions and MCP servers, validating… | Implementing tool call validation and authorization. For example, restricting tool calls to approved functions and MCP servers, validating… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Maintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti… | Maintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti… |
| match | high r=1.00 should | Conducting regular testing. Including defining testing scope and methodologies based on risk taxonomy and performing assessments of tool ca… | Conducting regular testing. Including defining testing scope and methodologies based on risk taxonomy and performing assessments of tool ca… |
| match | high r=1.00 should | Appointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m… | Appointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Establishing evidence collection requirements with guidance on preserving evidence for potential legal review. For example, system logs, us… | Establishing evidence collection requirements with guidance on preserving evidence for potential legal review. For example, system logs, us… |
| match | high r=1.00 should | Implementing security remediation measures. For example, system freeze capabilities, vulnerability fixes, access control updates, and coord… | Implementing security remediation measures. For example, system freeze capabilities, vulnerability fixes, access control updates, and coord… |
| match | high r=1.00 should | Defining breach notification procedures. For example, customer communications, regulatory reporting requirements, and vendor notifications… | Defining breach notification procedures. For example, customer communications, regulatory reporting requirements, and vendor notifications… |
| match | high r=1.00 should | Assigning a breach response lead from existing staff. For example, IT manager, security officer, or designated executive with authority to… | Assigning a breach response lead from existing staff. For example, IT manager, security officer, or designated executive with authority to… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Coordinating external support engagement. For example, legal counsel consultation, PR support, and insurance claim procedures. | Coordinating external support engagement. For example, legal counsel consultation, PR support, and insurance claim procedures. |
| match | high r=1.00 may | Defining harmful output categories with reference to risk taxonomy. For example, discriminatory content, offensive material, inappropriate… | Defining harmful output categories with reference to risk taxonomy. For example, discriminatory content, offensive material, inappropriate… |
| match | high r=1.00 should | Establishing immediate mitigation steps with designated staff responsibilities. For example, system freeze capabilities, output suppression… | Establishing immediate mitigation steps with designated staff responsibilities. For example, system freeze capabilities, output suppression… |
| match | high r=1.00 should | Implementing customer communication protocols. For example, disclosure procedures, explanation of corrective actions, and follow-up commitm… | Implementing customer communication protocols. For example, disclosure procedures, explanation of corrective actions, and follow-up commitm… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Coordinating potential external support. For example, legal consultation for significant claims, financial review when needed, and insuranc… | Coordinating potential external support. For example, legal consultation for significant claims, financial review when needed, and insuranc… |
| match | high r=1.00 may | Defining hallucination incident types. | Defining hallucination incident types. |
| match | mid r=0.73 should | Implementing remediation measures. For example, system freeze capabilities, model adjustments, output validation improvements, customer not… | Establishing immediate mitigation steps with designated staff responsibilities. For example, system freeze capabilities, model adjustments,… |
| removed | should | Establishing compensation assessment procedures. For example, loss evaluation methods, settlement approaches, and payment authorization lev… | |
| added | should | Implementing customer communication protocols. For example, disclosure procedures, explanation of corrective actions, and follow-up commitm… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Implementing code signing and verification processes for AI models, libraries, and deployment artefacts to ensure only digitally signed com… | Implementing code signing and verification processes for AI models, libraries, and deployment artefacts to ensure only digitally signed com… |
| match | high r=1.00 should | Assigning an accountable lead as approver for each of these changes. Can follow a RACI structure to formalize roles of those consulted and… | Assigning an accountable lead as approver for each of these changes. Can follow a RACI structure to formalize roles of those consulted and… |
| match | high r=1.00 should | Defining AI system changes requiring approval including model selection, material changes to the meta prompt, adding / removing guardrails,… | Defining AI system changes requiring approval including model selection, material changes to the meta prompt, adding / removing guardrails,… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| removed | should | Conducting deployment risk assessments. For example, evaluating data sensitivity, regulatory compliance requirements, IP protection needs,… | |
| removed | should | Documenting decision criteria and rationale. For example, establishing clear selection factors, maintaining records of deployment choices w… | |
| removed | should | Reviewing deployment decisions when requirements change. For example, reassessing choices when data sensitivity, regulations, or threat lan… | |
| added | should | Documenting data storage security. For example, assessments around cloud vs. on-premises processing. |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Maintaining assessment records with sufficient detail for audit purposes and retaining due diligence evidence before vendor approval. | Maintaining assessment records with sufficient detail for audit purposes and retaining due diligence evidence before vendor approval. |
| match | high r=1.00 should | Conducting documented assessments. For example, scoring results, verification activities such as certifications reviewed and references con… | Conducting documented assessments. For example, scoring results, verification activities such as certifications reviewed and references con… |
| match | high r=1.00 should | Defining assessment criteria for foundational or upstream AI models. For example, data handling and ownership practices, PII controls, secu… | Defining assessment criteria for foundational or upstream AI models. For example, data handling and ownership practices, PII controls, secu… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Documenting formal review and approval decisions for changes defined in E004: Assign accountability. | Documenting formal review and approval decisions for changes defined in E004: Assign accountability. |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Collecting and implementing external feedback on AI systems. For example, system risks, new threat patterns, new mitigation strategies. | Collecting and implementing external feedback on AI systems. For example, system risks, new threat patterns, new mitigation strategies. |
| match | high r=1.00 should | Documenting and tracking remediation of any risks identified. | Documenting and tracking remediation of any risks identified. |
| match | high r=1.00 should | Maintaining a centralized repository of decision records and internal review of these record. For example, supporting evidence reviewed, re… | Maintaining a centralized repository of decision records and internal review of these record. For example, supporting evidence reviewed, re… |
| match | high r=1.00 should | Reviewing decision processes every quarter including AI system changes, foundational model selection, security assessment. | Reviewing decision processes every quarter including AI system changes, foundational model selection, security assessment. |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Capturing access metadata. For example, user identification, authentication timestamps, accessed resources, session duration, origin IP add… | Capturing access metadata. For example, user identification, authentication timestamps, accessed resources, session duration, origin IP add… |
| match | high r=1.00 should | Configuring logging for third-party interactions. For example, capturing API connections, user access sessions, data exchanges, and service… | Configuring logging for third-party interactions. For example, capturing API connections, user access sessions, data exchanges, and service… |
| added | may | Generating alerts on anomalous third-party access patterns against defined detection rules. For example, alerting on unexpected call volume… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Conducting regular effectiveness reviews. For example, quarterly analysis of violation trends, tool performance assessment, policy updates… | Conducting regular effectiveness reviews. For example, quarterly analysis of violation trends, tool performance assessment, policy updates… |
| match | high r=1.00 may | Maintaining logging and tracking systems. For example, incident creation, violation tracking with case assignment and resolution documentat… | Maintaining logging and tracking systems. For example, incident creation, violation tracking with case assignment and resolution documentat… |
| match | high r=1.00 may | Real-time monitoring, blocking, or alerting capabilities. | Real-time monitoring, blocking, or alerting capabilities. |
| match | high r=1.00 should | Implementing user feedback when policy is breached. For example, showing alerts or error messages when inputs violate acceptable use. | Implementing user feedback when policy is breached. For example, showing alerts or error messages when inputs violate acceptable use. |
| match | high r=1.00 should | Implementing detection and monitoring tools. For example, prompt analysis, output filtering, usage pattern anomalies, and suspicious access… | Implementing detection and monitoring tools. For example, prompt analysis, output filtering, usage pattern anomalies, and suspicious access… |
| match | high r=1.00 should | Defining prohibited AI usage for end-users. For example, jailbreak attempts, malicious prompt injection, unauthorized data extraction, gene… | Defining prohibited AI usage for end-users. For example, jailbreak attempts, malicious prompt injection, unauthorized data extraction, gene… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Implementing transfer compliance procedures. For example, assessing data transfer requirements for AI training data and inference processin… | Implementing transfer compliance procedures. For example, assessing data transfer requirements for AI training data and inference processin… |
| match | high r=1.00 should | Reviewing and updating documentation regularly. | Reviewing and updating documentation regularly. |
| match | high r=1.00 should | Maintaining AI infrastructure location documentation. For example, geographic locations of foundation model processing locations and infere… | Maintaining AI infrastructure location documentation. For example, geographic locations of foundation model processing locations and infere… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Reviewing the repository every 6 months and when additional requirements may be triggered. For example, regulations change or business oper… | Reviewing the repository every 6 months and when additional requirements may be triggered. For example, regulations change or business oper… |
| match | high r=1.00 should | Documenting compliance procedures and strategies appropriate for company size and operations. | Documenting compliance procedures and strategies appropriate for company size and operations. |
| match | high r=1.00 should | Identifying relevant regulations. For example, data protection laws. For example, GDPR, CCPA, sector-specific requirements, emerging AI sta… | Identifying relevant regulations. For example, data protection laws. For example, GDPR, CCPA, sector-specific requirements, emerging AI sta… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Documenting communication procedures with regulatory authorities and stakeholders. For example, establishing protocols for regulatory repor… | Documenting communication procedures with regulatory authorities and stakeholders. For example, establishing protocols for regulatory repor… |
| match | high r=1.00 may | Establishing data management and record-keeping systems. For example, documenting data governance procedures, maintaining technical documen… | Establishing data management and record-keeping systems. For example, documenting data governance procedures, maintaining technical documen… |
| match | high r=1.00 should | Implementing defect tracking, continuous improvement, and post-market monitoring. For example, maintaining issue tracking systems, conducti… | Implementing defect tracking, continuous improvement, and post-market monitoring. For example, maintaining issue tracking systems, conducti… |
| match | high r=1.00 should | Establishing change management, approval processes, and documentation standards. For example, defining review and approval requirements for… | Establishing change management, approval processes, and documentation standards. For example, defining review and approval requirements for… |
| match | high r=1.00 should | Defining quality objectives, metrics, and risk management approach for AI systems. For example, establishing performance targets, safety th… | Defining quality objectives, metrics, and risk management approach for AI systems. For example, establishing performance targets, safety th… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| added | may | This requirement was merged into E017 at the Q1, 2026 standard update. See aiuc-1.com/changelog for more information. |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Implementing technical controls to ensure logs are tamper-evident and independently verifiable. For example, ensuring that captured records… | Implementing technical controls to ensure logs are tamper-evident and independently verifiable. For example, ensuring that captured records… |
| match | high r=1.00 may | Capturing full execution chains of agentic workflows to support investigation of agent-specific incidents. For example, logging agent prove… | Capturing full execution chains of agentic workflows to support investigation of agent-specific incidents. For example, logging agent prove… |
| match | high r=1.00 should | Implementing log storage with appropriate retention periods, access controls, and data sanitation to support auditing and incident response. | Implementing log storage with appropriate retention periods, access controls, and data sanitation to support auditing and incident response. |
| match | high r=1.00 should | Capturing system activity details to support incident investigation and behavior explanation. For example, logging inputs, processing steps… | Capturing system activity details to support incident investigation and behavior explanation. For example, logging inputs, processing steps… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Establishing reactive disclosure capabilities when users ask if they are interacting with AI. | Establishing reactive disclosure capabilities when users ask if they are interacting with AI. |
| match | high r=1.00 should | Disclosing when autonomous AI agents or systems are performing actions. For example, notifying users when AI systems are making decisions,… | Disclosing when autonomous AI agents or systems are performing actions. For example, notifying users when AI systems are making decisions,… |
| match | high r=1.00 should | Labelling AI-generated media and documents in a machine-readable and detectable format. For example, marking AI-generated images, videos, a… | Labelling AI-generated media and documents in a machine-readable and detectable format. For example, marking AI-generated images, videos, a… |
| match | high r=1.00 should | Implementing AI disclosure for voice-based interactions. For example, providing audio notifications at the beginning of voice calls or inte… | Implementing AI disclosure for voice-based interactions. For example, providing audio notifications at the beginning of voice calls or inte… |
| match | high r=1.00 should | Implementing AI disclosure for text-based interactions. For example, displaying clear notices when users interact with AI chatbots, virtual… | Implementing AI disclosure for text-based interactions. For example, displaying clear notices when users interact with AI chatbots, virtual… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Documenting sharing procedures including approval workflows, version control, and distribution tracking. For example, establishing approval… | Documenting sharing procedures including approval workflows, version control, and distribution tracking. For example, establishing approval… |
| match | high r=1.00 may | Defining policies for sharing transparency documentation with external stakeholders. For example, establishing when reports are shared, spe… | Defining policies for sharing transparency documentation with external stakeholders. For example, establishing when reports are shared, spe… |
| match | high r=1.00 should | Creating transparency documentation for major AI systems. For example, documenting system characteristics, data provenance, and model behav… | Creating transparency documentation for major AI systems. For example, documenting system characteristics, data provenance, and model behav… |
| removed | should | Establishing a transparency policy defining documentation requirements for major AI systems. For example, specifying required documentation… | |
| added | may | Documenting platform-level and deployer-level security responsibilities for AI systems. For example, delineating which security obligations… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Implementing malicious use detection and blocking. For example, deploying available content filtering to detect requests for malicious code… | Implementing malicious use detection and blocking. For example, deploying available content filtering to detect requests for malicious code… |
| match | high r=1.00 should | Results of testing from foundation model developer on offensive cyber capabilities and mitigations. | Results of testing from foundation model developer on offensive cyber capabilities and mitigations. |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Establishing catastrophic misuse monitoring. For example, monitoring AI system interactions for patterns indicating weapons development or… | Establishing catastrophic misuse monitoring. For example, monitoring AI system interactions for patterns indicating weapons development or… |
| match | high r=1.00 should | Results of testing from foundation model developer on CBRN capabilities and mitigations. | Results of testing from foundation model developer on CBRN capabilities and mitigations. |