Sources: jan-2026: website · commit 3f3ad18 | apr-2026: website · commit 2948ae0
Introduced new controls for MCP and A2A protocol security, standardizing authentication, transport, runtime containment, and logging across agentic interfaces Expanded third-party risk controls including making third-party access monitoring mandatory Expanded controls for agent identity, permissions, and access management
| ID | Title | Nature | Dist. | Shoulds/Mays | Site narrative |
|---|---|---|---|---|---|
A002 | Establish output data policy | editorial | 0.013 | 2/0 → 2/1 (Δ +0s/+1m) | revision Included both opt-in and out practices revision Included both opt-in and out practices, ensuring balanced coverage of consent models |
A003 | Limit AI agent data access | clarification | 0.229 | 1/2 → 1/3 (Δ +0s/+1m) | specification Specified that the requirement covers data access more generally, and included more controls on agent IAM within it clarification Clarified the control to cover agent access and identity management, not just data collection |
A006 | Prevent PII leakage | clarification | 0.059 | 2/1 → 2/1 (Δ +0s/+0m) |
| ID | Title | Nature | Dist. | Shoulds/Mays | Site narrative |
|---|---|---|---|---|---|
B002 | Detect adversarial input | editorial | 0.045 | 3/2 → 3/2 (Δ +0s/+0m) | clarification Clarified that monitoring is to enable responding to adversarial inputs |
B008 | Protect AI system deployment environment | editorial | 0.037 | 2/2 → 3/3 (Δ +1s/+1m) | revision Expanded scope of requirement from the AI model only to system clarification Expanded scope of control from the AI model only to system |
| ID | Title | Nature | Dist. | Shoulds/Mays | Site narrative |
|---|---|---|---|---|---|
C001 | Define AI risk taxonomy | substantive | 0.648 | 4/0 → 4/0 (Δ +0s/+0m) | specification Generalized the risk taxonomy requirement and changed testing frequency to every 12 months specification Aligned testing frequency to a 12-month cycle consistent with the risk management framework update schedule |
C009 | Enable real-time feedback and intervention | clarification | 0.096 | 2/2 → 2/1 (Δ +0s/-1m) | revision Changed on a controls level - synthesized controls and added in control to action user feedback clarification Included practical validation and actioning of relevant user feedback, and streamlined three controls into one |
| ID | Title | Nature | Dist. | Shoulds/Mays | Site narrative |
|---|---|---|---|---|---|
E005 | Document data storage security | substantive | 0.305 | 3/0 → 3/0 (Δ +0s/+0m) | clarification Clarified that the requirement is around ensuring companies establish clear security and compliance requirements for hosting platforms, rather than the act of… |
E015 | Log AI system activity | editorial | 0.025 | 2/1 → 2/2 (Δ +0s/+1m) | revision Expanded scope of requirement from the AI model only to system addition Extended logging to cover the intermediate steps between input and output (i.e., tool calls, sub-agent actions, and provenance metadata) getting traceability a… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Documenting processes for handling end-user data subject rights. For example, handling requests for opt-in/opt-out rights, access, portabil… | Documenting processes for handling end-user data subject rights. For example, handling requests for opt-in/opt-out rights, access, portabil… |
| match | high r=1.00 should | Implementing technical controls to enforce data retention and deletion policies. For example, automating data deletion based on retention s… | Implementing technical controls to enforce data retention and deletion policies. For example, automating data deletion based on retention s… |
| match | high r=1.00 should | Defining and communicating input data usage policies. Including specifying how customer data is used for inference and model training, esta… | Defining and communicating input data usage policies. Including specifying how customer data is used for inference and model training, esta… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Establishing output ownership and usage rights policies. For example, specifying customer ownership of AI-generated outputs versus AI input… | Establishing output ownership and usage rights policies. For example, specifying customer ownership of AI-generated outputs versus AI input… |
| match | high r=0.91 should | Disclosing opt-out and deletion procedures for AI outputs. For example, documenting how customers can opt out of output storage or reuse, e… | Disclosing opt-in/opt-out and deletion policies for AI outputs. For example, documenting how customers can opt out of output storage or reu… |
| added | may | Implementing technical controls to enforce AI output opt-in/opt-out and deletion policies. For example, automating customer preference enfo… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Deploying monitoring mechanisms. Including ensuring AI systems only perform necessary inference and logging deviations from defined operati… | Deploying monitoring mechanisms. Including ensuring AI systems only perform necessary inference and logging deviations from defined operati… |
| match | high r=0.94 should | Configuring data collection limits to reduce data and privacy exposure. For example, limiting data collection to task-relevant information… | Configuring data access limits to reduce data and privacy exposure. For example, limiting data access to task-relevant information based on… |
| removed | may | Integrating with existing authorization systems to align agent access permissions with organizational policies. | |
| added | may | Enabling agent identity management. For example, assigning each agent a unique, cryptographically verifiable identity; supporting standard… | |
| added | may | Enabling agent access and governance through permission-ready architecture. For example, exposing per-agent permission scopes mappable to e… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Establishing output monitoring for high-risk IP scenarios. For example, logging AI responses that accessed confidential data sources, imple… | Establishing output monitoring for high-risk IP scenarios. For example, logging AI responses that accessed confidential data sources, imple… |
| match | high r=1.00 may | Implementing technical controls to detect proprietary information in outputs. | Implementing technical controls to detect proprietary information in outputs. |
| match | high r=1.00 may | Leveraging foundation model provider protections. For example, using providers with zero data retention policies, requiring contractual com… | Leveraging foundation model provider protections. For example, using providers with zero data retention policies, requiring contractual com… |
| match | high r=1.00 should | Providing user guidance on protecting confidential information. For example, instructing employees not to input trade secrets, proprietary… | Providing user guidance on protecting confidential information. For example, instructing employees not to input trade secrets, proprietary… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Implementing specific privacy-enhancing technologies (PETs) to reduce competitive exposure. | Implementing specific privacy-enhancing technologies (PETs) to reduce competitive exposure. |
| match | high r=1.00 should | Implementing customer data isolation controls. For example, enforcing strict logical and physical separation of customer data, applying ten… | Implementing customer data isolation controls. For example, enforcing strict logical and physical separation of customer data, applying ten… |
| match | high r=1.00 should | Establishing explicit consent and disclosure for combined data usage. For example, informing customers when their data will be combined wit… | Establishing explicit consent and disclosure for combined data usage. For example, informing customers when their data will be combined wit… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Integrating with existing data loss prevention (DLP) systems to monitor and block outputs containing personal data in violation of policy. | Integrating with existing data loss prevention (DLP) systems to monitor and block outputs containing personal data in violation of policy. |
| match | high r=1.00 should | Requiring authentication and authorization for PII access. For example, role-based access controls for PII-containing systems, multi-factor… | Requiring authentication and authorization for PII access. For example, role-based access controls for PII-containing systems, multi-factor… |
| match | high r=1.00 should | Implementing safeguards to prevent personal data leakage through AI system outputs and logs. For example, filtering prompts and outputs for… | Implementing safeguards to prevent personal data leakage through AI system outputs and logs. For example, filtering prompts and outputs for… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Implementing restrictions in AI acceptable use policy. | Implementing restrictions in AI acceptable use policy. |
| match | high r=1.00 may | Implementing user guidance and guardrails to reduce IP risk. For example, usage policies that explain prohibited content types, user warnin… | Implementing user guidance and guardrails to reduce IP risk. For example, usage policies that explain prohibited content types, user warnin… |
| match | high r=1.00 may | Establishing supplementary content filtering mechanisms where provider protections have gaps or limitations. For example, detecting copyrig… | Establishing supplementary content filtering mechanisms where provider protections have gaps or limitations. For example, detecting copyrig… |
| match | high r=1.00 should | Documenting foundation model provider IP protections which may serve as primary infringement safeguards. For example, indemnification claus… | Documenting foundation model provider IP protections which may serve as primary infringement safeguards. For example, indemnification claus… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Aligning adversarial testing with broader security testing programs. For example, integrating AI-specific test cases into broader penetrati… | Aligning adversarial testing with broader security testing programs. For example, integrating AI-specific test cases into broader penetrati… |
| match | high r=1.00 should | Establishing improvement processes based on findings. For example, assigning owners and remediation timelines based on test severity, track… | Establishing improvement processes based on findings. For example, assigning owners and remediation timelines based on test severity, track… |
| match | high r=1.00 should | Maintaining secure testing documentation. For example, recording test cases, methods, outcomes, and system behaviors with restricted access… | Maintaining secure testing documentation. For example, recording test cases, methods, outcomes, and system behaviors with restricted access… |
| match | high r=1.00 should | Conducting comprehensive adversarial testing at least quarterly. For example, performing structured red-teaming, prompt injection assessmen… | Conducting comprehensive adversarial testing at least quarterly. For example, performing structured red-teaming, prompt injection assessmen… |
| match | high r=1.00 should | Establishing a taxonomy for adversarial risks. For example, drawing on NIST's AI 100-2e2023 attack classifications and aligning these to sy… | Establishing a taxonomy for adversarial risks. For example, drawing on NIST's AI 100-2e2023 attack classifications and aligning these to sy… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Integrating adversarial input detection into existing security operations tooling. For example, forwarding flagged inputs to SIEM platforms… | Integrating adversarial input detection into existing security operations tooling. For example, forwarding flagged inputs to SIEM platforms… |
| match | high r=1.00 may | Implementing adversarial input detection prior to AI model processing where feasible. For example, using pre-processing filters to flag lik… | Implementing adversarial input detection prior to AI model processing where feasible. For example, using pre-processing filters to flag lik… |
| match | high r=1.00 should | Maintaining detection effectiveness through quarterly reviews. For example, updating detection rules based on emerging adversarial techniqu… | Maintaining detection effectiveness through quarterly reviews. For example, updating detection rules based on emerging adversarial techniqu… |
| match | high r=1.00 should | Implementing incident logging and response procedures. For example, logging suspected adversarial attacks with relevant context, escalating… | Implementing incident logging and response procedures. For example, logging suspected adversarial attacks with relevant context, escalating… |
| match | high r=1.00 should | Establishing detection and alerting. For example, implementing monitoring for prompt injection patterns, jailbreak techniques, adversarial… | Establishing detection and alerting. For example, implementing monitoring for prompt injection patterns, jailbreak techniques, adversarial… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Establishing approval processes. For example, requiring designated review for public content referencing AI capabilities in e.g. publicatio… | Establishing approval processes. For example, requiring designated review for public content referencing AI capabilities in e.g. publicatio… |
| match | high r=1.00 should | Controlling organizational information to balance transparency with security. For example, limiting disclosure of AI team details, developm… | Controlling organizational information to balance transparency with security. For example, limiting disclosure of AI team details, developm… |
| match | high r=1.00 should | Documenting limitations on technical information release. For example, limiting public disclosure of model architectures, algorithms, train… | Documenting limitations on technical information release. For example, limiting public disclosure of model architectures, algorithms, train… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Maintaining endpoint security through remediation. For example, tracking identified vulnerabilities, implementing protective measures based… | Maintaining endpoint security through remediation. For example, tracking identified vulnerabilities, implementing protective measures based… |
| match | high r=1.00 should | Conducting simulated external attack testing of AI endpoints. For example, performing automated attack simulations, testing endpoint protec… | Conducting simulated external attack testing of AI endpoints. For example, performing automated attack simulations, testing endpoint protec… |
| match | high r=1.00 should | Implementing rate limiting and query restrictions. For example, establishing per-user quotas to prevent model extraction, blocking excessiv… | Implementing rate limiting and query restrictions. For example, establishing per-user quotas to prevent model extraction, blocking excessiv… |
| match | high r=1.00 should | Implementing systems distinguishing between high-volume legitimate usage and adversarial behavior. For example, using behavioral analytics… | Implementing systems distinguishing between high-volume legitimate usage and adversarial behavior. For example, using behavioral analytics… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Periodically evaluating filter performance and adjusting thresholds accordingly. For example, accuracy, latency, false positives/negatives. | Periodically evaluating filter performance and adjusting thresholds accordingly. For example, accuracy, latency, false positives/negatives. |
| match | high r=1.00 may | Logging flagged prompts for analysis and refinement of filters, while ensuring compliance with privacy obligations. | Logging flagged prompts for analysis and refinement of filters, while ensuring compliance with privacy obligations. |
| match | high r=1.00 may | Providing feedback to users when inputs are blocked. | Providing feedback to users when inputs are blocked. |
| match | high r=1.00 may | Documenting the moderation logic and rationale. For example, explaining chosen moderation tools, threshold justifications, and decision cri… | Documenting the moderation logic and rationale. For example, explaining chosen moderation tools, threshold justifications, and decision cri… |
| match | high r=1.00 should | Integrating automated moderation tools to filter inputs before they reach the foundation model. For example, integrating third-party modera… | Integrating automated moderation tools to filter inputs before they reach the foundation model. For example, integrating third-party modera… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Deploying monitoring and alerting for agent actions that exceed security boundaries. For example, logging all agent service interactions, a… | Deploying monitoring and alerting for agent actions that exceed security boundaries. For example, logging all agent service interactions, a… |
| match | high r=0.97 should | Implementing technical restrictions that limit agent capabilities to authorized scope. For example, restricting agent access to approved ba… | Implementing technical restrictions that limit agent capabilities to authorized scope. For example, restricting agent access to approved ba… |
| added | may | Implementing additional safeguards to contain runtime risk. For example, applying sandboxed execution environments with restricted filesyst… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Conducting access reviews and updates at least quarterly. For example, validating access assignments, updating based on policy or role chan… | Conducting access reviews and updates at least quarterly. For example, validating access assignments, updating based on policy or role chan… |
| match | high r=1.00 should | Restricting administrative and configuration privileges to authorized personnel. For example, limiting ability to alter system behavior, to… | Restricting administrative and configuration privileges to authorized personnel. For example, limiting ability to alter system behavior, to… |
| match | high r=1.00 should | Implementing system-level access controls tailored to AI systems. For example, using role-based or attribute-based access to restrict acces… | Implementing system-level access controls tailored to AI systems. For example, using role-based or attribute-based access to restrict acces… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Verifying model integrity before and during deployment. For example, using cryptographic checksums or signed artifacts to detect tampering,… | Verifying model integrity before and during deployment. For example, using cryptographic checksums or signed artifacts to detect tampering,… |
| match | high r=1.00 may | Securing model hosting environments. For example, using up-to-date and minimal container images, scanning for known vulnerabilities in depe… | Securing model hosting environments. For example, using up-to-date and minimal container images, scanning for known vulnerabilities in depe… |
| match | high r=0.95 should | Implementing model access protection. For example, restricting access to production AI models based on job function and operational need, i… | Implementing AI system access protection. For example, restricting access to production AI systems based on job function and operational ne… |
| removed | should | Establishing deployment security controls. For example, applying scoped API tokens or signed requests, using TLS for all endpoint traffic,… | |
| added | should | Enforcing caller authentication across API endpoints and agentic interfaces. For example, applying scoped API tokens or signed requests for… | |
| added | should | Securing data in transit across model API endpoints and agentic interfaces. For example, enforcing TLS for all model API endpoint traffic,… | |
| added | may | Enforcing data integrity across agentic interfaces. For example, implementing cryptographic message signing for agent-to-agent communicatio… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Limiting the fidelity of model outputs in certain use cases. For example, applying output rounding, threshold bands, or obfuscation techniq… | Limiting the fidelity of model outputs in certain use cases. For example, applying output rounding, threshold bands, or obfuscation techniq… |
| match | high r=1.00 may | Providing user-facing notices or documentation about output limitations. | Providing user-facing notices or documentation about output limitations. |
| match | high r=1.00 should | Reducing or limiting the number of results shown in outputs to relevant only to balance security and utility. For example, character limits… | Reducing or limiting the number of results shown in outputs to relevant only to balance security and utility. For example, character limits… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Maintaining taxonomy currency with documented change management. For example, updating based on emerging threats or incidents. | Maintaining taxonomy currency with documented change management. For example, updating based on emerging threats or incidents. |
| match | high r=1.00 should | Establishing severity grading appropriate to organizational context and risk tolerance. For example, implementing consistent scoring method… | Establishing severity grading appropriate to organizational context and risk tolerance. For example, implementing consistent scoring method… |
| match | high r=1.00 should | Aligning risk taxonomy with external frameworks and standards. | Aligning risk taxonomy with external frameworks and standards. |
| match | high r=1.00 should | Defining risk categories with severity levels and examples based on industry and deployment context. For example, classifying harmful outpu… | Defining risk categories with severity levels and examples based on industry and deployment context. For example, classifying harmful outpu… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Implementing pre-deployment vulnerability scanning of AI artifacts and dependencies. For example, scanning AI models and ML libraries for s… | Implementing pre-deployment vulnerability scanning of AI artifacts and dependencies. For example, scanning AI models and ML libraries for s… |
| match | high r=1.00 may | Integrating AI system testing into established software development lifecycle (SDLC) gates. For example, including threat modelling and ris… | Integrating AI system testing into established software development lifecycle (SDLC) gates. For example, including threat modelling and ris… |
| match | high r=1.00 should | Obtaining approval sign-offs from designated accountable. For example, documented rationale for approval decisions and maintained records f… | Obtaining approval sign-offs from designated accountable. For example, documented rationale for approval decisions and maintained records f… |
| match | high r=1.00 should | Completing risk assessments of identified issues before system deployment. For example, potential impact analysis, mitigation strategies, a… | Completing risk assessments of identified issues before system deployment. For example, potential impact analysis, mitigation strategies, a… |
| match | high r=1.00 should | Conducting pre-deployment testing with documented results and identified issues. For example, structured hallucination testing, adversarial… | Conducting pre-deployment testing with documented results and identified issues. For example, structured hallucination testing, adversarial… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Evaluating harm mitigation controls using performance metrics. | Evaluating harm mitigation controls using performance metrics. |
| match | high r=1.00 may | Implementing bias detection and mitigation controls. For example, monitoring for discriminatory patterns, implementing fairness checks in o… | Implementing bias detection and mitigation controls. For example, monitoring for discriminatory patterns, implementing fairness checks in o… |
| match | high r=1.00 should | Implementing guardrails for advice generation. For example, restricting high-risk recommendations in sensitive domains, requiring disclaime… | Implementing guardrails for advice generation. For example, restricting high-risk recommendations in sensitive domains, requiring disclaime… |
| match | high r=1.00 should | Implementing content filtering for harmful output types. For example, detecting and blocking distressed responses, angry language, offensiv… | Implementing content filtering for harmful output types. For example, detecting and blocking distressed responses, angry language, offensiv… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Providing user guidance on system capabilities and limitations. For example, communicating what the AI system can and cannot do, intended u… | Providing user guidance on system capabilities and limitations. For example, communicating what the AI system can and cannot do, intended u… |
| match | high r=1.00 should | Tracking out-of-scope violations and updating boundaries. For example, logging boundary violations, adjusting restrictions based on misuse… | Tracking out-of-scope violations and updating boundaries. For example, logging boundary violations, adjusting restrictions based on misuse… |
| match | high r=1.00 should | Detecting and blocking out-of-scope requests. For example, detecting conversations outside intended use cases, blocking prohibited topics,… | Detecting and blocking out-of-scope requests. For example, detecting conversations outside intended use cases, blocking prohibited topics,… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Implementing automated real-time interventions. For example, blocking or modifying outputs based on severity. | Implementing automated real-time interventions. For example, blocking or modifying outputs based on severity. |
| match | high r=1.00 may | Establishing escalation procedures for flagged high-risk content. For example, defining when human review is required and establishing appr… | Establishing escalation procedures for flagged high-risk content. For example, defining when human review is required and establishing appr… |
| match | high r=1.00 should | Implementing response actions for detected risks. For example, blocking high-severity outputs, flagging medium-risk content for review, log… | Implementing response actions for detected risks. For example, blocking high-severity outputs, flagging medium-risk content for review, log… |
| match | high r=1.00 should | Implementing detection and blocking mechanisms aligned with organizational risk taxonomy. For example, deploying filtering based on defined… | Implementing detection and blocking mechanisms aligned with organizational risk taxonomy. For example, deploying filtering based on defined… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Detecting advanced output-based attack patterns. For example, identifying prompt injection attempts, model subversion techniques, payloads… | Detecting advanced output-based attack patterns. For example, identifying prompt injection attempts, model subversion techniques, payloads… |
| match | high r=1.00 should | Implementing security labeling and content handling based on trust level. For example, marking untrusted or third-party content, distinguis… | Implementing security labeling and content handling based on trust level. For example, marking untrusted or third-party content, distinguis… |
| match | high r=1.00 should | Establishing output sanitization and validation procedures before presenting content to users. For example, encoding or stripping potential… | Establishing output sanitization and validation procedures before presenting content to users. For example, encoding or stripping potential… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Implementing automated detection mechanisms for high-risk outputs. For example, using content filtering, risk scoring, or classification mo… | Implementing automated detection mechanisms for high-risk outputs. For example, using content filtering, risk scoring, or classification mo… |
| match | high r=1.00 should | Defining high-risk output criteria drawing on risk taxonomy. | Defining high-risk output criteria drawing on risk taxonomy. |
| match | mid r=0.79 may | Establishing human review workflows for flagged high-risk outputs. For example, assigning reviewers, defining escalation procedures for com… | Establishing human review workflows for flagged high-risk outputs. For example, assigning reviewers, defining escalation procedures for com… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Integrating AI output monitoring with existing security tools. For example, forwarding alerts and flagged outputs to SIEM platforms, applyi… | Integrating AI output monitoring with existing security tools. For example, forwarding alerts and flagged outputs to SIEM platforms, applyi… |
| match | high r=1.00 may | Maintaining documentation. For example, recording identified scenarios with clear examples, updating risk taxonomy based on monitoring find… | Maintaining documentation. For example, recording identified scenarios with clear examples, updating risk taxonomy based on monitoring find… |
| match | high r=1.00 should | Establishing ongoing monitoring of AI outputs across risk categories. For example, conducting regular evaluations prioritized by risk sever… | Establishing ongoing monitoring of AI outputs across risk categories. For example, conducting regular evaluations prioritized by risk sever… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Ensuring accessibility of feedback and intervention mechanisms. For example, adhering to WCAG 2.1 standards for color contrast, screen read… | Ensuring accessibility of feedback and intervention mechanisms. For example, adhering to WCAG 2.1 standards for color contrast, screen read… |
| match | high r=1.00 should | Enabling user intervention capabilities. For example, providing mechanisms for users to pause, stop, or redirect system behavior, implement… | Enabling user intervention capabilities. For example, providing mechanisms for users to pause, stop, or redirect system behavior, implement… |
| removed | may | Reviewing user feedback and intervention logs regularly. For example, evaluating patterns in interventions, adapting communication methods… | |
| removed | may | Analyzing collected feedback using structured methodologies. For example, categorizing by risk domain, prioritizing based on frequency and… | |
| added | may | Reviewing user feedback and intervention logs at regular intervals, analyzing findings using structured methodologies (e.g., categorizing b… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Maintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti… | Maintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti… |
| match | high r=1.00 should | Conducting regular testing. Including performing assessments of harmful outputs at least every quarter, defining testing scope and methodol… | Conducting regular testing. Including performing assessments of harmful outputs at least every quarter, defining testing scope and methodol… |
| match | high r=1.00 should | Appointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m… | Appointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Maintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti… | Maintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti… |
| match | high r=1.00 should | Conducting regular testing. Including defining testing scope and methodologies based on risk taxonomy and performing assessments of out-of-… | Conducting regular testing. Including defining testing scope and methodologies based on risk taxonomy and performing assessments of out-of-… |
| match | high r=1.00 should | Appointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m… | Appointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Maintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti… | Maintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti… |
| match | high r=1.00 should | Conducting regular testing. Including defining testing scope and methodologies based on risk taxonomy and performing assessments of high-ri… | Conducting regular testing. Including defining testing scope and methodologies based on risk taxonomy and performing assessments of high-ri… |
| match | high r=1.00 should | Appointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m… | Appointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Maintaining uncertainty communication. For example, displaying confidence levels, providing appropriate disclaimers for generated informati… | Maintaining uncertainty communication. For example, displaying confidence levels, providing appropriate disclaimers for generated informati… |
| match | high r=1.00 should | Establishing information source validation. For example, requiring citations for factual claims, implementing source reliability checks. | Establishing information source validation. For example, requiring citations for factual claims, implementing source reliability checks. |
| match | high r=1.00 should | Implementing factual accuracy controls. For example, deploying available fact-checking mechanisms, flagging uncertain or low-confidence res… | Implementing factual accuracy controls. For example, deploying available fact-checking mechanisms, flagging uncertain or low-confidence res… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Maintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti… | Maintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti… |
| match | high r=1.00 should | Conducting regular testing. Including defining testing scope and methodologies based on risk taxonomy and performing assessments at least e… | Conducting regular testing. Including defining testing scope and methodologies based on risk taxonomy and performing assessments at least e… |
| match | high r=1.00 should | Appointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m… | Appointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Reviewing patterns of AI tool usage. For example, identifying anomalies, updating tool permissions, and retiring unused or high-risk functi… | Reviewing patterns of AI tool usage. For example, identifying anomalies, updating tool permissions, and retiring unused or high-risk functi… |
| match | high r=1.00 should | Establishing execution monitoring and logging. For example, tracking all tool calls, monitoring for unauthorized access attempts or scope v… | Establishing execution monitoring and logging. For example, tracking all tool calls, monitoring for unauthorized access attempts or scope v… |
| match | high r=1.00 should | Enforcing rate limits and transaction caps for autonomous tool use. | Enforcing rate limits and transaction caps for autonomous tool use. |
| match | high r=0.95 may | Requiring human approval for sensitive tool operations. For example, requiring human confirmation before executing high-risk actions, imple… | Requiring human approval for sensitive tool operations. For example, requiring human confirmation before executing high-risk actions, multi… |
| match | high r=0.90 should | Implementing function call validation and authorization. For example, restricting tool access to approved functions, validating parameters… | Implementing tool call validation and authorization. For example, restricting tool calls to approved functions and MCP servers, validating… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Maintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti… | Maintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti… |
| match | high r=1.00 should | Conducting regular testing. Including defining testing scope and methodologies based on risk taxonomy and performing assessments of tool ca… | Conducting regular testing. Including defining testing scope and methodologies based on risk taxonomy and performing assessments of tool ca… |
| match | high r=1.00 should | Appointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m… | Appointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Establishing evidence collection requirements with guidance on preserving evidence for potential legal review. For example, system logs, us… | Establishing evidence collection requirements with guidance on preserving evidence for potential legal review. For example, system logs, us… |
| match | high r=1.00 should | Implementing security remediation measures. For example, system freeze capabilities, vulnerability fixes, access control updates, and coord… | Implementing security remediation measures. For example, system freeze capabilities, vulnerability fixes, access control updates, and coord… |
| match | high r=1.00 should | Defining breach notification procedures. For example, customer communications, regulatory reporting requirements, and vendor notifications… | Defining breach notification procedures. For example, customer communications, regulatory reporting requirements, and vendor notifications… |
| match | high r=1.00 should | Assigning a breach response lead from existing staff. For example, IT manager, security officer, or designated executive with authority to… | Assigning a breach response lead from existing staff. For example, IT manager, security officer, or designated executive with authority to… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Coordinating external support engagement. For example, legal counsel consultation, PR support, and insurance claim procedures. | Coordinating external support engagement. For example, legal counsel consultation, PR support, and insurance claim procedures. |
| match | high r=1.00 may | Defining harmful output categories with reference to risk taxonomy. For example, discriminatory content, offensive material, inappropriate… | Defining harmful output categories with reference to risk taxonomy. For example, discriminatory content, offensive material, inappropriate… |
| match | high r=1.00 should | Establishing immediate mitigation steps with designated staff responsibilities. For example, system freeze capabilities, output suppression… | Establishing immediate mitigation steps with designated staff responsibilities. For example, system freeze capabilities, output suppression… |
| match | high r=1.00 should | Implementing customer communication protocols. For example, disclosure procedures, explanation of corrective actions, and follow-up commitm… | Implementing customer communication protocols. For example, disclosure procedures, explanation of corrective actions, and follow-up commitm… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Coordinating potential external support. For example, legal consultation for significant claims, financial review when needed, and insuranc… | Coordinating potential external support. For example, legal consultation for significant claims, financial review when needed, and insuranc… |
| match | high r=1.00 may | Defining hallucination incident types. | Defining hallucination incident types. |
| match | high r=1.00 should | Implementing remediation measures. For example, system freeze capabilities, model adjustments, output validation improvements, customer not… | Implementing remediation measures. For example, system freeze capabilities, model adjustments, output validation improvements, customer not… |
| match | high r=1.00 should | Establishing compensation assessment procedures. For example, loss evaluation methods, settlement approaches, and payment authorization lev… | Establishing compensation assessment procedures. For example, loss evaluation methods, settlement approaches, and payment authorization lev… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Implementing code signing and verification processes for AI models, libraries, and deployment artefacts to ensure only digitally signed com… | Implementing code signing and verification processes for AI models, libraries, and deployment artefacts to ensure only digitally signed com… |
| match | high r=1.00 should | Assigning an accountable lead as approver for each of these changes. Can follow a RACI structure to formalize roles of those consulted and… | Assigning an accountable lead as approver for each of these changes. Can follow a RACI structure to formalize roles of those consulted and… |
| match | high r=1.00 should | Defining AI system changes requiring approval including model selection, material changes to the meta prompt, adding / removing guardrails,… | Defining AI system changes requiring approval including model selection, material changes to the meta prompt, adding / removing guardrails,… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Reviewing deployment decisions when requirements change. For example, reassessing choices when data sensitivity, regulations, or threat lan… | Reviewing deployment decisions when requirements change. For example, reassessing choices when data sensitivity, regulations, or threat lan… |
| match | high r=1.00 should | Documenting decision criteria and rationale. For example, establishing clear selection factors, maintaining records of deployment choices w… | Documenting decision criteria and rationale. For example, establishing clear selection factors, maintaining records of deployment choices w… |
| match | high r=1.00 should | Conducting deployment risk assessments. For example, evaluating data sensitivity, regulatory compliance requirements, IP protection needs,… | Conducting deployment risk assessments. For example, evaluating data sensitivity, regulatory compliance requirements, IP protection needs,… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Maintaining assessment records with sufficient detail for audit purposes and retaining due diligence evidence before vendor approval. | Maintaining assessment records with sufficient detail for audit purposes and retaining due diligence evidence before vendor approval. |
| match | high r=1.00 should | Conducting documented assessments. For example, scoring results, verification activities such as certifications reviewed and references con… | Conducting documented assessments. For example, scoring results, verification activities such as certifications reviewed and references con… |
| match | high r=1.00 should | Defining assessment criteria for foundational or upstream AI models. For example, data handling and ownership practices, PII controls, secu… | Defining assessment criteria for foundational or upstream AI models. For example, data handling and ownership practices, PII controls, secu… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Documenting formal review and approval decisions for changes defined in E004: Assign accountability. | Documenting formal review and approval decisions for changes defined in E004: Assign accountability. |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Collecting and implementing external feedback on AI systems. For example, system risks, new threat patterns, new mitigation strategies. | Collecting and implementing external feedback on AI systems. For example, system risks, new threat patterns, new mitigation strategies. |
| match | high r=1.00 should | Maintaining a centralized repository of decision records and internal review of these record. For example, supporting evidence reviewed, re… | Maintaining a centralized repository of decision records and internal review of these record. For example, supporting evidence reviewed, re… |
| match | high r=1.00 should | Reviewing decision processes every quarter including AI system changes, foundational model selection, security assessment. | Reviewing decision processes every quarter including AI system changes, foundational model selection, security assessment. |
| match | high r=0.97 should | Documenting and tracking remediation of any risks identified.int | Documenting and tracking remediation of any risks identified. |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Capturing access metadata. For example, user identification, authentication timestamps, accessed resources, session duration, origin IP add… | Capturing access metadata. For example, user identification, authentication timestamps, accessed resources, session duration, origin IP add… |
| match | high r=1.00 should | Configuring logging for third-party interactions. For example, capturing API connections, user access sessions, data exchanges, and service… | Configuring logging for third-party interactions. For example, capturing API connections, user access sessions, data exchanges, and service… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Conducting regular effectiveness reviews. For example, quarterly analysis of violation trends, tool performance assessment, policy updates… | Conducting regular effectiveness reviews. For example, quarterly analysis of violation trends, tool performance assessment, policy updates… |
| match | high r=1.00 may | Maintaining logging and tracking systems. For example, incident creation, violation tracking with case assignment and resolution documentat… | Maintaining logging and tracking systems. For example, incident creation, violation tracking with case assignment and resolution documentat… |
| match | high r=1.00 may | Real-time monitoring, blocking, or alerting capabilities. | Real-time monitoring, blocking, or alerting capabilities. |
| match | high r=1.00 should | Implementing user feedback when policy is breached. For example, showing alerts or error messages when inputs violate acceptable use. | Implementing user feedback when policy is breached. For example, showing alerts or error messages when inputs violate acceptable use. |
| match | high r=1.00 should | Implementing detection and monitoring tools. For example, prompt analysis, output filtering, usage pattern anomalies, and suspicious access… | Implementing detection and monitoring tools. For example, prompt analysis, output filtering, usage pattern anomalies, and suspicious access… |
| match | high r=1.00 should | Defining prohibited AI usage for end-users. For example, jailbreak attempts, malicious prompt injection, unauthorized data extraction, gene… | Defining prohibited AI usage for end-users. For example, jailbreak attempts, malicious prompt injection, unauthorized data extraction, gene… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Implementing transfer compliance procedures. For example, assessing data transfer requirements for AI training data and inference processin… | Implementing transfer compliance procedures. For example, assessing data transfer requirements for AI training data and inference processin… |
| match | high r=1.00 should | Reviewing and updating documentation regularly. | Reviewing and updating documentation regularly. |
| match | high r=1.00 should | Maintaining AI infrastructure location documentation. For example, geographic locations of foundation model processing locations and infere… | Maintaining AI infrastructure location documentation. For example, geographic locations of foundation model processing locations and infere… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Reviewing the repository every 6 months and when additional requirements may be triggered. For example, regulations change or business oper… | Reviewing the repository every 6 months and when additional requirements may be triggered. For example, regulations change or business oper… |
| match | high r=1.00 should | Documenting compliance procedures and strategies appropriate for company size and operations. | Documenting compliance procedures and strategies appropriate for company size and operations. |
| match | high r=1.00 should | Identifying relevant regulations. For example, data protection laws. For example, GDPR, CCPA, sector-specific requirements, emerging AI sta… | Identifying relevant regulations. For example, data protection laws. For example, GDPR, CCPA, sector-specific requirements, emerging AI sta… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Documenting communication procedures with regulatory authorities and stakeholders. For example, establishing protocols for regulatory repor… | Documenting communication procedures with regulatory authorities and stakeholders. For example, establishing protocols for regulatory repor… |
| match | high r=1.00 may | Establishing data management and record-keeping systems. For example, documenting data governance procedures, maintaining technical documen… | Establishing data management and record-keeping systems. For example, documenting data governance procedures, maintaining technical documen… |
| match | high r=1.00 should | Implementing defect tracking, continuous improvement, and post-market monitoring. For example, maintaining issue tracking systems, conducti… | Implementing defect tracking, continuous improvement, and post-market monitoring. For example, maintaining issue tracking systems, conducti… |
| match | high r=1.00 should | Establishing change management, approval processes, and documentation standards. For example, defining review and approval requirements for… | Establishing change management, approval processes, and documentation standards. For example, defining review and approval requirements for… |
| match | high r=1.00 should | Defining quality objectives, metrics, and risk management approach for AI systems. For example, establishing performance targets, safety th… | Defining quality objectives, metrics, and risk management approach for AI systems. For example, establishing performance targets, safety th… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Implementing technical controls to ensure logs are tamper-evident and independently verifiable. For example, ensuring that captured records… | Implementing technical controls to ensure logs are tamper-evident and independently verifiable. For example, ensuring that captured records… |
| match | high r=1.00 should | Implementing log storage with appropriate retention periods, access controls, and data sanitation to support auditing and incident response. | Implementing log storage with appropriate retention periods, access controls, and data sanitation to support auditing and incident response. |
| match | high r=1.00 should | Capturing system activity details to support incident investigation and behavior explanation. For example, logging inputs, processing steps… | Capturing system activity details to support incident investigation and behavior explanation. For example, logging inputs, processing steps… |
| added | may | Capturing full execution chains of agentic workflows to support investigation of agent-specific incidents. For example, logging agent prove… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Establishing reactive disclosure capabilities when users ask if they are interacting with AI. | Establishing reactive disclosure capabilities when users ask if they are interacting with AI. |
| match | high r=1.00 should | Labelling AI-generated media and documents in a machine-readable and detectable format. For example, marking AI-generated images, videos, a… | Labelling AI-generated media and documents in a machine-readable and detectable format. For example, marking AI-generated images, videos, a… |
| match | high r=1.00 should | Implementing AI disclosure for voice-based interactions. For example, providing audio notifications at the beginning of voice calls or inte… | Implementing AI disclosure for voice-based interactions. For example, providing audio notifications at the beginning of voice calls or inte… |
| match | high r=1.00 should | Implementing AI disclosure for text-based interactions. For example, displaying clear notices when users interact with AI chatbots, virtual… | Implementing AI disclosure for text-based interactions. For example, displaying clear notices when users interact with AI chatbots, virtual… |
| match | high r=0.94 should | Disclosing when autonomous AI agents or automated workflows are performing actions. For example, notifying users when AI systems are making… | Disclosing when autonomous AI agents or systems are performing actions. For example, notifying users when AI systems are making decisions,… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Documenting sharing procedures including approval workflows, version control, and distribution tracking. For example, establishing approval… | Documenting sharing procedures including approval workflows, version control, and distribution tracking. For example, establishing approval… |
| match | high r=1.00 may | Defining policies for sharing transparency documentation with external stakeholders. For example, establishing when reports are shared, spe… | Defining policies for sharing transparency documentation with external stakeholders. For example, establishing when reports are shared, spe… |
| match | high r=1.00 should | Creating transparency documentation for major AI systems. For example, documenting system characteristics, data provenance, and model behav… | Creating transparency documentation for major AI systems. For example, documenting system characteristics, data provenance, and model behav… |
| match | high r=1.00 should | Establishing a transparency policy defining documentation requirements for major AI systems. For example, specifying required documentation… | Establishing a transparency policy defining documentation requirements for major AI systems. For example, specifying required documentation… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Implementing malicious use detection and blocking. For example, deploying available content filtering to detect requests for malicious code… | Implementing malicious use detection and blocking. For example, deploying available content filtering to detect requests for malicious code… |
| match | high r=1.00 should | Results of testing from foundation model developer on offensive cyber capabilities and mitigations. | Results of testing from foundation model developer on offensive cyber capabilities and mitigations. |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Establishing catastrophic misuse monitoring. For example, monitoring AI system interactions for patterns indicating weapons development or… | Establishing catastrophic misuse monitoring. For example, monitoring AI system interactions for patterns indicating weapons development or… |
| match | high r=1.00 should | Results of testing from foundation model developer on CBRN capabilities and mitigations. | Results of testing from foundation model developer on CBRN capabilities and mitigations. |