jan-2026 → apr-2026

How nature of change is determined. For each requirement present in both releases, we compare the normalised wording of the previous and current versions and measure how much of it changed. We then classify the result into four categories:These categories drive the Nature column in the tables below. On this transition, the publisher's own change summary covers requirements and their underlying control activities jointly, while the Nature column below grades the requirement text only — so the labels are a working approximation rather than a calibrated reading.
release_type
incremental
requirements
identical 42 · editorial 4 · clarification 3 · substantive 2 · added 0 · removed 0
control bullets
prev 173 → cur 178 · matched 169 · added 9 · removed 4 · merges 0 · match rate 97.7%

Overview: website change summary

Introduced new controls for MCP and A2A protocol security, standardizing authentication, transport, runtime containment, and logging across agentic interfaces Expanded third-party risk controls including making third-party access monitoring mandatory Expanded controls for agent identity, permissions, and access management

Per-principle change distribution

per-principle distribution

Requirement-level changes and control composition

A. Data & Privacy

IDTitleNatureDist.Shoulds/MaysSite narrative
A002Establish output data policyeditorial0.0132/0 → 2/1 (Δ +0s/+1m)revision Included both opt-in and out practices
revision Included both opt-in and out practices, ensuring balanced coverage of consent models
A003Limit AI agent data accessclarification0.2291/2 → 1/3 (Δ +0s/+1m)specification Specified that the requirement covers data access more generally, and included more controls on agent IAM within it
clarification Clarified the control to cover agent access and identity management, not just data collection
A006Prevent PII leakageclarification0.0592/1 → 2/1 (Δ +0s/+0m)

B. Security

IDTitleNatureDist.Shoulds/MaysSite narrative
B002Detect adversarial inputeditorial0.0453/2 → 3/2 (Δ +0s/+0m)clarification Clarified that monitoring is to enable responding to adversarial inputs
B008Protect AI system deployment environmenteditorial0.0372/2 → 3/3 (Δ +1s/+1m)revision Expanded scope of requirement from the AI model only to system
clarification Expanded scope of control from the AI model only to system

C. Safety

IDTitleNatureDist.Shoulds/MaysSite narrative
C001Define AI risk taxonomysubstantive0.6484/0 → 4/0 (Δ +0s/+0m)specification Generalized the risk taxonomy requirement and changed testing frequency to every 12 months
specification Aligned testing frequency to a 12-month cycle consistent with the risk management framework update schedule
C009Enable real-time feedback and interventionclarification0.0962/2 → 2/1 (Δ +0s/-1m)revision Changed on a controls level - synthesized controls and added in control to action user feedback
clarification Included practical validation and actioning of relevant user feedback, and streamlined three controls into one

E. Accountability

IDTitleNatureDist.Shoulds/MaysSite narrative
E005Document data storage securitysubstantive0.3053/0 → 3/0 (Δ +0s/+0m)clarification Clarified that the requirement is around ensuring companies establish clear security and compliance requirements for hosting platforms, rather than the act of…
E015Log AI system activityeditorial0.0252/1 → 2/2 (Δ +0s/+1m)revision Expanded scope of requirement from the AI model only to system
addition Extended logging to cover the intermediate steps between input and output (i.e., tool calls, sub-agent actions, and provenance metadata) getting traceability a…

Per-bullet detail (indicative on consolidation releases)

A001 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayDocumenting processes for handling end-user data subject rights. For example, handling requests for opt-in/opt-out rights, access, portabil…Documenting processes for handling end-user data subject rights. For example, handling requests for opt-in/opt-out rights, access, portabil…
matchhigh r=1.00 shouldImplementing technical controls to enforce data retention and deletion policies. For example, automating data deletion based on retention s…Implementing technical controls to enforce data retention and deletion policies. For example, automating data deletion based on retention s…
matchhigh r=1.00 shouldDefining and communicating input data usage policies. Including specifying how customer data is used for inference and model training, esta…Defining and communicating input data usage policies. Including specifying how customer data is used for inference and model training, esta…
A002 — matched 2 · added 1 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldEstablishing output ownership and usage rights policies. For example, specifying customer ownership of AI-generated outputs versus AI input…Establishing output ownership and usage rights policies. For example, specifying customer ownership of AI-generated outputs versus AI input…
matchhigh r=0.91 shouldDisclosing opt-out and deletion procedures for AI outputs. For example, documenting how customers can opt out of output storage or reuse, e…Disclosing opt-in/opt-out and deletion policies for AI outputs. For example, documenting how customers can opt out of output storage or reu…
addedmayImplementing technical controls to enforce AI output opt-in/opt-out and deletion policies. For example, automating customer preference enfo…
A003 — matched 2 · added 2 · removed 1 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayDeploying monitoring mechanisms. Including ensuring AI systems only perform necessary inference and logging deviations from defined operati…Deploying monitoring mechanisms. Including ensuring AI systems only perform necessary inference and logging deviations from defined operati…
matchhigh r=0.94 shouldConfiguring data collection limits to reduce data and privacy exposure. For example, limiting data collection to task-relevant information…Configuring data access limits to reduce data and privacy exposure. For example, limiting data access to task-relevant information based on…
removedmayIntegrating with existing authorization systems to align agent access permissions with organizational policies.
addedmayEnabling agent identity management. For example, assigning each agent a unique, cryptographically verifiable identity; supporting standard…
addedmayEnabling agent access and governance through permission-ready architecture. For example, exposing per-agent permission scopes mappable to e…
A004 — matched 4 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayEstablishing output monitoring for high-risk IP scenarios. For example, logging AI responses that accessed confidential data sources, imple…Establishing output monitoring for high-risk IP scenarios. For example, logging AI responses that accessed confidential data sources, imple…
matchhigh r=1.00 mayImplementing technical controls to detect proprietary information in outputs.Implementing technical controls to detect proprietary information in outputs.
matchhigh r=1.00 mayLeveraging foundation model provider protections. For example, using providers with zero data retention policies, requiring contractual com…Leveraging foundation model provider protections. For example, using providers with zero data retention policies, requiring contractual com…
matchhigh r=1.00 shouldProviding user guidance on protecting confidential information. For example, instructing employees not to input trade secrets, proprietary…Providing user guidance on protecting confidential information. For example, instructing employees not to input trade secrets, proprietary…
A005 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayImplementing specific privacy-enhancing technologies (PETs) to reduce competitive exposure.Implementing specific privacy-enhancing technologies (PETs) to reduce competitive exposure.
matchhigh r=1.00 shouldImplementing customer data isolation controls. For example, enforcing strict logical and physical separation of customer data, applying ten…Implementing customer data isolation controls. For example, enforcing strict logical and physical separation of customer data, applying ten…
matchhigh r=1.00 shouldEstablishing explicit consent and disclosure for combined data usage. For example, informing customers when their data will be combined wit…Establishing explicit consent and disclosure for combined data usage. For example, informing customers when their data will be combined wit…
A006 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayIntegrating with existing data loss prevention (DLP) systems to monitor and block outputs containing personal data in violation of policy.Integrating with existing data loss prevention (DLP) systems to monitor and block outputs containing personal data in violation of policy.
matchhigh r=1.00 shouldRequiring authentication and authorization for PII access. For example, role-based access controls for PII-containing systems, multi-factor…Requiring authentication and authorization for PII access. For example, role-based access controls for PII-containing systems, multi-factor…
matchhigh r=1.00 shouldImplementing safeguards to prevent personal data leakage through AI system outputs and logs. For example, filtering prompts and outputs for…Implementing safeguards to prevent personal data leakage through AI system outputs and logs. For example, filtering prompts and outputs for…
A007 — matched 4 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayImplementing restrictions in AI acceptable use policy.Implementing restrictions in AI acceptable use policy.
matchhigh r=1.00 mayImplementing user guidance and guardrails to reduce IP risk. For example, usage policies that explain prohibited content types, user warnin…Implementing user guidance and guardrails to reduce IP risk. For example, usage policies that explain prohibited content types, user warnin…
matchhigh r=1.00 mayEstablishing supplementary content filtering mechanisms where provider protections have gaps or limitations. For example, detecting copyrig…Establishing supplementary content filtering mechanisms where provider protections have gaps or limitations. For example, detecting copyrig…
matchhigh r=1.00 shouldDocumenting foundation model provider IP protections which may serve as primary infringement safeguards. For example, indemnification claus…Documenting foundation model provider IP protections which may serve as primary infringement safeguards. For example, indemnification claus…
B001 — matched 5 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayAligning adversarial testing with broader security testing programs. For example, integrating AI-specific test cases into broader penetrati…Aligning adversarial testing with broader security testing programs. For example, integrating AI-specific test cases into broader penetrati…
matchhigh r=1.00 shouldEstablishing improvement processes based on findings. For example, assigning owners and remediation timelines based on test severity, track…Establishing improvement processes based on findings. For example, assigning owners and remediation timelines based on test severity, track…
matchhigh r=1.00 shouldMaintaining secure testing documentation. For example, recording test cases, methods, outcomes, and system behaviors with restricted access…Maintaining secure testing documentation. For example, recording test cases, methods, outcomes, and system behaviors with restricted access…
matchhigh r=1.00 shouldConducting comprehensive adversarial testing at least quarterly. For example, performing structured red-teaming, prompt injection assessmen…Conducting comprehensive adversarial testing at least quarterly. For example, performing structured red-teaming, prompt injection assessmen…
matchhigh r=1.00 shouldEstablishing a taxonomy for adversarial risks. For example, drawing on NIST's AI 100-2e2023 attack classifications and aligning these to sy…Establishing a taxonomy for adversarial risks. For example, drawing on NIST's AI 100-2e2023 attack classifications and aligning these to sy…
B002 — matched 5 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayIntegrating adversarial input detection into existing security operations tooling. For example, forwarding flagged inputs to SIEM platforms…Integrating adversarial input detection into existing security operations tooling. For example, forwarding flagged inputs to SIEM platforms…
matchhigh r=1.00 mayImplementing adversarial input detection prior to AI model processing where feasible. For example, using pre-processing filters to flag lik…Implementing adversarial input detection prior to AI model processing where feasible. For example, using pre-processing filters to flag lik…
matchhigh r=1.00 shouldMaintaining detection effectiveness through quarterly reviews. For example, updating detection rules based on emerging adversarial techniqu…Maintaining detection effectiveness through quarterly reviews. For example, updating detection rules based on emerging adversarial techniqu…
matchhigh r=1.00 shouldImplementing incident logging and response procedures. For example, logging suspected adversarial attacks with relevant context, escalating…Implementing incident logging and response procedures. For example, logging suspected adversarial attacks with relevant context, escalating…
matchhigh r=1.00 shouldEstablishing detection and alerting. For example, implementing monitoring for prompt injection patterns, jailbreak techniques, adversarial…Establishing detection and alerting. For example, implementing monitoring for prompt injection patterns, jailbreak techniques, adversarial…
B003 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayEstablishing approval processes. For example, requiring designated review for public content referencing AI capabilities in e.g. publicatio…Establishing approval processes. For example, requiring designated review for public content referencing AI capabilities in e.g. publicatio…
matchhigh r=1.00 shouldControlling organizational information to balance transparency with security. For example, limiting disclosure of AI team details, developm…Controlling organizational information to balance transparency with security. For example, limiting disclosure of AI team details, developm…
matchhigh r=1.00 shouldDocumenting limitations on technical information release. For example, limiting public disclosure of model architectures, algorithms, train…Documenting limitations on technical information release. For example, limiting public disclosure of model architectures, algorithms, train…
B004 — matched 4 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldMaintaining endpoint security through remediation. For example, tracking identified vulnerabilities, implementing protective measures based…Maintaining endpoint security through remediation. For example, tracking identified vulnerabilities, implementing protective measures based…
matchhigh r=1.00 shouldConducting simulated external attack testing of AI endpoints. For example, performing automated attack simulations, testing endpoint protec…Conducting simulated external attack testing of AI endpoints. For example, performing automated attack simulations, testing endpoint protec…
matchhigh r=1.00 shouldImplementing rate limiting and query restrictions. For example, establishing per-user quotas to prevent model extraction, blocking excessiv…Implementing rate limiting and query restrictions. For example, establishing per-user quotas to prevent model extraction, blocking excessiv…
matchhigh r=1.00 shouldImplementing systems distinguishing between high-volume legitimate usage and adversarial behavior. For example, using behavioral analytics…Implementing systems distinguishing between high-volume legitimate usage and adversarial behavior. For example, using behavioral analytics…
B005 — matched 5 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayPeriodically evaluating filter performance and adjusting thresholds accordingly. For example, accuracy, latency, false positives/negatives.Periodically evaluating filter performance and adjusting thresholds accordingly. For example, accuracy, latency, false positives/negatives.
matchhigh r=1.00 mayLogging flagged prompts for analysis and refinement of filters, while ensuring compliance with privacy obligations.Logging flagged prompts for analysis and refinement of filters, while ensuring compliance with privacy obligations.
matchhigh r=1.00 mayProviding feedback to users when inputs are blocked.Providing feedback to users when inputs are blocked.
matchhigh r=1.00 mayDocumenting the moderation logic and rationale. For example, explaining chosen moderation tools, threshold justifications, and decision cri…Documenting the moderation logic and rationale. For example, explaining chosen moderation tools, threshold justifications, and decision cri…
matchhigh r=1.00 shouldIntegrating automated moderation tools to filter inputs before they reach the foundation model. For example, integrating third-party modera…Integrating automated moderation tools to filter inputs before they reach the foundation model. For example, integrating third-party modera…
B006 — matched 2 · added 1 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldDeploying monitoring and alerting for agent actions that exceed security boundaries. For example, logging all agent service interactions, a…Deploying monitoring and alerting for agent actions that exceed security boundaries. For example, logging all agent service interactions, a…
matchhigh r=0.97 shouldImplementing technical restrictions that limit agent capabilities to authorized scope. For example, restricting agent access to approved ba…Implementing technical restrictions that limit agent capabilities to authorized scope. For example, restricting agent access to approved ba…
addedmayImplementing additional safeguards to contain runtime risk. For example, applying sandboxed execution environments with restricted filesyst…
B007 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldConducting access reviews and updates at least quarterly. For example, validating access assignments, updating based on policy or role chan…Conducting access reviews and updates at least quarterly. For example, validating access assignments, updating based on policy or role chan…
matchhigh r=1.00 shouldRestricting administrative and configuration privileges to authorized personnel. For example, limiting ability to alter system behavior, to…Restricting administrative and configuration privileges to authorized personnel. For example, limiting ability to alter system behavior, to…
matchhigh r=1.00 shouldImplementing system-level access controls tailored to AI systems. For example, using role-based or attribute-based access to restrict acces…Implementing system-level access controls tailored to AI systems. For example, using role-based or attribute-based access to restrict acces…
B008 — matched 3 · added 3 · removed 1 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayVerifying model integrity before and during deployment. For example, using cryptographic checksums or signed artifacts to detect tampering,…Verifying model integrity before and during deployment. For example, using cryptographic checksums or signed artifacts to detect tampering,…
matchhigh r=1.00 maySecuring model hosting environments. For example, using up-to-date and minimal container images, scanning for known vulnerabilities in depe…Securing model hosting environments. For example, using up-to-date and minimal container images, scanning for known vulnerabilities in depe…
matchhigh r=0.95 shouldImplementing model access protection. For example, restricting access to production AI models based on job function and operational need, i…Implementing AI system access protection. For example, restricting access to production AI systems based on job function and operational ne…
removedshouldEstablishing deployment security controls. For example, applying scoped API tokens or signed requests, using TLS for all endpoint traffic,…
addedshouldEnforcing caller authentication across API endpoints and agentic interfaces. For example, applying scoped API tokens or signed requests for…
addedshouldSecuring data in transit across model API endpoints and agentic interfaces. For example, enforcing TLS for all model API endpoint traffic,…
addedmayEnforcing data integrity across agentic interfaces. For example, implementing cryptographic message signing for agent-to-agent communicatio…
B009 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayLimiting the fidelity of model outputs in certain use cases. For example, applying output rounding, threshold bands, or obfuscation techniq…Limiting the fidelity of model outputs in certain use cases. For example, applying output rounding, threshold bands, or obfuscation techniq…
matchhigh r=1.00 mayProviding user-facing notices or documentation about output limitations.Providing user-facing notices or documentation about output limitations.
matchhigh r=1.00 shouldReducing or limiting the number of results shown in outputs to relevant only to balance security and utility. For example, character limits…Reducing or limiting the number of results shown in outputs to relevant only to balance security and utility. For example, character limits…
C001 — matched 4 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldMaintaining taxonomy currency with documented change management. For example, updating based on emerging threats or incidents.Maintaining taxonomy currency with documented change management. For example, updating based on emerging threats or incidents.
matchhigh r=1.00 shouldEstablishing severity grading appropriate to organizational context and risk tolerance. For example, implementing consistent scoring method…Establishing severity grading appropriate to organizational context and risk tolerance. For example, implementing consistent scoring method…
matchhigh r=1.00 shouldAligning risk taxonomy with external frameworks and standards.Aligning risk taxonomy with external frameworks and standards.
matchhigh r=1.00 shouldDefining risk categories with severity levels and examples based on industry and deployment context. For example, classifying harmful outpu…Defining risk categories with severity levels and examples based on industry and deployment context. For example, classifying harmful outpu…
C002 — matched 5 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayImplementing pre-deployment vulnerability scanning of AI artifacts and dependencies. For example, scanning AI models and ML libraries for s…Implementing pre-deployment vulnerability scanning of AI artifacts and dependencies. For example, scanning AI models and ML libraries for s…
matchhigh r=1.00 mayIntegrating AI system testing into established software development lifecycle (SDLC) gates. For example, including threat modelling and ris…Integrating AI system testing into established software development lifecycle (SDLC) gates. For example, including threat modelling and ris…
matchhigh r=1.00 shouldObtaining approval sign-offs from designated accountable. For example, documented rationale for approval decisions and maintained records f…Obtaining approval sign-offs from designated accountable. For example, documented rationale for approval decisions and maintained records f…
matchhigh r=1.00 shouldCompleting risk assessments of identified issues before system deployment. For example, potential impact analysis, mitigation strategies, a…Completing risk assessments of identified issues before system deployment. For example, potential impact analysis, mitigation strategies, a…
matchhigh r=1.00 shouldConducting pre-deployment testing with documented results and identified issues. For example, structured hallucination testing, adversarial…Conducting pre-deployment testing with documented results and identified issues. For example, structured hallucination testing, adversarial…
C003 — matched 4 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayEvaluating harm mitigation controls using performance metrics.Evaluating harm mitigation controls using performance metrics.
matchhigh r=1.00 mayImplementing bias detection and mitigation controls. For example, monitoring for discriminatory patterns, implementing fairness checks in o…Implementing bias detection and mitigation controls. For example, monitoring for discriminatory patterns, implementing fairness checks in o…
matchhigh r=1.00 shouldImplementing guardrails for advice generation. For example, restricting high-risk recommendations in sensitive domains, requiring disclaime…Implementing guardrails for advice generation. For example, restricting high-risk recommendations in sensitive domains, requiring disclaime…
matchhigh r=1.00 shouldImplementing content filtering for harmful output types. For example, detecting and blocking distressed responses, angry language, offensiv…Implementing content filtering for harmful output types. For example, detecting and blocking distressed responses, angry language, offensiv…
C004 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayProviding user guidance on system capabilities and limitations. For example, communicating what the AI system can and cannot do, intended u…Providing user guidance on system capabilities and limitations. For example, communicating what the AI system can and cannot do, intended u…
matchhigh r=1.00 shouldTracking out-of-scope violations and updating boundaries. For example, logging boundary violations, adjusting restrictions based on misuse…Tracking out-of-scope violations and updating boundaries. For example, logging boundary violations, adjusting restrictions based on misuse…
matchhigh r=1.00 shouldDetecting and blocking out-of-scope requests. For example, detecting conversations outside intended use cases, blocking prohibited topics,…Detecting and blocking out-of-scope requests. For example, detecting conversations outside intended use cases, blocking prohibited topics,…
C005 — matched 4 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayImplementing automated real-time interventions. For example, blocking or modifying outputs based on severity.Implementing automated real-time interventions. For example, blocking or modifying outputs based on severity.
matchhigh r=1.00 mayEstablishing escalation procedures for flagged high-risk content. For example, defining when human review is required and establishing appr…Establishing escalation procedures for flagged high-risk content. For example, defining when human review is required and establishing appr…
matchhigh r=1.00 shouldImplementing response actions for detected risks. For example, blocking high-severity outputs, flagging medium-risk content for review, log…Implementing response actions for detected risks. For example, blocking high-severity outputs, flagging medium-risk content for review, log…
matchhigh r=1.00 shouldImplementing detection and blocking mechanisms aligned with organizational risk taxonomy. For example, deploying filtering based on defined…Implementing detection and blocking mechanisms aligned with organizational risk taxonomy. For example, deploying filtering based on defined…
C006 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayDetecting advanced output-based attack patterns. For example, identifying prompt injection attempts, model subversion techniques, payloads…Detecting advanced output-based attack patterns. For example, identifying prompt injection attempts, model subversion techniques, payloads…
matchhigh r=1.00 shouldImplementing security labeling and content handling based on trust level. For example, marking untrusted or third-party content, distinguis…Implementing security labeling and content handling based on trust level. For example, marking untrusted or third-party content, distinguis…
matchhigh r=1.00 shouldEstablishing output sanitization and validation procedures before presenting content to users. For example, encoding or stripping potential…Establishing output sanitization and validation procedures before presenting content to users. For example, encoding or stripping potential…
C007 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldImplementing automated detection mechanisms for high-risk outputs. For example, using content filtering, risk scoring, or classification mo…Implementing automated detection mechanisms for high-risk outputs. For example, using content filtering, risk scoring, or classification mo…
matchhigh r=1.00 shouldDefining high-risk output criteria drawing on risk taxonomy.Defining high-risk output criteria drawing on risk taxonomy.
matchmid r=0.79 mayEstablishing human review workflows for flagged high-risk outputs. For example, assigning reviewers, defining escalation procedures for com…Establishing human review workflows for flagged high-risk outputs. For example, assigning reviewers, defining escalation procedures for com…
C008 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayIntegrating AI output monitoring with existing security tools. For example, forwarding alerts and flagged outputs to SIEM platforms, applyi…Integrating AI output monitoring with existing security tools. For example, forwarding alerts and flagged outputs to SIEM platforms, applyi…
matchhigh r=1.00 mayMaintaining documentation. For example, recording identified scenarios with clear examples, updating risk taxonomy based on monitoring find…Maintaining documentation. For example, recording identified scenarios with clear examples, updating risk taxonomy based on monitoring find…
matchhigh r=1.00 shouldEstablishing ongoing monitoring of AI outputs across risk categories. For example, conducting regular evaluations prioritized by risk sever…Establishing ongoing monitoring of AI outputs across risk categories. For example, conducting regular evaluations prioritized by risk sever…
C009 — matched 2 · added 1 · removed 2 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldEnsuring accessibility of feedback and intervention mechanisms. For example, adhering to WCAG 2.1 standards for color contrast, screen read…Ensuring accessibility of feedback and intervention mechanisms. For example, adhering to WCAG 2.1 standards for color contrast, screen read…
matchhigh r=1.00 shouldEnabling user intervention capabilities. For example, providing mechanisms for users to pause, stop, or redirect system behavior, implement…Enabling user intervention capabilities. For example, providing mechanisms for users to pause, stop, or redirect system behavior, implement…
removedmayReviewing user feedback and intervention logs regularly. For example, evaluating patterns in interventions, adapting communication methods…
removedmayAnalyzing collected feedback using structured methodologies. For example, categorizing by risk domain, prioritizing based on frequency and…
addedmayReviewing user feedback and intervention logs at regular intervals, analyzing findings using structured methodologies (e.g., categorizing b…
C010 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldMaintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti…Maintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti…
matchhigh r=1.00 shouldConducting regular testing. Including performing assessments of harmful outputs at least every quarter, defining testing scope and methodol…Conducting regular testing. Including performing assessments of harmful outputs at least every quarter, defining testing scope and methodol…
matchhigh r=1.00 shouldAppointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m…Appointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m…
C011 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldMaintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti…Maintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti…
matchhigh r=1.00 shouldConducting regular testing. Including defining testing scope and methodologies based on risk taxonomy and performing assessments of out-of-…Conducting regular testing. Including defining testing scope and methodologies based on risk taxonomy and performing assessments of out-of-…
matchhigh r=1.00 shouldAppointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m…Appointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m…
C012 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldMaintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti…Maintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti…
matchhigh r=1.00 shouldConducting regular testing. Including defining testing scope and methodologies based on risk taxonomy and performing assessments of high-ri…Conducting regular testing. Including defining testing scope and methodologies based on risk taxonomy and performing assessments of high-ri…
matchhigh r=1.00 shouldAppointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m…Appointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m…
D001 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayMaintaining uncertainty communication. For example, displaying confidence levels, providing appropriate disclaimers for generated informati…Maintaining uncertainty communication. For example, displaying confidence levels, providing appropriate disclaimers for generated informati…
matchhigh r=1.00 shouldEstablishing information source validation. For example, requiring citations for factual claims, implementing source reliability checks.Establishing information source validation. For example, requiring citations for factual claims, implementing source reliability checks.
matchhigh r=1.00 shouldImplementing factual accuracy controls. For example, deploying available fact-checking mechanisms, flagging uncertain or low-confidence res…Implementing factual accuracy controls. For example, deploying available fact-checking mechanisms, flagging uncertain or low-confidence res…
D002 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldMaintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti…Maintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti…
matchhigh r=1.00 shouldConducting regular testing. Including defining testing scope and methodologies based on risk taxonomy and performing assessments at least e…Conducting regular testing. Including defining testing scope and methodologies based on risk taxonomy and performing assessments at least e…
matchhigh r=1.00 shouldAppointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m…Appointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m…
D003 — matched 5 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayReviewing patterns of AI tool usage. For example, identifying anomalies, updating tool permissions, and retiring unused or high-risk functi…Reviewing patterns of AI tool usage. For example, identifying anomalies, updating tool permissions, and retiring unused or high-risk functi…
matchhigh r=1.00 shouldEstablishing execution monitoring and logging. For example, tracking all tool calls, monitoring for unauthorized access attempts or scope v…Establishing execution monitoring and logging. For example, tracking all tool calls, monitoring for unauthorized access attempts or scope v…
matchhigh r=1.00 shouldEnforcing rate limits and transaction caps for autonomous tool use.Enforcing rate limits and transaction caps for autonomous tool use.
matchhigh r=0.95 mayRequiring human approval for sensitive tool operations. For example, requiring human confirmation before executing high-risk actions, imple…Requiring human approval for sensitive tool operations. For example, requiring human confirmation before executing high-risk actions, multi…
matchhigh r=0.90 shouldImplementing function call validation and authorization. For example, restricting tool access to approved functions, validating parameters…Implementing tool call validation and authorization. For example, restricting tool calls to approved functions and MCP servers, validating…
D004 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldMaintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti…Maintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti…
matchhigh r=1.00 shouldConducting regular testing. Including defining testing scope and methodologies based on risk taxonomy and performing assessments of tool ca…Conducting regular testing. Including defining testing scope and methodologies based on risk taxonomy and performing assessments of tool ca…
matchhigh r=1.00 shouldAppointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m…Appointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m…
E001 — matched 4 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldEstablishing evidence collection requirements with guidance on preserving evidence for potential legal review. For example, system logs, us…Establishing evidence collection requirements with guidance on preserving evidence for potential legal review. For example, system logs, us…
matchhigh r=1.00 shouldImplementing security remediation measures. For example, system freeze capabilities, vulnerability fixes, access control updates, and coord…Implementing security remediation measures. For example, system freeze capabilities, vulnerability fixes, access control updates, and coord…
matchhigh r=1.00 shouldDefining breach notification procedures. For example, customer communications, regulatory reporting requirements, and vendor notifications…Defining breach notification procedures. For example, customer communications, regulatory reporting requirements, and vendor notifications…
matchhigh r=1.00 shouldAssigning a breach response lead from existing staff. For example, IT manager, security officer, or designated executive with authority to…Assigning a breach response lead from existing staff. For example, IT manager, security officer, or designated executive with authority to…
E002 — matched 4 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayCoordinating external support engagement. For example, legal counsel consultation, PR support, and insurance claim procedures.Coordinating external support engagement. For example, legal counsel consultation, PR support, and insurance claim procedures.
matchhigh r=1.00 mayDefining harmful output categories with reference to risk taxonomy. For example, discriminatory content, offensive material, inappropriate…Defining harmful output categories with reference to risk taxonomy. For example, discriminatory content, offensive material, inappropriate…
matchhigh r=1.00 shouldEstablishing immediate mitigation steps with designated staff responsibilities. For example, system freeze capabilities, output suppression…Establishing immediate mitigation steps with designated staff responsibilities. For example, system freeze capabilities, output suppression…
matchhigh r=1.00 shouldImplementing customer communication protocols. For example, disclosure procedures, explanation of corrective actions, and follow-up commitm…Implementing customer communication protocols. For example, disclosure procedures, explanation of corrective actions, and follow-up commitm…
E003 — matched 4 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayCoordinating potential external support. For example, legal consultation for significant claims, financial review when needed, and insuranc…Coordinating potential external support. For example, legal consultation for significant claims, financial review when needed, and insuranc…
matchhigh r=1.00 mayDefining hallucination incident types.Defining hallucination incident types.
matchhigh r=1.00 shouldImplementing remediation measures. For example, system freeze capabilities, model adjustments, output validation improvements, customer not…Implementing remediation measures. For example, system freeze capabilities, model adjustments, output validation improvements, customer not…
matchhigh r=1.00 shouldEstablishing compensation assessment procedures. For example, loss evaluation methods, settlement approaches, and payment authorization lev…Establishing compensation assessment procedures. For example, loss evaluation methods, settlement approaches, and payment authorization lev…
E004 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayImplementing code signing and verification processes for AI models, libraries, and deployment artefacts to ensure only digitally signed com…Implementing code signing and verification processes for AI models, libraries, and deployment artefacts to ensure only digitally signed com…
matchhigh r=1.00 shouldAssigning an accountable lead as approver for each of these changes. Can follow a RACI structure to formalize roles of those consulted and…Assigning an accountable lead as approver for each of these changes. Can follow a RACI structure to formalize roles of those consulted and…
matchhigh r=1.00 shouldDefining AI system changes requiring approval including model selection, material changes to the meta prompt, adding / removing guardrails,…Defining AI system changes requiring approval including model selection, material changes to the meta prompt, adding / removing guardrails,…
E005 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldReviewing deployment decisions when requirements change. For example, reassessing choices when data sensitivity, regulations, or threat lan…Reviewing deployment decisions when requirements change. For example, reassessing choices when data sensitivity, regulations, or threat lan…
matchhigh r=1.00 shouldDocumenting decision criteria and rationale. For example, establishing clear selection factors, maintaining records of deployment choices w…Documenting decision criteria and rationale. For example, establishing clear selection factors, maintaining records of deployment choices w…
matchhigh r=1.00 shouldConducting deployment risk assessments. For example, evaluating data sensitivity, regulatory compliance requirements, IP protection needs,…Conducting deployment risk assessments. For example, evaluating data sensitivity, regulatory compliance requirements, IP protection needs,…
E006 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldMaintaining assessment records with sufficient detail for audit purposes and retaining due diligence evidence before vendor approval.Maintaining assessment records with sufficient detail for audit purposes and retaining due diligence evidence before vendor approval.
matchhigh r=1.00 shouldConducting documented assessments. For example, scoring results, verification activities such as certifications reviewed and references con…Conducting documented assessments. For example, scoring results, verification activities such as certifications reviewed and references con…
matchhigh r=1.00 shouldDefining assessment criteria for foundational or upstream AI models. For example, data handling and ownership practices, PII controls, secu…Defining assessment criteria for foundational or upstream AI models. For example, data handling and ownership practices, PII controls, secu…
E007 — matched 1 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldDocumenting formal review and approval decisions for changes defined in E004: Assign accountability.Documenting formal review and approval decisions for changes defined in E004: Assign accountability.
E008 — matched 4 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayCollecting and implementing external feedback on AI systems. For example, system risks, new threat patterns, new mitigation strategies.Collecting and implementing external feedback on AI systems. For example, system risks, new threat patterns, new mitigation strategies.
matchhigh r=1.00 shouldMaintaining a centralized repository of decision records and internal review of these record. For example, supporting evidence reviewed, re…Maintaining a centralized repository of decision records and internal review of these record. For example, supporting evidence reviewed, re…
matchhigh r=1.00 shouldReviewing decision processes every quarter including AI system changes, foundational model selection, security assessment.Reviewing decision processes every quarter including AI system changes, foundational model selection, security assessment.
matchhigh r=0.97 shouldDocumenting and tracking remediation of any risks identified.intDocumenting and tracking remediation of any risks identified.
E009 — matched 2 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldCapturing access metadata. For example, user identification, authentication timestamps, accessed resources, session duration, origin IP add…Capturing access metadata. For example, user identification, authentication timestamps, accessed resources, session duration, origin IP add…
matchhigh r=1.00 shouldConfiguring logging for third-party interactions. For example, capturing API connections, user access sessions, data exchanges, and service…Configuring logging for third-party interactions. For example, capturing API connections, user access sessions, data exchanges, and service…
E010 — matched 6 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayConducting regular effectiveness reviews. For example, quarterly analysis of violation trends, tool performance assessment, policy updates…Conducting regular effectiveness reviews. For example, quarterly analysis of violation trends, tool performance assessment, policy updates…
matchhigh r=1.00 mayMaintaining logging and tracking systems. For example, incident creation, violation tracking with case assignment and resolution documentat…Maintaining logging and tracking systems. For example, incident creation, violation tracking with case assignment and resolution documentat…
matchhigh r=1.00 mayReal-time monitoring, blocking, or alerting capabilities.Real-time monitoring, blocking, or alerting capabilities.
matchhigh r=1.00 shouldImplementing user feedback when policy is breached. For example, showing alerts or error messages when inputs violate acceptable use.Implementing user feedback when policy is breached. For example, showing alerts or error messages when inputs violate acceptable use.
matchhigh r=1.00 shouldImplementing detection and monitoring tools. For example, prompt analysis, output filtering, usage pattern anomalies, and suspicious access…Implementing detection and monitoring tools. For example, prompt analysis, output filtering, usage pattern anomalies, and suspicious access…
matchhigh r=1.00 shouldDefining prohibited AI usage for end-users. For example, jailbreak attempts, malicious prompt injection, unauthorized data extraction, gene…Defining prohibited AI usage for end-users. For example, jailbreak attempts, malicious prompt injection, unauthorized data extraction, gene…
E011 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayImplementing transfer compliance procedures. For example, assessing data transfer requirements for AI training data and inference processin…Implementing transfer compliance procedures. For example, assessing data transfer requirements for AI training data and inference processin…
matchhigh r=1.00 shouldReviewing and updating documentation regularly.Reviewing and updating documentation regularly.
matchhigh r=1.00 shouldMaintaining AI infrastructure location documentation. For example, geographic locations of foundation model processing locations and infere…Maintaining AI infrastructure location documentation. For example, geographic locations of foundation model processing locations and infere…
E012 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldReviewing the repository every 6 months and when additional requirements may be triggered. For example, regulations change or business oper…Reviewing the repository every 6 months and when additional requirements may be triggered. For example, regulations change or business oper…
matchhigh r=1.00 shouldDocumenting compliance procedures and strategies appropriate for company size and operations.Documenting compliance procedures and strategies appropriate for company size and operations.
matchhigh r=1.00 shouldIdentifying relevant regulations. For example, data protection laws. For example, GDPR, CCPA, sector-specific requirements, emerging AI sta…Identifying relevant regulations. For example, data protection laws. For example, GDPR, CCPA, sector-specific requirements, emerging AI sta…
E013 — matched 5 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayDocumenting communication procedures with regulatory authorities and stakeholders. For example, establishing protocols for regulatory repor…Documenting communication procedures with regulatory authorities and stakeholders. For example, establishing protocols for regulatory repor…
matchhigh r=1.00 mayEstablishing data management and record-keeping systems. For example, documenting data governance procedures, maintaining technical documen…Establishing data management and record-keeping systems. For example, documenting data governance procedures, maintaining technical documen…
matchhigh r=1.00 shouldImplementing defect tracking, continuous improvement, and post-market monitoring. For example, maintaining issue tracking systems, conducti…Implementing defect tracking, continuous improvement, and post-market monitoring. For example, maintaining issue tracking systems, conducti…
matchhigh r=1.00 shouldEstablishing change management, approval processes, and documentation standards. For example, defining review and approval requirements for…Establishing change management, approval processes, and documentation standards. For example, defining review and approval requirements for…
matchhigh r=1.00 shouldDefining quality objectives, metrics, and risk management approach for AI systems. For example, establishing performance targets, safety th…Defining quality objectives, metrics, and risk management approach for AI systems. For example, establishing performance targets, safety th…
E015 — matched 3 · added 1 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayImplementing technical controls to ensure logs are tamper-evident and independently verifiable. For example, ensuring that captured records…Implementing technical controls to ensure logs are tamper-evident and independently verifiable. For example, ensuring that captured records…
matchhigh r=1.00 shouldImplementing log storage with appropriate retention periods, access controls, and data sanitation to support auditing and incident response.Implementing log storage with appropriate retention periods, access controls, and data sanitation to support auditing and incident response.
matchhigh r=1.00 shouldCapturing system activity details to support incident investigation and behavior explanation. For example, logging inputs, processing steps…Capturing system activity details to support incident investigation and behavior explanation. For example, logging inputs, processing steps…
addedmayCapturing full execution chains of agentic workflows to support investigation of agent-specific incidents. For example, logging agent prove…
E016 — matched 5 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldEstablishing reactive disclosure capabilities when users ask if they are interacting with AI.Establishing reactive disclosure capabilities when users ask if they are interacting with AI.
matchhigh r=1.00 shouldLabelling AI-generated media and documents in a machine-readable and detectable format. For example, marking AI-generated images, videos, a…Labelling AI-generated media and documents in a machine-readable and detectable format. For example, marking AI-generated images, videos, a…
matchhigh r=1.00 shouldImplementing AI disclosure for voice-based interactions. For example, providing audio notifications at the beginning of voice calls or inte…Implementing AI disclosure for voice-based interactions. For example, providing audio notifications at the beginning of voice calls or inte…
matchhigh r=1.00 shouldImplementing AI disclosure for text-based interactions. For example, displaying clear notices when users interact with AI chatbots, virtual…Implementing AI disclosure for text-based interactions. For example, displaying clear notices when users interact with AI chatbots, virtual…
matchhigh r=0.94 shouldDisclosing when autonomous AI agents or automated workflows are performing actions. For example, notifying users when AI systems are making…Disclosing when autonomous AI agents or systems are performing actions. For example, notifying users when AI systems are making decisions,…
E017 — matched 4 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayDocumenting sharing procedures including approval workflows, version control, and distribution tracking. For example, establishing approval…Documenting sharing procedures including approval workflows, version control, and distribution tracking. For example, establishing approval…
matchhigh r=1.00 mayDefining policies for sharing transparency documentation with external stakeholders. For example, establishing when reports are shared, spe…Defining policies for sharing transparency documentation with external stakeholders. For example, establishing when reports are shared, spe…
matchhigh r=1.00 shouldCreating transparency documentation for major AI systems. For example, documenting system characteristics, data provenance, and model behav…Creating transparency documentation for major AI systems. For example, documenting system characteristics, data provenance, and model behav…
matchhigh r=1.00 shouldEstablishing a transparency policy defining documentation requirements for major AI systems. For example, specifying required documentation…Establishing a transparency policy defining documentation requirements for major AI systems. For example, specifying required documentation…
F001 — matched 2 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayImplementing malicious use detection and blocking. For example, deploying available content filtering to detect requests for malicious code…Implementing malicious use detection and blocking. For example, deploying available content filtering to detect requests for malicious code…
matchhigh r=1.00 shouldResults of testing from foundation model developer on offensive cyber capabilities and mitigations.Results of testing from foundation model developer on offensive cyber capabilities and mitigations.
F002 — matched 2 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayEstablishing catastrophic misuse monitoring. For example, monitoring AI system interactions for patterns indicating weapons development or…Establishing catastrophic misuse monitoring. For example, monitoring AI system interactions for patterns indicating weapons development or…
matchhigh r=1.00 shouldResults of testing from foundation model developer on CBRN capabilities and mitigations.Results of testing from foundation model developer on CBRN capabilities and mitigations.
Generated by AIUC1explorer v0.1.0.dev0 — per-release change analysis of the AIUC-1 standard.
AIUC-1 (c) 2025-2026 Caliber Labs PBC, DBA Artificial Intelligence Underwriting Company (AIUC).
AIUC1explorer analysis and publication (c) 2025-2026 Cabahu Pty Ltd DBA axigetik.