oct-2025 → jan-2026

Release type: structural. Per-bullet matching is indicative only on this release. Lead with the requirement-level changes and control composition; the bullet breakdown below reflects merges and rewrites scored as remove+add.
How nature of change is determined. For each requirement present in both releases, we compare the normalised wording of the previous and current versions and measure how much of it changed. We then classify the result into four categories:These categories drive the Nature column in the tables below. On this transition, the publisher's own change summary covers requirements and their underlying control activities jointly, while the Nature column below grades the requirement text only — so the labels are a working approximation rather than a calibrated reading.
release_type
structural
requirements
identical 44 · editorial 1 · clarification 3 · substantive 3 · added 0 · removed 0
control bullets
prev 208 → cur 173 · matched 118 · added 55 · removed 90 · merges 0 · match rate 56.7%

Overview: website change summary

Updated 26 requirements based on audit experience, input from technical contributors, feedback from AIUC-1 Consortium members, and external peer-review comments. Detailed typical evidence submitted to pass AIUC-1 with suggested locations and concrete examples, making it easier for organizations to begin a readiness assessment of AIUC-1 Published AIUC-1 scoping questionnaire and certification process details to ensure consistent application of AIUC-1 across accredited auditors

Per-principle change distribution

per-principle distribution

Requirement-level changes and control composition

A. Data & Privacy

IDTitleNatureDist.Shoulds/MaysSite narrative
A006Prevent PII leakageclarification0.0593/3 → 2/1 (Δ -1s/-2m)specification Increased PII protection requirements for logs Removed incident management control to avoid overlap with E001 Removed cross-tenant contaminant control to avoid…

B. Security

IDTitleNatureDist.Shoulds/MaysSite narrative
B006Prevent unauthorized AI agent actionssubstantive0.3883/2 → 2/0 (Δ -1s/-2m)clarification Clarified the requirement's focus on security aspects of system limiting Emphasized agent privilege restrictions and monitoring

C. Safety

IDTitleNatureDist.Shoulds/MaysSite narrative
C002Conduct pre-deployment testingclarification0.2403/2 → 3/2 (Δ +0s/+0m)specification Included explicit reference to threat modelling in controls based on peer-review feedback
C007Flag high risk outputsclarification0.1033/0 → 2/1 (Δ -1s/+1m)

E. Accountability

IDTitleNatureDist.Shoulds/MaysSite narrative
E007[Retired] Document system change approvalssubstantive0.7592/0 → 1/0 (Δ -1s/+0m)retired This requirement was merged into E004: Assign accountability, which already requires documenting approval with supporting evidence
E014Share transparency reportssubstantive0.7902/2 → 0/0 (Δ -2s/-2m)retired This requirement was merged into E017 to avoid overlap and to recognize transparency policy sharing procedures
E016Implement AI disclosure mechanismseditorial0.0385/2 → 5/0 (Δ +0s/-2m)revision Revised control activities to ensure coverage of multiple modalities (e.g. voice, text, image)

Per-bullet detail (indicative on consolidation releases)

A001 — matched 1 · added 2 · removed 3 · merges 0
KindDetailPrevCur
matchmid r=0.69 mayDocumenting processes for customer data subject rights. For example, handling requests for access, portability, or deletion of input data,…Documenting processes for handling end-user data subject rights. For example, handling requests for opt-in/opt-out rights, access, portabil…
removedshouldDefining input data usage policies. For example, opt-in/opt-out mechanisms, disclosure requirements, boundaries between training and post-d…
removedshouldImplementing data retention and deletion procedures for inputs. For example, defining retention periods for training data, inference logs,…
removedshouldDocumenting and justifying retention periods for different categories of input data.
addedshouldDefining and communicating input data usage policies. Including specifying how customer data is used for inference and model training, esta…
addedshouldImplementing technical controls to enforce data retention and deletion policies. For example, automating data deletion based on retention s…
A002 — matched 0 · added 2 · removed 3 · merges 0
KindDetailPrevCur
removedshouldDefining output ownership rights with clear distinctions between customer inputs and AI outputs. For example, specifying customer versus ve…
removedshouldDisclosing consent and opt-out procedures for outputs. For example, documenting how consent for re-use of AI-generated content is collected…
removedshouldEstablishing output usage policies communicated through accessible terms of service. For example, permitted uses of AI-generated content, r…
addedshouldEstablishing output ownership and usage rights policies. For example, specifying customer ownership of AI-generated outputs versus AI input…
addedshouldDisclosing opt-out and deletion procedures for AI outputs. For example, documenting how customers can opt out of output storage or reuse, e…
A003 — matched 2 · added 1 · removed 2 · merges 0
KindDetailPrevCur
matchhigh r=0.89 mayDeploying monitoring and enforcement mechanisms. For example, ensuring AI systems only perform necessary inference and logging deviations f…Deploying monitoring mechanisms. Including ensuring AI systems only perform necessary inference and logging deviations from defined operati…
matchmid r=0.77 mayIntegrating with existing identity and access management (IAM) systems to align agent access permissions with organizational policies. For…Integrating with existing authorization systems to align agent access permissions with organizational policies.
removedshouldConfiguring data collection limits to reduce data and privacy exposure. For example, limiting to time-bounded, task-specific, purpose-limit…
removedmayEstablishing dynamic context-based restrictions to adjust access decisions if user role or environment changes during agent session. For ex…
addedshouldConfiguring data collection limits to reduce data and privacy exposure. For example, limiting data collection to task-relevant information…
A004 — matched 0 · added 4 · removed 4 · merges 0
KindDetailPrevCur
removedshouldDocumenting foundation model provider safeguards which may serve as primary IP protection. For example, reviewing contractual data handling…
removedshouldEstablishing supplementary data access controls where provider protections are insufficient. For example, limiting AI exposure to proprieta…
removedmayImplementing output monitoring procedures with automated review processes for high-risk scenarios. For example, scanning responses for prop…
removedmayMaintaining internal IP incident response and escalation procedures as part of AI failure plan on data breaches. For example, documenting i…
addedshouldProviding user guidance on protecting confidential information. For example, instructing employees not to input trade secrets, proprietary…
addedmayLeveraging foundation model provider protections. For example, using providers with zero data retention policies, requiring contractual com…
addedmayImplementing technical controls to detect proprietary information in outputs.
addedmayEstablishing output monitoring for high-risk IP scenarios. For example, logging AI responses that accessed confidential data sources, imple…
A005 — matched 2 · added 1 · removed 3 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldImplementing customer data isolation controls. For example, enforcing strict logical and physical separation of customer data, applying ten…Implementing customer data isolation controls. For example, enforcing strict logical and physical separation of customer data, applying ten…
matchhigh r=1.00 shouldEstablishing explicit consent and disclosure for combined data usage. For example, informing customers when their data will be combined wit…Establishing explicit consent and disclosure for combined data usage. For example, informing customers when their data will be combined wit…
removedmayImplementing specific privacy-enhancing technologies (PETs) to reduce competitive exposure. For example, applying differential privacy to o…
removedmayImplementing inference-time data isolation to prevent leakage of one customer's data or model-derived insights into responses for other cus…
removedmayAdapting safeguards to industry-specific competitive risks. For example, applying stricter isolation for customers in the same vertical, av…
addedmayImplementing specific privacy-enhancing technologies (PETs) to reduce competitive exposure.
A006 — matched 1 · added 2 · removed 5 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayIntegrating with existing data loss prevention (DLP) systems to monitor and block outputs containing personal data in violation of policy.Integrating with existing data loss prevention (DLP) systems to monitor and block outputs containing personal data in violation of policy.
removedshouldEstablishing data segregation controls. For example, isolating user sessions, implementing user-specific boundaries, preventing reuse of pr…
removedshouldEstablishing safeguards to prevent personal data leakage between users. For example, isolating user sessions, applying user-specific output…
removedshouldDocumenting protection procedures and incident management. For example, identifying PII, defining output handling policies, maintaining lea…
removedmayImplementing output monitoring. For example, scanning outputs for cross-customer data leakage, validating data source attribution.
removedmayImplementing automated detection and redaction of personal data in AI outputs. For example, using named entity recognition (NER) or data cl…
addedshouldImplementing safeguards to prevent personal data leakage through AI system outputs and logs. For example, filtering prompts and outputs for…
addedshouldRequiring authentication and authorization for PII access. For example, role-based access controls for PII-containing systems, multi-factor…
A007 — matched 3 · added 1 · removed 2 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayImplementing restrictions in AI acceptable use policy.Implementing restrictions in AI acceptable use policy.
matchhigh r=1.00 should→mayEstablishing supplementary content filtering mechanisms where provider protections have gaps or limitations. For example, detecting copyrig…Establishing supplementary content filtering mechanisms where provider protections have gaps or limitations. For example, detecting copyrig…
matchmid r=0.63 shouldDocumenting foundation model provider IP protections which may serve as primary infringement safeguards. For example, reviewing copyright a…Documenting foundation model provider IP protections which may serve as primary infringement safeguards. For example, indemnification claus…
removedmayImplementing user guidance and guardrails to reduce IP risk. For example, providing usage policies that explain prohibited content types, e…
removedmayMaintaining third-party IP incident response procedures. For example, identifying potential infringement, documenting incidents and remedia…
addedmayImplementing user guidance and guardrails to reduce IP risk. For example, usage policies that explain prohibited content types, user warnin…
B001 — matched 4 · added 1 · removed 1 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldMaintaining secure testing documentation. For example, recording test cases, methods, outcomes, and system behaviors with restricted access…Maintaining secure testing documentation. For example, recording test cases, methods, outcomes, and system behaviors with restricted access…
matchhigh r=0.98 mayAligning adversarial testing with broader security testing programs. For example, integrating AI-specific test cases into penetration testi…Aligning adversarial testing with broader security testing programs. For example, integrating AI-specific test cases into broader penetrati…
matchmid r=0.79 shouldConducting comprehensive adversarial testing quarterly and after material system changes. For example, performing structured red-teaming, p…Conducting comprehensive adversarial testing at least quarterly. For example, performing structured red-teaming, prompt injection assessmen…
matchmid r=0.70 shouldEstablishing a taxonomy for adversarial risks. For example, referencing and tailoring relevant categories from NIST's AI 100-2e2023 attack…Establishing a taxonomy for adversarial risks. For example, drawing on NIST's AI 100-2e2023 attack classifications and aligning these to sy…
removedshouldEstablishing improvement processes based on findings. For example, assigning owners and remediation timelines based on test severity (e.g.…
addedshouldEstablishing improvement processes based on findings. For example, assigning owners and remediation timelines based on test severity, track…
B002 — matched 4 · added 1 · removed 1 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayIntegrating adversarial input detection into existing security operations tooling. For example, forwarding flagged inputs to SIEM platforms…Integrating adversarial input detection into existing security operations tooling. For example, forwarding flagged inputs to SIEM platforms…
matchhigh r=1.00 shouldMaintaining detection effectiveness through quarterly reviews. For example, updating detection rules based on emerging adversarial techniqu…Maintaining detection effectiveness through quarterly reviews. For example, updating detection rules based on emerging adversarial techniqu…
matchhigh r=1.00 shouldEstablishing detection and alerting. For example, implementing monitoring for prompt injection patterns, jailbreak techniques, adversarial…Establishing detection and alerting. For example, implementing monitoring for prompt injection patterns, jailbreak techniques, adversarial…
matchmid r=0.65 mayImplementing adversarial input detection prior to AI model processing where feasible. For example, using lightweight pattern-matching, beha…Implementing adversarial input detection prior to AI model processing where feasible. For example, using pre-processing filters to flag lik…
removedshouldImplementing incident logging and response procedures. For example, logging suspected attacks with timestamps, user/session context, and in…
addedshouldImplementing incident logging and response procedures. For example, logging suspected adversarial attacks with relevant context, escalating…
B003 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayEstablishing approval processes. For example, requiring designated review for public content referencing AI capabilities in e.g. publicatio…Establishing approval processes. For example, requiring designated review for public content referencing AI capabilities in e.g. publicatio…
matchhigh r=1.00 shouldControlling organizational information to balance transparency with security. For example, limiting disclosure of AI team details, developm…Controlling organizational information to balance transparency with security. For example, limiting disclosure of AI team details, developm…
matchhigh r=1.00 shouldDocumenting limitations on technical information release. For example, limiting public disclosure of model architectures, algorithms, train…Documenting limitations on technical information release. For example, limiting public disclosure of model architectures, algorithms, train…
B004 — matched 1 · added 3 · removed 3 · merges 0
KindDetailPrevCur
matchmid r=0.75 shouldImplementing systems distinguishing between high-volume legitimate usage and adversarial behavior. For example, using behavioral analytics,…Implementing systems distinguishing between high-volume legitimate usage and adversarial behavior. For example, using behavioral analytics…
removedshouldImplementing rate limiting and query restrictions. For example, establishing per-user query quotas and rate limits to prevent model extract…
removedshouldConducting simulated external attack testing. For example, performing automated scraping tests, brute force attempts, and reconnaissance ac…
removedshouldMaintaining endpoint security through remediation. For example, documenting test results and identified vulnerabilities, implementing prote…
addedshouldImplementing rate limiting and query restrictions. For example, establishing per-user quotas to prevent model extraction, blocking excessiv…
addedshouldConducting simulated external attack testing of AI endpoints. For example, performing automated attack simulations, testing endpoint protec…
addedshouldMaintaining endpoint security through remediation. For example, tracking identified vulnerabilities, implementing protective measures based…
B005 — matched 3 · added 2 · removed 4 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayPeriodically evaluating filter performance and adjusting thresholds accordingly. For example, accuracy, latency, false positives/negatives.Periodically evaluating filter performance and adjusting thresholds accordingly. For example, accuracy, latency, false positives/negatives.
matchhigh r=1.00 mayProviding feedback to users when inputs are blocked.Providing feedback to users when inputs are blocked.
matchmid r=0.61 mayLogging flagged prompts for analysis and refinement of filters, while ensuring compliance with privacy obligations. For example, excluding…Logging flagged prompts for analysis and refinement of filters, while ensuring compliance with privacy obligations.
removedshouldIntegrating automated moderation tools to scan user inputs for violations of content policies such as violence, hate, or self-harm. For exa…
removedshouldBlocking, redirecting, or modifying flagged inputs before they reach the foundation model.
removedshouldEstablishing confidence thresholds or rules for when to block, warn, log, or allow inputs based on risk category and severity.
removedshouldDocumenting the moderation logic and thresholds used, including rationale for chosen tool(s).
addedshouldIntegrating automated moderation tools to filter inputs before they reach the foundation model. For example, integrating third-party modera…
addedmayDocumenting the moderation logic and rationale. For example, explaining chosen moderation tools, threshold justifications, and decision cri…
B006 — matched 0 · added 2 · removed 5 · merges 0
KindDetailPrevCur
removedshouldConfiguring contextual access controls for AI agents. For example, enforcing task-based tool access using declarative policy models (e.g. J…
removedshouldImplementing privilege limiting for autonomous behavior. For example, restricting agents from escalating access or acting beyond permitted…
removedshouldDeploying monitoring and enforcement mechanisms. For example, ensuring AI systems only perform necessary inference and logging deviations f…
removedmayDefining automatic restriction triggers. For example, revoking tool access or suppressing outputs when agent context diverges from declared…
removedmayIntegrating agent access decisions with existing identity and access management (IAM) systems. For example, aligning agent privileges with…
addedshouldImplementing technical restrictions that limit agent capabilities to authorized scope. For example, restricting agent access to approved ba…
addedshouldDeploying monitoring and alerting for agent actions that exceed security boundaries. For example, logging all agent service interactions, a…
B007 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldConducting access reviews and updates at least quarterly. For example, validating access assignments, updating based on policy or role chan…Conducting access reviews and updates at least quarterly. For example, validating access assignments, updating based on policy or role chan…
matchhigh r=1.00 shouldRestricting administrative and configuration privileges to authorized personnel. For example, limiting ability to alter system behavior, to…Restricting administrative and configuration privileges to authorized personnel. For example, limiting ability to alter system behavior, to…
matchhigh r=1.00 shouldImplementing system-level access controls tailored to AI systems. For example, using role-based or attribute-based access to restrict acces…Implementing system-level access controls tailored to AI systems. For example, using role-based or attribute-based access to restrict acces…
B008 — matched 4 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 maySecuring model hosting environments. For example, using up-to-date and minimal container images, scanning for known vulnerabilities in depe…Securing model hosting environments. For example, using up-to-date and minimal container images, scanning for known vulnerabilities in depe…
matchhigh r=1.00 shouldEstablishing deployment security controls. For example, applying scoped API tokens or signed requests, using TLS for all endpoint traffic,…Establishing deployment security controls. For example, applying scoped API tokens or signed requests, using TLS for all endpoint traffic,…
matchhigh r=1.00 shouldImplementing model access protection. For example, restricting access to production AI models based on job function and operational need, i…Implementing model access protection. For example, restricting access to production AI models based on job function and operational need, i…
matchhigh r=0.81 mayVerifying model integrity before and during deployment. For example, using cryptographic checksums or signed artifacts to detect tampering,…Verifying model integrity before and during deployment. For example, using cryptographic checksums or signed artifacts to detect tampering,…
B009 — matched 2 · added 1 · removed 2 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldReducing or limiting the number of results shown in outputs to relevant only to balance security and utility. For example, character limits…Reducing or limiting the number of results shown in outputs to relevant only to balance security and utility. For example, character limits…
matchhigh r=0.88 mayLimiting the fidelity of numerical outputs in certain use cases. For example, applying output rounding, threshold bands, or obfuscation tec…Limiting the fidelity of model outputs in certain use cases. For example, applying output rounding, threshold bands, or obfuscation techniq…
removedshouldFiltering sensitive information that may reveal internal system behavior. For example, removing or abstracting technical details about mode…
removedshouldProviding user-facing notices or documentation about output limitations. For example, clearly indicating when results have been truncated,…
addedmayProviding user-facing notices or documentation about output limitations.
C001 — matched 3 · added 1 · removed 2 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldEstablishing severity grading appropriate to organizational context and risk tolerance. For example, implementing consistent scoring method…Establishing severity grading appropriate to organizational context and risk tolerance. For example, implementing consistent scoring method…
matchhigh r=1.00 shouldDefining risk categories with severity levels and examples based on industry and deployment context. For example, classifying harmful outpu…Defining risk categories with severity levels and examples based on industry and deployment context. For example, classifying harmful outpu…
matchmid r=0.62 shouldAligning risk taxonomy with external frameworks and standards. For example, NIST AI RMF functions, EU AI Act article 9, ISO42001 controls.Aligning risk taxonomy with external frameworks and standards.
removedshouldMaintaining taxonomy currency with documented change management. For example, reviewing and updating risk categories quarterly or when new…
removedmayIdentifying additional risk categories that are considered harmful given nature of operations. For example, hallucinations, out-of-scope co…
addedshouldMaintaining taxonomy currency with documented change management. For example, updating based on emerging threats or incidents.
C002 — matched 4 · added 1 · removed 1 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldCompleting risk assessments of identified issues before system deployment. For example, potential impact analysis, mitigation strategies, a…Completing risk assessments of identified issues before system deployment. For example, potential impact analysis, mitigation strategies, a…
matchhigh r=1.00 shouldConducting pre-deployment testing with documented results and identified issues. For example, structured hallucination testing, adversarial…Conducting pre-deployment testing with documented results and identified issues. For example, structured hallucination testing, adversarial…
matchhigh r=0.94 shouldObtaining approval sign-offs from designated accountable leads with documented rationale for approval decisions and maintained records for…Obtaining approval sign-offs from designated accountable. For example, documented rationale for approval decisions and maintained records f…
matchmid r=0.79 mayIntegrating AI system testing into established software development lifecycle (SDLC) gates. For example, requiring risk evaluation and sign…Integrating AI system testing into established software development lifecycle (SDLC) gates. For example, including threat modelling and ris…
removedmayImplementing pre-deployment vulnerability scanning of AI artifacts and dependencies. For example, scanning model files (e.g. pickle, ONNX)…
addedmayImplementing pre-deployment vulnerability scanning of AI artifacts and dependencies. For example, scanning AI models and ML libraries for s…
C003 — matched 3 · added 1 · removed 2 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldImplementing content filtering for harmful output types. For example, detecting and blocking distressed responses, angry language, offensiv…Implementing content filtering for harmful output types. For example, detecting and blocking distressed responses, angry language, offensiv…
matchhigh r=0.96 should→mayMaintaining bias detection and mitigation controls. For example, monitoring for discriminatory patterns, implementing fairness checks in ou…Implementing bias detection and mitigation controls. For example, monitoring for discriminatory patterns, implementing fairness checks in o…
matchhigh r=0.93 shouldEstablishing safety guardrails for advice generation. For example, restricting high-risk recommendations in sensitive domains, requiring di…Implementing guardrails for advice generation. For example, restricting high-risk recommendations in sensitive domains, requiring disclaime…
removedmayEvaluating harm mitigation controls using performance metrics. For example, tracking false positives (overblocking safe content) and false…
removedmayEstablishing review and appeal mechanisms. For example, allowing flagged outputs to be escalated for manual review, recording override deci…
addedmayEvaluating harm mitigation controls using performance metrics.
C004 — matched 1 · added 2 · removed 3 · merges 0
KindDetailPrevCur
matchmid r=0.66 shouldMaintaining scope monitoring and adjustment capabilities. For example, tracking boundary violations, updating restrictions based on emergin…Tracking out-of-scope violations and updating boundaries. For example, logging boundary violations, adjusting restrictions based on misuse…
removedshouldImplementing topic boundary enforcement. For example, detecting and redirecting conversations outside intended use cases as defined in AI a…
removedshouldEstablishing scope violation response procedures. For example, automated redirection messages, escalation for persistent attempts.
removedmayImplementing user education on system scope and limitations. For example, displaying onboarding tooltips, publishing usage guidelines or FA…
addedshouldDetecting and blocking out-of-scope requests. For example, detecting conversations outside intended use cases, blocking prohibited topics,…
addedmayProviding user guidance on system capabilities and limitations. For example, communicating what the AI system can and cannot do, intended u…
C005 — matched 2 · added 2 · removed 2 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldImplementing detection and blocking mechanisms aligned with organizational risk taxonomy. For example, deploying filtering based on defined…Implementing detection and blocking mechanisms aligned with organizational risk taxonomy. For example, deploying filtering based on defined…
matchmid r=0.61 mayEstablishing escalation procedures for flagged high risk content. For example, human review workflows, approval requirements for edge cases…Establishing escalation procedures for flagged high-risk content. For example, defining when human review is required and establishing appr…
removedshouldMaintaining risk-based response controls. For example, flagging and blocking mechanisms, logging for monitoring purposes.
removedmayImplementing automated real-time response mechanisms. For example, triggering dynamic warnings, blocking or modifying model responses based…
addedshouldImplementing response actions for detected risks. For example, blocking high-severity outputs, flagging medium-risk content for review, log…
addedmayImplementing automated real-time interventions. For example, blocking or modifying outputs based on severity.
C006 — matched 1 · added 2 · removed 3 · merges 0
KindDetailPrevCur
matchmid r=0.66 mayDetecting advanced output-based attack patterns. For example, identifying prompt injection chains, model-output subversion (e.g. jailbreak…Detecting advanced output-based attack patterns. For example, identifying prompt injection attempts, model subversion techniques, payloads…
removedshouldEstablishing output sanitization and validation procedures before presenting content to users. For example, stripping or encoding HTML, Jav…
removedshouldImplementing safety-specific labeling and handling protocols. For example, clearly marking untrusted, distinguishing untrusted third-party…
removedshouldMaintaining detection and monitoring capabilities. For example, logging sanitization activities, implementing alerting for suspicious conte…
addedshouldEstablishing output sanitization and validation procedures before presenting content to users. For example, encoding or stripping potential…
addedshouldImplementing security labeling and content handling based on trust level. For example, marking untrusted or third-party content, distinguis…
C007 — matched 0 · added 3 · removed 3 · merges 0
KindDetailPrevCur
removedshouldDefining high-risk recommendation criteria drawing on risk taxonomy. For example, financial advice exceeding company thresholds, medical or…
removedshouldImplementing automated detection using keyword filtering, confidence scoring, or rule-based assessment with adjustable sensitivity settings.
removedshouldEstablishing human review workflows. For example, designated reviewers from available staff, escalation procedures for complex cases, queue…
addedshouldDefining high-risk output criteria drawing on risk taxonomy.
addedshouldImplementing automated detection mechanisms for high-risk outputs. For example, using content filtering, risk scoring, or classification mo…
addedmayEstablishing human review workflows for flagged high-risk outputs. For example, assigning reviewers, defining escalation procedures for com…
C008 — matched 2 · added 1 · removed 2 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayIntegrating AI output monitoring with existing security tools. For example, forwarding alerts and flagged outputs to SIEM platforms, applyi…Integrating AI output monitoring with existing security tools. For example, forwarding alerts and flagged outputs to SIEM platforms, applyi…
matchhigh r=1.00 should→mayMaintaining documentation. For example, recording identified scenarios with clear examples, updating risk taxonomy based on monitoring find…Maintaining documentation. For example, recording identified scenarios with clear examples, updating risk taxonomy based on monitoring find…
removedshouldImplementing proactive detection. For example, defining potential scenarios based on risk taxonomy that could generate harmful outputs unde…
removedshouldEstablishing ongoing monitoring. For example, conducting regular evaluations prioritized by risk severity, using methods such as output sam…
addedshouldEstablishing ongoing monitoring of AI outputs across risk categories. For example, conducting regular evaluations prioritized by risk sever…
C009 — matched 4 · added 0 · removed 1 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayAnalyzing collected feedback using structured methodologies. For example, categorizing by risk domain, prioritizing based on frequency and…Analyzing collected feedback using structured methodologies. For example, categorizing by risk domain, prioritizing based on frequency and…
matchhigh r=1.00 should→mayReviewing user feedback and intervention logs regularly. For example, evaluating patterns in interventions, adapting communication methods…Reviewing user feedback and intervention logs regularly. For example, evaluating patterns in interventions, adapting communication methods…
matchhigh r=1.00 shouldEnsuring accessibility of feedback and intervention mechanisms. For example, adhering to WCAG 2.1 standards for color contrast, screen read…Ensuring accessibility of feedback and intervention mechanisms. For example, adhering to WCAG 2.1 standards for color contrast, screen read…
matchhigh r=1.00 shouldEnabling user intervention capabilities. For example, providing mechanisms for users to pause, stop, or redirect system behavior, implement…Enabling user intervention capabilities. For example, providing mechanisms for users to pause, stop, or redirect system behavior, implement…
removedshouldEstablishing on-screen communication systems. For example, implementing real-time display of system status, intervention notices, disclaime…
C010 — matched 2 · added 1 · removed 1 · merges 0
KindDetailPrevCur
matchhigh r=0.95 shouldAppointing qualified third-party assessors. For example, selecting assessors with relevant technical capabilities for identified risk areas…Appointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m…
matchhigh r=0.85 shouldMaintaining documentation. For example, recording third-party qualifications, testing scope, results, and remediation actions taken, tracki…Maintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti…
removedshouldConducting regular testing. For example, performing assessments of harmful outputs at least every quarter, defining testing scope and metho…
addedshouldConducting regular testing. Including performing assessments of harmful outputs at least every quarter, defining testing scope and methodol…
C011 — matched 2 · added 1 · removed 1 · merges 0
KindDetailPrevCur
matchhigh r=0.95 shouldAppointing qualified third-party assessors. For example, selecting assessors with relevant technical capabilities for identified risk areas…Appointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m…
matchhigh r=0.85 shouldMaintaining documentation. For example, recording third-party qualifications, testing scope, results, and remediation actions taken, tracki…Maintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti…
removedshouldConducting regular testing. For example, performing assessments of out-of-scope outputs at least every quarter, defining testing scope and…
addedshouldConducting regular testing. Including defining testing scope and methodologies based on risk taxonomy and performing assessments of out-of-…
C012 — matched 2 · added 1 · removed 1 · merges 0
KindDetailPrevCur
matchhigh r=0.95 shouldAppointing qualified third-party assessors. For example, selecting assessors with relevant technical capabilities for identified risk areas…Appointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m…
matchhigh r=0.85 shouldMaintaining documentation. For example, recording third-party qualifications, testing scope, results, and remediation actions taken, tracki…Maintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti…
removedshouldConducting regular testing. For example, performing assessments of high-risk areas at least every quarter, defining testing scope and metho…
addedshouldConducting regular testing. Including defining testing scope and methodologies based on risk taxonomy and performing assessments of high-ri…
D001 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayMaintaining uncertainty communication. For example, displaying confidence levels, providing appropriate disclaimers for generated informati…Maintaining uncertainty communication. For example, displaying confidence levels, providing appropriate disclaimers for generated informati…
matchhigh r=1.00 shouldEstablishing information source validation. For example, requiring citations for factual claims, implementing source reliability checks.Establishing information source validation. For example, requiring citations for factual claims, implementing source reliability checks.
matchhigh r=1.00 shouldImplementing factual accuracy controls. For example, deploying available fact-checking mechanisms, flagging uncertain or low-confidence res…Implementing factual accuracy controls. For example, deploying available fact-checking mechanisms, flagging uncertain or low-confidence res…
D002 — matched 2 · added 1 · removed 1 · merges 0
KindDetailPrevCur
matchhigh r=0.95 shouldAppointing qualified third-party assessors. For example, selecting assessors with relevant technical capabilities for identified risk areas…Appointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m…
matchhigh r=0.85 shouldMaintaining documentation. For example, recording third-party qualifications, testing scope, results, and remediation actions taken, tracki…Maintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti…
removedshouldConducting regular testing. For example, performing assessments of hallucinated outputs at least every quarter, defining testing scope and…
addedshouldConducting regular testing. Including defining testing scope and methodologies based on risk taxonomy and performing assessments at least e…
D003 — matched 4 · added 1 · removed 1 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldEstablishing execution monitoring and logging. For example, tracking all tool calls, monitoring for unauthorized access attempts or scope v…Establishing execution monitoring and logging. For example, tracking all tool calls, monitoring for unauthorized access attempts or scope v…
matchhigh r=1.00 shouldEnforcing rate limits and transaction caps for autonomous tool use.Enforcing rate limits and transaction caps for autonomous tool use.
matchhigh r=1.00 shouldImplementing function call validation and authorization. For example, restricting tool access to approved functions, validating parameters…Implementing function call validation and authorization. For example, restricting tool access to approved functions, validating parameters…
matchhigh r=0.93 should→mayReviewing patterns of AI tool usage for anomalies, updating tool permissions, and retiring unused or high-risk functions during scheduled e…Reviewing patterns of AI tool usage. For example, identifying anomalies, updating tool permissions, and retiring unused or high-risk functi…
removedshouldMaintaining decision boundary enforcement. For example, limiting autonomous actions to defined parameters, requiring human approval for sen…
addedmayRequiring human approval for sensitive tool operations. For example, requiring human confirmation before executing high-risk actions, imple…
D004 — matched 2 · added 1 · removed 1 · merges 0
KindDetailPrevCur
matchhigh r=0.95 shouldAppointing qualified third-party assessors. For example, selecting assessors with relevant technical capabilities for identified risk areas…Appointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m…
matchhigh r=0.85 shouldMaintaining documentation. For example, recording third-party qualifications, testing scope, results, and remediation actions taken, tracki…Maintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti…
removedshouldConducting regular testing. For example, performing assessments of tool calls at least every quarter, defining testing scope and methodolog…
addedshouldConducting regular testing. Including defining testing scope and methodologies based on risk taxonomy and performing assessments of tool ca…
E001 — matched 4 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldEstablishing evidence collection requirements with guidance on preserving evidence for potential legal review. For example, system logs, us…Establishing evidence collection requirements with guidance on preserving evidence for potential legal review. For example, system logs, us…
matchhigh r=1.00 shouldImplementing security remediation measures. For example, system freeze capabilities, vulnerability fixes, access control updates, and coord…Implementing security remediation measures. For example, system freeze capabilities, vulnerability fixes, access control updates, and coord…
matchhigh r=1.00 shouldDefining breach notification procedures. For example, customer communications, regulatory reporting requirements, and vendor notifications…Defining breach notification procedures. For example, customer communications, regulatory reporting requirements, and vendor notifications…
matchhigh r=1.00 shouldAssigning a breach response lead from existing staff. For example, IT manager, security officer, or designated executive with authority to…Assigning a breach response lead from existing staff. For example, IT manager, security officer, or designated executive with authority to…
E002 — matched 4 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayCoordinating external support engagement. For example, legal counsel consultation, PR support, and insurance claim procedures.Coordinating external support engagement. For example, legal counsel consultation, PR support, and insurance claim procedures.
matchhigh r=1.00 mayDefining harmful output categories with reference to risk taxonomy. For example, discriminatory content, offensive material, inappropriate…Defining harmful output categories with reference to risk taxonomy. For example, discriminatory content, offensive material, inappropriate…
matchhigh r=1.00 shouldEstablishing immediate mitigation steps with designated staff responsibilities. For example, system freeze capabilities, output suppression…Establishing immediate mitigation steps with designated staff responsibilities. For example, system freeze capabilities, output suppression…
matchhigh r=1.00 shouldImplementing customer communication protocols. For example, disclosure procedures, explanation of corrective actions, and follow-up commitm…Implementing customer communication protocols. For example, disclosure procedures, explanation of corrective actions, and follow-up commitm…
E003 — matched 3 · added 1 · removed 1 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayCoordinating potential external support. For example, legal consultation for significant claims, financial review when needed, and insuranc…Coordinating potential external support. For example, legal consultation for significant claims, financial review when needed, and insuranc…
matchhigh r=1.00 shouldImplementing remediation measures. For example, system freeze capabilities, model adjustments, output validation improvements, customer not…Implementing remediation measures. For example, system freeze capabilities, model adjustments, output validation improvements, customer not…
matchhigh r=1.00 shouldEstablishing compensation assessment procedures. For example, loss evaluation methods, settlement approaches, and payment authorization lev…Establishing compensation assessment procedures. For example, loss evaluation methods, settlement approaches, and payment authorization lev…
removedmayDefining hallucination incident types. For example, factual errors or incorrect recommendations relevant to company context and customer b…
addedmayDefining hallucination incident types.
E004 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayImplementing code signing and verification processes for AI models, libraries, and deployment artefacts to ensure only digitally signed com…Implementing code signing and verification processes for AI models, libraries, and deployment artefacts to ensure only digitally signed com…
matchhigh r=1.00 shouldAssigning an accountable lead as approver for each of these changes. Can follow a RACI structure to formalize roles of those consulted and…Assigning an accountable lead as approver for each of these changes. Can follow a RACI structure to formalize roles of those consulted and…
matchhigh r=1.00 shouldDefining AI system changes requiring approval including model selection, material changes to the meta prompt, adding / removing guardrails,…Defining AI system changes requiring approval including model selection, material changes to the meta prompt, adding / removing guardrails,…
E005 — matched 3 · added 0 · removed 3 · merges 0
KindDetailPrevCur
matchhigh r=1.00 may→shouldReviewing deployment decisions when requirements change. For example, reassessing choices when data sensitivity, regulations, or threat lan…Reviewing deployment decisions when requirements change. For example, reassessing choices when data sensitivity, regulations, or threat lan…
matchhigh r=1.00 shouldDocumenting decision criteria and rationale. For example, establishing clear selection factors, maintaining records of deployment choices w…Documenting decision criteria and rationale. For example, establishing clear selection factors, maintaining records of deployment choices w…
matchhigh r=1.00 shouldConducting deployment risk assessments. For example, evaluating data sensitivity, regulatory compliance requirements, IP protection needs,…Conducting deployment risk assessments. For example, evaluating data sensitivity, regulatory compliance requirements, IP protection needs,…
removedshouldImplementing deployment-appropriate security controls. For example, configuring cloud-specific protections or on-premises security measures…
removedmayImplementing hybrid deployment strategies. For example, using on-premises for sensitive data, cloud for less sensitive workloads, with secu…
removedmayEstablishing cloud vendor management procedures. For example, conducting provider due diligence, implementing contractual protections for d…
E006 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldMaintaining assessment records with sufficient detail for audit purposes and retaining due diligence evidence before vendor approval.Maintaining assessment records with sufficient detail for audit purposes and retaining due diligence evidence before vendor approval.
matchhigh r=0.96 shouldDefining assessment criteria for foundational or upstream AI models. For example, data handling practices, PII controls, security measures,…Defining assessment criteria for foundational or upstream AI models. For example, data handling and ownership practices, PII controls, secu…
matchhigh r=0.92 shouldConducting documented assessments. For example, scoring results, verification activities such as certifications reviewed and references con…Conducting documented assessments. For example, scoring results, verification activities such as certifications reviewed and references con…
E007 — matched 1 · added 0 · removed 1 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldDocumenting formal review and approval decisions for changes defined in E004: Assign accountability.Documenting formal review and approval decisions for changes defined in E004: Assign accountability.
removedshouldDocumenting the approval workflow with sufficient detail for review purposes. For example, who approved the change, what evidence was revie…
E008 — matched 4 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayCollecting and implementing external feedback on AI systems. For example, system risks, new threat patterns, new mitigation strategies.Collecting and implementing external feedback on AI systems. For example, system risks, new threat patterns, new mitigation strategies.
matchhigh r=1.00 shouldMaintaining a centralized repository of decision records and internal review of these record. For example, supporting evidence reviewed, re…Maintaining a centralized repository of decision records and internal review of these record. For example, supporting evidence reviewed, re…
matchhigh r=1.00 shouldReviewing decision processes every quarter including AI system changes, foundational model selection, security assessment.Reviewing decision processes every quarter including AI system changes, foundational model selection, security assessment.
matchhigh r=0.97 shouldDocumenting and tracking remediation of any risks identified.Documenting and tracking remediation of any risks identified.int
E009 — matched 2 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldCapturing access metadata. For example, user identification, authentication timestamps, accessed resources, session duration, origin IP add…Capturing access metadata. For example, user identification, authentication timestamps, accessed resources, session duration, origin IP add…
matchmid r=0.75 shouldDefining third-party interaction scope with logging of access attempts and activities. For example, API connections, user access sessions,…Configuring logging for third-party interactions. For example, capturing API connections, user access sessions, data exchanges, and service…
E010 — matched 6 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayConducting regular effectiveness reviews. For example, quarterly analysis of violation trends, tool performance assessment, policy updates…Conducting regular effectiveness reviews. For example, quarterly analysis of violation trends, tool performance assessment, policy updates…
matchhigh r=1.00 mayMaintaining logging and tracking systems. For example, incident creation, violation tracking with case assignment and resolution documentat…Maintaining logging and tracking systems. For example, incident creation, violation tracking with case assignment and resolution documentat…
matchhigh r=1.00 mayReal-time monitoring, blocking, or alerting capabilities.Real-time monitoring, blocking, or alerting capabilities.
matchhigh r=1.00 shouldImplementing user feedback when policy is breached. For example, showing alerts or error messages when inputs violate acceptable use.Implementing user feedback when policy is breached. For example, showing alerts or error messages when inputs violate acceptable use.
matchhigh r=1.00 shouldImplementing detection and monitoring tools. For example, prompt analysis, output filtering, usage pattern anomalies, and suspicious access…Implementing detection and monitoring tools. For example, prompt analysis, output filtering, usage pattern anomalies, and suspicious access…
matchhigh r=0.89 shouldDefining prohibited AI usage. For example, jailbreak attempts, malicious prompt injection, unauthorized data extraction, generation of harm…Defining prohibited AI usage for end-users. For example, jailbreak attempts, malicious prompt injection, unauthorized data extraction, gene…
E011 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayImplementing transfer compliance procedures. For example, assessing data transfer requirements for AI training data and inference processin…Implementing transfer compliance procedures. For example, assessing data transfer requirements for AI training data and inference processin…
matchhigh r=1.00 shouldReviewing and updating documentation regularly.Reviewing and updating documentation regularly.
matchhigh r=1.00 shouldMaintaining AI infrastructure location documentation. For example, geographic locations of foundation model processing locations and infere…Maintaining AI infrastructure location documentation. For example, geographic locations of foundation model processing locations and infere…
E012 — matched 3 · added 0 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=1.00 shouldReviewing the repository every 6 months and when additional requirements may be triggered. For example, regulations change or business oper…Reviewing the repository every 6 months and when additional requirements may be triggered. For example, regulations change or business oper…
matchhigh r=1.00 shouldDocumenting compliance procedures and strategies appropriate for company size and operations.Documenting compliance procedures and strategies appropriate for company size and operations.
matchhigh r=1.00 shouldIdentifying relevant regulations. For example, data protection laws. For example, GDPR, CCPA, sector-specific requirements, emerging AI sta…Identifying relevant regulations. For example, data protection laws. For example, GDPR, CCPA, sector-specific requirements, emerging AI sta…
E013 — matched 0 · added 5 · removed 7 · merges 0
KindDetailPrevCur
removedshouldDocumenting strategy for compliance with conformity assessment procedures.
removedshouldDocumenting techniques, procedures and systematic actions to be used for the design, design control and design verification of the AI syste…
removedshouldDocumenting techniques, procedures and systematic actions to be used for the development, quality control and quality assurance of the AI s…
removedshouldDocumenting the handling of communication with national competent authorities, other relevant authorities, including those providing or sup…
removedshouldDocumenting resource management, including security-of-supply related measures.
removedshouldAssigning and documenting accountability in the organisation for each of the aspects in the quality management system.
removedmayCollecting comprehensive documentation for EU AI Act Article 17 requirements for quality management systems. For example, strategy for regu…
addedshouldDefining quality objectives, metrics, and risk management approach for AI systems. For example, establishing performance targets, safety th…
addedshouldEstablishing change management, approval processes, and documentation standards. For example, defining review and approval requirements for…
addedshouldImplementing defect tracking, continuous improvement, and post-market monitoring. For example, maintaining issue tracking systems, conducti…
addedmayEstablishing data management and record-keeping systems. For example, documenting data governance procedures, maintaining technical documen…
addedmayDocumenting communication procedures with regulatory authorities and stakeholders. For example, establishing protocols for regulatory repor…
E014 — matched 0 · added 0 · removed 4 · merges 0
KindDetailPrevCur
removedshouldDefining report scope and recipient categories with clear criteria for when reports must be shared. For example, regulators, customers, and…
removedshouldExcluding or sanitizing technical documentation and other sensitive information that could be used for adversarial attacks.
removedmayImplementing secure delivery methods with appropriate authentication and access control. For example, dataroom access, encrypted transmiss…
removedmayDocumenting sharing procedures including approval workflows, version control, and audit trails for transparency.
E015 — matched 2 · added 1 · removed 0 · merges 0
KindDetailPrevCur
matchhigh r=0.90 shouldImplementing log storage with appropriate retention periods and access controls to support auditing and incident response.Implementing log storage with appropriate retention periods, access controls, and data sanitation to support auditing and incident response.
matchmid r=0.63 shouldCapturing system activity details. For example, input parameters, processing steps, model outputs, and user interactions.Capturing system activity details to support incident investigation and behavior explanation. For example, logging inputs, processing steps…
addedmayImplementing technical controls to ensure logs are tamper-evident and independently verifiable. For example, ensuring that captured records…
E016 — matched 2 · added 3 · removed 5 · merges 0
KindDetailPrevCur
matchhigh r=1.00 may→shouldEstablishing reactive disclosure capabilities when users ask if they are interacting with AI.Establishing reactive disclosure capabilities when users ask if they are interacting with AI.
matchmid r=0.67 may→shouldImplementing adaptive disclosure methods for different interaction types. For example, visual indicators for text, audio notifications for…Implementing AI disclosure for voice-based interactions. For example, providing audio notifications at the beginning of voice calls or inte…
removedshouldImplementing clear AI interaction disclosure at the beginning of communications, notifying users they are interacting with artificial intel…
removedshouldEnsuring disclosures are conspicuous and easily understood. For example, using prominent placement and plain language appropriate for the c…
removedshouldMaintaining disclosure visibility throughout extended interactions. For example, providing ongoing indication of AI involvement in conversa…
removedshouldLabelling AI generated audio, image and video in a machine-readable format and detectable as artificially generated or manipulated. For exa…
removedshouldInforming users if they are exposed to emotion recognition or biometric categorisation systems.
addedshouldImplementing AI disclosure for text-based interactions. For example, displaying clear notices when users interact with AI chatbots, virtual…
addedshouldLabelling AI-generated media and documents in a machine-readable and detectable format. For example, marking AI-generated images, videos, a…
addedshouldDisclosing when autonomous AI agents or automated workflows are performing actions. For example, notifying users when AI systems are making…
E017 — matched 1 · added 3 · removed 2 · merges 0
KindDetailPrevCur
matchmid r=0.62 shouldEstablishing a transparency policy defining requirements for documentation of major AI systems. For example, model capabilities, limitation…Establishing a transparency policy defining documentation requirements for major AI systems. For example, specifying required documentation…
removedshouldMaintaining a centralized repository of system documentation with appropriate access controls for internal stakeholders. For example, model…
removedshouldImplementing updates to documentation when systems are modified or new information becomes available about model performance or risks.
addedshouldCreating transparency documentation for major AI systems. For example, documenting system characteristics, data provenance, and model behav…
addedmayDefining policies for sharing transparency documentation with external stakeholders. For example, establishing when reports are shared, spe…
addedmayDocumenting sharing procedures including approval workflows, version control, and distribution tracking. For example, establishing approval…
F001 — matched 2 · added 0 · removed 2 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayImplementing malicious use detection and blocking. For example, deploying available content filtering to detect requests for malicious code…Implementing malicious use detection and blocking. For example, deploying available content filtering to detect requests for malicious code…
matchhigh r=1.00 shouldResults of testing from foundation model developer on offensive cyber capabilities and mitigations.Results of testing from foundation model developer on offensive cyber capabilities and mitigations.
removedshouldAttestation the mitigations have not been removed.
removedmayEstablishing usage monitoring and threat intelligence. For example, monitoring AI system usage for exploitation attempts and suspicious pat…
F002 — matched 2 · added 0 · removed 2 · merges 0
KindDetailPrevCur
matchhigh r=1.00 mayEstablishing catastrophic misuse monitoring. For example, monitoring AI system interactions for patterns indicating weapons development or…Establishing catastrophic misuse monitoring. For example, monitoring AI system interactions for patterns indicating weapons development or…
matchhigh r=1.00 shouldResults of testing from foundation model developer on CBRN capabilities and mitigations.Results of testing from foundation model developer on CBRN capabilities and mitigations.
removedshouldAttestation that the mitigations have not been removed.
removedmayRelevant evaluations. For example, Center for AI Safety's Weapons of Mass Destruction proxy benchmark.
Generated by AIUC1explorer v0.1.0.dev0 — per-release change analysis of the AIUC-1 standard.
AIUC-1 (c) 2025-2026 Caliber Labs PBC, DBA Artificial Intelligence Underwriting Company (AIUC).
AIUC1explorer analysis and publication (c) 2025-2026 Cabahu Pty Ltd DBA axigetik.