Sources: oct-2025: website · commit 736d027 | jan-2026: website · commit 3f3ad18
Updated 26 requirements based on audit experience, input from technical contributors, feedback from AIUC-1 Consortium members, and external peer-review comments. Detailed typical evidence submitted to pass AIUC-1 with suggested locations and concrete examples, making it easier for organizations to begin a readiness assessment of AIUC-1 Published AIUC-1 scoping questionnaire and certification process details to ensure consistent application of AIUC-1 across accredited auditors
| ID | Title | Nature | Dist. | Shoulds/Mays | Site narrative |
|---|---|---|---|---|---|
A006 | Prevent PII leakage | clarification | 0.059 | 3/3 → 2/1 (Δ -1s/-2m) | specification Increased PII protection requirements for logs Removed incident management control to avoid overlap with E001 Removed cross-tenant contaminant control to avoid… |
| ID | Title | Nature | Dist. | Shoulds/Mays | Site narrative |
|---|---|---|---|---|---|
B006 | Prevent unauthorized AI agent actions | substantive | 0.388 | 3/2 → 2/0 (Δ -1s/-2m) | clarification Clarified the requirement's focus on security aspects of system limiting Emphasized agent privilege restrictions and monitoring |
| ID | Title | Nature | Dist. | Shoulds/Mays | Site narrative |
|---|---|---|---|---|---|
C002 | Conduct pre-deployment testing | clarification | 0.240 | 3/2 → 3/2 (Δ +0s/+0m) | specification Included explicit reference to threat modelling in controls based on peer-review feedback |
C007 | Flag high risk outputs | clarification | 0.103 | 3/0 → 2/1 (Δ -1s/+1m) |
| ID | Title | Nature | Dist. | Shoulds/Mays | Site narrative |
|---|---|---|---|---|---|
E007 | [Retired] Document system change approvals | substantive | 0.759 | 2/0 → 1/0 (Δ -1s/+0m) | retired This requirement was merged into E004: Assign accountability, which already requires documenting approval with supporting evidence |
E014 | Share transparency reports | substantive | 0.790 | 2/2 → 0/0 (Δ -2s/-2m) | retired This requirement was merged into E017 to avoid overlap and to recognize transparency policy sharing procedures |
E016 | Implement AI disclosure mechanisms | editorial | 0.038 | 5/2 → 5/0 (Δ +0s/-2m) | revision Revised control activities to ensure coverage of multiple modalities (e.g. voice, text, image) |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | mid r=0.69 may | Documenting processes for customer data subject rights. For example, handling requests for access, portability, or deletion of input data,… | Documenting processes for handling end-user data subject rights. For example, handling requests for opt-in/opt-out rights, access, portabil… |
| removed | should | Defining input data usage policies. For example, opt-in/opt-out mechanisms, disclosure requirements, boundaries between training and post-d… | |
| removed | should | Implementing data retention and deletion procedures for inputs. For example, defining retention periods for training data, inference logs,… | |
| removed | should | Documenting and justifying retention periods for different categories of input data. | |
| added | should | Defining and communicating input data usage policies. Including specifying how customer data is used for inference and model training, esta… | |
| added | should | Implementing technical controls to enforce data retention and deletion policies. For example, automating data deletion based on retention s… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| removed | should | Defining output ownership rights with clear distinctions between customer inputs and AI outputs. For example, specifying customer versus ve… | |
| removed | should | Disclosing consent and opt-out procedures for outputs. For example, documenting how consent for re-use of AI-generated content is collected… | |
| removed | should | Establishing output usage policies communicated through accessible terms of service. For example, permitted uses of AI-generated content, r… | |
| added | should | Establishing output ownership and usage rights policies. For example, specifying customer ownership of AI-generated outputs versus AI input… | |
| added | should | Disclosing opt-out and deletion procedures for AI outputs. For example, documenting how customers can opt out of output storage or reuse, e… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=0.89 may | Deploying monitoring and enforcement mechanisms. For example, ensuring AI systems only perform necessary inference and logging deviations f… | Deploying monitoring mechanisms. Including ensuring AI systems only perform necessary inference and logging deviations from defined operati… |
| match | mid r=0.77 may | Integrating with existing identity and access management (IAM) systems to align agent access permissions with organizational policies. For… | Integrating with existing authorization systems to align agent access permissions with organizational policies. |
| removed | should | Configuring data collection limits to reduce data and privacy exposure. For example, limiting to time-bounded, task-specific, purpose-limit… | |
| removed | may | Establishing dynamic context-based restrictions to adjust access decisions if user role or environment changes during agent session. For ex… | |
| added | should | Configuring data collection limits to reduce data and privacy exposure. For example, limiting data collection to task-relevant information… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| removed | should | Documenting foundation model provider safeguards which may serve as primary IP protection. For example, reviewing contractual data handling… | |
| removed | should | Establishing supplementary data access controls where provider protections are insufficient. For example, limiting AI exposure to proprieta… | |
| removed | may | Implementing output monitoring procedures with automated review processes for high-risk scenarios. For example, scanning responses for prop… | |
| removed | may | Maintaining internal IP incident response and escalation procedures as part of AI failure plan on data breaches. For example, documenting i… | |
| added | should | Providing user guidance on protecting confidential information. For example, instructing employees not to input trade secrets, proprietary… | |
| added | may | Leveraging foundation model provider protections. For example, using providers with zero data retention policies, requiring contractual com… | |
| added | may | Implementing technical controls to detect proprietary information in outputs. | |
| added | may | Establishing output monitoring for high-risk IP scenarios. For example, logging AI responses that accessed confidential data sources, imple… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Implementing customer data isolation controls. For example, enforcing strict logical and physical separation of customer data, applying ten… | Implementing customer data isolation controls. For example, enforcing strict logical and physical separation of customer data, applying ten… |
| match | high r=1.00 should | Establishing explicit consent and disclosure for combined data usage. For example, informing customers when their data will be combined wit… | Establishing explicit consent and disclosure for combined data usage. For example, informing customers when their data will be combined wit… |
| removed | may | Implementing specific privacy-enhancing technologies (PETs) to reduce competitive exposure. For example, applying differential privacy to o… | |
| removed | may | Implementing inference-time data isolation to prevent leakage of one customer's data or model-derived insights into responses for other cus… | |
| removed | may | Adapting safeguards to industry-specific competitive risks. For example, applying stricter isolation for customers in the same vertical, av… | |
| added | may | Implementing specific privacy-enhancing technologies (PETs) to reduce competitive exposure. |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Integrating with existing data loss prevention (DLP) systems to monitor and block outputs containing personal data in violation of policy. | Integrating with existing data loss prevention (DLP) systems to monitor and block outputs containing personal data in violation of policy. |
| removed | should | Establishing data segregation controls. For example, isolating user sessions, implementing user-specific boundaries, preventing reuse of pr… | |
| removed | should | Establishing safeguards to prevent personal data leakage between users. For example, isolating user sessions, applying user-specific output… | |
| removed | should | Documenting protection procedures and incident management. For example, identifying PII, defining output handling policies, maintaining lea… | |
| removed | may | Implementing output monitoring. For example, scanning outputs for cross-customer data leakage, validating data source attribution. | |
| removed | may | Implementing automated detection and redaction of personal data in AI outputs. For example, using named entity recognition (NER) or data cl… | |
| added | should | Implementing safeguards to prevent personal data leakage through AI system outputs and logs. For example, filtering prompts and outputs for… | |
| added | should | Requiring authentication and authorization for PII access. For example, role-based access controls for PII-containing systems, multi-factor… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Implementing restrictions in AI acceptable use policy. | Implementing restrictions in AI acceptable use policy. |
| match | high r=1.00 should→may | Establishing supplementary content filtering mechanisms where provider protections have gaps or limitations. For example, detecting copyrig… | Establishing supplementary content filtering mechanisms where provider protections have gaps or limitations. For example, detecting copyrig… |
| match | mid r=0.63 should | Documenting foundation model provider IP protections which may serve as primary infringement safeguards. For example, reviewing copyright a… | Documenting foundation model provider IP protections which may serve as primary infringement safeguards. For example, indemnification claus… |
| removed | may | Implementing user guidance and guardrails to reduce IP risk. For example, providing usage policies that explain prohibited content types, e… | |
| removed | may | Maintaining third-party IP incident response procedures. For example, identifying potential infringement, documenting incidents and remedia… | |
| added | may | Implementing user guidance and guardrails to reduce IP risk. For example, usage policies that explain prohibited content types, user warnin… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Maintaining secure testing documentation. For example, recording test cases, methods, outcomes, and system behaviors with restricted access… | Maintaining secure testing documentation. For example, recording test cases, methods, outcomes, and system behaviors with restricted access… |
| match | high r=0.98 may | Aligning adversarial testing with broader security testing programs. For example, integrating AI-specific test cases into penetration testi… | Aligning adversarial testing with broader security testing programs. For example, integrating AI-specific test cases into broader penetrati… |
| match | mid r=0.79 should | Conducting comprehensive adversarial testing quarterly and after material system changes. For example, performing structured red-teaming, p… | Conducting comprehensive adversarial testing at least quarterly. For example, performing structured red-teaming, prompt injection assessmen… |
| match | mid r=0.70 should | Establishing a taxonomy for adversarial risks. For example, referencing and tailoring relevant categories from NIST's AI 100-2e2023 attack… | Establishing a taxonomy for adversarial risks. For example, drawing on NIST's AI 100-2e2023 attack classifications and aligning these to sy… |
| removed | should | Establishing improvement processes based on findings. For example, assigning owners and remediation timelines based on test severity (e.g.… | |
| added | should | Establishing improvement processes based on findings. For example, assigning owners and remediation timelines based on test severity, track… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Integrating adversarial input detection into existing security operations tooling. For example, forwarding flagged inputs to SIEM platforms… | Integrating adversarial input detection into existing security operations tooling. For example, forwarding flagged inputs to SIEM platforms… |
| match | high r=1.00 should | Maintaining detection effectiveness through quarterly reviews. For example, updating detection rules based on emerging adversarial techniqu… | Maintaining detection effectiveness through quarterly reviews. For example, updating detection rules based on emerging adversarial techniqu… |
| match | high r=1.00 should | Establishing detection and alerting. For example, implementing monitoring for prompt injection patterns, jailbreak techniques, adversarial… | Establishing detection and alerting. For example, implementing monitoring for prompt injection patterns, jailbreak techniques, adversarial… |
| match | mid r=0.65 may | Implementing adversarial input detection prior to AI model processing where feasible. For example, using lightweight pattern-matching, beha… | Implementing adversarial input detection prior to AI model processing where feasible. For example, using pre-processing filters to flag lik… |
| removed | should | Implementing incident logging and response procedures. For example, logging suspected attacks with timestamps, user/session context, and in… | |
| added | should | Implementing incident logging and response procedures. For example, logging suspected adversarial attacks with relevant context, escalating… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Establishing approval processes. For example, requiring designated review for public content referencing AI capabilities in e.g. publicatio… | Establishing approval processes. For example, requiring designated review for public content referencing AI capabilities in e.g. publicatio… |
| match | high r=1.00 should | Controlling organizational information to balance transparency with security. For example, limiting disclosure of AI team details, developm… | Controlling organizational information to balance transparency with security. For example, limiting disclosure of AI team details, developm… |
| match | high r=1.00 should | Documenting limitations on technical information release. For example, limiting public disclosure of model architectures, algorithms, train… | Documenting limitations on technical information release. For example, limiting public disclosure of model architectures, algorithms, train… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | mid r=0.75 should | Implementing systems distinguishing between high-volume legitimate usage and adversarial behavior. For example, using behavioral analytics,… | Implementing systems distinguishing between high-volume legitimate usage and adversarial behavior. For example, using behavioral analytics… |
| removed | should | Implementing rate limiting and query restrictions. For example, establishing per-user query quotas and rate limits to prevent model extract… | |
| removed | should | Conducting simulated external attack testing. For example, performing automated scraping tests, brute force attempts, and reconnaissance ac… | |
| removed | should | Maintaining endpoint security through remediation. For example, documenting test results and identified vulnerabilities, implementing prote… | |
| added | should | Implementing rate limiting and query restrictions. For example, establishing per-user quotas to prevent model extraction, blocking excessiv… | |
| added | should | Conducting simulated external attack testing of AI endpoints. For example, performing automated attack simulations, testing endpoint protec… | |
| added | should | Maintaining endpoint security through remediation. For example, tracking identified vulnerabilities, implementing protective measures based… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Periodically evaluating filter performance and adjusting thresholds accordingly. For example, accuracy, latency, false positives/negatives. | Periodically evaluating filter performance and adjusting thresholds accordingly. For example, accuracy, latency, false positives/negatives. |
| match | high r=1.00 may | Providing feedback to users when inputs are blocked. | Providing feedback to users when inputs are blocked. |
| match | mid r=0.61 may | Logging flagged prompts for analysis and refinement of filters, while ensuring compliance with privacy obligations. For example, excluding… | Logging flagged prompts for analysis and refinement of filters, while ensuring compliance with privacy obligations. |
| removed | should | Integrating automated moderation tools to scan user inputs for violations of content policies such as violence, hate, or self-harm. For exa… | |
| removed | should | Blocking, redirecting, or modifying flagged inputs before they reach the foundation model. | |
| removed | should | Establishing confidence thresholds or rules for when to block, warn, log, or allow inputs based on risk category and severity. | |
| removed | should | Documenting the moderation logic and thresholds used, including rationale for chosen tool(s). | |
| added | should | Integrating automated moderation tools to filter inputs before they reach the foundation model. For example, integrating third-party modera… | |
| added | may | Documenting the moderation logic and rationale. For example, explaining chosen moderation tools, threshold justifications, and decision cri… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| removed | should | Configuring contextual access controls for AI agents. For example, enforcing task-based tool access using declarative policy models (e.g. J… | |
| removed | should | Implementing privilege limiting for autonomous behavior. For example, restricting agents from escalating access or acting beyond permitted… | |
| removed | should | Deploying monitoring and enforcement mechanisms. For example, ensuring AI systems only perform necessary inference and logging deviations f… | |
| removed | may | Defining automatic restriction triggers. For example, revoking tool access or suppressing outputs when agent context diverges from declared… | |
| removed | may | Integrating agent access decisions with existing identity and access management (IAM) systems. For example, aligning agent privileges with… | |
| added | should | Implementing technical restrictions that limit agent capabilities to authorized scope. For example, restricting agent access to approved ba… | |
| added | should | Deploying monitoring and alerting for agent actions that exceed security boundaries. For example, logging all agent service interactions, a… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Conducting access reviews and updates at least quarterly. For example, validating access assignments, updating based on policy or role chan… | Conducting access reviews and updates at least quarterly. For example, validating access assignments, updating based on policy or role chan… |
| match | high r=1.00 should | Restricting administrative and configuration privileges to authorized personnel. For example, limiting ability to alter system behavior, to… | Restricting administrative and configuration privileges to authorized personnel. For example, limiting ability to alter system behavior, to… |
| match | high r=1.00 should | Implementing system-level access controls tailored to AI systems. For example, using role-based or attribute-based access to restrict acces… | Implementing system-level access controls tailored to AI systems. For example, using role-based or attribute-based access to restrict acces… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Securing model hosting environments. For example, using up-to-date and minimal container images, scanning for known vulnerabilities in depe… | Securing model hosting environments. For example, using up-to-date and minimal container images, scanning for known vulnerabilities in depe… |
| match | high r=1.00 should | Establishing deployment security controls. For example, applying scoped API tokens or signed requests, using TLS for all endpoint traffic,… | Establishing deployment security controls. For example, applying scoped API tokens or signed requests, using TLS for all endpoint traffic,… |
| match | high r=1.00 should | Implementing model access protection. For example, restricting access to production AI models based on job function and operational need, i… | Implementing model access protection. For example, restricting access to production AI models based on job function and operational need, i… |
| match | high r=0.81 may | Verifying model integrity before and during deployment. For example, using cryptographic checksums or signed artifacts to detect tampering,… | Verifying model integrity before and during deployment. For example, using cryptographic checksums or signed artifacts to detect tampering,… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Reducing or limiting the number of results shown in outputs to relevant only to balance security and utility. For example, character limits… | Reducing or limiting the number of results shown in outputs to relevant only to balance security and utility. For example, character limits… |
| match | high r=0.88 may | Limiting the fidelity of numerical outputs in certain use cases. For example, applying output rounding, threshold bands, or obfuscation tec… | Limiting the fidelity of model outputs in certain use cases. For example, applying output rounding, threshold bands, or obfuscation techniq… |
| removed | should | Filtering sensitive information that may reveal internal system behavior. For example, removing or abstracting technical details about mode… | |
| removed | should | Providing user-facing notices or documentation about output limitations. For example, clearly indicating when results have been truncated,… | |
| added | may | Providing user-facing notices or documentation about output limitations. |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Establishing severity grading appropriate to organizational context and risk tolerance. For example, implementing consistent scoring method… | Establishing severity grading appropriate to organizational context and risk tolerance. For example, implementing consistent scoring method… |
| match | high r=1.00 should | Defining risk categories with severity levels and examples based on industry and deployment context. For example, classifying harmful outpu… | Defining risk categories with severity levels and examples based on industry and deployment context. For example, classifying harmful outpu… |
| match | mid r=0.62 should | Aligning risk taxonomy with external frameworks and standards. For example, NIST AI RMF functions, EU AI Act article 9, ISO42001 controls. | Aligning risk taxonomy with external frameworks and standards. |
| removed | should | Maintaining taxonomy currency with documented change management. For example, reviewing and updating risk categories quarterly or when new… | |
| removed | may | Identifying additional risk categories that are considered harmful given nature of operations. For example, hallucinations, out-of-scope co… | |
| added | should | Maintaining taxonomy currency with documented change management. For example, updating based on emerging threats or incidents. |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Completing risk assessments of identified issues before system deployment. For example, potential impact analysis, mitigation strategies, a… | Completing risk assessments of identified issues before system deployment. For example, potential impact analysis, mitigation strategies, a… |
| match | high r=1.00 should | Conducting pre-deployment testing with documented results and identified issues. For example, structured hallucination testing, adversarial… | Conducting pre-deployment testing with documented results and identified issues. For example, structured hallucination testing, adversarial… |
| match | high r=0.94 should | Obtaining approval sign-offs from designated accountable leads with documented rationale for approval decisions and maintained records for… | Obtaining approval sign-offs from designated accountable. For example, documented rationale for approval decisions and maintained records f… |
| match | mid r=0.79 may | Integrating AI system testing into established software development lifecycle (SDLC) gates. For example, requiring risk evaluation and sign… | Integrating AI system testing into established software development lifecycle (SDLC) gates. For example, including threat modelling and ris… |
| removed | may | Implementing pre-deployment vulnerability scanning of AI artifacts and dependencies. For example, scanning model files (e.g. pickle, ONNX)… | |
| added | may | Implementing pre-deployment vulnerability scanning of AI artifacts and dependencies. For example, scanning AI models and ML libraries for s… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Implementing content filtering for harmful output types. For example, detecting and blocking distressed responses, angry language, offensiv… | Implementing content filtering for harmful output types. For example, detecting and blocking distressed responses, angry language, offensiv… |
| match | high r=0.96 should→may | Maintaining bias detection and mitigation controls. For example, monitoring for discriminatory patterns, implementing fairness checks in ou… | Implementing bias detection and mitigation controls. For example, monitoring for discriminatory patterns, implementing fairness checks in o… |
| match | high r=0.93 should | Establishing safety guardrails for advice generation. For example, restricting high-risk recommendations in sensitive domains, requiring di… | Implementing guardrails for advice generation. For example, restricting high-risk recommendations in sensitive domains, requiring disclaime… |
| removed | may | Evaluating harm mitigation controls using performance metrics. For example, tracking false positives (overblocking safe content) and false… | |
| removed | may | Establishing review and appeal mechanisms. For example, allowing flagged outputs to be escalated for manual review, recording override deci… | |
| added | may | Evaluating harm mitigation controls using performance metrics. |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | mid r=0.66 should | Maintaining scope monitoring and adjustment capabilities. For example, tracking boundary violations, updating restrictions based on emergin… | Tracking out-of-scope violations and updating boundaries. For example, logging boundary violations, adjusting restrictions based on misuse… |
| removed | should | Implementing topic boundary enforcement. For example, detecting and redirecting conversations outside intended use cases as defined in AI a… | |
| removed | should | Establishing scope violation response procedures. For example, automated redirection messages, escalation for persistent attempts. | |
| removed | may | Implementing user education on system scope and limitations. For example, displaying onboarding tooltips, publishing usage guidelines or FA… | |
| added | should | Detecting and blocking out-of-scope requests. For example, detecting conversations outside intended use cases, blocking prohibited topics,… | |
| added | may | Providing user guidance on system capabilities and limitations. For example, communicating what the AI system can and cannot do, intended u… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Implementing detection and blocking mechanisms aligned with organizational risk taxonomy. For example, deploying filtering based on defined… | Implementing detection and blocking mechanisms aligned with organizational risk taxonomy. For example, deploying filtering based on defined… |
| match | mid r=0.61 may | Establishing escalation procedures for flagged high risk content. For example, human review workflows, approval requirements for edge cases… | Establishing escalation procedures for flagged high-risk content. For example, defining when human review is required and establishing appr… |
| removed | should | Maintaining risk-based response controls. For example, flagging and blocking mechanisms, logging for monitoring purposes. | |
| removed | may | Implementing automated real-time response mechanisms. For example, triggering dynamic warnings, blocking or modifying model responses based… | |
| added | should | Implementing response actions for detected risks. For example, blocking high-severity outputs, flagging medium-risk content for review, log… | |
| added | may | Implementing automated real-time interventions. For example, blocking or modifying outputs based on severity. |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | mid r=0.66 may | Detecting advanced output-based attack patterns. For example, identifying prompt injection chains, model-output subversion (e.g. jailbreak… | Detecting advanced output-based attack patterns. For example, identifying prompt injection attempts, model subversion techniques, payloads… |
| removed | should | Establishing output sanitization and validation procedures before presenting content to users. For example, stripping or encoding HTML, Jav… | |
| removed | should | Implementing safety-specific labeling and handling protocols. For example, clearly marking untrusted, distinguishing untrusted third-party… | |
| removed | should | Maintaining detection and monitoring capabilities. For example, logging sanitization activities, implementing alerting for suspicious conte… | |
| added | should | Establishing output sanitization and validation procedures before presenting content to users. For example, encoding or stripping potential… | |
| added | should | Implementing security labeling and content handling based on trust level. For example, marking untrusted or third-party content, distinguis… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| removed | should | Defining high-risk recommendation criteria drawing on risk taxonomy. For example, financial advice exceeding company thresholds, medical or… | |
| removed | should | Implementing automated detection using keyword filtering, confidence scoring, or rule-based assessment with adjustable sensitivity settings. | |
| removed | should | Establishing human review workflows. For example, designated reviewers from available staff, escalation procedures for complex cases, queue… | |
| added | should | Defining high-risk output criteria drawing on risk taxonomy. | |
| added | should | Implementing automated detection mechanisms for high-risk outputs. For example, using content filtering, risk scoring, or classification mo… | |
| added | may | Establishing human review workflows for flagged high-risk outputs. For example, assigning reviewers, defining escalation procedures for com… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Integrating AI output monitoring with existing security tools. For example, forwarding alerts and flagged outputs to SIEM platforms, applyi… | Integrating AI output monitoring with existing security tools. For example, forwarding alerts and flagged outputs to SIEM platforms, applyi… |
| match | high r=1.00 should→may | Maintaining documentation. For example, recording identified scenarios with clear examples, updating risk taxonomy based on monitoring find… | Maintaining documentation. For example, recording identified scenarios with clear examples, updating risk taxonomy based on monitoring find… |
| removed | should | Implementing proactive detection. For example, defining potential scenarios based on risk taxonomy that could generate harmful outputs unde… | |
| removed | should | Establishing ongoing monitoring. For example, conducting regular evaluations prioritized by risk severity, using methods such as output sam… | |
| added | should | Establishing ongoing monitoring of AI outputs across risk categories. For example, conducting regular evaluations prioritized by risk sever… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Analyzing collected feedback using structured methodologies. For example, categorizing by risk domain, prioritizing based on frequency and… | Analyzing collected feedback using structured methodologies. For example, categorizing by risk domain, prioritizing based on frequency and… |
| match | high r=1.00 should→may | Reviewing user feedback and intervention logs regularly. For example, evaluating patterns in interventions, adapting communication methods… | Reviewing user feedback and intervention logs regularly. For example, evaluating patterns in interventions, adapting communication methods… |
| match | high r=1.00 should | Ensuring accessibility of feedback and intervention mechanisms. For example, adhering to WCAG 2.1 standards for color contrast, screen read… | Ensuring accessibility of feedback and intervention mechanisms. For example, adhering to WCAG 2.1 standards for color contrast, screen read… |
| match | high r=1.00 should | Enabling user intervention capabilities. For example, providing mechanisms for users to pause, stop, or redirect system behavior, implement… | Enabling user intervention capabilities. For example, providing mechanisms for users to pause, stop, or redirect system behavior, implement… |
| removed | should | Establishing on-screen communication systems. For example, implementing real-time display of system status, intervention notices, disclaime… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=0.95 should | Appointing qualified third-party assessors. For example, selecting assessors with relevant technical capabilities for identified risk areas… | Appointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m… |
| match | high r=0.85 should | Maintaining documentation. For example, recording third-party qualifications, testing scope, results, and remediation actions taken, tracki… | Maintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti… |
| removed | should | Conducting regular testing. For example, performing assessments of harmful outputs at least every quarter, defining testing scope and metho… | |
| added | should | Conducting regular testing. Including performing assessments of harmful outputs at least every quarter, defining testing scope and methodol… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=0.95 should | Appointing qualified third-party assessors. For example, selecting assessors with relevant technical capabilities for identified risk areas… | Appointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m… |
| match | high r=0.85 should | Maintaining documentation. For example, recording third-party qualifications, testing scope, results, and remediation actions taken, tracki… | Maintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti… |
| removed | should | Conducting regular testing. For example, performing assessments of out-of-scope outputs at least every quarter, defining testing scope and… | |
| added | should | Conducting regular testing. Including defining testing scope and methodologies based on risk taxonomy and performing assessments of out-of-… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=0.95 should | Appointing qualified third-party assessors. For example, selecting assessors with relevant technical capabilities for identified risk areas… | Appointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m… |
| match | high r=0.85 should | Maintaining documentation. For example, recording third-party qualifications, testing scope, results, and remediation actions taken, tracki… | Maintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti… |
| removed | should | Conducting regular testing. For example, performing assessments of high-risk areas at least every quarter, defining testing scope and metho… | |
| added | should | Conducting regular testing. Including defining testing scope and methodologies based on risk taxonomy and performing assessments of high-ri… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Maintaining uncertainty communication. For example, displaying confidence levels, providing appropriate disclaimers for generated informati… | Maintaining uncertainty communication. For example, displaying confidence levels, providing appropriate disclaimers for generated informati… |
| match | high r=1.00 should | Establishing information source validation. For example, requiring citations for factual claims, implementing source reliability checks. | Establishing information source validation. For example, requiring citations for factual claims, implementing source reliability checks. |
| match | high r=1.00 should | Implementing factual accuracy controls. For example, deploying available fact-checking mechanisms, flagging uncertain or low-confidence res… | Implementing factual accuracy controls. For example, deploying available fact-checking mechanisms, flagging uncertain or low-confidence res… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=0.95 should | Appointing qualified third-party assessors. For example, selecting assessors with relevant technical capabilities for identified risk areas… | Appointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m… |
| match | high r=0.85 should | Maintaining documentation. For example, recording third-party qualifications, testing scope, results, and remediation actions taken, tracki… | Maintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti… |
| removed | should | Conducting regular testing. For example, performing assessments of hallucinated outputs at least every quarter, defining testing scope and… | |
| added | should | Conducting regular testing. Including defining testing scope and methodologies based on risk taxonomy and performing assessments at least e… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Establishing execution monitoring and logging. For example, tracking all tool calls, monitoring for unauthorized access attempts or scope v… | Establishing execution monitoring and logging. For example, tracking all tool calls, monitoring for unauthorized access attempts or scope v… |
| match | high r=1.00 should | Enforcing rate limits and transaction caps for autonomous tool use. | Enforcing rate limits and transaction caps for autonomous tool use. |
| match | high r=1.00 should | Implementing function call validation and authorization. For example, restricting tool access to approved functions, validating parameters… | Implementing function call validation and authorization. For example, restricting tool access to approved functions, validating parameters… |
| match | high r=0.93 should→may | Reviewing patterns of AI tool usage for anomalies, updating tool permissions, and retiring unused or high-risk functions during scheduled e… | Reviewing patterns of AI tool usage. For example, identifying anomalies, updating tool permissions, and retiring unused or high-risk functi… |
| removed | should | Maintaining decision boundary enforcement. For example, limiting autonomous actions to defined parameters, requiring human approval for sen… | |
| added | may | Requiring human approval for sensitive tool operations. For example, requiring human confirmation before executing high-risk actions, imple… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=0.95 should | Appointing qualified third-party assessors. For example, selecting assessors with relevant technical capabilities for identified risk areas… | Appointing qualified third-party assessors. Including selecting assessors with relevant technical capabilities for identified risk areas, m… |
| match | high r=0.85 should | Maintaining documentation. For example, recording third-party qualifications, testing scope, results, and remediation actions taken, tracki… | Maintaining documentation. Including testing scope, results, and remediation actions taken, tracking follow-up activities and resolution ti… |
| removed | should | Conducting regular testing. For example, performing assessments of tool calls at least every quarter, defining testing scope and methodolog… | |
| added | should | Conducting regular testing. Including defining testing scope and methodologies based on risk taxonomy and performing assessments of tool ca… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Establishing evidence collection requirements with guidance on preserving evidence for potential legal review. For example, system logs, us… | Establishing evidence collection requirements with guidance on preserving evidence for potential legal review. For example, system logs, us… |
| match | high r=1.00 should | Implementing security remediation measures. For example, system freeze capabilities, vulnerability fixes, access control updates, and coord… | Implementing security remediation measures. For example, system freeze capabilities, vulnerability fixes, access control updates, and coord… |
| match | high r=1.00 should | Defining breach notification procedures. For example, customer communications, regulatory reporting requirements, and vendor notifications… | Defining breach notification procedures. For example, customer communications, regulatory reporting requirements, and vendor notifications… |
| match | high r=1.00 should | Assigning a breach response lead from existing staff. For example, IT manager, security officer, or designated executive with authority to… | Assigning a breach response lead from existing staff. For example, IT manager, security officer, or designated executive with authority to… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Coordinating external support engagement. For example, legal counsel consultation, PR support, and insurance claim procedures. | Coordinating external support engagement. For example, legal counsel consultation, PR support, and insurance claim procedures. |
| match | high r=1.00 may | Defining harmful output categories with reference to risk taxonomy. For example, discriminatory content, offensive material, inappropriate… | Defining harmful output categories with reference to risk taxonomy. For example, discriminatory content, offensive material, inappropriate… |
| match | high r=1.00 should | Establishing immediate mitigation steps with designated staff responsibilities. For example, system freeze capabilities, output suppression… | Establishing immediate mitigation steps with designated staff responsibilities. For example, system freeze capabilities, output suppression… |
| match | high r=1.00 should | Implementing customer communication protocols. For example, disclosure procedures, explanation of corrective actions, and follow-up commitm… | Implementing customer communication protocols. For example, disclosure procedures, explanation of corrective actions, and follow-up commitm… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Coordinating potential external support. For example, legal consultation for significant claims, financial review when needed, and insuranc… | Coordinating potential external support. For example, legal consultation for significant claims, financial review when needed, and insuranc… |
| match | high r=1.00 should | Implementing remediation measures. For example, system freeze capabilities, model adjustments, output validation improvements, customer not… | Implementing remediation measures. For example, system freeze capabilities, model adjustments, output validation improvements, customer not… |
| match | high r=1.00 should | Establishing compensation assessment procedures. For example, loss evaluation methods, settlement approaches, and payment authorization lev… | Establishing compensation assessment procedures. For example, loss evaluation methods, settlement approaches, and payment authorization lev… |
| removed | may | Defining hallucination incident types. For example, factual errors or incorrect recommendations relevant to company context and customer b… | |
| added | may | Defining hallucination incident types. |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Implementing code signing and verification processes for AI models, libraries, and deployment artefacts to ensure only digitally signed com… | Implementing code signing and verification processes for AI models, libraries, and deployment artefacts to ensure only digitally signed com… |
| match | high r=1.00 should | Assigning an accountable lead as approver for each of these changes. Can follow a RACI structure to formalize roles of those consulted and… | Assigning an accountable lead as approver for each of these changes. Can follow a RACI structure to formalize roles of those consulted and… |
| match | high r=1.00 should | Defining AI system changes requiring approval including model selection, material changes to the meta prompt, adding / removing guardrails,… | Defining AI system changes requiring approval including model selection, material changes to the meta prompt, adding / removing guardrails,… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may→should | Reviewing deployment decisions when requirements change. For example, reassessing choices when data sensitivity, regulations, or threat lan… | Reviewing deployment decisions when requirements change. For example, reassessing choices when data sensitivity, regulations, or threat lan… |
| match | high r=1.00 should | Documenting decision criteria and rationale. For example, establishing clear selection factors, maintaining records of deployment choices w… | Documenting decision criteria and rationale. For example, establishing clear selection factors, maintaining records of deployment choices w… |
| match | high r=1.00 should | Conducting deployment risk assessments. For example, evaluating data sensitivity, regulatory compliance requirements, IP protection needs,… | Conducting deployment risk assessments. For example, evaluating data sensitivity, regulatory compliance requirements, IP protection needs,… |
| removed | should | Implementing deployment-appropriate security controls. For example, configuring cloud-specific protections or on-premises security measures… | |
| removed | may | Implementing hybrid deployment strategies. For example, using on-premises for sensitive data, cloud for less sensitive workloads, with secu… | |
| removed | may | Establishing cloud vendor management procedures. For example, conducting provider due diligence, implementing contractual protections for d… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Maintaining assessment records with sufficient detail for audit purposes and retaining due diligence evidence before vendor approval. | Maintaining assessment records with sufficient detail for audit purposes and retaining due diligence evidence before vendor approval. |
| match | high r=0.96 should | Defining assessment criteria for foundational or upstream AI models. For example, data handling practices, PII controls, security measures,… | Defining assessment criteria for foundational or upstream AI models. For example, data handling and ownership practices, PII controls, secu… |
| match | high r=0.92 should | Conducting documented assessments. For example, scoring results, verification activities such as certifications reviewed and references con… | Conducting documented assessments. For example, scoring results, verification activities such as certifications reviewed and references con… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Documenting formal review and approval decisions for changes defined in E004: Assign accountability. | Documenting formal review and approval decisions for changes defined in E004: Assign accountability. |
| removed | should | Documenting the approval workflow with sufficient detail for review purposes. For example, who approved the change, what evidence was revie… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Collecting and implementing external feedback on AI systems. For example, system risks, new threat patterns, new mitigation strategies. | Collecting and implementing external feedback on AI systems. For example, system risks, new threat patterns, new mitigation strategies. |
| match | high r=1.00 should | Maintaining a centralized repository of decision records and internal review of these record. For example, supporting evidence reviewed, re… | Maintaining a centralized repository of decision records and internal review of these record. For example, supporting evidence reviewed, re… |
| match | high r=1.00 should | Reviewing decision processes every quarter including AI system changes, foundational model selection, security assessment. | Reviewing decision processes every quarter including AI system changes, foundational model selection, security assessment. |
| match | high r=0.97 should | Documenting and tracking remediation of any risks identified. | Documenting and tracking remediation of any risks identified.int |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Capturing access metadata. For example, user identification, authentication timestamps, accessed resources, session duration, origin IP add… | Capturing access metadata. For example, user identification, authentication timestamps, accessed resources, session duration, origin IP add… |
| match | mid r=0.75 should | Defining third-party interaction scope with logging of access attempts and activities. For example, API connections, user access sessions,… | Configuring logging for third-party interactions. For example, capturing API connections, user access sessions, data exchanges, and service… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Conducting regular effectiveness reviews. For example, quarterly analysis of violation trends, tool performance assessment, policy updates… | Conducting regular effectiveness reviews. For example, quarterly analysis of violation trends, tool performance assessment, policy updates… |
| match | high r=1.00 may | Maintaining logging and tracking systems. For example, incident creation, violation tracking with case assignment and resolution documentat… | Maintaining logging and tracking systems. For example, incident creation, violation tracking with case assignment and resolution documentat… |
| match | high r=1.00 may | Real-time monitoring, blocking, or alerting capabilities. | Real-time monitoring, blocking, or alerting capabilities. |
| match | high r=1.00 should | Implementing user feedback when policy is breached. For example, showing alerts or error messages when inputs violate acceptable use. | Implementing user feedback when policy is breached. For example, showing alerts or error messages when inputs violate acceptable use. |
| match | high r=1.00 should | Implementing detection and monitoring tools. For example, prompt analysis, output filtering, usage pattern anomalies, and suspicious access… | Implementing detection and monitoring tools. For example, prompt analysis, output filtering, usage pattern anomalies, and suspicious access… |
| match | high r=0.89 should | Defining prohibited AI usage. For example, jailbreak attempts, malicious prompt injection, unauthorized data extraction, generation of harm… | Defining prohibited AI usage for end-users. For example, jailbreak attempts, malicious prompt injection, unauthorized data extraction, gene… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Implementing transfer compliance procedures. For example, assessing data transfer requirements for AI training data and inference processin… | Implementing transfer compliance procedures. For example, assessing data transfer requirements for AI training data and inference processin… |
| match | high r=1.00 should | Reviewing and updating documentation regularly. | Reviewing and updating documentation regularly. |
| match | high r=1.00 should | Maintaining AI infrastructure location documentation. For example, geographic locations of foundation model processing locations and infere… | Maintaining AI infrastructure location documentation. For example, geographic locations of foundation model processing locations and infere… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 should | Reviewing the repository every 6 months and when additional requirements may be triggered. For example, regulations change or business oper… | Reviewing the repository every 6 months and when additional requirements may be triggered. For example, regulations change or business oper… |
| match | high r=1.00 should | Documenting compliance procedures and strategies appropriate for company size and operations. | Documenting compliance procedures and strategies appropriate for company size and operations. |
| match | high r=1.00 should | Identifying relevant regulations. For example, data protection laws. For example, GDPR, CCPA, sector-specific requirements, emerging AI sta… | Identifying relevant regulations. For example, data protection laws. For example, GDPR, CCPA, sector-specific requirements, emerging AI sta… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| removed | should | Documenting strategy for compliance with conformity assessment procedures. | |
| removed | should | Documenting techniques, procedures and systematic actions to be used for the design, design control and design verification of the AI syste… | |
| removed | should | Documenting techniques, procedures and systematic actions to be used for the development, quality control and quality assurance of the AI s… | |
| removed | should | Documenting the handling of communication with national competent authorities, other relevant authorities, including those providing or sup… | |
| removed | should | Documenting resource management, including security-of-supply related measures. | |
| removed | should | Assigning and documenting accountability in the organisation for each of the aspects in the quality management system. | |
| removed | may | Collecting comprehensive documentation for EU AI Act Article 17 requirements for quality management systems. For example, strategy for regu… | |
| added | should | Defining quality objectives, metrics, and risk management approach for AI systems. For example, establishing performance targets, safety th… | |
| added | should | Establishing change management, approval processes, and documentation standards. For example, defining review and approval requirements for… | |
| added | should | Implementing defect tracking, continuous improvement, and post-market monitoring. For example, maintaining issue tracking systems, conducti… | |
| added | may | Establishing data management and record-keeping systems. For example, documenting data governance procedures, maintaining technical documen… | |
| added | may | Documenting communication procedures with regulatory authorities and stakeholders. For example, establishing protocols for regulatory repor… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| removed | should | Defining report scope and recipient categories with clear criteria for when reports must be shared. For example, regulators, customers, and… | |
| removed | should | Excluding or sanitizing technical documentation and other sensitive information that could be used for adversarial attacks. | |
| removed | may | Implementing secure delivery methods with appropriate authentication and access control. For example, dataroom access, encrypted transmiss… | |
| removed | may | Documenting sharing procedures including approval workflows, version control, and audit trails for transparency. |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=0.90 should | Implementing log storage with appropriate retention periods and access controls to support auditing and incident response. | Implementing log storage with appropriate retention periods, access controls, and data sanitation to support auditing and incident response. |
| match | mid r=0.63 should | Capturing system activity details. For example, input parameters, processing steps, model outputs, and user interactions. | Capturing system activity details to support incident investigation and behavior explanation. For example, logging inputs, processing steps… |
| added | may | Implementing technical controls to ensure logs are tamper-evident and independently verifiable. For example, ensuring that captured records… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may→should | Establishing reactive disclosure capabilities when users ask if they are interacting with AI. | Establishing reactive disclosure capabilities when users ask if they are interacting with AI. |
| match | mid r=0.67 may→should | Implementing adaptive disclosure methods for different interaction types. For example, visual indicators for text, audio notifications for… | Implementing AI disclosure for voice-based interactions. For example, providing audio notifications at the beginning of voice calls or inte… |
| removed | should | Implementing clear AI interaction disclosure at the beginning of communications, notifying users they are interacting with artificial intel… | |
| removed | should | Ensuring disclosures are conspicuous and easily understood. For example, using prominent placement and plain language appropriate for the c… | |
| removed | should | Maintaining disclosure visibility throughout extended interactions. For example, providing ongoing indication of AI involvement in conversa… | |
| removed | should | Labelling AI generated audio, image and video in a machine-readable format and detectable as artificially generated or manipulated. For exa… | |
| removed | should | Informing users if they are exposed to emotion recognition or biometric categorisation systems. | |
| added | should | Implementing AI disclosure for text-based interactions. For example, displaying clear notices when users interact with AI chatbots, virtual… | |
| added | should | Labelling AI-generated media and documents in a machine-readable and detectable format. For example, marking AI-generated images, videos, a… | |
| added | should | Disclosing when autonomous AI agents or automated workflows are performing actions. For example, notifying users when AI systems are making… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | mid r=0.62 should | Establishing a transparency policy defining requirements for documentation of major AI systems. For example, model capabilities, limitation… | Establishing a transparency policy defining documentation requirements for major AI systems. For example, specifying required documentation… |
| removed | should | Maintaining a centralized repository of system documentation with appropriate access controls for internal stakeholders. For example, model… | |
| removed | should | Implementing updates to documentation when systems are modified or new information becomes available about model performance or risks. | |
| added | should | Creating transparency documentation for major AI systems. For example, documenting system characteristics, data provenance, and model behav… | |
| added | may | Defining policies for sharing transparency documentation with external stakeholders. For example, establishing when reports are shared, spe… | |
| added | may | Documenting sharing procedures including approval workflows, version control, and distribution tracking. For example, establishing approval… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Implementing malicious use detection and blocking. For example, deploying available content filtering to detect requests for malicious code… | Implementing malicious use detection and blocking. For example, deploying available content filtering to detect requests for malicious code… |
| match | high r=1.00 should | Results of testing from foundation model developer on offensive cyber capabilities and mitigations. | Results of testing from foundation model developer on offensive cyber capabilities and mitigations. |
| removed | should | Attestation the mitigations have not been removed. | |
| removed | may | Establishing usage monitoring and threat intelligence. For example, monitoring AI system usage for exploitation attempts and suspicious pat… |
| Kind | Detail | Prev | Cur |
|---|---|---|---|
| match | high r=1.00 may | Establishing catastrophic misuse monitoring. For example, monitoring AI system interactions for patterns indicating weapons development or… | Establishing catastrophic misuse monitoring. For example, monitoring AI system interactions for patterns indicating weapons development or… |
| match | high r=1.00 should | Results of testing from foundation model developer on CBRN capabilities and mitigations. | Results of testing from foundation model developer on CBRN capabilities and mitigations. |
| removed | should | Attestation that the mitigations have not been removed. | |
| removed | may | Relevant evaluations. For example, Center for AI Safety's Weapons of Mass Destruction proxy benchmark. |