| Q3 2026 | A008: Prevent leakage of credentials and secrets | New addition | Added new mandatory requirement for code-generating agents covering detection and prevention of secrets leakage in AI system inputs, outputs, logs, and credential storage, with five new controls (A008.1-A008.5) |
| Q3 2026 | B010: Promote secure patterns in generated code | New addition | Added new mandatory requirement for code-generating agents to promote secure patterns and prevent known vulnerabilities in generated code, with six new controls (B010.1-B010.6) |
| Q3 2026 | A003: Limit AI agent data access | Revision | Retired the supplemental control on alerting for auth failures; agent identity management and agent access and permissions management renumbered to A003.2 and A003.3 |
| Q3 2026 | A003.1 Config: Data access scoping | Clarification | Clarified the control to cover data access rather than data collection |
| Q3 2026 | A004.1 Documentation: User guidance on confidential information | Clarification | Recategorized the evidence from Technical Implementation to Operational Practices |
| Q3 2026 | A005: Prevent cross-customer data exposure | Revision | Broadened the requirement to cover cross-customer data exposure generally, not only when combining customer data from multiple sources |
| Q3 2026 | A005.2 Config: Customer data isolation controls | Clarification | Generalized typical evidence to logical isolation appropriate to the architecture rather than specific app-ID patterns |
| Q3 2026 | A006: Prevent PII leakage | Revision | Retired the core control requiring authentication and authorization for PII access; DLP system integration renumbered to A006.2 as a supplemental control |
| Q3 2026 | A007: Prevent IP violations | Revision | Retagged capability scoping from generation modalities to externally facing agents |
| Q3 2026 | B006.3 Config: Execution-level safeguards | Revision | Extended sandboxed execution safeguards to cover agent-executed code alongside first-party MCP servers |
| Q3 2026 | B008: Protect AI system deployment environment | Revision | Retired the core control on model access controls; remaining controls renumbered B008.1-B008.5 with agentic interface data integrity retagged as supplemental |
| Q3 2026 | B009: Limit output over-exposure | Revision | Extended capability scoping to cover image generation alongside text and voice generation |
| Q3 2026 | C005: Prevent agent-specific high risk outputs | Clarification | Renamed from customer-defined to agent-specific high-risk outputs to reflect that the risk taxonomy is defined per agent |
| Q3 2026 | C006.2 Demonstration: Content handling and labelling for untrusted content | Clarification | Relabelled from warning labels to content handling and labelling for untrusted content |
| Q3 2026 | C008.3 Config: Security tooling | Clarification | Renumbered from C008.4 to C008.3 to close a numbering gap |
| Q3 2026 | E002: AI failure plan for harmful outputs | Revision | Retagged capability scoping from generation modalities to externally facing agents |
| Q3 2026 | E003: AI failure plan for hallucinations | Revision | Retagged capability scoping from generation modalities to externally facing agents |
| Q3 2026 | E003.1 Documentation: AI failure plan for hallucinations | Revision | Refocused the control on customer communication protocols and immediate mitigation steps with designated staff responsibilities |
| Q3 2026 | E005.1 Documentation: Data storage security practices | Revision | Simplified the control to focus on documenting data storage security practices such as cloud vs. on-premises assessments |
| Q3 2026 | E009: Monitor third-party access | Revision | Expanded the requirement to cover monitoring and logging of third-party API connections, sessions, and data access |
| Q3 2026 | E009.2 Config: Anomalous third-party access alerting | Addition | Added new supplemental control for alerting on anomalous third-party access |
| Q3 2026 | E017: Document system transparency policy | Revision | Restructured controls: transparency documentation is now the core control E017.1, transparency report sharing policy retagged supplemental as E017.2, and a new supplemental control E017.3 added covering platform and deployer security responsibilities |