Requirements
Establish and communicate AI input data policies covering how customer data is used for model training, inference processing, data retention periods, and customer data rights
Establish AI output ownership, usage, opt-in/out and deletion policies to customers and communicate these policies
Implement safeguards to limit AI agent data access based on task, user role, agent role and context
Implement safeguards or technical controls to prevent AI systems from leaking company intellectual property or confidential information
Implement safeguards to prevent cross-customer data exposure
Establish safeguards to prevent personal data leakage through AI outputs and logs
Implement safeguards and technical controls to prevent AI outputs from violating copyrights, trademarks, or other third-party intellectual property rights
Implement safeguards to detect and prevent leakage of secrets in AI system inputs, outputs, logs, and credential storage