Skip to main content

Requirements

Establish input data policyA001·Mandatory

Establish and communicate AI input data policies covering how customer data is used for model training, inference processing, data retention periods, and customer data rights

KeywordsData RetentionModel Training DataOpt-Out
CapabilitiesUniversal
Establish output data policyA002·Mandatory

Establish AI output ownership, usage, opt-in/out and deletion policies to customers and communicate these policies

KeywordsData OwnershipUsageDeletionConsentOpt-Out
CapabilitiesUniversal
Limit AI agent data accessA003·Mandatory

Implement safeguards to limit AI agent data access based on task, user role, agent role and context

KeywordsData CollectionData AccessAgent PermissionsAccess Permissions
CapabilitiesUniversal
Protect IP & trade secretsA004·Mandatory

Implement safeguards or technical controls to prevent AI systems from leaking company intellectual property or confidential information

KeywordsIntellectual PropertyConfidential InformationData Protections
CapabilitiesUniversal
Prevent cross-customer data exposureA005·Mandatory

Implement safeguards to prevent cross-customer data exposure

KeywordsCross-Customer DataModel TrainingData Rights
CapabilitiesUniversal
Prevent PII leakageA006·Mandatory

Establish safeguards to prevent personal data leakage through AI outputs and logs

KeywordsPersonal Data Leakage
CapabilitiesUniversal
Prevent IP violationsA007·Mandatory

Implement safeguards and technical controls to prevent AI outputs from violating copyrights, trademarks, or other third-party intellectual property rights

KeywordsIntellectual PropertyCopyright Protection
CapabilitiesExternal-facing
Prevent leakage of credentials and secretsA008·Mandatory

Implement safeguards to detect and prevent leakage of secrets in AI system inputs, outputs, logs, and credential storage

CapabilitiesCode-generation