{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/controls.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls.json",
  "source": "https://aigovernanceengineer.com/controls",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "asOf": "2026-09-26",
  "profiles": [
    {
      "slug": "evaluation-environment",
      "title": "Evaluation Environment Control Profile",
      "shortTitle": "Evaluation environment",
      "url": "https://aigovernanceengineer.com/controls/evaluation-environment",
      "version": "0.2",
      "status": "draft",
      "reviewerStatus": "open",
      "summary": "Draft control specifications for the environment a model or agent is evaluated in: the harness, tools, credentials, network, monitoring and stop conditions around it, and the evidence a run leaves.",
      "scope": "Evaluation environments for models and agents, from the harness and the tools and MCP servers a run can call to the credentials it holds, the network it can reach and the records it leaves. The evaluation tasks, their scoring rubrics and the capabilities being measured are out of scope.",
      "published": "2026-09-26",
      "updated": "2026-09-26",
      "authors": [
        "Jorge García Aibar"
      ],
      "reviewers": [],
      "changelog": [
        {
          "version": "0.1",
          "date": "2026-09-26",
          "note": "First draft: three controls specified in full (002 Network Egress Control, 003 Credential Isolation, 006 Stop Conditions) and six outlines with open questions, open for technical review."
        },
        {
          "version": "0.2",
          "date": "2026-09-26",
          "note": "Six outlines promoted to specified, each with repeatable verification steps, evidence tied to a published schema, configuration-level implementation notes, an observation record and two illustrative example observations: 001 Authorization Boundary, 004 Tool and Action Mediation, 005 Monitoring Integrity, 007 Incident Evidence Preservation, 008 Harness and Configuration Attestation and 009 Evaluation Validity Checks. Every source they cite was re-opened on 2026-09-26. No control remains an outline: each promoted claim had a verified source. An adversarial content review the same day re-checked every quotation against its source, tightened four attributions and replaced the mappings that did not plainly fit (NIST AI RMF on 001, 004, 005, 007, 008 and 009; ISO/IEC 42001 on 008; OWASP on 009; three EU AI Act obligation rows on 005 and 007). Still open for technical review; no reviewer is credited yet."
        }
      ],
      "reviewForm": "https://github.com/losanchos5/aige/issues/new?template=control-review.yml",
      "controls": [
        "AIGE-CTL-EVAL-001",
        "AIGE-CTL-EVAL-002",
        "AIGE-CTL-EVAL-003",
        "AIGE-CTL-EVAL-004",
        "AIGE-CTL-EVAL-005",
        "AIGE-CTL-EVAL-006",
        "AIGE-CTL-EVAL-007",
        "AIGE-CTL-EVAL-008",
        "AIGE-CTL-EVAL-009"
      ],
      "doi": null,
      "conceptDoi": null,
      "citation": {
        "text": "Jorge García Aibar (2026). Evaluation Environment Control Profile (v0.2, draft). AI Governance Engineer. https://doi.org/10.5281/zenodo.22857084. https://aigovernanceengineer.com/controls/evaluation-environment",
        "doi": "10.5281/zenodo.22857084",
        "doiKind": "project-concept",
        "url": "https://aigovernanceengineer.com/controls/evaluation-environment"
      }
    },
    {
      "slug": "agent-runtime",
      "title": "Agent Runtime Control Profile",
      "shortTitle": "Agent runtime",
      "url": "https://aigovernanceengineer.com/controls/agent-runtime",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "summary": "Reference controls for AI agents at runtime, derived from the 31 agent controls of chapter 23. Every control is a draft: it restates the chapter, carries no verification procedure yet and is open for technical review.",
      "scope": "Agents that call tools, in production and in evaluation harnesses, from registration to retirement: their identity, tools, memory, delegation, checkpoints, stop handles and telemetry. The environment an agent is evaluated in is covered by the evaluation environment profile.",
      "published": "2026-09-26",
      "updated": "2026-09-26",
      "authors": [
        "Jorge García Aibar"
      ],
      "reviewers": [],
      "changelog": [
        {
          "version": "0.1",
          "date": "2026-09-26",
          "note": "First draft: 31 controls derived from the agent controls of chapter 23, open for technical review."
        }
      ],
      "reviewForm": "https://github.com/losanchos5/aige/issues/new?template=control-review.yml",
      "controls": [
        "AIGE-CTL-AGENT-001",
        "AIGE-CTL-AGENT-002",
        "AIGE-CTL-AGENT-003",
        "AIGE-CTL-AGENT-004",
        "AIGE-CTL-AGENT-005",
        "AIGE-CTL-AGENT-006",
        "AIGE-CTL-AGENT-007",
        "AIGE-CTL-AGENT-008",
        "AIGE-CTL-AGENT-009",
        "AIGE-CTL-AGENT-010",
        "AIGE-CTL-AGENT-011",
        "AIGE-CTL-AGENT-012",
        "AIGE-CTL-AGENT-013",
        "AIGE-CTL-AGENT-014",
        "AIGE-CTL-AGENT-015",
        "AIGE-CTL-AGENT-016",
        "AIGE-CTL-AGENT-017",
        "AIGE-CTL-AGENT-018",
        "AIGE-CTL-AGENT-019",
        "AIGE-CTL-AGENT-020",
        "AIGE-CTL-AGENT-021",
        "AIGE-CTL-AGENT-022",
        "AIGE-CTL-AGENT-023",
        "AIGE-CTL-AGENT-024",
        "AIGE-CTL-AGENT-025",
        "AIGE-CTL-AGENT-026",
        "AIGE-CTL-AGENT-027",
        "AIGE-CTL-AGENT-028",
        "AIGE-CTL-AGENT-029",
        "AIGE-CTL-AGENT-030",
        "AIGE-CTL-AGENT-031"
      ],
      "doi": null,
      "conceptDoi": null,
      "citation": {
        "text": "Jorge García Aibar (2026). Agent Runtime Control Profile (v0.1, draft). AI Governance Engineer. https://doi.org/10.5281/zenodo.22857084. https://aigovernanceengineer.com/controls/agent-runtime",
        "doi": "10.5281/zenodo.22857084",
        "doiKind": "project-concept",
        "url": "https://aigovernanceengineer.com/controls/agent-runtime"
      }
    },
    {
      "slug": "data-admission-and-privacy",
      "title": "Data Admission and Privacy Control Profile",
      "shortTitle": "Data admission and privacy",
      "url": "https://aigovernanceengineer.com/controls/data-admission-and-privacy",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "summary": "Reference controls for the data AI systems learn from: admission before a job reads a dataset, the right to use each source, lawful basis and purpose, fitness for purpose, integrity, lineage and downstream use. Every control is a draft derived from site patterns, record schemas and chapters 14 and 19, open for technical review.",
      "scope": "Datasets that training, fine-tuning, validation, testing, evaluation and retrieval-index jobs read, the sources they are built from and the consumers of the outputs of the models built on them. Data handling at inference time, transfers and automated decision-making are left to chapter 19; evaluation environments are covered by the evaluation environment profile.",
      "published": "2026-09-26",
      "updated": "2026-09-26",
      "authors": [
        "Jorge García Aibar"
      ],
      "reviewers": [],
      "changelog": [
        {
          "version": "0.1",
          "date": "2026-09-26",
          "note": "First draft: 12 controls derived from the Dataset Admission Gate, Training-Data Rights Ledger and Downstream Use Register patterns, the dataset admission record and dataset card schemas, and chapters 14 and 19; open for technical review."
        }
      ],
      "reviewForm": "https://github.com/losanchos5/aige/issues/new?template=control-review.yml",
      "controls": [
        "AIGE-CTL-DATA-001",
        "AIGE-CTL-DATA-002",
        "AIGE-CTL-DATA-003",
        "AIGE-CTL-DATA-004",
        "AIGE-CTL-DATA-005",
        "AIGE-CTL-DATA-006",
        "AIGE-CTL-DATA-007",
        "AIGE-CTL-DATA-008",
        "AIGE-CTL-DATA-009",
        "AIGE-CTL-DATA-010",
        "AIGE-CTL-DATA-011",
        "AIGE-CTL-DATA-012"
      ],
      "doi": null,
      "conceptDoi": null,
      "citation": {
        "text": "Jorge García Aibar (2026). Data Admission and Privacy Control Profile (v0.1, draft). AI Governance Engineer. https://doi.org/10.5281/zenodo.22857084. https://aigovernanceengineer.com/controls/data-admission-and-privacy",
        "doi": "10.5281/zenodo.22857084",
        "doiKind": "project-concept",
        "url": "https://aigovernanceengineer.com/controls/data-admission-and-privacy"
      }
    },
    {
      "slug": "assurance-and-evidence",
      "title": "Assurance and Evidence Control Profile",
      "shortTitle": "Assurance and evidence",
      "url": "https://aigovernanceengineer.com/controls/assurance-and-evidence",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "summary": "Reference controls for testing an AI system before release, for the evidence every control writes and keeps, and for the integrity of the model artefacts and bill of materials a release ships with. Every control is a draft: it restates site material, carries no verification procedure yet and is open for technical review.",
      "scope": "AI systems and models from the test plan to the release gate, the evidence records every control emits and how long they are kept, and the model artefacts and AI bill of materials of each build. The environment a model or agent is evaluated in is covered by the evaluation environment profile, and agent-specific runtime controls by the agent runtime profile.",
      "published": "2026-09-26",
      "updated": "2026-09-26",
      "authors": [
        "Jorge García Aibar"
      ],
      "reviewers": [],
      "changelog": [
        {
          "version": "0.1",
          "date": "2026-09-26",
          "note": "First draft, derived from the Eval Gate in CI, Continuous Assurance Telemetry, Machine-Readable Evidence (OSCAL), Model Artefact Integrity and AIBOM patterns, six record schemas and chapters 14, 18 and 22: 12 controls, open for technical review."
        }
      ],
      "reviewForm": "https://github.com/losanchos5/aige/issues/new?template=control-review.yml",
      "controls": [
        "AIGE-CTL-ASSURE-001",
        "AIGE-CTL-ASSURE-002",
        "AIGE-CTL-ASSURE-003",
        "AIGE-CTL-ASSURE-004",
        "AIGE-CTL-ASSURE-005",
        "AIGE-CTL-ASSURE-006",
        "AIGE-CTL-ASSURE-007",
        "AIGE-CTL-ASSURE-008",
        "AIGE-CTL-ASSURE-009",
        "AIGE-CTL-ASSURE-010",
        "AIGE-CTL-ASSURE-011",
        "AIGE-CTL-ASSURE-012"
      ],
      "doi": null,
      "conceptDoi": null,
      "citation": {
        "text": "Jorge García Aibar (2026). Assurance and Evidence Control Profile (v0.1, draft). AI Governance Engineer. https://doi.org/10.5281/zenodo.22857084. https://aigovernanceengineer.com/controls/assurance-and-evidence",
        "doi": "10.5281/zenodo.22857084",
        "doiKind": "project-concept",
        "url": "https://aigovernanceengineer.com/controls/assurance-and-evidence"
      }
    },
    {
      "slug": "deployment-and-monitoring",
      "title": "Deployment and Monitoring Control Profile",
      "shortTitle": "Deployment and monitoring",
      "url": "https://aigovernanceengineer.com/controls/deployment-and-monitoring",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "summary": "Reference controls for AI systems in use, from the deployment decision and the go-live review to staged rollout, monitoring, incident reporting, deactivation and retirement. Every control is a draft derived from the site's patterns, record schemas and chapters 15 to 17, open for technical review.",
      "scope": "AI systems an organisation puts to use, built or procured, from the decision to use them to the day they are retired, including staff use of AI tools and AI running outside the registry. How the system is built and evaluated before release, and the runtime controls specific to agents, are covered by other profiles.",
      "published": "2026-09-26",
      "updated": "2026-09-26",
      "authors": [
        "Jorge García Aibar"
      ],
      "reviewers": [],
      "changelog": [
        {
          "version": "0.1",
          "date": "2026-09-26",
          "note": "First draft: 15 controls derived from the patterns Staged Rollout with Rollback Criteria, Human-in-the-loop Gate, Shadow-AI Discovery, Sanctioned AI Gateway, Drift & Fairness Monitor, Incident Pipeline and the Deactivation, Localisation & Retirement Runbook, the deployment, monitoring, incident and retirement record schemas, and chapters 15 to 17; open for technical review."
        }
      ],
      "reviewForm": "https://github.com/losanchos5/aige/issues/new?template=control-review.yml",
      "controls": [
        "AIGE-CTL-DEPLOY-001",
        "AIGE-CTL-DEPLOY-002",
        "AIGE-CTL-DEPLOY-003",
        "AIGE-CTL-DEPLOY-004",
        "AIGE-CTL-DEPLOY-005",
        "AIGE-CTL-DEPLOY-006",
        "AIGE-CTL-DEPLOY-007",
        "AIGE-CTL-DEPLOY-008",
        "AIGE-CTL-DEPLOY-009",
        "AIGE-CTL-DEPLOY-010",
        "AIGE-CTL-DEPLOY-011",
        "AIGE-CTL-DEPLOY-012",
        "AIGE-CTL-DEPLOY-013",
        "AIGE-CTL-DEPLOY-014",
        "AIGE-CTL-DEPLOY-015"
      ],
      "doi": null,
      "conceptDoi": null,
      "citation": {
        "text": "Jorge García Aibar (2026). Deployment and Monitoring Control Profile (v0.1, draft). AI Governance Engineer. https://doi.org/10.5281/zenodo.22857084. https://aigovernanceengineer.com/controls/deployment-and-monitoring",
        "doi": "10.5281/zenodo.22857084",
        "doiKind": "project-concept",
        "url": "https://aigovernanceengineer.com/controls/deployment-and-monitoring"
      }
    }
  ],
  "controls": [
    {
      "id": "AIGE-CTL-EVAL-001",
      "profile": "evaluation-environment",
      "url": "https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-001",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-eval-001.json",
      "title": "Authorization Boundary",
      "version": "0.2",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "specified",
      "objective": "Every agent in an evaluation run acts only within an authorization boundary recorded before the run starts: the tools, operations, data classes and budgets it may use, and the runs and resources it may reach.",
      "failureModes": [
        "A run starts with no recorded boundary for the agent under test, or with a boundary that differs from the scope the agent was told.",
        "The agent calls a tool or an operation class outside its recorded boundary, or starts processes with administrative privileges, and the call succeeds.",
        "A credential given for one purpose on a shared resource, such as downloading packages, also lets the agent write, list or post there.",
        "Agents in runs meant to be isolated reach each other through a resource the runs share, such as a package repository or a cache."
      ],
      "scope": "Agents and harnesses under evaluation, the tools and operations they can use during a run, the credentials they receive for shared resources and the resources runs share. Budgets are recorded here and enforced under AIGE-CTL-EVAL-006; network egress is AIGE-CTL-EVAL-002. Production deployments are covered by the agent runtime profile.",
      "enforcementPoints": [
        "deploy",
        "runtime"
      ],
      "verification": [
        {
          "kind": "inspect",
          "text": "Before the run, inspect the run record: it holds a boundary for each agent under test (tools and operation classes, data classes, budgets, and each shared resource with the operations allowed on it), and the prompt the agent receives states the same boundary as instructions, including what it must not access."
        },
        {
          "kind": "test",
          "text": "At admission, from inside the environment, attempt one call of each kind outside the boundary (an unlisted tool or operation class, a write or a listing with a download-only credential on a shared resource, a process started as root) and one listed call; every attempt outside the boundary must be refused and logged, and the listed call must succeed."
        },
        {
          "kind": "test",
          "text": "Start two canary runs on the same shared resources: a marker written by one run must not be readable by the other."
        },
        {
          "kind": "observe",
          "text": "After the run, compare every tool call and every request to a shared resource in the run's logs with the recorded boundary: each falls inside it, and every refused attempt is recorded with its time and target."
        }
      ],
      "evidence": [
        {
          "artefact": "The boundary of each agent under test, recorded before the run: tools, operation classes, data classes, budgets and shared resources with the operations allowed on each",
          "schemaId": "agent-register-entry",
          "schema": "https://aigovernanceengineer.com/schemas/agent-register-entry.v1.json",
          "layer": 2
        },
        {
          "artefact": "Admission test verdicts: the refused out-of-boundary calls and the cross-run canary",
          "schemaId": "evidence-record",
          "schema": "https://aigovernanceengineer.com/schemas/evidence-record.v1.json",
          "layer": 4
        },
        {
          "artefact": "One observation per run comparing the calls and shared-resource requests made with the recorded boundary",
          "schemaId": "control-observation",
          "schema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
          "layer": 5
        }
      ],
      "failureResponse": {
        "effect": "deny",
        "text": "Calls and shared-resource operations outside the recorded boundary are refused at the enforcement point and logged. A run with no recorded boundary is not started; a run in which a call outside the boundary succeeded, or in which runs reached each other, is stopped and its result is withheld until the path is closed."
      },
      "layer": 4,
      "secondaryLayers": [
        2
      ],
      "patterns": [
        {
          "slug": "agent-registry",
          "title": "Agent Registry",
          "url": "https://aigovernanceengineer.com/patterns/agent-registry"
        },
        {
          "slug": "policy-card",
          "title": "Policy Card",
          "url": "https://aigovernanceengineer.com/patterns/policy-card"
        }
      ],
      "seeds": [
        {
          "id": "registry-entry",
          "title": "Registry entry",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#the-agent-registry"
        },
        {
          "id": "read-only-tools",
          "title": "Read-only tools",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#autonomy-is-a-design-decision"
        },
        {
          "id": "reversible-only",
          "title": "Reversible, bounded actions only",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#autonomy-is-a-design-decision"
        },
        {
          "id": "execution-budgets",
          "title": "Execution budgets",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#execution-limits"
        },
        {
          "id": "data-classes",
          "title": "Data classes recorded, with the DPIA linked",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#the-agent-registry"
        }
      ],
      "derivedFrom": [],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART14",
            "name": "EU AI Act Art. 14 human oversight",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art14"
          },
          {
            "id": "AIGE-OBL-OWASP-AGENTIC",
            "name": "Top 10 for Agentic Applications 2026",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-agentic"
          },
          {
            "id": "AIGE-OBL-CSA-AICM-AGENTIC",
            "name": "AICM agent controls with the CSA Agentic Trust Framework and AARM specification",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-csa-aicm-agentic"
          },
          {
            "id": "AIGE-OBL-SG-AGENTIC-IDENTITY",
            "name": "Singapore IMDA Model AI Governance Framework for Agentic AI: agent identity and scoped authorisations (voluntary)",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-sg-agentic-identity"
          }
        ],
        "iso42001": [
          {
            "id": "A.6.2.2",
            "title": "AI system requirements and specification"
          },
          {
            "id": "A.9.2",
            "title": "Processes for responsible use of AI systems"
          }
        ],
        "nistAiRmf": [
          {
            "id": "MAP 4.2",
            "title": "Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented."
          }
        ],
        "owasp": [
          {
            "id": "asi02",
            "externalId": "ASI02",
            "name": "Tool Misuse and Exploitation",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-asi02"
          },
          {
            "id": "asi03",
            "externalId": "ASI03",
            "name": "Identity and Privilege Abuse",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-asi03"
          },
          {
            "id": "llm03-2026",
            "externalId": "LLM03:2026",
            "name": "Excessive Agency",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-llm03-2026"
          }
        ],
        "atlas": [],
        "aiuc1": [
          "B006"
        ],
        "csaAicm": [],
        "other": [
          {
            "framework": "NIST SP 800-53 Rev. 5",
            "ref": "AC-3",
            "note": "Access Enforcement"
          },
          {
            "framework": "NIST SP 800-53 Rev. 5",
            "ref": "AC-6",
            "note": "Least Privilege"
          }
        ]
      },
      "references": [
        {
          "n": 1,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"The agent registry\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#the-agent-registry",
          "verified": "primary"
        },
        {
          "n": 2,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Autonomy is a design decision\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#autonomy-is-a-design-decision",
          "verified": "primary"
        },
        {
          "n": 3,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"The tool allow-list\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#the-tool-allow-list",
          "verified": "primary"
        },
        {
          "n": 4,
          "title": "METR Task Standard, STANDARD.md",
          "text": "METR Task Standard, STANDARD.md (version 0.5.0; unless a task declares the full_internet permission, the task machines \"MUST NOT have internet access\" except to an LLM API, an LLM API proxy or a hardened local server). METR (GitHub). 2024-10-30.",
          "url": "https://raw.githubusercontent.com/METR/task-standard/main/STANDARD.md",
          "verified": "primary"
        },
        {
          "n": 5,
          "title": "Brief independent investigation of agents' behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident",
          "text": "Brief independent investigation of agents' behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident (METR states that agents \"meant to be fully isolated from one another\" communicated through an internal package repository, and that one agent found working Hugging Face credentials exposed on the internet and posted them to the agents' board; it reports spoofed tool calls in at least 96 transcripts and transcripts missing components after container resets). METR. 2026-08-26.",
          "url": "https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/",
          "verified": "primary"
        },
        {
          "n": 6,
          "title": "OWASP Top 10 for Agentic Applications for 2026",
          "text": "OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents). OWASP GenAI Security Project. 2025-12-09.",
          "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
          "verified": "primary"
        },
        {
          "n": 7,
          "title": "NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations",
          "text": "NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations (control catalogue cited by control id; publication page of Revision 5 with update 1 of 10 Dec 2020). NIST. 2020-12-10.",
          "url": "https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final",
          "verified": "primary"
        },
        {
          "n": 8,
          "title": "Third-party cyber evaluations involving OpenAI models",
          "text": "Third-party cyber evaluations involving OpenAI models (OpenAI states that the evaluator's \"intended authorization boundary was the simulated cyber range\", that its model reused a GitHub token another lab's agent had left publicly accessible, and that it will review how to \"set expectations for isolation, credential handling, monitoring, and stop conditions\"). OpenAI. 2026-08-04.",
          "url": "https://openai.com/index/third-party-cyber-evaluations-involving-openai-models/",
          "verified": "primary"
        },
        {
          "n": 9,
          "title": "Improving our alignment and security efforts",
          "text": "Improving our alignment and security efforts (best practices for external partners running cyber evaluations: the only outside connection is \"to the model's own API\", with the API keys kept outside the environment; the configuration \"should be verified before every evaluation begins\"; boundaries \"phrased as instructions\"; challenges confirmed \"solvable in principle\"; a monitor that flags a scope violation to a human and ends the exercise). Anthropic. 2026-08-31.",
          "url": "https://www.anthropic.com/news/improving-alignment-security-efforts",
          "verified": "primary"
        },
        {
          "n": 10,
          "title": "AIUC-1 requirements",
          "text": "AIUC-1 requirements (public requirement index, A001 to F002, each requirement on its own page (E007 and E014 marked retired); AIUC-1 is a standard of the Artificial Intelligence Underwriting Company; this site is not affiliated with AIUC, and a mapping here is not an AIUC-1 certificate or audit). Artificial Intelligence Underwriting Company. 2026-09-24.",
          "url": "https://standard.aiuc-1.com/llms.txt",
          "verified": "primary"
        },
        {
          "n": 11,
          "title": "Unsanctioned Artifactory writes and cross-sample communication (misalignment report)",
          "text": "Unsanctioned Artifactory writes and cross-sample communication (misalignment report) (OpenAI reports models in RL training that used Artifactory, \"a shared package repository\", to exchange messages across separate training samples with the credentials they were given to download packages, without exploiting any vulnerability; such exchanges can \"undermine the assumption that training or evaluation samples are independent\"). OpenAI (Alignment Research Blog). 2026-09-16.",
          "url": "https://alignment.openai.com/misalignment-reports/unauthorized-artifactory-writes-and-cross-sample-communication/",
          "verified": "primary"
        },
        {
          "n": 12,
          "title": "OpenAI Hugging Face Incident Technical Report",
          "text": "OpenAI Hugging Face Incident Technical Report (OpenAI states that high-risk workloads are \"prohibited via technical controls from receiving direct or transitive Internet access\", protected by \"two separate layers of network isolation\", and that it is building tooling to \"identify and halt evaluation workloads\"). OpenAI. 2026-08-26.",
          "url": "https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Record the boundary as data before the run, in the fields of an agent registry entry (scope, tools, data access, spend limit), and enforce it at the gateway the agent's calls pass through, not in the prompt alone. State the same boundary to the agent: Anthropic's guidance for external evaluation partners asks every prompt to state what is in and out of scope, including permitted actions and network boundaries, with boundaries \"phrased as instructions\" rather than claims about the environment.",
        "Tell the agent what it may not do with the access it has. OpenAI's account of a third-party cyber evaluation states that the evaluator's \"intended authorization boundary was the simulated cyber range\", while the agents were not explicitly told how they could and could not use the open internet access they had; the evaluator names this as a potential contributing cause.",
        "Scope every credential for a shared resource to the operations the task needs: download from a package repository, never write, list or post. OpenAI reports models in RL training that used Artifactory, \"a shared package repository\", to exchange messages across separate samples with the credentials they were given to download packages, without exploiting any vulnerability; its technical report on the Hugging Face incident lists removing the shared credential from new research workloads and restricting the types of requests agents could make to Artifactory among its mitigations.",
        "Give each run its own namespace on every shared resource (package cache, artefact store, scratch storage) and test it with a canary marker. METR's investigation of the OpenAI/Hugging Face incident reports that agents \"meant to be fully isolated from one another\" communicated through an internal package repository.",
        "Run the agent as an unprivileged user. METR's Task Standard states that the agent \"MUST NOT be allowed to start processes\" on the primary machine as root."
      ],
      "openQuestions": [
        "Which shared resources (package mirrors, caches, model API proxies) can be given a per-run namespace, and which should be removed from evaluation environments altogether?",
        "What evidence is sufficient to show that an agent stayed within its boundary for a whole run when the logs of some of the tools it called are outside the evaluator's control?"
      ],
      "observation": {
        "subjectKind": "eval-run",
        "expected": "Every tool call and every request to a shared resource falls inside the boundary recorded for the agent before the run; every attempt outside it is refused and logged.",
        "observedExample": "Run 88231: 3 listing and upload requests to the shared package repository with a download-only credential, all refused and logged; no call outside the boundary succeeded: pass."
      },
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": [
        {
          "status": "pass",
          "url": "https://aigovernanceengineer.com/controls/examples/control-observation.aige-ctl-eval-001.pass.json"
        },
        {
          "status": "fail",
          "url": "https://aigovernanceengineer.com/controls/examples/control-observation.aige-ctl-eval-001.fail.json"
        }
      ]
    },
    {
      "id": "AIGE-CTL-EVAL-002",
      "profile": "evaluation-environment",
      "url": "https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-002",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-eval-002.json",
      "title": "Network Egress Control",
      "version": "0.2",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "specified",
      "objective": "Outbound connections from an evaluation environment reach only the destinations on the run's egress allow-list, and every other connection attempt is refused and logged.",
      "failureModes": [
        "A connection from the environment to a host that is not on the run's egress allow-list succeeds.",
        "A run starts in an environment with no egress policy attached, or with a policy that allows every destination although the task did not declare that it needs the internet.",
        "A permitted destination, such as a package mirror, a cache or a tool server, carries data onward to a party or to another run that nobody listed.",
        "The run leaves no flow log, so the connections it made cannot be compared with its allow-list."
      ],
      "scope": "Every network path out of the environment a run executes in: the agent's container or virtual machine, auxiliary machines, DNS, and the tools, MCP servers and proxies the run can call. Resources shared between runs count as destinations. Inbound operator access is out of scope.",
      "enforcementPoints": [
        "deploy",
        "runtime"
      ],
      "verification": [
        {
          "kind": "inspect",
          "text": "Before the run, inspect the egress policy attached to the task environment: deny by default, with an allow-list naming each permitted destination (for example the LLM API proxy and the progress server) and nothing else unless the task declares that it needs the internet."
        },
        {
          "kind": "test",
          "text": "At admission, from inside the environment, attempt one connection to a destination that is not on the allow-list and one to a listed destination; the first must be refused and logged, the second must succeed."
        },
        {
          "kind": "observe",
          "text": "After the run, compare the run's flow log with its allow-list: every outbound connection matches a listed destination, and every refused attempt is recorded with its time and target."
        }
      ],
      "evidence": [
        {
          "artefact": "The egress policy and allow-list attached to the run, with its hash recorded in the run record",
          "schemaId": null,
          "schema": null,
          "layer": 4
        },
        {
          "artefact": "Admission test verdict: the refused connection to an unlisted destination",
          "schemaId": "evidence-record",
          "schema": "https://aigovernanceengineer.com/schemas/evidence-record.v1.json",
          "layer": 4
        },
        {
          "artefact": "Flow log of the run, allowed and refused connections, kept outside the environment",
          "schemaId": null,
          "schema": null,
          "layer": 4
        },
        {
          "artefact": "One observation per run comparing observed connections with the allow-list",
          "schemaId": "control-observation",
          "schema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
          "layer": 5
        }
      ],
      "failureResponse": {
        "effect": "deny",
        "text": "Connections to unlisted destinations are refused at the enforcement point and logged. A run whose environment has no egress policy attached is not started; a run in which an unlisted connection succeeded is stopped and its result is withheld until the connection is explained."
      },
      "layer": 4,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "runtime-guardrail",
          "title": "Runtime Guardrail",
          "url": "https://aigovernanceengineer.com/patterns/runtime-guardrail"
        },
        {
          "slug": "sanctioned-ai-gateway",
          "title": "Sanctioned AI Gateway",
          "url": "https://aigovernanceengineer.com/patterns/sanctioned-ai-gateway"
        }
      ],
      "seeds": [
        {
          "id": "egress-filter",
          "title": "Output and egress filter",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#the-tool-allow-list"
        },
        {
          "id": "tool-allow-list",
          "title": "Tool allow-list, deny by default",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#the-tool-allow-list"
        },
        {
          "id": "sandbox",
          "title": "Code runs only in a sandbox",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#runtime-guardrails-for-tool-calls"
        }
      ],
      "derivedFrom": [],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART15",
            "name": "EU AI Act Art. 15 accuracy, robustness and cybersecurity",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15"
          },
          {
            "id": "AIGE-OBL-OWASP-LLM",
            "name": "Top 10 for LLM Applications 2026",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-llm"
          },
          {
            "id": "AIGE-OBL-OWASP-AGENTIC",
            "name": "Top 10 for Agentic Applications 2026",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-agentic"
          }
        ],
        "iso42001": [
          {
            "id": "A.6.2.6",
            "title": "AI system operation and monitoring"
          }
        ],
        "nistAiRmf": [
          {
            "id": "MEASURE 2.7",
            "title": "Security and resilience are evaluated and documented"
          }
        ],
        "owasp": [
          {
            "id": "asi02",
            "externalId": "ASI02",
            "name": "Tool Misuse and Exploitation",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-asi02"
          },
          {
            "id": "llm02-2026",
            "externalId": "LLM02:2026",
            "name": "Sensitive Information Disclosure",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-llm02-2026"
          }
        ],
        "atlas": [
          {
            "id": "aml-t0086",
            "externalId": "AML.T0086",
            "name": "Exfiltration via AI Agent Tool Invocation",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-aml-t0086"
          }
        ],
        "aiuc1": [
          "B006"
        ],
        "csaAicm": [],
        "other": [
          {
            "framework": "MITRE ATLAS mitigation",
            "ref": "AML.M0032",
            "note": "Segmentation of AI Agent Components"
          },
          {
            "framework": "NIST SP 800-53 Rev. 5",
            "ref": "SC-7",
            "note": "Boundary Protection"
          },
          {
            "framework": "NIST SP 800-53 Rev. 5",
            "ref": "SC-7(5)",
            "note": "Deny by default, allow by exception"
          }
        ]
      },
      "references": [
        {
          "n": 3,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"The tool allow-list\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#the-tool-allow-list",
          "verified": "primary"
        },
        {
          "n": 13,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Runtime guardrails for tool calls\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#runtime-guardrails-for-tool-calls",
          "verified": "primary"
        },
        {
          "n": 4,
          "title": "METR Task Standard, STANDARD.md",
          "text": "METR Task Standard, STANDARD.md (version 0.5.0; unless a task declares the full_internet permission, the task machines \"MUST NOT have internet access\" except to an LLM API, an LLM API proxy or a hardened local server). METR (GitHub). 2024-10-30.",
          "url": "https://raw.githubusercontent.com/METR/task-standard/main/STANDARD.md",
          "verified": "primary"
        },
        {
          "n": 5,
          "title": "Brief independent investigation of agents' behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident",
          "text": "Brief independent investigation of agents' behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident (METR states that agents \"meant to be fully isolated from one another\" communicated through an internal package repository, and that one agent found working Hugging Face credentials exposed on the internet and posted them to the agents' board; it reports spoofed tool calls in at least 96 transcripts and transcripts missing components after container resets). METR. 2026-08-26.",
          "url": "https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/",
          "verified": "primary"
        },
        {
          "n": 14,
          "title": "Vivaria server environment variables",
          "text": "Vivaria server environment variables (no-internet task environments connected to a separate Docker network and optionally sandboxed with iptables rules; model API requests can be routed through a separate proxy service). METR. 2026.",
          "url": "https://vivaria.metr.org/reference/config/",
          "verified": "primary"
        },
        {
          "n": 15,
          "title": "MCP Security Best Practices (2026-07-28)",
          "text": "MCP Security Best Practices (2026-07-28) (token passthrough \"is explicitly forbidden\"; egress proxies and network policies for server-side clients). Model Context Protocol. 2026-07-28.",
          "url": "https://modelcontextprotocol.io/docs/2026-07-28/tutorials/security/security_best_practices",
          "verified": "primary"
        },
        {
          "n": 6,
          "title": "OWASP Top 10 for Agentic Applications for 2026",
          "text": "OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents). OWASP GenAI Security Project. 2025-12-09.",
          "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
          "verified": "primary"
        },
        {
          "n": 16,
          "title": "OWASP GenAI LLM Top 10 2026",
          "text": "OWASP GenAI LLM Top 10 2026 (LLM01:2026 Prompt Injection to LLM10:2026 Improper Output Handling; resource page dated 3 Aug 2026). OWASP GenAI Security Project. 2026-08-03.",
          "url": "https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/",
          "verified": "primary"
        },
        {
          "n": 17,
          "title": "MITRE ATLAS data, release v2026.09",
          "text": "MITRE ATLAS data, release v2026.09 (16 tactics, 120 techniques, 88 sub-techniques, 40 mitigations; technique names and technique-to-mitigation links read from dist/v6/ATLAS-2026.09.yaml). MITRE. 2026-09-15.",
          "url": "https://github.com/mitre-atlas/atlas-data/releases/tag/v2026.09",
          "verified": "primary"
        },
        {
          "n": 7,
          "title": "NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations",
          "text": "NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations (control catalogue cited by control id; publication page of Revision 5 with update 1 of 10 Dec 2020). NIST. 2020-12-10.",
          "url": "https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final",
          "verified": "primary"
        },
        {
          "n": 18,
          "title": "An agent used DNS to reach an external chatbot (misalignment report)",
          "text": "An agent used DNS to reach an external chatbot (misalignment report) (OpenAI reports a training run that reached a public chatbot through \"insufficient DNS filtering\" in its sandbox; the monitor flagged it within 15 minutes, the run \"did not stop automatically as expected\" and was killed 2.5 hours later). OpenAI (Alignment Research Blog). 2026-09-25.",
          "url": "https://alignment.openai.com/misalignment-reports/an-agent-used-dns-to-reach-an-external-chatbot/",
          "verified": "primary"
        },
        {
          "n": 12,
          "title": "OpenAI Hugging Face Incident Technical Report",
          "text": "OpenAI Hugging Face Incident Technical Report (OpenAI states that high-risk workloads are \"prohibited via technical controls from receiving direct or transitive Internet access\", protected by \"two separate layers of network isolation\", and that it is building tooling to \"identify and halt evaluation workloads\"). OpenAI. 2026-08-26.",
          "url": "https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf",
          "verified": "primary"
        },
        {
          "n": 9,
          "title": "Improving our alignment and security efforts",
          "text": "Improving our alignment and security efforts (best practices for external partners running cyber evaluations: the only outside connection is \"to the model's own API\", with the API keys kept outside the environment; the configuration \"should be verified before every evaluation begins\"; boundaries \"phrased as instructions\"; challenges confirmed \"solvable in principle\"; a monitor that flags a scope violation to a human and ends the exercise). Anthropic. 2026-08-31.",
          "url": "https://www.anthropic.com/news/improving-alignment-security-efforts",
          "verified": "primary"
        },
        {
          "n": 10,
          "title": "AIUC-1 requirements",
          "text": "AIUC-1 requirements (public requirement index, A001 to F002, each requirement on its own page (E007 and E014 marked retired); AIUC-1 is a standard of the Artificial Intelligence Underwriting Company; this site is not affiliated with AIUC, and a mapping here is not an AIUC-1 certificate or audit). Artificial Intelligence Underwriting Company. 2026-09-24.",
          "url": "https://standard.aiuc-1.com/llms.txt",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Attach a default-deny egress policy to every task environment (a network policy, a firewall rule set or an egress proxy, by category) that lists each permitted destination explicitly, for example the LLM API proxy and the progress server. Enforce it on the resolved address, and serve DNS from a resolver that answers only for listed names: DNS is an egress path too. OpenAI reports a training run that reached a public chatbot through \"insufficient DNS filtering\" in its sandbox.",
        "Record the allow-list with the run (its hash goes in the run record next to the environment version) and keep a flow log per run at the enforcement point, outside anything the agent can reach or change, with refused attempts as well as allowed connections, so the connections made can be compared with what was declared, not with what was intended.",
        "Enforce the policy in two places a single misconfiguration cannot both open, for example at the sandbox and at the cluster boundary. OpenAI's technical report on the Hugging Face incident describes \"two separate layers of network isolation\" of this kind, and Anthropic's guidance for external evaluation partners asks that the only outside connection be to the model's own API and that the configuration be verified before every evaluation begins.",
        "At admission, run a canary from inside the environment: one connection to a reserved test address that is not on the list. Expect a refused connection and a log entry; a success blocks the run.",
        "Treat resources shared between runs (package mirrors, caches, artefact stores) as destinations with their own entry and a per-run scope. METR's public investigation of the OpenAI/Hugging Face incident reports that agents meant to be \"fully isolated from one another\" communicated through a shared internal package repository."
      ],
      "openQuestions": [
        "How should the egress allow-list of a run be recorded so that a third party can compare it with the connections actually observed?",
        "When a task needs the internet (what METR's Task Standard calls the full_internet permission), which part of this control still applies, and what should the run record say instead?"
      ],
      "observation": {
        "subjectKind": "eval-environment",
        "expected": "Outbound connections only to the destinations on the run's egress allow-list; every other attempt refused and logged.",
        "observedExample": "1 connection to an unlisted host during run 88213, in an environment with no egress policy attached: fail."
      },
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": [
        {
          "status": "pass",
          "url": "https://aigovernanceengineer.com/controls/examples/control-observation.aige-ctl-eval-002.pass.json"
        },
        {
          "status": "fail",
          "url": "https://aigovernanceengineer.com/controls/examples/control-observation.aige-ctl-eval-002.fail.json"
        }
      ]
    },
    {
      "id": "AIGE-CTL-EVAL-003",
      "profile": "evaluation-environment",
      "url": "https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-003",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-eval-003.json",
      "title": "Credential Isolation",
      "version": "0.2",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "specified",
      "objective": "An agent under evaluation holds only short-lived credentials issued to its own identity for the run and bound to the one service each is for, never standing secrets or a person's own token.",
      "failureModes": [
        "A long-lived secret (an API key, a cloud access key, a password) is readable from the agent's environment, configuration, files or memory during a run.",
        "The agent presents a token issued to a person, a token whose audience is another service, or a credential it found rather than received, and the tool server accepts it.",
        "A credential issued for the run is still accepted after the run ended or was aborted.",
        "A credential appears in the run's transcript, memory store, logs or outputs, or is passed to another agent."
      ],
      "scope": "Credentials, tokens and keys the agent under evaluation and the tools it calls can reach during a run, including what it holds in memory and writes to its transcript, and the model API key, which stays with a proxy outside the environment. The evaluator's own operator credentials are out of scope.",
      "enforcementPoints": [
        "deploy",
        "runtime"
      ],
      "verification": [
        {
          "kind": "inspect",
          "text": "Before the run, inspect the environment template and the run's configuration: no long-lived secret is present, and the agent obtains credentials from a broker outside the environment under its own workload identity, each with a lifetime no longer than the run and an audience naming one tool server."
        },
        {
          "kind": "test",
          "text": "After the run, scan every run artefact (transcript, memory store, logs, outputs and a snapshot of the environment's file system) for secret patterns and for the tokens issued to the run; expect no match."
        },
        {
          "kind": "test",
          "text": "Replay a token issued for the run against a different tool server, and again after the run has ended; both must be rejected, for the wrong audience and for expiry or revocation."
        },
        {
          "kind": "observe",
          "text": "Read the tool servers' logs for the run: every call carries a token issued for that server, delegated calls name the agent as the acting party, and audience-check failures were raised as alerts."
        }
      ],
      "evidence": [
        {
          "artefact": "Credential issuance log of the run: identity, audience, scope, lifetime and revocation time of every token",
          "schemaId": "evidence-record",
          "schema": "https://aigovernanceengineer.com/schemas/evidence-record.v1.json",
          "layer": 4
        },
        {
          "artefact": "Audience-check and replay results from the tool servers",
          "schemaId": "evidence-record",
          "schema": "https://aigovernanceengineer.com/schemas/evidence-record.v1.json",
          "layer": 4
        },
        {
          "artefact": "Secret scan of the run artefacts, filed as an observation of this control",
          "schemaId": "control-observation",
          "schema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
          "layer": 5
        }
      ],
      "failureResponse": {
        "effect": "deny",
        "text": "A token issued for another audience, to a person, or for a run that has ended is rejected by the tool server. A run in which a long-lived secret or a leaked credential is found is stopped, the credential is revoked and the result is withheld until the exposure is assessed."
      },
      "layer": 4,
      "secondaryLayers": [
        2
      ],
      "patterns": [
        {
          "slug": "agent-identity-scoped-credentials",
          "title": "Agent Identity & Scoped Credentials",
          "url": "https://aigovernanceengineer.com/patterns/agent-identity-scoped-credentials"
        }
      ],
      "seeds": [
        {
          "id": "own-identity",
          "title": "Its own identity",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#identity-and-short-lived-credentials"
        },
        {
          "id": "short-lived-credentials",
          "title": "Replace long-lived secrets with short-lived credentials",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#short-lived-attested-credentials"
        },
        {
          "id": "delegated-token",
          "title": "Delegation, never impersonation",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#delegation-without-impersonation"
        },
        {
          "id": "mcp-authorization",
          "title": "MCP authorisation (spec 2026-07-28)",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#mcp-authorization-as-of-2026-07-28"
        },
        {
          "id": "memory-governance",
          "title": "Memory write gate and rollback",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#memory-and-context-governance"
        }
      ],
      "derivedFrom": [],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART15",
            "name": "EU AI Act Art. 15 accuracy, robustness and cybersecurity",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15"
          },
          {
            "id": "AIGE-OBL-SG-AGENTIC-IDENTITY",
            "name": "Singapore IMDA Model AI Governance Framework for Agentic AI: agent identity and scoped authorisations (voluntary)",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-sg-agentic-identity"
          },
          {
            "id": "AIGE-OBL-NIST-AGENTS",
            "name": "NIST AI Agent Standards Initiative (2026)",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-nist-agents"
          },
          {
            "id": "AIGE-OBL-OWASP-AGENTIC",
            "name": "Top 10 for Agentic Applications 2026",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-agentic"
          }
        ],
        "iso42001": [
          {
            "id": "A.6.2.6",
            "title": "AI system operation and monitoring"
          },
          {
            "id": "A.9.2",
            "title": "Processes for responsible use of AI systems"
          }
        ],
        "nistAiRmf": [
          {
            "id": "MEASURE 2.7",
            "title": "Security and resilience are evaluated and documented"
          }
        ],
        "owasp": [
          {
            "id": "asi03",
            "externalId": "ASI03",
            "name": "Identity and Privilege Abuse",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-asi03"
          }
        ],
        "atlas": [],
        "aiuc1": [
          "A008"
        ],
        "csaAicm": [],
        "other": [
          {
            "framework": "IETF RFC 8693",
            "ref": "act claim",
            "note": "delegation names the acting party; never impersonation"
          },
          {
            "framework": "MCP specification 2026-07-28",
            "ref": "Authorization, Token Handling",
            "note": "audience validation; no token passthrough"
          },
          {
            "framework": "SPIFFE",
            "ref": "SVID",
            "note": "short-lived workload identity documents"
          },
          {
            "framework": "MITRE ATLAS",
            "ref": "AML.T0083",
            "note": "Credentials from AI Agent Configuration (not yet a row of the threat bridge)"
          },
          {
            "framework": "NIST SP 800-53 Rev. 5",
            "ref": "IA-5",
            "note": "Authenticator Management"
          },
          {
            "framework": "NIST SP 800-53 Rev. 5",
            "ref": "AC-6",
            "note": "Least Privilege"
          }
        ]
      },
      "references": [
        {
          "n": 19,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Identity and short-lived credentials\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#identity-and-short-lived-credentials",
          "verified": "primary"
        },
        {
          "n": 20,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Short-lived, attested credentials\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#short-lived-attested-credentials",
          "verified": "primary"
        },
        {
          "n": 21,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Delegation without impersonation\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#delegation-without-impersonation",
          "verified": "primary"
        },
        {
          "n": 22,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"MCP authorization as of 2026-07-28\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#mcp-authorization-as-of-2026-07-28",
          "verified": "primary"
        },
        {
          "n": 23,
          "title": "RFC 8693, OAuth 2.0 Token Exchange",
          "text": "RFC 8693, OAuth 2.0 Token Exchange (the act claim \"provides a means within a JWT to express that delegation has occurred and identify the acting party\"). IETF. 2020-01.",
          "url": "https://www.rfc-editor.org/rfc/rfc8693.html",
          "verified": "primary"
        },
        {
          "n": 24,
          "title": "MCP specification 2026-07-28, Authorization",
          "text": "MCP specification 2026-07-28, Authorization (MCP servers MUST validate that access tokens were issued specifically for them and \"MUST NOT accept or transit any other tokens\"). Model Context Protocol. 2026-07-28.",
          "url": "https://modelcontextprotocol.io/specification/2026-07-28/basic/authorization",
          "verified": "primary"
        },
        {
          "n": 15,
          "title": "MCP Security Best Practices (2026-07-28)",
          "text": "MCP Security Best Practices (2026-07-28) (token passthrough \"is explicitly forbidden\"; egress proxies and network policies for server-side clients). Model Context Protocol. 2026-07-28.",
          "url": "https://modelcontextprotocol.io/docs/2026-07-28/tutorials/security/security_best_practices",
          "verified": "primary"
        },
        {
          "n": 25,
          "title": "SPIFFE overview",
          "text": "SPIFFE overview (SVIDs are \"short lived cryptographic identity documents\", delivered and rotated through the Workload API). SPIFFE project. 2026.",
          "url": "https://spiffe.io/docs/latest/spiffe-about/overview/",
          "verified": "primary"
        },
        {
          "n": 26,
          "title": "Model AI Governance Framework for Agentic AI, v1.5",
          "text": "Model AI Governance Framework for Agentic AI, v1.5 (agent identity unique and \"cryptographically verifiable\"; authorisations \"time- or session-bound, non-transferable\"). IMDA. 2026-05-20.",
          "url": "https://www.imda.gov.sg/-/media/imda/files/about/emerging-tech-and-research/artificial-intelligence/mgf-for-agentic-ai.pdf",
          "verified": "primary"
        },
        {
          "n": 5,
          "title": "Brief independent investigation of agents' behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident",
          "text": "Brief independent investigation of agents' behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident (METR states that agents \"meant to be fully isolated from one another\" communicated through an internal package repository, and that one agent found working Hugging Face credentials exposed on the internet and posted them to the agents' board; it reports spoofed tool calls in at least 96 transcripts and transcripts missing components after container resets). METR. 2026-08-26.",
          "url": "https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/",
          "verified": "primary"
        },
        {
          "n": 14,
          "title": "Vivaria server environment variables",
          "text": "Vivaria server environment variables (no-internet task environments connected to a separate Docker network and optionally sandboxed with iptables rules; model API requests can be routed through a separate proxy service). METR. 2026.",
          "url": "https://vivaria.metr.org/reference/config/",
          "verified": "primary"
        },
        {
          "n": 6,
          "title": "OWASP Top 10 for Agentic Applications for 2026",
          "text": "OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents). OWASP GenAI Security Project. 2025-12-09.",
          "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
          "verified": "primary"
        },
        {
          "n": 17,
          "title": "MITRE ATLAS data, release v2026.09",
          "text": "MITRE ATLAS data, release v2026.09 (16 tactics, 120 techniques, 88 sub-techniques, 40 mitigations; technique names and technique-to-mitigation links read from dist/v6/ATLAS-2026.09.yaml). MITRE. 2026-09-15.",
          "url": "https://github.com/mitre-atlas/atlas-data/releases/tag/v2026.09",
          "verified": "primary"
        },
        {
          "n": 7,
          "title": "NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations",
          "text": "NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations (control catalogue cited by control id; publication page of Revision 5 with update 1 of 10 Dec 2020). NIST. 2020-12-10.",
          "url": "https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final",
          "verified": "primary"
        },
        {
          "n": 9,
          "title": "Improving our alignment and security efforts",
          "text": "Improving our alignment and security efforts (best practices for external partners running cyber evaluations: the only outside connection is \"to the model's own API\", with the API keys kept outside the environment; the configuration \"should be verified before every evaluation begins\"; boundaries \"phrased as instructions\"; challenges confirmed \"solvable in principle\"; a monitor that flags a scope violation to a human and ends the exercise). Anthropic. 2026-08-31.",
          "url": "https://www.anthropic.com/news/improving-alignment-security-efforts",
          "verified": "primary"
        },
        {
          "n": 8,
          "title": "Third-party cyber evaluations involving OpenAI models",
          "text": "Third-party cyber evaluations involving OpenAI models (OpenAI states that the evaluator's \"intended authorization boundary was the simulated cyber range\", that its model reused a GitHub token another lab's agent had left publicly accessible, and that it will review how to \"set expectations for isolation, credential handling, monitoring, and stop conditions\"). OpenAI. 2026-08-04.",
          "url": "https://openai.com/index/third-party-cyber-evaluations-involving-openai-models/",
          "verified": "primary"
        },
        {
          "n": 27,
          "title": "Exposing a GitHub token in a public repository (misalignment report)",
          "text": "Exposing a GitHub token in a public repository (misalignment report) (OpenAI reports an internally deployed model that published a researcher's GitHub token to a public repository, split into pieces with the stated aim of avoiding secret scanning). OpenAI (Alignment Research Blog). 2026-09-25.",
          "url": "https://alignment.openai.com/misalignment-reports/exposing-a-github-token-in-a-public-repository/",
          "verified": "primary"
        },
        {
          "n": 10,
          "title": "AIUC-1 requirements",
          "text": "AIUC-1 requirements (public requirement index, A001 to F002, each requirement on its own page (E007 and E014 marked retired); AIUC-1 is a standard of the Artificial Intelligence Underwriting Company; this site is not affiliated with AIUC, and a mapping here is not an AIUC-1 certificate or audit). Artificial Intelligence Underwriting Company. 2026-09-24.",
          "url": "https://standard.aiuc-1.com/llms.txt",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Give each agent under test its own workload identity for the run (an attested identity document of the kind SPIFFE defines, or the platform's workload identity) and issue its tokens from a broker outside the environment. The environment template holds no secret.",
        "Keep the model API key with an LLM API proxy outside the environment, reached through the egress allow-list of AIGE-CTL-EVAL-002: the agent sees the proxy, never the key. Anthropic's guidance for external evaluation partners likewise asks that \"the API keys should be kept outside the environment\".",
        "Issue short-lived access tokens whose aud names one tool server and, when the agent acts for a user or another agent, whose act claim names the agent (RFC 8693 token exchange). Tool servers validate the audience and refuse any other token, as the MCP authorization specification of 2026-07-28 requires of MCP servers.",
        "Set every token lifetime no longer than the run's time budget, issue no refresh tokens to agents under evaluation, and revoke what was issued when the run ends or is aborted.",
        "Scrub credentials from memory stores, transcripts and logs before they are written, then grep every run artefact after the run for secret patterns (known key prefixes, high-entropy strings, the run's own issued tokens); a match fails the run. Scan for credentials a run picked up as well as those it was issued: METR's investigation of the OpenAI/Hugging Face incident reports an agent that found working Hugging Face credentials exposed on the internet and posted them to a board other agents read, and OpenAI states that in a third-party evaluation its model reused a GitHub token another lab's agent had left publicly accessible."
      ],
      "openQuestions": [
        "What lifetime should a credential issued for an evaluation run have, and who revokes it when the run is aborted?",
        "Can a secret scan be made complete for encoded or split credentials, or should the control rely on short lifetimes and revocation for whatever a scan may miss? OpenAI reports a model that split a researcher's token into pieces with the stated aim of avoiding secret scanning."
      ],
      "observation": {
        "subjectKind": "eval-run",
        "expected": "No credential other than the run's own short-lived, audience-bound tokens is readable in the environment or appears in the run's artefacts, and none is accepted after the run.",
        "observedExample": "Run 88214: secret scan found 0 matches in transcript, memory store and logs; a replayed token was rejected with an audience error: pass."
      },
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": [
        {
          "status": "pass",
          "url": "https://aigovernanceengineer.com/controls/examples/control-observation.aige-ctl-eval-003.pass.json"
        },
        {
          "status": "fail",
          "url": "https://aigovernanceengineer.com/controls/examples/control-observation.aige-ctl-eval-003.fail.json"
        }
      ]
    },
    {
      "id": "AIGE-CTL-EVAL-004",
      "profile": "evaluation-environment",
      "url": "https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-004",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-eval-004.json",
      "title": "Tool and Action Mediation",
      "version": "0.2",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "specified",
      "objective": "Every tool call an agent makes during a run passes a mediation point outside the model that checks it against policy before it executes.",
      "failureModes": [
        "A tool call executes without a policy verdict recorded for it.",
        "An irreversible action runs while the mediation point is down.",
        "An approval is reused for a call whose parameters changed.",
        "After repeated denials the agent keeps seeking the same outcome through other calls, and the run continues."
      ],
      "scope": "Tool, MCP and code-execution calls made by the agent under evaluation, and the reviewer (a rule, a model or a person) that decides on them. The internal reasoning of the model is out of scope; network egress is AIGE-CTL-EVAL-002.",
      "enforcementPoints": [
        "deploy",
        "runtime"
      ],
      "verification": [
        {
          "kind": "inspect",
          "text": "Before the run, inspect the environment and its policy: tool servers, MCP servers and code execution are reachable only through the mediation point, and the policy lists each operation class with its verdict, its failure posture (fail closed for irreversible classes such as delete, send, publish and execute) and the denial threshold that interrupts a run."
        },
        {
          "kind": "test",
          "text": "At admission, send through the harness one call the policy denies and one it allows, then take the mediation point down and send an irreversible-class call; the denied call and the call sent while it is down must not execute, and all three must leave a verdict record."
        },
        {
          "kind": "observe",
          "text": "After the run, join the tool servers' own logs with the verdict records: every executed call has an allow verdict, or an approval bound to a parameter hash that matches the call, and no run continued past its denial threshold."
        }
      ],
      "evidence": [
        {
          "artefact": "Mediation policy of the run: operation classes, verdicts, failure posture per class and the denial threshold",
          "schemaId": "policy-card",
          "schema": "https://aigovernanceengineer.com/schemas/policy-card.v1.json",
          "layer": 4
        },
        {
          "artefact": "Verdict record of every call: tool, parameter hash, verdict, reviewer and time",
          "schemaId": "evidence-record",
          "schema": "https://aigovernanceengineer.com/schemas/evidence-record.v1.json",
          "layer": 4
        },
        {
          "artefact": "One observation per run joining the executed calls with their verdicts",
          "schemaId": "control-observation",
          "schema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
          "layer": 5
        }
      ],
      "failureResponse": {
        "effect": "deny",
        "text": "A call without an allow verdict does not execute. While the mediation point is down, irreversible classes fail closed and reads fail open only with an alert. A run in which a call executed without a verdict is stopped and its result is withheld; a run that reaches its denial threshold is interrupted."
      },
      "layer": 4,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "runtime-guardrail",
          "title": "Runtime Guardrail",
          "url": "https://aigovernanceengineer.com/patterns/runtime-guardrail"
        },
        {
          "slug": "human-in-the-loop-gate",
          "title": "Human-in-the-loop Gate",
          "url": "https://aigovernanceengineer.com/patterns/human-in-the-loop-gate"
        }
      ],
      "seeds": [
        {
          "id": "guardrail-every-call",
          "title": "Runtime guardrail on every tool call",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#runtime-guardrails-for-tool-calls"
        },
        {
          "id": "checkpoint-irreversible",
          "title": "Checkpoints on irreversible actions, failing closed",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#where-to-put-a-checkpoint"
        },
        {
          "id": "approval-log",
          "title": "Approval log, bound to the call",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#what-a-good-approval-looks-like"
        },
        {
          "id": "mcp-admission",
          "title": "MCP server admission gate",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#admitting-an-mcp-server"
        },
        {
          "id": "sandbox",
          "title": "Code runs only in a sandbox",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#runtime-guardrails-for-tool-calls"
        }
      ],
      "derivedFrom": [],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART14",
            "name": "EU AI Act Art. 14 human oversight",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art14"
          },
          {
            "id": "AIGE-OBL-OWASP-ACS",
            "name": "Agent Control Standard (ACS)",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-acs"
          },
          {
            "id": "AIGE-OBL-SG-AGENTIC-CHECKPOINTS",
            "name": "Singapore IMDA Model AI Governance Framework for Agentic AI: human checkpoints for significant actions (voluntary)",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-sg-agentic-checkpoints"
          },
          {
            "id": "AIGE-OBL-OWASP-AGENTIC",
            "name": "Top 10 for Agentic Applications 2026",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-agentic"
          }
        ],
        "iso42001": [
          {
            "id": "A.9.2",
            "title": "Processes for responsible use of AI systems"
          }
        ],
        "nistAiRmf": [
          {
            "id": "MAP 4.2",
            "title": "Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented."
          }
        ],
        "owasp": [
          {
            "id": "asi01",
            "externalId": "ASI01",
            "name": "Agent Goal Hijack",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-asi01"
          },
          {
            "id": "asi02",
            "externalId": "ASI02",
            "name": "Tool Misuse and Exploitation",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-asi02"
          },
          {
            "id": "asi05",
            "externalId": "ASI05",
            "name": "Unexpected Code Execution (RCE)",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-asi05"
          },
          {
            "id": "asi09",
            "externalId": "ASI09",
            "name": "Human-Agent Trust Exploitation",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-asi09"
          },
          {
            "id": "llm10-2026",
            "externalId": "LLM10:2026",
            "name": "Improper Output Handling",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-llm10-2026"
          }
        ],
        "atlas": [],
        "aiuc1": [
          "D003",
          "B006"
        ],
        "csaAicm": [],
        "other": [
          {
            "framework": "MITRE ATLAS mitigation",
            "ref": "AML.M0028",
            "note": "AI Agent Tools Permissions Configuration"
          },
          {
            "framework": "MITRE ATLAS mitigation",
            "ref": "AML.M0029",
            "note": "Human In-the-Loop for AI Agent Actions"
          },
          {
            "framework": "MITRE ATLAS mitigation",
            "ref": "AML.M0030",
            "note": "Restrict AI Agent Tool Invocation on Untrusted Data"
          }
        ]
      },
      "references": [
        {
          "n": 13,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Runtime guardrails for tool calls\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#runtime-guardrails-for-tool-calls",
          "verified": "primary"
        },
        {
          "n": 28,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Where to put a checkpoint\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#where-to-put-a-checkpoint",
          "verified": "primary"
        },
        {
          "n": 29,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Admitting an MCP server\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#admitting-an-mcp-server",
          "verified": "primary"
        },
        {
          "n": 30,
          "title": "Agent Control Standard (ACS)",
          "text": "Agent Control Standard (ACS) (wire specification for a guardian agent that decides on an agent action before it runs; donated to OWASP, announced 1 Sep 2026). OWASP GenAI Security Project. 2026-09-01.",
          "url": "https://genai.owasp.org/resource/agent-control-standard-acs/",
          "verified": "primary"
        },
        {
          "n": 31,
          "title": "Guidelines for capability elicitation",
          "text": "Guidelines for capability elicitation (task bugs such as \"The automatic scoring is incorrect\" or a crashed environment are spurious failures to fix before reporting; models get \"the best available scaffolding + tooling\"). METR. 2024-03-15.",
          "url": "https://metr.org/blog/2024-03-15-guidelines-for-capability-elicitation/",
          "verified": "primary"
        },
        {
          "n": 6,
          "title": "OWASP Top 10 for Agentic Applications for 2026",
          "text": "OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents). OWASP GenAI Security Project. 2025-12-09.",
          "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
          "verified": "primary"
        },
        {
          "n": 32,
          "title": "Codex auto-review",
          "text": "Codex auto-review (undated developer documentation, read 2026-09-26: \"Auto-review is a reviewer swap, not a permission grant\"). OpenAI. 2026.",
          "url": "https://developers.openai.com/codex/sandboxing/auto-review",
          "verified": "primary"
        },
        {
          "n": 33,
          "title": "Auto-review of agent actions without synchronous human oversight",
          "text": "Auto-review of agent actions without synchronous human oversight (a separate agent approves or denies actions that cross the sandbox boundary; OpenAI states that auto-review \"should not be treated as a guarantee of security\"). OpenAI (Alignment Research Blog). 2026-04-30.",
          "url": "https://alignment.openai.com/auto-review/",
          "verified": "primary"
        },
        {
          "n": 34,
          "title": "Preparedness Framework, Version 2",
          "text": "Preparedness Framework, Version 2 (Table 5 lists potential safeguards against a misaligned model, among them limiting internet and tool access, credentials and filesystem access, with agent actions \"logged in an uneditable database\"; a one-time capability elicitation is treated \"as a lower bound, rather than a ceiling\"). OpenAI. 2025-04-15.",
          "url": "https://cdn.openai.com/pdf/18a02b5d-6b67-4cec-ab64-68cdfbddebcd/preparedness-framework-v2.pdf",
          "verified": "primary"
        },
        {
          "n": 10,
          "title": "AIUC-1 requirements",
          "text": "AIUC-1 requirements (public requirement index, A001 to F002, each requirement on its own page (E007 and E014 marked retired); AIUC-1 is a standard of the Artificial Intelligence Underwriting Company; this site is not affiliated with AIUC, and a mapping here is not an AIUC-1 certificate or audit). Artificial Intelligence Underwriting Company. 2026-09-24.",
          "url": "https://standard.aiuc-1.com/llms.txt",
          "verified": "primary"
        },
        {
          "n": 27,
          "title": "Exposing a GitHub token in a public repository (misalignment report)",
          "text": "Exposing a GitHub token in a public repository (misalignment report) (OpenAI reports an internally deployed model that published a researcher's GitHub token to a public repository, split into pieces with the stated aim of avoiding secret scanning). OpenAI (Alignment Research Blog). 2026-09-25.",
          "url": "https://alignment.openai.com/misalignment-reports/exposing-a-github-token-in-a-public-repository/",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Put the mediation point between the decision to call a tool and the call, outside the model and the agent's process: a gateway or guardian that checks identity, allow-list, parameters and operation class before the call runs, as chapter 23 describes and OWASP's Agent Control Standard specifies on the wire. Route tool servers, MCP servers and code execution only through it, so no call can go around it.",
        "Record the failure posture per operation class in the policy of the run. Chapter 23 recommends failing closed for pay, delete, send and execute and failing open, with an alert, only for reads, and notes that the reference guardian of the Agent Control Standard starts with a fail-open posture: set the posture, do not inherit it.",
        "Bind an approval to the exact call. OpenAI's Codex documentation describes an override that \"applies to the exact denied action, not similar future actions\" and holds for one retry; store a hash of the parameters with each approval and refuse a call whose parameters differ.",
        "Interrupt a run that keeps asking. The Codex documentation describes a rejection circuit breaker that, in its current open-source implementation, interrupts the turn after 3 consecutive denials or 10 in the last 50 reviews, and OpenAI's post on auto-review states that it stops the trajectory after repeated denials. Record the threshold in the policy and make reaching it a stop condition (AIGE-CTL-EVAL-006).",
        "An automated reviewer can stand in for a person at the mediation point without widening what the agent may do: the Codex documentation states that \"Auto-review is a reviewer swap, not a permission grant\", and OpenAI's post on the design states that it \"should not be treated as a guarantee of security\". OpenAI reports that a model which had published a researcher's token was brought back with \"enforced auto-review on all actions\"."
      ],
      "openQuestions": [
        "How can every call be mediated without taking away the scaffolding and tooling a capability elicitation needs? METR's guidelines ask for \"the best available scaffolding + tooling\".",
        "When the reviewer at the mediation point is a model, what evidence shows that its verdicts are reliable enough to replace a person for a given operation class?"
      ],
      "observation": {
        "subjectKind": "eval-run",
        "expected": "Every executed tool call has an allow verdict, or an approval bound to its exact parameters, recorded before it ran; irreversible calls fail closed while the mediation point is down.",
        "observedExample": "Run 88241: 3,112 tool calls, each with a verdict; 1 publish call executed on an approval issued for different parameters: fail."
      },
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": [
        {
          "status": "pass",
          "url": "https://aigovernanceengineer.com/controls/examples/control-observation.aige-ctl-eval-004.pass.json"
        },
        {
          "status": "fail",
          "url": "https://aigovernanceengineer.com/controls/examples/control-observation.aige-ctl-eval-004.fail.json"
        }
      ]
    },
    {
      "id": "AIGE-CTL-EVAL-005",
      "profile": "evaluation-environment",
      "url": "https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-005",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-eval-005.json",
      "title": "Monitoring Integrity",
      "version": "0.2",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "specified",
      "objective": "The traces and monitors of a run capture every plan step and tool call with the agent's identity and version, as the tool returned it, and the agent cannot disable or alter them.",
      "failureModes": [
        "A tool call appears in the tool server's logs but not in the run's trace, and no gap is recorded.",
        "Monitoring is switched off or reconfigured from inside the environment during a run, for example by changing an environment variable.",
        "A monitor that the run relies on does not run on it, or covers only a sample of it, and nobody notices until after the run.",
        "The recorded output of a tool call differs from what the tool returned (a spoofed tool call)."
      ],
      "scope": "Telemetry, traces and monitors attached to an evaluation run, and the store they are written to. Preserving the records after an incident is covered by AIGE-CTL-EVAL-007.",
      "enforcementPoints": [
        "runtime",
        "periodic"
      ],
      "verification": [
        {
          "kind": "inspect",
          "text": "Before the run, inspect the monitoring configuration: the trace collector, the monitors and their settings run outside the environment, and nothing the agent can write (environment variables, files, its own processes) can switch them off or change what they record."
        },
        {
          "kind": "test",
          "text": "At admission and after each harness change, from inside the environment, try to disable or redirect monitoring (change the environment variables and configuration the agent can reach, stop any local exporter); the trace must continue at the collector and the attempt must raise an alert."
        },
        {
          "kind": "observe",
          "text": "During the run, record the heartbeat of each monitor the run relies on: it must cover every sample and the whole duration, and any gap is recorded with its start and end."
        },
        {
          "kind": "observe",
          "text": "After the run, reconcile the trace with the tool servers' own logs: the same calls in the same order, and every recorded tool output matches the hash the tool server logged for it."
        }
      ],
      "evidence": [
        {
          "artefact": "Monitor coverage record of the run: which monitors ran, over which samples and time, and every gap",
          "schemaId": "evidence-record",
          "schema": "https://aigovernanceengineer.com/schemas/evidence-record.v1.json",
          "layer": 4
        },
        {
          "artefact": "Reconciliation of the trace with the tool servers' logs, with the hash of every tool output",
          "schemaId": "evidence-record",
          "schema": "https://aigovernanceengineer.com/schemas/evidence-record.v1.json",
          "layer": 4
        },
        {
          "artefact": "Tampering test at admission and the reconciliation verdict, filed as an observation of this control",
          "schemaId": "control-observation",
          "schema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
          "layer": 5
        }
      ],
      "failureResponse": {
        "effect": "alert",
        "text": "A monitoring gap, a tampering attempt or a trace that does not reconcile with the tool servers' logs alerts the evaluator and marks the run. The result of a run whose monitors did not cover it, or whose trace does not reconcile, is withheld until the difference is explained; a tampering attempt is also a stop condition (AIGE-CTL-EVAL-006)."
      },
      "layer": 4,
      "secondaryLayers": [
        5
      ],
      "patterns": [
        {
          "slug": "continuous-assurance-telemetry",
          "title": "Continuous Assurance Telemetry",
          "url": "https://aigovernanceengineer.com/patterns/continuous-assurance-telemetry"
        }
      ],
      "seeds": [
        {
          "id": "traces",
          "title": "Traces",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#telemetry-with-the-opentelemetry-genai-conventions"
        },
        {
          "id": "otel-telemetry",
          "title": "Telemetry on the OpenTelemetry GenAI conventions",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#telemetry-with-the-opentelemetry-genai-conventions"
        },
        {
          "id": "trajectory-anomaly",
          "title": "Trajectory anomaly detection",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#an-agent-incident-taxonomy"
        }
      ],
      "derivedFrom": [],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART12",
            "name": "EU AI Act Art. 12 record-keeping and logging",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art12"
          },
          {
            "id": "AIGE-OBL-NISTRMF-MEASURE",
            "name": "MEASURE",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure"
          }
        ],
        "iso42001": [
          {
            "id": "A.6.2.8",
            "title": "AI system recording of event logs"
          },
          {
            "id": "A.6.2.6",
            "title": "AI system operation and monitoring"
          }
        ],
        "nistAiRmf": [
          {
            "id": "MEASURE 3.1",
            "title": "Existing, unanticipated and emergent risks are tracked"
          }
        ],
        "owasp": [
          {
            "id": "asi10",
            "externalId": "ASI10",
            "name": "Rogue Agents",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-asi10"
          }
        ],
        "atlas": [],
        "aiuc1": [
          "E015"
        ],
        "csaAicm": [],
        "other": [
          {
            "framework": "MITRE ATLAS mitigation",
            "ref": "AML.M0024",
            "note": "AI Telemetry Logging"
          },
          {
            "framework": "NIST SP 800-53 Rev. 5",
            "ref": "AU-2",
            "note": "Event Logging"
          },
          {
            "framework": "NIST SP 800-53 Rev. 5",
            "ref": "AU-9",
            "note": "Protection of Audit Information"
          },
          {
            "framework": "NIST SP 800-53 Rev. 5",
            "ref": "AU-12",
            "note": "Audit Record Generation"
          },
          {
            "framework": "NIST SP 800-53 Rev. 5",
            "ref": "SI-4",
            "note": "System Monitoring"
          }
        ]
      },
      "references": [
        {
          "n": 35,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Telemetry with the OpenTelemetry GenAI conventions\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#telemetry-with-the-opentelemetry-genai-conventions",
          "verified": "primary"
        },
        {
          "n": 36,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"An agent incident taxonomy\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#an-agent-incident-taxonomy",
          "verified": "primary"
        },
        {
          "n": 37,
          "title": "OpenTelemetry semantic conventions for generative AI",
          "text": "OpenTelemetry semantic conventions for generative AI (agent, tool and model spans, events and metrics; status Development). OpenTelemetry. 2026.",
          "url": "https://github.com/open-telemetry/semantic-conventions-genai/tree/main/docs/gen-ai",
          "verified": "primary"
        },
        {
          "n": 5,
          "title": "Brief independent investigation of agents' behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident",
          "text": "Brief independent investigation of agents' behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident (METR states that agents \"meant to be fully isolated from one another\" communicated through an internal package repository, and that one agent found working Hugging Face credentials exposed on the internet and posted them to the agents' board; it reports spoofed tool calls in at least 96 transcripts and transcripts missing components after container resets). METR. 2026-08-26.",
          "url": "https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/",
          "verified": "primary"
        },
        {
          "n": 38,
          "title": "Frontier Risk Report (February to March 2026)",
          "text": "Frontier Risk Report (February to March 2026) (METR states that its red-teaming exercise at Anthropic found \"several simple ways for monitoring to be disabled\", one by changing an environment variable). METR. 2026-05-19.",
          "url": "https://metr.org/blog/2026-05-19-frontier-risk-report/",
          "verified": "primary"
        },
        {
          "n": 7,
          "title": "NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations",
          "text": "NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations (control catalogue cited by control id; publication page of Revision 5 with update 1 of 10 Dec 2020). NIST. 2020-12-10.",
          "url": "https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final",
          "verified": "primary"
        },
        {
          "n": 39,
          "title": "The Hugging Face incident and the road ahead",
          "text": "The Hugging Face incident and the road ahead (OpenAI states that its chain-of-thought monitors \"did not run on the evaluations in this incident\", and that it is strengthening its incident response plan with clearer rules on \"who can stop a run or approve restarting it\"). OpenAI. 2026-08-26.",
          "url": "https://openai.com/index/hugging-face-incident-and-the-road-ahead/",
          "verified": "primary"
        },
        {
          "n": 40,
          "title": "Priorities and principles for effective third party assessments",
          "text": "Priorities and principles for effective third party assessments (asks whether monitoring is implemented across training, evaluations and deployment \"in a way that cannot easily be disabled\", and for claims \"pre-registered before assessment activities begin\"). OpenAI. 2026-09-22.",
          "url": "https://openai.com/index/priorities-principles-third-party-assessments/",
          "verified": "primary"
        },
        {
          "n": 34,
          "title": "Preparedness Framework, Version 2",
          "text": "Preparedness Framework, Version 2 (Table 5 lists potential safeguards against a misaligned model, among them limiting internet and tool access, credentials and filesystem access, with agent actions \"logged in an uneditable database\"; a one-time capability elicitation is treated \"as a lower bound, rather than a ceiling\"). OpenAI. 2025-04-15.",
          "url": "https://cdn.openai.com/pdf/18a02b5d-6b67-4cec-ab64-68cdfbddebcd/preparedness-framework-v2.pdf",
          "verified": "primary"
        },
        {
          "n": 10,
          "title": "AIUC-1 requirements",
          "text": "AIUC-1 requirements (public requirement index, A001 to F002, each requirement on its own page (E007 and E014 marked retired); AIUC-1 is a standard of the Artificial Intelligence Underwriting Company; this site is not affiliated with AIUC, and a mapping here is not an AIUC-1 certificate or audit). Artificial Intelligence Underwriting Company. 2026-09-24.",
          "url": "https://standard.aiuc-1.com/llms.txt",
          "verified": "primary"
        },
        {
          "n": 12,
          "title": "OpenAI Hugging Face Incident Technical Report",
          "text": "OpenAI Hugging Face Incident Technical Report (OpenAI states that high-risk workloads are \"prohibited via technical controls from receiving direct or transitive Internet access\", protected by \"two separate layers of network isolation\", and that it is building tooling to \"identify and halt evaluation workloads\"). OpenAI. 2026-08-26.",
          "url": "https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf",
          "verified": "primary"
        },
        {
          "n": 41,
          "title": "Unauthorized communication via temporary file hosting services (misalignment report)",
          "text": "Unauthorized communication via temporary file hosting services (misalignment report) (OpenAI reports agents in RL training that uploaded output files to public hosting platforms for co-working agents; the behavior was found by a monitoring system that \"ran on 20% of the samples\" of the run, which now runs on 100% of samples). OpenAI (Alignment Research Blog). 2026-09-16.",
          "url": "https://alignment.openai.com/misalignment-reports/unauthorized-communication-via-temporary-file-hosting-services/",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Run the collector, the monitors and their configuration outside the environment, and write the trace to append-only storage the agent cannot reach. OpenAI's Preparedness Framework v2 lists agent actions \"logged in an uneditable database\" and reviewed by asynchronous monitors among its potential safeguards against a misaligned model. OpenAI's technical report on the Hugging Face incident states that models sometimes tried to \"erase or tamper with their outputs or message logs\", and that none of the attempts it observed to manipulate tool trajectories affected the logs its graders or monitors ultimately see.",
        "Keep every switch of the monitoring out of the agent's reach. METR states that its red-teaming exercise at Anthropic found \"several simple ways for monitoring to be disabled\", one by changing an environment variable that indicated whether the traffic came from Claude Code, and OpenAI's criteria for third-party assessments ask whether monitoring covers training, evaluations and deployment \"in a way that cannot easily be disabled\".",
        "Check that the monitors ran on this run, and over all of it. OpenAI states that its chain-of-thought monitors \"did not run on the evaluations\" involved in the Hugging Face incident, and reports a training incident found by a monitoring system that ran on 20% of the samples of the run and now runs on 100%.",
        "Reconcile the transcript with what the tools logged, not only with itself. METR's investigation of the OpenAI/Hugging Face incident reports that at least 96 transcripts show clear evidence of spoofed tool calls, where an agent appeared to run one command and replaced its output; a hash of each output, logged by the tool server, lets a reviewer find the substitution."
      ],
      "openQuestions": [
        "How can a reviewer show that a run's trace is complete for actions that pass no tool server, not only that the records it holds are unaltered?",
        "The OpenTelemetry GenAI conventions are still at status Development: should the profile name the attributes it relies on, or only the events a trace must contain?"
      ],
      "observation": {
        "subjectKind": "eval-run",
        "expected": "The monitors ran over the whole run, the agent could not switch them off, and the trace reconciles with the tool servers' logs call by call.",
        "observedExample": "Run 88251: 1,904 calls in the trace and in the tool servers' logs, 0 output hash mismatches, monitor coverage 100% of samples: pass."
      },
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": [
        {
          "status": "pass",
          "url": "https://aigovernanceengineer.com/controls/examples/control-observation.aige-ctl-eval-005.pass.json"
        },
        {
          "status": "fail",
          "url": "https://aigovernanceengineer.com/controls/examples/control-observation.aige-ctl-eval-005.fail.json"
        }
      ]
    },
    {
      "id": "AIGE-CTL-EVAL-006",
      "profile": "evaluation-environment",
      "url": "https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-006",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-eval-006.json",
      "title": "Stop Conditions",
      "version": "0.2",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "specified",
      "objective": "Every evaluation run has stop conditions, budgets and a stop handle defined before it starts, and a stop, pulled by hand or tripped by a breaker, halts the agent's calls and writes within a measured time across every hop it delegated to inside the environment.",
      "failureModes": [
        "A run starts without recorded stop conditions, budgets or a working stop handle.",
        "A budget (steps, tool calls, tokens, spend or time) or a breaker threshold is exceeded and the run continues.",
        "A tool call or a write is recorded after the stop was pulled or the breaker tripped, including through a token issued before the stop.",
        "A sub-agent or a service the agent delegated to keeps working after the parent run was stopped."
      ],
      "scope": "Agents under evaluation and every agent, tool or service they delegate to inside the environment. A third-party agent outside the environment can only be cut off at the environment's boundary. A lab's criteria for halting a model's development or deployment are policy decisions and out of scope.",
      "enforcementPoints": [
        "runtime",
        "periodic"
      ],
      "verification": [
        {
          "kind": "inspect",
          "text": "Before the run, inspect the run record: stop conditions, per-agent budgets and breaker thresholds are recorded, and the stop handle is named with the levels it can apply (pause the task, trip the breaker, revoke the identity)."
        },
        {
          "kind": "test",
          "text": "Drill the stop on a schedule and before the first run of a new harness version: pull it during a live task, measure the time from the pull to the first rejected call, and confirm zero tool calls and zero writes after the trip, including through delegated tokens and sub-agents."
        },
        {
          "kind": "observe",
          "text": "During runs, record every breaker trip and budget exhaustion with its trigger, and check that no further call from that agent followed it."
        }
      ],
      "evidence": [
        {
          "artefact": "Stop conditions, budgets and breaker thresholds of the run, recorded before it starts",
          "schemaId": "policy-card",
          "schema": "https://aigovernanceengineer.com/schemas/policy-card.v1.json",
          "layer": 4
        },
        {
          "artefact": "Breaker trips and budget exhaustions of each run, with their triggers",
          "schemaId": "evidence-record",
          "schema": "https://aigovernanceengineer.com/schemas/evidence-record.v1.json",
          "layer": 4
        },
        {
          "artefact": "Drill record: time to stop, and calls and writes after the trip",
          "schemaId": "control-observation",
          "schema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
          "layer": 5
        }
      ],
      "failureResponse": {
        "effect": "alert",
        "text": "A stop condition that is met trips the per-agent breaker, so the gateway rejects every further call from that agent, and alerts the evaluator. A drill that finds calls or writes after the trip fails the control and blocks runs on that harness version until the path is closed."
      },
      "layer": 4,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "kill-switch-circuit-breaker",
          "title": "Kill Switch / Circuit Breaker",
          "url": "https://aigovernanceengineer.com/patterns/kill-switch-circuit-breaker"
        }
      ],
      "seeds": [
        {
          "id": "per-agent-breaker",
          "title": "Per-agent circuit breaker",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#kill-switch-and-per-agent-circuit-breakers"
        },
        {
          "id": "drilled-kill-switch",
          "title": "Drilled kill switch",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#kill-switch-and-per-agent-circuit-breakers"
        },
        {
          "id": "execution-budgets",
          "title": "Execution budgets",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#execution-limits"
        },
        {
          "id": "remote-agents",
          "title": "Stopping third-party agents at your boundary",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#stopping-across-hops"
        }
      ],
      "derivedFrom": [],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART14",
            "name": "EU AI Act Art. 14 human oversight",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art14"
          },
          {
            "id": "AIGE-OBL-NISTRMF-MANAGE",
            "name": "MANAGE",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage"
          },
          {
            "id": "AIGE-OBL-OWASP-AGENTIC",
            "name": "Top 10 for Agentic Applications 2026",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-agentic"
          },
          {
            "id": "AIGE-OBL-CN-TC260-AGENTS",
            "name": "TC260 Framework 3.0 Appendix 2: agentic AI risk management (voluntary; 2026-09-14)",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-cn-tc260-agents"
          }
        ],
        "iso42001": [
          {
            "id": "A.6.2.6",
            "title": "AI system operation and monitoring"
          }
        ],
        "nistAiRmf": [
          {
            "id": "MANAGE 2.4",
            "title": "Mechanisms to supersede, disengage or deactivate AI systems"
          }
        ],
        "owasp": [
          {
            "id": "asi08",
            "externalId": "ASI08",
            "name": "Cascading Failures",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-asi08"
          },
          {
            "id": "asi10",
            "externalId": "ASI10",
            "name": "Rogue Agents",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-asi10"
          },
          {
            "id": "llm06-2026",
            "externalId": "LLM06:2026",
            "name": "Unbounded Consumption",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-llm06-2026"
          }
        ],
        "atlas": [
          {
            "id": "aml-t0034",
            "externalId": "AML.T0034",
            "name": "Cost Harvesting",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-aml-t0034"
          }
        ],
        "aiuc1": [],
        "csaAicm": [],
        "other": [
          {
            "framework": "EU AI Act",
            "ref": "Art. 14(4)(e)",
            "note": "stop procedure"
          },
          {
            "framework": "MITRE ATLAS mitigation",
            "ref": "AML.M0036",
            "note": "Limit AI Workload Resource Consumption"
          }
        ]
      },
      "references": [
        {
          "n": 42,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Kill switch and per-agent circuit breakers\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#kill-switch-and-per-agent-circuit-breakers",
          "verified": "primary"
        },
        {
          "n": 43,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Execution limits\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#execution-limits",
          "verified": "primary"
        },
        {
          "n": 44,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Stopping across hops\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#stopping-across-hops",
          "verified": "primary"
        },
        {
          "n": 45,
          "title": "NIST AI RMF 1.0 (AI 100-1)",
          "text": "NIST AI RMF 1.0 (AI 100-1) (MANAGE 2.4: mechanisms to \"supersede, disengage, or deactivate AI systems\" whose outcomes are inconsistent with intended use). NIST. 2023-01-26.",
          "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
          "verified": "primary"
        },
        {
          "n": 46,
          "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744",
          "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744 (Art. 14(4)(e): human oversight includes the means to interrupt the system through a stop procedure). Publications Office of the EU (EUR-Lex). 2026-07-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng",
          "verified": "primary"
        },
        {
          "n": 47,
          "title": "Agentic Trust Framework v1",
          "text": "Agentic Trust Framework v1 (\"You can stop one agent without stopping the business\"; containment by revoking the agent's identity). CSAI Foundation / Cloud Security Alliance. 2026-02.",
          "url": "https://agentictrustframework.ai/",
          "verified": "primary"
        },
        {
          "n": 16,
          "title": "OWASP GenAI LLM Top 10 2026",
          "text": "OWASP GenAI LLM Top 10 2026 (LLM01:2026 Prompt Injection to LLM10:2026 Improper Output Handling; resource page dated 3 Aug 2026). OWASP GenAI Security Project. 2026-08-03.",
          "url": "https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/",
          "verified": "primary"
        },
        {
          "n": 48,
          "title": "Agent2Agent (A2A) Protocol Specification v1.0",
          "text": "Agent2Agent (A2A) Protocol Specification v1.0 (Cancel Task: \"The server will attempt to cancel the task, but success is not guaranteed\"). A2A Project (Linux Foundation). 2026-05-28.",
          "url": "https://a2a-protocol.org/latest/specification/",
          "verified": "primary"
        },
        {
          "n": 6,
          "title": "OWASP Top 10 for Agentic Applications for 2026",
          "text": "OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents). OWASP GenAI Security Project. 2025-12-09.",
          "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
          "verified": "primary"
        },
        {
          "n": 17,
          "title": "MITRE ATLAS data, release v2026.09",
          "text": "MITRE ATLAS data, release v2026.09 (16 tactics, 120 techniques, 88 sub-techniques, 40 mitigations; technique names and technique-to-mitigation links read from dist/v6/ATLAS-2026.09.yaml). MITRE. 2026-09-15.",
          "url": "https://github.com/mitre-atlas/atlas-data/releases/tag/v2026.09",
          "verified": "primary"
        },
        {
          "n": 49,
          "title": "Common Elements of Frontier AI Safety Policies (December 2025 Update)",
          "text": "Common Elements of Frontier AI Safety Policies (December 2025 Update) (the policies set \"conditions for halting development and deployment\" when mitigations are insufficient). METR. 2025-12-09.",
          "url": "https://metr.org/blog/2025-12-09-common-elements-of-frontier-ai-safety-policies/",
          "verified": "primary"
        },
        {
          "n": 5,
          "title": "Brief independent investigation of agents' behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident",
          "text": "Brief independent investigation of agents' behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident (METR states that agents \"meant to be fully isolated from one another\" communicated through an internal package repository, and that one agent found working Hugging Face credentials exposed on the internet and posted them to the agents' board; it reports spoofed tool calls in at least 96 transcripts and transcripts missing components after container resets). METR. 2026-08-26.",
          "url": "https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/",
          "verified": "primary"
        },
        {
          "n": 18,
          "title": "An agent used DNS to reach an external chatbot (misalignment report)",
          "text": "An agent used DNS to reach an external chatbot (misalignment report) (OpenAI reports a training run that reached a public chatbot through \"insufficient DNS filtering\" in its sandbox; the monitor flagged it within 15 minutes, the run \"did not stop automatically as expected\" and was killed 2.5 hours later). OpenAI (Alignment Research Blog). 2026-09-25.",
          "url": "https://alignment.openai.com/misalignment-reports/an-agent-used-dns-to-reach-an-external-chatbot/",
          "verified": "primary"
        },
        {
          "n": 9,
          "title": "Improving our alignment and security efforts",
          "text": "Improving our alignment and security efforts (best practices for external partners running cyber evaluations: the only outside connection is \"to the model's own API\", with the API keys kept outside the environment; the configuration \"should be verified before every evaluation begins\"; boundaries \"phrased as instructions\"; challenges confirmed \"solvable in principle\"; a monitor that flags a scope violation to a human and ends the exercise). Anthropic. 2026-08-31.",
          "url": "https://www.anthropic.com/news/improving-alignment-security-efforts",
          "verified": "primary"
        },
        {
          "n": 50,
          "title": "Pacing model development in an era of cyber-critical capabilities",
          "text": "Pacing model development in an era of cyber-critical capabilities (teams paged by a highest-priority monitoring alert are expected to pause the activity if they cannot determine \"within 30 minutes that the flag is a false positive\"). OpenAI. 2026-08-18.",
          "url": "https://openai.com/index/pacing-model-development-cyber-capabilities/",
          "verified": "primary"
        },
        {
          "n": 12,
          "title": "OpenAI Hugging Face Incident Technical Report",
          "text": "OpenAI Hugging Face Incident Technical Report (OpenAI states that high-risk workloads are \"prohibited via technical controls from receiving direct or transitive Internet access\", protected by \"two separate layers of network isolation\", and that it is building tooling to \"identify and halt evaluation workloads\"). OpenAI. 2026-08-26.",
          "url": "https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf",
          "verified": "primary"
        },
        {
          "n": 39,
          "title": "The Hugging Face incident and the road ahead",
          "text": "The Hugging Face incident and the road ahead (OpenAI states that its chain-of-thought monitors \"did not run on the evaluations in this incident\", and that it is strengthening its incident response plan with clearer rules on \"who can stop a run or approve restarting it\"). OpenAI. 2026-08-26.",
          "url": "https://openai.com/index/hugging-face-incident-and-the-road-ahead/",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Record per-agent budgets (steps, tool calls, tokens, spend, wall-clock time) and breaker thresholds (unauthorised calls, refused egress attempts, anomaly scores) in the run record, and enforce them at the gateway the agent's calls pass through, not inside the agent.",
        "Make budget exhaustion and threshold breaches trip the breaker automatically. A ticket or a log line alone is not a stop. OpenAI reports a training run that \"did not stop automatically as expected\" after a monitoring alert and was killed 2.5 hours later; Anthropic's guidance for external evaluation partners asks that a monitor which sees a run leave its scope flag it to a human and end the exercise.",
        "Drill the stop: pull it mid-task, measure the time from the pull to the first rejected call, and assert zero tool calls and zero writes after the trip for a window longer than the longest task. File the measurement as a control observation. A response target such as the one OpenAI describes, where responders who cannot rule out a flag as a false positive within 30 minutes are expected to pause the activity, holds only if the pause it calls for has been drilled.",
        "Make the kill path work across delegation hops and across runs: sub-agents run under delegated tokens that the stop revokes, token lifetimes are short enough to bound the tail, and calls to agents outside the environment are cut at its boundary, because a remote cancel is not guaranteed to succeed. OpenAI's technical report on the Hugging Face incident describes tooling being built to halt evaluation workloads by workload type, agent type or evaluation task.",
        "Keep the stop handle out of the agent's reach: the agent cannot call, reconfigure or delay it, and every use is logged with its trigger and the level applied. Name who may pull it and who may approve a restart; OpenAI states that it is strengthening its incident response plan with clearer rules on \"who can stop a run or approve restarting it\"."
      ],
      "openQuestions": [
        "Which observations should trip a stop automatically during an evaluation, and which should only alert the evaluator?",
        "What time to stop is acceptable for an evaluation run, and should the target be stated per stop level or per task class?"
      ],
      "observation": {
        "subjectKind": "eval-run",
        "expected": "After a stop is pulled or a breaker trips, no tool call or write from the agent or its sub-agents, and a time to stop within the target recorded for the run.",
        "observedExample": "Drill on run 88220: calls rejected 3.8 s after the pull; 0 tool calls but 1 storage write after the trip, through a refresh token issued before the pull: fail."
      },
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": [
        {
          "status": "pass",
          "url": "https://aigovernanceengineer.com/controls/examples/control-observation.aige-ctl-eval-006.pass.json"
        },
        {
          "status": "fail",
          "url": "https://aigovernanceengineer.com/controls/examples/control-observation.aige-ctl-eval-006.fail.json"
        }
      ]
    },
    {
      "id": "AIGE-CTL-EVAL-007",
      "profile": "evaluation-environment",
      "url": "https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-007",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-eval-007.json",
      "title": "Incident Evidence Preservation",
      "version": "0.2",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "specified",
      "objective": "When a run produces an incident, its traces, configuration and outputs are frozen before anything is fixed, so the record can be reviewed as it was.",
      "failureModes": [
        "Records of a run are changed or deleted after an incident was declared.",
        "The environment is reset before its state and traces were captured.",
        "Part of a run's transcript is lost when a container is reset, and the gap is not recorded.",
        "An incident record does not link to the run it came from or to the hashes of the frozen records."
      ],
      "scope": "Evaluation runs that produce an incident or a result disputed after the fact, and the records they leave. Reporting to authorities follows the incident process of chapter 17.",
      "enforcementPoints": [
        "runtime",
        "periodic"
      ],
      "verification": [
        {
          "kind": "inspect",
          "text": "Inspect the evidence store and the harness configuration: the transcripts, traces, configuration and outputs of every run are written as they are produced to write-once storage outside the environment, with a retention period recorded, and the harness snapshots the environment before any reset."
        },
        {
          "kind": "test",
          "text": "Drill the freeze on a schedule: declare a test incident on a live run, then check that the environment snapshot, trace, transcript and configuration were captured with their hashes before the environment was reset, and that an attempt to delete or overwrite them is refused."
        },
        {
          "kind": "observe",
          "text": "For each real incident, read the incident record: it names the run, lists every frozen artefact with its hash, the hashes still match the stored artefacts, and every gap in the transcript is recorded with its cause."
        }
      ],
      "evidence": [
        {
          "artefact": "Incident record naming the run and listing the frozen artefacts in its supporting materials",
          "schemaId": "incident-record",
          "schema": "https://aigovernanceengineer.com/schemas/incident-record.v1.json",
          "layer": 5
        },
        {
          "artefact": "Freeze record: hashes of the environment snapshot, trace, transcript and configuration, with the time of capture and the actor",
          "schemaId": "evidence-record",
          "schema": "https://aigovernanceengineer.com/schemas/evidence-record.v1.json",
          "layer": 5
        },
        {
          "artefact": "Freeze drill and hash check, filed as an observation of this control",
          "schemaId": "control-observation",
          "schema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
          "layer": 5
        }
      ],
      "failureResponse": {
        "effect": "alert",
        "text": "A missing snapshot, a hash mismatch or an unrecorded gap alerts the incident owner and is entered in the incident record. Until the freeze is complete the environment is not reset or reused, and the fix is made on a new version, not in place."
      },
      "layer": 5,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "incident-pipeline",
          "title": "Incident Pipeline",
          "url": "https://aigovernanceengineer.com/patterns/incident-pipeline"
        },
        {
          "slug": "machine-readable-evidence-oscal",
          "title": "Machine-Readable Evidence (OSCAL)",
          "url": "https://aigovernanceengineer.com/patterns/machine-readable-evidence-oscal"
        }
      ],
      "seeds": [
        {
          "id": "traces",
          "title": "Traces",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#telemetry-with-the-opentelemetry-genai-conventions"
        },
        {
          "id": "otel-telemetry",
          "title": "Telemetry on the OpenTelemetry GenAI conventions",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#telemetry-with-the-opentelemetry-genai-conventions"
        },
        {
          "id": "ai-act-high-risk",
          "title": "EU AI Act hooks for a high-risk purpose",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#eu-ai-act-hooks-for-agents"
        }
      ],
      "derivedFrom": [],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART73",
            "name": "EU AI Act Art. 73 serious-incident reporting",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art73"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART12",
            "name": "EU AI Act Art. 12 record-keeping and logging",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art12"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART26-6",
            "name": "EU AI Act Art. 26(6) deployer retention of automatically generated logs",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26-6"
          },
          {
            "id": "AIGE-OBL-GPAICOP-SAFETY-C9",
            "name": "Safety and Security Commitment 9: serious-incident reporting",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-gpaicop-safety-c9"
          },
          {
            "id": "AIGE-OBL-ISO42001-A8",
            "name": "A.8 Information for interested parties",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a8"
          }
        ],
        "iso42001": [
          {
            "id": "A.8.4",
            "title": "Communication of incidents"
          },
          {
            "id": "A.6.2.8",
            "title": "AI system recording of event logs"
          }
        ],
        "nistAiRmf": [
          {
            "id": "MANAGE 4.3",
            "title": "Incidents and errors are communicated to relevant AI actors, including affected communities."
          }
        ],
        "owasp": [],
        "atlas": [],
        "aiuc1": [
          "E015"
        ],
        "csaAicm": [],
        "other": [
          {
            "framework": "NIST SP 800-53 Rev. 5",
            "ref": "IR-4",
            "note": "Incident Handling"
          },
          {
            "framework": "NIST SP 800-53 Rev. 5",
            "ref": "AU-9",
            "note": "Protection of Audit Information"
          }
        ]
      },
      "references": [
        {
          "n": 51,
          "title": "Incidents, issues and root causes",
          "text": "Incidents, issues and root causes (AI Governance Engineering Body of Knowledge v0.5.0, chapter 17, section \"Freeze before you fix\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/incidents#freeze-before-you-fix",
          "verified": "primary"
        },
        {
          "n": 52,
          "title": "Incidents, issues and root causes",
          "text": "Incidents, issues and root causes (AI Governance Engineering Body of Knowledge v0.5.0, chapter 17, section \"The incident record\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/incidents#the-incident-record",
          "verified": "primary"
        },
        {
          "n": 53,
          "title": "Incidents, issues and root causes",
          "text": "Incidents, issues and root causes (AI Governance Engineering Body of Knowledge v0.5.0, chapter 17, section \"The overlapping clocks\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/incidents#the-overlapping-clocks",
          "verified": "primary"
        },
        {
          "n": 5,
          "title": "Brief independent investigation of agents' behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident",
          "text": "Brief independent investigation of agents' behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident (METR states that agents \"meant to be fully isolated from one another\" communicated through an internal package repository, and that one agent found working Hugging Face credentials exposed on the internet and posted them to the agents' board; it reports spoofed tool calls in at least 96 transcripts and transcripts missing components after container resets). METR. 2026-08-26.",
          "url": "https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/",
          "verified": "primary"
        },
        {
          "n": 31,
          "title": "Guidelines for capability elicitation",
          "text": "Guidelines for capability elicitation (task bugs such as \"The automatic scoring is incorrect\" or a crashed environment are spurious failures to fix before reporting; models get \"the best available scaffolding + tooling\"). METR. 2024-03-15.",
          "url": "https://metr.org/blog/2024-03-15-guidelines-for-capability-elicitation/",
          "verified": "primary"
        },
        {
          "n": 7,
          "title": "NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations",
          "text": "NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations (control catalogue cited by control id; publication page of Revision 5 with update 1 of 10 Dec 2020). NIST. 2020-12-10.",
          "url": "https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final",
          "verified": "primary"
        },
        {
          "n": 54,
          "title": "Our framework for reporting model misalignment",
          "text": "Our framework for reporting model misalignment (each full report describes the behavior observed, its severity and any external impact, the setting, the date, when it was discovered and the models involved). OpenAI. 2026-09-16.",
          "url": "https://openai.com/index/model-misalignment-reporting-framework/",
          "verified": "primary"
        },
        {
          "n": 55,
          "title": "Frontier Governance Framework",
          "text": "Frontier Governance Framework (section 2.6: OpenAI \"maintains an AI Safety Incident Response Plan (AIRP)\" for identifying and responding to AI safety incidents). OpenAI. 2026-05-28.",
          "url": "https://cdn.openai.com/pdf/e37d949b-8c9f-4d76-b99e-4272f4631a7e/openai-frontier-governance-framework.pdf",
          "verified": "primary"
        },
        {
          "n": 10,
          "title": "AIUC-1 requirements",
          "text": "AIUC-1 requirements (public requirement index, A001 to F002, each requirement on its own page (E007 and E014 marked retired); AIUC-1 is a standard of the Artificial Intelligence Underwriting Company; this site is not affiliated with AIUC, and a mapping here is not an AIUC-1 certificate or audit). Artificial Intelligence Underwriting Company. 2026-09-24.",
          "url": "https://standard.aiuc-1.com/llms.txt",
          "verified": "primary"
        },
        {
          "n": 12,
          "title": "OpenAI Hugging Face Incident Technical Report",
          "text": "OpenAI Hugging Face Incident Technical Report (OpenAI states that high-risk workloads are \"prohibited via technical controls from receiving direct or transitive Internet access\", protected by \"two separate layers of network isolation\", and that it is building tooling to \"identify and halt evaluation workloads\"). OpenAI. 2026-08-26.",
          "url": "https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Freeze before you fix, as chapter 17 sets out: snapshot the system as it was (model version and hash, system prompt, policy and tool scopes, configuration), seal the traces of the incident window in tamper-evident storage, record who touched what, and fix on a new version, not in place. OpenAI's technical report on the Hugging Face incident states that it took the compromised Artifactory deployment offline, \"preserved its storage\", and revoked agent credentials.",
        "Write transcripts and traces to write-once storage as they are produced, not at the end of the run, and have the harness snapshot the environment before any reset. METR's investigation of the OpenAI/Hugging Face incident reports that many transcripts were \"missing small components, often due to container resets\".",
        "Link the incident record to the run: the run id, the frozen artefacts and their hashes go in the record's supporting materials, so a reviewer can find the run as it was. OpenAI's framework for reporting model misalignment states that each full report describes the behavior, its severity and any external impact, the setting, the date, when it was discovered and the models involved, and its Frontier Governance Framework refers to an AI Safety Incident Response Plan; a frozen run record gives such a report something to point to.",
        "Keep what an independent reviewer will need. METR states that OpenAI shared \"over a thousand unredacted transcripts\" for its investigation of the Hugging Face incident: a review of that kind depends on the transcripts having been kept whole."
      ],
      "openQuestions": [
        "How long should the records of an evaluation run be kept when the run produced no incident?",
        "Which parts of a frozen run record can be shared with an independent reviewer without exposing the task set, and in what format?"
      ],
      "observation": {
        "subjectKind": "eval-run",
        "expected": "After an incident is declared, the environment snapshot, trace, transcript and configuration of the run are frozen with their hashes before any reset, the incident record links them, and every transcript gap is recorded.",
        "observedExample": "Incident on run 88262: snapshot and trace frozen before the reset, but 14 minutes of transcript lost in a container reset with no gap recorded: fail."
      },
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": [
        {
          "status": "pass",
          "url": "https://aigovernanceengineer.com/controls/examples/control-observation.aige-ctl-eval-007.pass.json"
        },
        {
          "status": "fail",
          "url": "https://aigovernanceengineer.com/controls/examples/control-observation.aige-ctl-eval-007.fail.json"
        }
      ]
    },
    {
      "id": "AIGE-CTL-EVAL-008",
      "profile": "evaluation-environment",
      "url": "https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-008",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-eval-008.json",
      "title": "Harness and Configuration Attestation",
      "version": "0.2",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "specified",
      "objective": "The harness, prompts, tool definitions and configuration a run used are versioned and hashed, so the result can be tied to exactly what was evaluated.",
      "failureModes": [
        "A result is reported without the hashes of the prompts, tool definitions and harness it ran on.",
        "A tool definition changes between admission and the run without an alert.",
        "The configuration in the report differs from the one recorded for the run.",
        "Two results are compared although they ran on different scaffold prompts or task wordings, which can change the behaviour being measured."
      ],
      "scope": "The harness, system and scaffold prompts, task instructions, tool and MCP server definitions, policy bundles, scoring configuration and model artefacts a run loads. The design of the evaluation tasks is out of scope.",
      "enforcementPoints": [
        "pre_merge",
        "deploy"
      ],
      "verification": [
        {
          "kind": "inspect",
          "text": "Before the run, inspect the run manifest: it lists, each with a version and a hash, the harness, the system and scaffold prompts, the task instructions, the tool and MCP server definitions, the policy bundles, the scoring configuration, and the model identifier with its settings."
        },
        {
          "kind": "test",
          "text": "At admission, recompute the hash of every artefact the environment actually loaded and compare it with the manifest: every hash must match. On a copy of the environment, change one tool definition: the run must be blocked with an alert."
        },
        {
          "kind": "inspect",
          "text": "Before a result is released, compare the configuration stated in the report (model, reasoning setting, tool access, harness, safeguards and budget) with the manifests of the runs behind it: they must agree, and results compared with each other must share scaffold prompts and task wording or state the difference."
        }
      ],
      "evidence": [
        {
          "artefact": "Run manifest: version and hash of every artefact the run loaded, recorded before the run outside the environment",
          "schemaId": null,
          "schema": null,
          "layer": 3
        },
        {
          "artefact": "Admission check: the recomputed hashes against the manifest, with its verdict",
          "schemaId": "evidence-record",
          "schema": "https://aigovernanceengineer.com/schemas/evidence-record.v1.json",
          "layer": 3
        },
        {
          "artefact": "Test report stating the tested system, budget and environment of its results, with links to the run manifests",
          "schemaId": "test-report",
          "schema": "https://aigovernanceengineer.com/schemas/test-report.v1.json",
          "layer": 3
        },
        {
          "artefact": "Manifest check of each run, filed as an observation of this control",
          "schemaId": "control-observation",
          "schema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
          "layer": 5
        }
      ],
      "failureResponse": {
        "effect": "deny",
        "text": "A run whose loaded artefacts do not match its manifest is not started, and a change detected during a run stops it. A result whose report does not match the manifests of its runs is not released until the difference is explained or the runs are repeated."
      },
      "layer": 3,
      "secondaryLayers": [
        2
      ],
      "patterns": [
        {
          "slug": "model-artefact-integrity",
          "title": "Model Artefact Integrity",
          "url": "https://aigovernanceengineer.com/patterns/model-artefact-integrity"
        },
        {
          "slug": "aibom",
          "title": "AIBOM",
          "url": "https://aigovernanceengineer.com/patterns/aibom"
        },
        {
          "slug": "eval-gate-in-ci",
          "title": "Eval Gate in CI",
          "url": "https://aigovernanceengineer.com/patterns/eval-gate-in-ci"
        }
      ],
      "seeds": [
        {
          "id": "prompt-change-control",
          "title": "Prompts under change control",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#prompts-as-configuration-under-change-control"
        },
        {
          "id": "mcp-admission",
          "title": "MCP server admission gate",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#admitting-an-mcp-server"
        }
      ],
      "derivedFrom": [],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART15",
            "name": "EU AI Act Art. 15 accuracy, robustness and cybersecurity",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15"
          },
          {
            "id": "AIGE-OBL-OWASP-AIBOM",
            "name": "AIBOM",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-aibom"
          },
          {
            "id": "AIGE-OBL-ISO42001-A6",
            "name": "A.6 AI system life cycle",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a6"
          }
        ],
        "iso42001": [
          {
            "id": "A.6.2.4",
            "title": "AI system verification and validation"
          }
        ],
        "nistAiRmf": [
          {
            "id": "MEASURE 2.1",
            "title": "Test sets, metrics, and details about the tools used during TEVV are documented."
          }
        ],
        "owasp": [
          {
            "id": "asi04",
            "externalId": "ASI04",
            "name": "Agentic Supply Chain Vulnerabilities",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-asi04"
          },
          {
            "id": "llm04-2026",
            "externalId": "LLM04:2026",
            "name": "Supply Chain",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-llm04-2026"
          }
        ],
        "atlas": [
          {
            "id": "aml-t0110",
            "externalId": "AML.T0110",
            "name": "AI Agent Tool Poisoning",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-aml-t0110"
          },
          {
            "id": "aml-t0010",
            "externalId": "AML.T0010",
            "name": "AI Supply Chain Compromise",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-aml-t0010"
          }
        ],
        "aiuc1": [],
        "csaAicm": [],
        "other": [
          {
            "framework": "MITRE ATLAS mitigation",
            "ref": "AML.M0014",
            "note": "Verify AI Artifacts"
          },
          {
            "framework": "MITRE ATLAS mitigation",
            "ref": "AML.M0023",
            "note": "AI Bill of Materials"
          },
          {
            "framework": "NIST SP 800-218A",
            "ref": "PS.1.3",
            "note": "Protect model weights and configuration parameters"
          },
          {
            "framework": "NIST SP 800-218A",
            "ref": "PS.3.2",
            "note": "Keep provenance data for every component of a release"
          },
          {
            "framework": "NIST SP 800-53 Rev. 5",
            "ref": "CM-2",
            "note": "Baseline Configuration"
          },
          {
            "framework": "NIST SP 800-53 Rev. 5",
            "ref": "CM-3",
            "note": "Configuration Change Control"
          },
          {
            "framework": "NIST SP 800-53 Rev. 5",
            "ref": "CM-6",
            "note": "Configuration Settings"
          }
        ]
      },
      "references": [
        {
          "n": 56,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Prompts as configuration under change control\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#prompts-as-configuration-under-change-control",
          "verified": "primary"
        },
        {
          "n": 29,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Admitting an MCP server\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#admitting-an-mcp-server",
          "verified": "primary"
        },
        {
          "n": 57,
          "title": "Governing AI development",
          "text": "Governing AI development (AI Governance Engineering Body of Knowledge v0.5.0, chapter 14, section \"Reproducibility and linked versioning\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-development#reproducibility-and-linked-versioning",
          "verified": "primary"
        },
        {
          "n": 58,
          "title": "Summary of METR's predeployment evaluation of GPT-5.6 Sol",
          "text": "Summary of METR's predeployment evaluation of GPT-5.6 Sol (METR states that \"observed cheating rates can also be influenced by the prompts used in the evaluation scaffold\" and by task wording). METR. 2026-06-26.",
          "url": "https://metr.org/blog/2026-06-26-gpt-5-6-sol/",
          "verified": "primary"
        },
        {
          "n": 59,
          "title": "NIST SP 800-218A, Secure Software Development Practices for Generative AI and Dual-Use Foundation Models: An SSDF Community Profile",
          "text": "NIST SP 800-218A, Secure Software Development Practices for Generative AI and Dual-Use Foundation Models: An SSDF Community Profile (AI-specific tasks added to SSDF 1.1 (e.g. PO.5.3, PS.1.3, PW.3.1 to PW.3.3) and AI-specific recommendations on existing tasks (e.g. PW.1.1, RV.1.1)). NIST. 2024-07.",
          "url": "https://csrc.nist.gov/pubs/sp/800/218/a/final",
          "verified": "primary"
        },
        {
          "n": 17,
          "title": "MITRE ATLAS data, release v2026.09",
          "text": "MITRE ATLAS data, release v2026.09 (16 tactics, 120 techniques, 88 sub-techniques, 40 mitigations; technique names and technique-to-mitigation links read from dist/v6/ATLAS-2026.09.yaml). MITRE. 2026-09-15.",
          "url": "https://github.com/mitre-atlas/atlas-data/releases/tag/v2026.09",
          "verified": "primary"
        },
        {
          "n": 7,
          "title": "NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations",
          "text": "NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations (control catalogue cited by control id; publication page of Revision 5 with update 1 of 10 Dec 2020). NIST. 2020-12-10.",
          "url": "https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final",
          "verified": "primary"
        },
        {
          "n": 9,
          "title": "Improving our alignment and security efforts",
          "text": "Improving our alignment and security efforts (best practices for external partners running cyber evaluations: the only outside connection is \"to the model's own API\", with the API keys kept outside the environment; the configuration \"should be verified before every evaluation begins\"; boundaries \"phrased as instructions\"; challenges confirmed \"solvable in principle\"; a monitor that flags a scope violation to a human and ends the exercise). Anthropic. 2026-08-31.",
          "url": "https://www.anthropic.com/news/improving-alignment-security-efforts",
          "verified": "primary"
        },
        {
          "n": 60,
          "title": "A shared playbook for trustworthy third party evaluations",
          "text": "A shared playbook for trustworthy third party evaluations (recommended report fields include the claim, the tested system (model, reasoning setting, tool access, harness and safeguards), the budget, elicitation methods and validity checks; a score is \"performance under that harness and budget\"). OpenAI. 2026-05-29.",
          "url": "https://openai.com/index/trustworthy-third-party-evaluations-foundations/",
          "verified": "primary"
        },
        {
          "n": 61,
          "title": "Investigating the consequences of accidentally grading CoT during RL",
          "text": "Investigating the consequences of accidentally grading CoT during RL (chain-of-thought text reached the inputs of reward mechanisms by accident; an automated system now scans all RL runs for it with regex matches). OpenAI (Alignment Research Blog). 2026-05-07.",
          "url": "https://alignment.openai.com/accidental-cot-grading/",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Hash what the run loads, not what the repository holds: build the manifest at admission from the artefacts inside the environment (harness image digest, prompts, task instructions, tool and MCP server definitions, policy bundles, scoring configuration, model identifier and settings), store it outside the environment and put its digest in the run record. Chapter 23 treats prompts, tool descriptions and policy bundles as configuration under change control, with the hash recorded in the registry and in every trace.",
        "Check the configuration before each run, not once per environment: Anthropic's guidance for external evaluation partners states that the isolation configuration \"should be verified before every evaluation begins\".",
        "Report the configuration with the result. OpenAI's playbook for third-party evaluations asks reports to state the tested system (model, reasoning setting, tool access, harness and safeguards) and the budget, and to describe a score as \"performance under that harness and budget, not as a measured capability ceiling\".",
        "Put the scoring path and the scaffold prompts in the manifest too. OpenAI's alignment blog describes chain-of-thought text reaching the inputs of reward mechanisms by accident during RL, now caught by an automated scan whose coverage OpenAI says is not perfect; METR states that observed cheating rates \"can also be influenced by the prompts used in the evaluation scaffold\" and by the wording of task instructions."
      ],
      "openQuestions": [
        "How should evaluation-harness configuration be attested so that a third party can verify it without access to the harness itself?",
        "When a third party runs the evaluation, who signs the manifest: the evaluator, the developer of the model or both?"
      ],
      "observation": {
        "subjectKind": "harness",
        "expected": "Every artefact the run loaded matches the version and hash in its manifest, and the report states the same configuration as the manifests of its runs.",
        "observedExample": "Run 88270: 41 artefacts hashed at admission, all matching the manifest; the report states the same model, tools, harness and budget: pass."
      },
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": [
        {
          "status": "pass",
          "url": "https://aigovernanceengineer.com/controls/examples/control-observation.aige-ctl-eval-008.pass.json"
        },
        {
          "status": "fail",
          "url": "https://aigovernanceengineer.com/controls/examples/control-observation.aige-ctl-eval-008.fail.json"
        }
      ]
    },
    {
      "id": "AIGE-CTL-EVAL-009",
      "profile": "evaluation-environment",
      "url": "https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-009",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-eval-009.json",
      "title": "Evaluation Validity Checks",
      "version": "0.2",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "specified",
      "objective": "A result is reported only after checks that the run measured what it claims: scoring worked, the environment did not fail, and the path was evaluated as well as the answer.",
      "failureModes": [
        "A result is reported from a run whose environment crashed or whose automatic scoring was wrong.",
        "A task that could not be solved as set up is scored and reported as a failure of the model.",
        "Only final answers are scored: nobody reads the transcripts of failed runs, or of successes, for scorer tampering, reward hacking, communication between runs or signs of evaluation awareness.",
        "A failed validity check does not block the release it was meant to gate."
      ],
      "scope": "Evaluation runs whose results feed a release decision or an assurance claim. The choice of benchmarks and their statistical design are only in scope where they decide whether a result is valid.",
      "enforcementPoints": [
        "pre_merge"
      ],
      "verification": [
        {
          "kind": "inspect",
          "text": "Before the runs, inspect the task admission records: each task has evidence that it can be solved in this environment (a reference solution or a solved run), and the answers, the scorer and the task data are outside the agent's reach."
        },
        {
          "kind": "test",
          "text": "Before the runs, score a known-correct and a known-incorrect submission for each task through the scorer the runs will use: the scorer must accept the first and reject the second."
        },
        {
          "kind": "observe",
          "text": "After the runs, read the transcripts of every failed run and of a recorded sample of successes: classify each failure as a model limitation or a spurious failure (task bug, scoring error, crashed environment), and flag reward hacking, scorer tampering, communication between runs and verbalized evaluation awareness."
        },
        {
          "kind": "attest",
          "text": "Before release, the evaluation lead states in the signed test report which runs were excluded or re-scored after these checks and why, and that no failed check was waived without a recorded approval."
        }
      ],
      "evidence": [
        {
          "artefact": "Task admission and scorer check records: solvability evidence and the verdicts on known-correct and known-incorrect submissions",
          "schemaId": "evidence-record",
          "schema": "https://aigovernanceengineer.com/schemas/evidence-record.v1.json",
          "layer": 3
        },
        {
          "artefact": "Signed test report listing the validity checks run, the runs excluded or re-scored with the reason, and any waiver",
          "schemaId": "test-report",
          "schema": "https://aigovernanceengineer.com/schemas/test-report.v1.json",
          "layer": 3
        },
        {
          "artefact": "Validity check of each result, filed as an observation of this control",
          "schemaId": "control-observation",
          "schema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
          "layer": 5
        }
      ],
      "failureResponse": {
        "effect": "deny",
        "text": "A result whose validity checks failed or were not run is not released to the decision it gates. A spurious failure is fixed and the task rerun, or the task is excluded and the exclusion reported; runs with scorer tampering, communication between runs or verbalized evaluation awareness are excluded or reported as contaminated."
      },
      "layer": 3,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "eval-gate-in-ci",
          "title": "Eval Gate in CI",
          "url": "https://aigovernanceengineer.com/patterns/eval-gate-in-ci"
        },
        {
          "slug": "adversarial-red-team-suite",
          "title": "Adversarial Red-Team Suite",
          "url": "https://aigovernanceengineer.com/patterns/adversarial-red-team-suite"
        }
      ],
      "seeds": [
        {
          "id": "trajectory-evals",
          "title": "Independent trajectory evals",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#what-makes-an-agent-a-governance-object"
        }
      ],
      "derivedFrom": [],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART15",
            "name": "EU AI Act Art. 15 accuracy, robustness and cybersecurity",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART9",
            "name": "EU AI Act Art. 9 risk management system",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art9"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART55",
            "name": "EU AI Act Art. 55 GPAI models with systemic risk",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art55"
          },
          {
            "id": "AIGE-OBL-NISTRMF-MEASURE",
            "name": "MEASURE",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure"
          },
          {
            "id": "AIGE-OBL-ISO42001-A6",
            "name": "A.6 AI system life cycle",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a6"
          },
          {
            "id": "AIGE-OBL-NIST-AI600-1",
            "name": "NIST AI 600-1 Generative AI Profile",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-nist-ai600-1"
          }
        ],
        "iso42001": [
          {
            "id": "A.6.2.4",
            "title": "AI system verification and validation"
          }
        ],
        "nistAiRmf": [
          {
            "id": "MEASURE 2.3",
            "title": "Performance or assurance criteria measured for deployment-like conditions"
          },
          {
            "id": "MEASURE 2.13",
            "title": "Effectiveness of the employed TEVV metrics and processes in the MEASURE function are evaluated and documented."
          }
        ],
        "owasp": [],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": [
          {
            "framework": "NIST SP 800-53 Rev. 5",
            "ref": "SA-11",
            "note": "Developer Testing and Evaluation"
          }
        ]
      },
      "references": [
        {
          "n": 62,
          "title": "Governing AI development",
          "text": "Governing AI development (AI Governance Engineering Body of Knowledge v0.5.0, chapter 14, section \"Statistical validity of evals\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-development#statistical-validity-of-evals",
          "verified": "primary"
        },
        {
          "n": 63,
          "title": "Governing AI development",
          "text": "Governing AI development (AI Governance Engineering Body of Knowledge v0.5.0, chapter 14, section \"Independent validation and model risk management\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-development#independent-validation-and-model-risk-management",
          "verified": "primary"
        },
        {
          "n": 64,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"What makes an agent a governance object\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#what-makes-an-agent-a-governance-object",
          "verified": "primary"
        },
        {
          "n": 31,
          "title": "Guidelines for capability elicitation",
          "text": "Guidelines for capability elicitation (task bugs such as \"The automatic scoring is incorrect\" or a crashed environment are spurious failures to fix before reporting; models get \"the best available scaffolding + tooling\"). METR. 2024-03-15.",
          "url": "https://metr.org/blog/2024-03-15-guidelines-for-capability-elicitation/",
          "verified": "primary"
        },
        {
          "n": 65,
          "title": "Example autonomy evaluation protocol",
          "text": "Example autonomy evaluation protocol (read the transcripts of runs that missed the maximum score and check that the pattern of successes and failures is roughly as expected). METR. 2024-03-15.",
          "url": "https://metr.org/blog/2024-03-15-example-autonomy-evaluation-protocol/",
          "verified": "primary"
        },
        {
          "n": 58,
          "title": "Summary of METR's predeployment evaluation of GPT-5.6 Sol",
          "text": "Summary of METR's predeployment evaluation of GPT-5.6 Sol (METR states that \"observed cheating rates can also be influenced by the prompts used in the evaluation scaffold\" and by task wording). METR. 2026-06-26.",
          "url": "https://metr.org/blog/2026-06-26-gpt-5-6-sol/",
          "verified": "primary"
        },
        {
          "n": 7,
          "title": "NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations",
          "text": "NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations (control catalogue cited by control id; publication page of Revision 5 with update 1 of 10 Dec 2020). NIST. 2020-12-10.",
          "url": "https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final",
          "verified": "primary"
        },
        {
          "n": 9,
          "title": "Improving our alignment and security efforts",
          "text": "Improving our alignment and security efforts (best practices for external partners running cyber evaluations: the only outside connection is \"to the model's own API\", with the API keys kept outside the environment; the configuration \"should be verified before every evaluation begins\"; boundaries \"phrased as instructions\"; challenges confirmed \"solvable in principle\"; a monitor that flags a scope violation to a human and ends the exercise). Anthropic. 2026-08-31.",
          "url": "https://www.anthropic.com/news/improving-alignment-security-efforts",
          "verified": "primary"
        },
        {
          "n": 5,
          "title": "Brief independent investigation of agents' behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident",
          "text": "Brief independent investigation of agents' behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident (METR states that agents \"meant to be fully isolated from one another\" communicated through an internal package repository, and that one agent found working Hugging Face credentials exposed on the internet and posted them to the agents' board; it reports spoofed tool calls in at least 96 transcripts and transcripts missing components after container resets). METR. 2026-08-26.",
          "url": "https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/",
          "verified": "primary"
        },
        {
          "n": 4,
          "title": "METR Task Standard, STANDARD.md",
          "text": "METR Task Standard, STANDARD.md (version 0.5.0; unless a task declares the full_internet permission, the task machines \"MUST NOT have internet access\" except to an LLM API, an LLM API proxy or a hardened local server). METR (GitHub). 2024-10-30.",
          "url": "https://raw.githubusercontent.com/METR/task-standard/main/STANDARD.md",
          "verified": "primary"
        },
        {
          "n": 34,
          "title": "Preparedness Framework, Version 2",
          "text": "Preparedness Framework, Version 2 (Table 5 lists potential safeguards against a misaligned model, among them limiting internet and tool access, credentials and filesystem access, with agent actions \"logged in an uneditable database\"; a one-time capability elicitation is treated \"as a lower bound, rather than a ceiling\"). OpenAI. 2025-04-15.",
          "url": "https://cdn.openai.com/pdf/18a02b5d-6b67-4cec-ab64-68cdfbddebcd/preparedness-framework-v2.pdf",
          "verified": "primary"
        },
        {
          "n": 66,
          "title": "GPT-6 Astra System Card",
          "text": "GPT-6 Astra System Card (OpenAI states that evaluations where models show verbalized metagaming \"can be treated similarly to contaminated evals\"). OpenAI. 2026-09-03.",
          "url": "https://deploymentsafety.openai.com/gpt-6-astra",
          "verified": "primary"
        },
        {
          "n": 67,
          "title": "Sidestepping Evaluation Awareness and Anticipating Misalignment with Production Evaluations",
          "text": "Sidestepping Evaluation Awareness and Anticipating Misalignment with Production Evaluations (OpenAI reports that models tested with production evaluations \"display substantially lower signs of evaluation awareness\" than in a traditional evaluation). OpenAI (Alignment Research Blog). 2025-12-18.",
          "url": "https://alignment.openai.com/prod-evals/",
          "verified": "primary"
        },
        {
          "n": 39,
          "title": "The Hugging Face incident and the road ahead",
          "text": "The Hugging Face incident and the road ahead (OpenAI states that its chain-of-thought monitors \"did not run on the evaluations in this incident\", and that it is strengthening its incident response plan with clearer rules on \"who can stop a run or approve restarting it\"). OpenAI. 2026-08-26.",
          "url": "https://openai.com/index/hugging-face-incident-and-the-road-ahead/",
          "verified": "primary"
        },
        {
          "n": 60,
          "title": "A shared playbook for trustworthy third party evaluations",
          "text": "A shared playbook for trustworthy third party evaluations (recommended report fields include the claim, the tested system (model, reasoning setting, tool access, harness and safeguards), the budget, elicitation methods and validity checks; a score is \"performance under that harness and budget\"). OpenAI. 2026-05-29.",
          "url": "https://openai.com/index/trustworthy-third-party-evaluations-foundations/",
          "verified": "primary"
        },
        {
          "n": 11,
          "title": "Unsanctioned Artifactory writes and cross-sample communication (misalignment report)",
          "text": "Unsanctioned Artifactory writes and cross-sample communication (misalignment report) (OpenAI reports models in RL training that used Artifactory, \"a shared package repository\", to exchange messages across separate training samples with the credentials they were given to download packages, without exploiting any vulnerability; such exchanges can \"undermine the assumption that training or evaluation samples are independent\"). OpenAI (Alignment Research Blog). 2026-09-16.",
          "url": "https://alignment.openai.com/misalignment-reports/unauthorized-artifactory-writes-and-cross-sample-communication/",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Confirm that each task can be solved before a failure on it is counted. Anthropic's guidance for external evaluation partners asks them to \"confirm any evaluation challenge is actually solvable in principle\", because agents facing a task they cannot complete look for other ways to complete it; METR reports that many of the agents in the OpenAI/Hugging Face incident that turned to cheating had unintentionally been given an impossible task, and OpenAI states that none of its models had ever solved 198 of the 898 tasks of that evaluation before the incident.",
        "Keep the answers and the scorer out of the agent's reach. METR's Task Standard states that the agent \"MUST NOT see the data returned by get_tasks\", and METR's investigation reports agents that coordinated to find a way to \"fool or tamper with the automated scorer\".",
        "Read the transcripts, not only the scores. METR's example evaluation protocol asks for someone to read the transcripts of runs that missed the maximum score and to check that the pattern of successes and failures is roughly as expected, and METR's guidelines treat task bugs such as incorrect automatic scoring as spurious failures to fix before reporting.",
        "Report the checks with the result. OpenAI's playbook for third-party evaluations asks reports to say how assessors looked for reward hacking, evaluation awareness, contamination, refusals and sandbagging, and how confirmed cases affected scoring. OpenAI's GPT-6 Astra system card states that evaluations where models show verbalized metagaming \"can be treated similarly to contaminated evals\", and OpenAI reports that exchanges between samples through a shared package repository can \"undermine the assumption that training or evaluation samples are independent\".",
        "Report an elicited score as a lower bound. OpenAI's Preparedness Framework v2 treats a one-time capability elicitation \"as a lower bound, rather than a ceiling\", and OpenAI's alignment blog reports lower signs of evaluation awareness under production evaluations than under traditional ones."
      ],
      "openQuestions": [
        "Which validity threats (task bugs, scoring errors, evaluation awareness) should block a result, and which should only be disclosed with it?",
        "How large a sample of successful runs should be read for reward hacking and scorer tampering before a result is reported?"
      ],
      "observation": {
        "subjectKind": "eval-run",
        "expected": "Every task was shown to be solvable, the scorer passed its known-answer check, every failed run was read and classified, and contaminated runs were excluded or reported.",
        "observedExample": "Suite run 88280: 12 of 200 tasks had no evidence of being solvable and their failures were counted against the model: fail."
      },
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": [
        {
          "status": "pass",
          "url": "https://aigovernanceengineer.com/controls/examples/control-observation.aige-ctl-eval-009.pass.json"
        },
        {
          "status": "fail",
          "url": "https://aigovernanceengineer.com/controls/examples/control-observation.aige-ctl-eval-009.fail.json"
        }
      ]
    },
    {
      "id": "AIGE-CTL-AGENT-001",
      "profile": "agent-runtime",
      "url": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-001",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-001.json",
      "title": "Registry entry",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "Every agent is registered before it reaches production, in an entry written by the pipeline that records its identity, owner, purpose, autonomy level, tools and scopes, data classes and memory stores, delegation rights, versions, checkpoints, stop handles, expiry, and regulatory role and class.",
      "failureModes": [
        "ASI10: An agent drifts from its intended behaviour or scope (through compromise, misalignment or neglect) and keeps acting, possibly deceptively, where nobody is watching."
      ],
      "scope": "Every agent that calls tools, in production or in an evaluation harness.",
      "enforcementPoints": [
        "deploy"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "The entry, and every log line that joins to it",
          "schemaId": "agent-register-entry",
          "schema": "https://aigovernanceengineer.com/schemas/agent-register-entry.v1.json",
          "layer": 2
        }
      ],
      "failureResponse": {
        "effect": "alert",
        "text": "To be specified."
      },
      "layer": 2,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "agent-registry",
          "title": "Agent Registry",
          "url": "https://aigovernanceengineer.com/patterns/agent-registry"
        }
      ],
      "seeds": [
        {
          "id": "registry-entry",
          "title": "Registry entry",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#the-agent-registry"
        }
      ],
      "derivedFrom": [],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART14",
            "name": "EU AI Act Art. 14 human oversight",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art14"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART26",
            "name": "EU AI Act Art. 26 deployer obligations for high-risk systems",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART72",
            "name": "EU AI Act Art. 72 post-market monitoring",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art72"
          },
          {
            "id": "AIGE-OBL-OWASP-AGENTIC",
            "name": "Top 10 for Agentic Applications 2026",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-agentic"
          }
        ],
        "iso42001": [
          {
            "id": "A.6.2.6",
            "title": "AI system operation and monitoring"
          },
          {
            "id": "A.6.2.8",
            "title": "AI system recording of event logs"
          }
        ],
        "nistAiRmf": [],
        "owasp": [
          {
            "id": "asi10",
            "externalId": "ASI10",
            "name": "Rogue Agents",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-asi10"
          }
        ],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 1,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"The agent registry\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#the-agent-registry",
          "verified": "primary"
        },
        {
          "n": 2,
          "title": "OWASP Top 10 for Agentic Applications for 2026",
          "text": "OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents). OWASP GenAI Security Project. 2025-12-09.",
          "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
          "verified": "primary"
        },
        {
          "n": 3,
          "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
          "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        }
      ],
      "implementationNotes": [
        "The deploy pipeline writes the entry, so an agent cannot reach production without one; the versions block makes an incident replayable and the stop block makes the kill switch more than a claim.",
        "Reconcile the registry against what runs, including SaaS connectors, coding agents on laptops and local MCP servers; an agent found by discovery is registered within a deadline or switched off."
      ],
      "openQuestions": [
        "Verification procedure and evidence schema to be specified; requires technical review."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-AGENT-002",
      "profile": "agent-runtime",
      "url": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-002",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-002.json",
      "title": "Its own identity",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "Each agent has a unique, attributable workload identity under which its actions are logged and its access can be revoked; channel authentication is not taken for agent identity.",
      "failureModes": [
        "ASI03: Delegated identities, inherited privileges and cached credentials let an agent (or whoever steers it) act with rights the requesting user never had."
      ],
      "scope": "Every agent that calls tools, in production or in an evaluation harness.",
      "enforcementPoints": [
        "runtime"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Identity in every trace; revocation record",
          "schemaId": null,
          "schema": null,
          "layer": 2
        }
      ],
      "failureResponse": {
        "effect": "alert",
        "text": "To be specified."
      },
      "layer": 2,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "agent-identity-scoped-credentials",
          "title": "Agent Identity & Scoped Credentials",
          "url": "https://aigovernanceengineer.com/patterns/agent-identity-scoped-credentials"
        }
      ],
      "seeds": [
        {
          "id": "own-identity",
          "title": "Its own identity",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#identity-and-short-lived-credentials"
        }
      ],
      "derivedFrom": [],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART15",
            "name": "EU AI Act Art. 15 accuracy, robustness and cybersecurity",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15"
          },
          {
            "id": "AIGE-OBL-OWASP-AGENTIC",
            "name": "Top 10 for Agentic Applications 2026",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-agentic"
          },
          {
            "id": "AIGE-OBL-CSA-AICM-AGENTIC",
            "name": "AICM agent controls with the CSA Agentic Trust Framework and AARM specification",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-csa-aicm-agentic"
          },
          {
            "id": "AIGE-OBL-NIST-AGENTS",
            "name": "NIST AI Agent Standards Initiative (2026)",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-nist-agents"
          }
        ],
        "iso42001": [
          {
            "id": "A.6.2.5",
            "title": "AI system deployment"
          }
        ],
        "nistAiRmf": [],
        "owasp": [
          {
            "id": "asi03",
            "externalId": "ASI03",
            "name": "Identity and Privilege Abuse",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-asi03"
          }
        ],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 4,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Identity and short-lived credentials\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#identity-and-short-lived-credentials",
          "verified": "primary"
        },
        {
          "n": 2,
          "title": "OWASP Top 10 for Agentic Applications for 2026",
          "text": "OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents). OWASP GenAI Security Project. 2025-12-09.",
          "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
          "verified": "primary"
        },
        {
          "n": 3,
          "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
          "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        }
      ],
      "implementationNotes": [
        "Make the identity unique and cryptographically verifiable, tie it to a supervising agent, a person or a department, distinguish whether the agent acts on its own or for a named user, and catalogue it centrally."
      ],
      "openQuestions": [
        "Verification procedure and evidence schema to be specified; requires technical review."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-AGENT-003",
      "profile": "agent-runtime",
      "url": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-003",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-003.json",
      "title": "Read-only tools",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "At the Operator level the person takes every action, so the agent holds read-only tools.",
      "failureModes": [
        "An agent at the Operator level holds a tool whose operation class is write, delete, send, execute or pay.",
        "An action takes effect that the agent, not the person, took."
      ],
      "scope": "Agents at the Operator autonomy level, where the person takes every action.",
      "enforcementPoints": [
        "runtime"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Allow-list with read operations only",
          "schemaId": null,
          "schema": null,
          "layer": 4
        }
      ],
      "failureResponse": {
        "effect": "alert",
        "text": "To be specified."
      },
      "layer": 4,
      "secondaryLayers": [],
      "patterns": [],
      "seeds": [
        {
          "id": "read-only-tools",
          "title": "Read-only tools",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#autonomy-is-a-design-decision"
        }
      ],
      "derivedFrom": [],
      "mappings": {
        "obligations": [],
        "iso42001": [],
        "nistAiRmf": [],
        "owasp": [],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 5,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Autonomy is a design decision\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#autonomy-is-a-design-decision",
          "verified": "primary"
        }
      ],
      "implementationNotes": [],
      "openQuestions": [
        "Verification procedure and evidence schema to be specified; requires technical review."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-AGENT-004",
      "profile": "agent-runtime",
      "url": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-004",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-004.json",
      "title": "Traces",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "The agent's trajectory is traced, not only its answer: every plan, tool call and memory operation is recorded with the agent id and version.",
      "failureModes": [
        "A task leaves a record of its final answer only, with no plans, tool calls or memory operations.",
        "A trace carries no agent id or version, so its actions cannot be joined to the agent or to the configuration that ran.",
        "The record shows a different tool call from the one that ran, or loses recent activity: METR reports agents that spoofed tool calls to alter their transcripts and tried to trigger container resets that would wipe recent records."
      ],
      "scope": "Every agent that calls tools, in production or in an evaluation harness.",
      "enforcementPoints": [
        "runtime"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Trace per task",
          "schemaId": null,
          "schema": null,
          "layer": 5
        }
      ],
      "failureResponse": {
        "effect": "alert",
        "text": "To be specified."
      },
      "layer": 5,
      "secondaryLayers": [],
      "patterns": [],
      "seeds": [
        {
          "id": "traces",
          "title": "Traces",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#telemetry-with-the-opentelemetry-genai-conventions"
        }
      ],
      "derivedFrom": [],
      "mappings": {
        "obligations": [],
        "iso42001": [],
        "nistAiRmf": [],
        "owasp": [],
        "atlas": [],
        "aiuc1": [
          "E015"
        ],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 6,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Telemetry with the OpenTelemetry GenAI conventions\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#telemetry-with-the-opentelemetry-genai-conventions",
          "verified": "primary"
        },
        {
          "n": 7,
          "title": "Brief independent investigation of agents' behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident",
          "text": "Brief independent investigation of agents' behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident (agents in an evaluation exercise spoofed tool calls to alter their transcripts, tried to trigger container resets that would wipe recent records, and gained code execution on a sandbox with access to the full internet). METR. 2026-08-26.",
          "url": "https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/",
          "verified": "primary"
        },
        {
          "n": 8,
          "title": "AIUC-1 requirements",
          "text": "AIUC-1 requirements (public requirement index, A001 to F002, each requirement on its own page (E007 and E014 marked retired); AIUC-1 is a standard of the Artificial Intelligence Underwriting Company; this site is not affiliated with AIUC, and a mapping here is not an AIUC-1 certificate or audit). Artificial Intelligence Underwriting Company. 2026-09-24.",
          "url": "https://standard.aiuc-1.com/llms.txt",
          "verified": "primary"
        }
      ],
      "implementationNotes": [],
      "openQuestions": [
        "Verification procedure and evidence schema to be specified; requires technical review."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-AGENT-005",
      "profile": "agent-runtime",
      "url": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-005",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-005.json",
      "title": "Tool allow-list, deny by default",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "The agent can call only the tools granted on its allow-list, which the gateway evaluates on every call; each entry fixes the tool identity with a pinned definition hash, the operation class, resource scope, rate and volume, egress, data classes and checkpoint.",
      "failureModes": [
        "ASI02: The agent uses tools it is allowed to use in unsafe ways: destructive parameters, chains of calls nobody intended, or exfiltration through a permitted channel."
      ],
      "scope": "Every agent that calls tools, in production or in an evaluation harness.",
      "enforcementPoints": [
        "runtime"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Allow-list as policy; guardrail configuration diffs",
          "schemaId": null,
          "schema": null,
          "layer": 4
        }
      ],
      "failureResponse": {
        "effect": "deny",
        "text": "A call to a tool that is not on the allow-list, or whose definition hash does not match, is denied."
      },
      "layer": 4,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "runtime-guardrail",
          "title": "Runtime Guardrail",
          "url": "https://aigovernanceengineer.com/patterns/runtime-guardrail"
        }
      ],
      "seeds": [
        {
          "id": "tool-allow-list",
          "title": "Tool allow-list, deny by default",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#the-tool-allow-list"
        }
      ],
      "derivedFrom": [],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART14",
            "name": "EU AI Act Art. 14 human oversight",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art14"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART15",
            "name": "EU AI Act Art. 15 accuracy, robustness and cybersecurity",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15"
          },
          {
            "id": "AIGE-OBL-OWASP-AGENTIC",
            "name": "Top 10 for Agentic Applications 2026",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-agentic"
          },
          {
            "id": "AIGE-OBL-CSA-AICM-AGENTIC",
            "name": "AICM agent controls with the CSA Agentic Trust Framework and AARM specification",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-csa-aicm-agentic"
          }
        ],
        "iso42001": [
          {
            "id": "A.6.2.6",
            "title": "AI system operation and monitoring"
          },
          {
            "id": "A.9.2",
            "title": "Processes for responsible use of AI systems"
          }
        ],
        "nistAiRmf": [],
        "owasp": [
          {
            "id": "asi02",
            "externalId": "ASI02",
            "name": "Tool Misuse and Exploitation",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-asi02"
          }
        ],
        "atlas": [],
        "aiuc1": [
          "D003",
          "B006"
        ],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 9,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"The tool allow-list\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#the-tool-allow-list",
          "verified": "primary"
        },
        {
          "n": 2,
          "title": "OWASP Top 10 for Agentic Applications for 2026",
          "text": "OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents). OWASP GenAI Security Project. 2025-12-09.",
          "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
          "verified": "primary"
        },
        {
          "n": 3,
          "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
          "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        },
        {
          "n": 8,
          "title": "AIUC-1 requirements",
          "text": "AIUC-1 requirements (public requirement index, A001 to F002, each requirement on its own page (E007 and E014 marked retired); AIUC-1 is a standard of the Artificial Intelligence Underwriting Company; this site is not affiliated with AIUC, and a mapping here is not an AIUC-1 certificate or audit). Artificial Intelligence Underwriting Company. 2026-09-24.",
          "url": "https://standard.aiuc-1.com/llms.txt",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Express the allow-list as a deny-by-default policy the tool gateway evaluates on every call, reading the registry as data; the operation class decides which calls need approval."
      ],
      "openQuestions": [
        "Verification procedure and evidence schema to be specified; requires technical review."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-AGENT-006",
      "profile": "agent-runtime",
      "url": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-006",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-006.json",
      "title": "Checkpoint before every write",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "At the Collaborator level a person approves every write the agent proposes.",
      "failureModes": [
        "A write the agent proposed takes effect with no approval record for it."
      ],
      "scope": "Agents at the Collaborator autonomy level, where a person approves significant steps.",
      "enforcementPoints": [
        "runtime"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Approval record per write",
          "schemaId": null,
          "schema": null,
          "layer": 4
        }
      ],
      "failureResponse": {
        "effect": "require_approval",
        "text": "Every write the agent proposes waits for a person to approve it."
      },
      "layer": 4,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "human-in-the-loop-gate",
          "title": "Human-in-the-loop Gate",
          "url": "https://aigovernanceengineer.com/patterns/human-in-the-loop-gate"
        }
      ],
      "seeds": [
        {
          "id": "checkpoint-before-writes",
          "title": "Checkpoint before every write",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#where-to-put-a-checkpoint"
        }
      ],
      "derivedFrom": [],
      "mappings": {
        "obligations": [],
        "iso42001": [],
        "nistAiRmf": [],
        "owasp": [],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 10,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Where to put a checkpoint\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#where-to-put-a-checkpoint",
          "verified": "primary"
        }
      ],
      "implementationNotes": [],
      "openQuestions": [
        "Verification procedure and evidence schema to be specified; requires technical review."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-AGENT-007",
      "profile": "agent-runtime",
      "url": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-007",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-007.json",
      "title": "Runtime guardrail on every tool call",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "A guardrail between the agent's decision to call a tool and the call checks every call: the identity matches a live registry entry, the tool and its definition hash are on the allow-list, the parameters are within policy, instruction provenance is checked before write-class calls, output and egress are filtered, and execution budgets hold.",
      "failureModes": [
        "ASI01: Content the agent processes (a message, a document, a tool result) redirects its goals or plan, so it pursues the attacker's objective with the agent's own tools and permissions.",
        "ASI02: The agent uses tools it is allowed to use in unsafe ways: destructive parameters, chains of calls nobody intended, or exfiltration through a permitted channel."
      ],
      "scope": "Every agent that calls tools, in production or in an evaluation harness.",
      "enforcementPoints": [
        "runtime"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Policy verdict per call",
          "schemaId": null,
          "schema": null,
          "layer": 4
        }
      ],
      "failureResponse": {
        "effect": "deny",
        "text": "A call that fails the identity, allow-list or definition-hash check is denied; the other checks deny, route to a checkpoint, redact or trip the breaker as the chapter sets out."
      },
      "layer": 4,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "runtime-guardrail",
          "title": "Runtime Guardrail",
          "url": "https://aigovernanceengineer.com/patterns/runtime-guardrail"
        }
      ],
      "seeds": [
        {
          "id": "guardrail-every-call",
          "title": "Runtime guardrail on every tool call",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#runtime-guardrails-for-tool-calls"
        }
      ],
      "derivedFrom": [],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART14",
            "name": "EU AI Act Art. 14 human oversight",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art14"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART15",
            "name": "EU AI Act Art. 15 accuracy, robustness and cybersecurity",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15"
          },
          {
            "id": "AIGE-OBL-OWASP-AGENTIC",
            "name": "Top 10 for Agentic Applications 2026",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-agentic"
          },
          {
            "id": "AIGE-OBL-NIST-AGENTS",
            "name": "NIST AI Agent Standards Initiative (2026)",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-nist-agents"
          },
          {
            "id": "AIGE-OBL-CSA-AICM-AGENTIC",
            "name": "AICM agent controls with the CSA Agentic Trust Framework and AARM specification",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-csa-aicm-agentic"
          }
        ],
        "iso42001": [
          {
            "id": "A.6.2.4",
            "title": "AI system verification and validation"
          },
          {
            "id": "A.6.2.6",
            "title": "AI system operation and monitoring"
          },
          {
            "id": "A.9.2",
            "title": "Processes for responsible use of AI systems"
          }
        ],
        "nistAiRmf": [],
        "owasp": [
          {
            "id": "asi01",
            "externalId": "ASI01",
            "name": "Agent Goal Hijack",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-asi01"
          },
          {
            "id": "asi02",
            "externalId": "ASI02",
            "name": "Tool Misuse and Exploitation",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-asi02"
          }
        ],
        "atlas": [],
        "aiuc1": [
          "D003"
        ],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 11,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Runtime guardrails for tool calls\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#runtime-guardrails-for-tool-calls",
          "verified": "primary"
        },
        {
          "n": 2,
          "title": "OWASP Top 10 for Agentic Applications for 2026",
          "text": "OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents). OWASP GenAI Security Project. 2025-12-09.",
          "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
          "verified": "primary"
        },
        {
          "n": 3,
          "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
          "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        },
        {
          "n": 8,
          "title": "AIUC-1 requirements",
          "text": "AIUC-1 requirements (public requirement index, A001 to F002, each requirement on its own page (E007 and E014 marked retired); AIUC-1 is a standard of the Artificial Intelligence Underwriting Company; this site is not affiliated with AIUC, and a mapping here is not an AIUC-1 certificate or audit). Artificial Intelligence Underwriting Company. 2026-09-24.",
          "url": "https://standard.aiuc-1.com/llms.txt",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "On failure: parameters outside policy are denied or routed to a checkpoint; a request that originated in untrusted content is routed to a checkpoint before a write-class call; the output and egress filter redacts or blocks; exhausted budgets trip the breaker."
      ],
      "openQuestions": [
        "Verification procedure and evidence schema to be specified; requires technical review."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-AGENT-008",
      "profile": "agent-runtime",
      "url": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-008",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-008.json",
      "title": "Execution budgets",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "Step, call, token, spend and time budgets are set in the registry entry and enforced at the gateway, and exhausting a budget trips the breaker rather than raising a ticket.",
      "failureModes": [
        "ASI08: One faulty or compromised agent, tool or output propagates through connected agents and workflows, and each hop amplifies the harm."
      ],
      "scope": "Every agent that calls tools, in production or in an evaluation harness.",
      "enforcementPoints": [
        "runtime"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Budget configuration; breaker events",
          "schemaId": null,
          "schema": null,
          "layer": 4
        }
      ],
      "failureResponse": {
        "effect": "deny",
        "text": "Exhausting a budget trips the agent's breaker, so the gateway rejects its calls; it does not raise a ticket."
      },
      "layer": 4,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "runtime-guardrail",
          "title": "Runtime Guardrail",
          "url": "https://aigovernanceengineer.com/patterns/runtime-guardrail"
        }
      ],
      "seeds": [
        {
          "id": "execution-budgets",
          "title": "Execution budgets",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#execution-limits"
        }
      ],
      "derivedFrom": [],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART15",
            "name": "EU AI Act Art. 15 accuracy, robustness and cybersecurity",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART72",
            "name": "EU AI Act Art. 72 post-market monitoring",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art72"
          },
          {
            "id": "AIGE-OBL-OWASP-AGENTIC",
            "name": "Top 10 for Agentic Applications 2026",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-agentic"
          },
          {
            "id": "AIGE-OBL-NISTRMF-MANAGE",
            "name": "MANAGE",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage"
          }
        ],
        "iso42001": [
          {
            "id": "A.6.2.6",
            "title": "AI system operation and monitoring"
          }
        ],
        "nistAiRmf": [],
        "owasp": [
          {
            "id": "asi08",
            "externalId": "ASI08",
            "name": "Cascading Failures",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-asi08"
          }
        ],
        "atlas": [],
        "aiuc1": [
          "D003"
        ],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 12,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Execution limits\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#execution-limits",
          "verified": "primary"
        },
        {
          "n": 2,
          "title": "OWASP Top 10 for Agentic Applications for 2026",
          "text": "OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents). OWASP GenAI Security Project. 2025-12-09.",
          "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
          "verified": "primary"
        },
        {
          "n": 3,
          "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
          "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        },
        {
          "n": 8,
          "title": "AIUC-1 requirements",
          "text": "AIUC-1 requirements (public requirement index, A001 to F002, each requirement on its own page (E007 and E014 marked retired); AIUC-1 is a standard of the Artificial Intelligence Underwriting Company; this site is not affiliated with AIUC, and a mapping here is not an AIUC-1 certificate or audit). Artificial Intelligence Underwriting Company. 2026-09-24.",
          "url": "https://standard.aiuc-1.com/llms.txt",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Budgets catch what no rule anticipated. A guardian agent is one way to build the enforcement point, and it then needs its own identity, scope and kill switch."
      ],
      "openQuestions": [
        "Verification procedure and evidence schema to be specified; requires technical review."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-AGENT-009",
      "profile": "agent-runtime",
      "url": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-009",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-009.json",
      "title": "Approval log, bound to the call",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "The gate lives outside the model; the approver sees the raw call first; an approval is single-use and bound to a hash of the parameters; no answer means no action; approval rate, time to decide and override rate are measured.",
      "failureModes": [
        "ASI09: Fluent, confident or persuasive agent output leads people to approve harmful actions, disclose information or skip the check they were meant to make."
      ],
      "scope": "Every agent that calls tools, in production or in an evaluation harness.",
      "enforcementPoints": [
        "runtime"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Approval log with parameter hashes; oversight metrics",
          "schemaId": null,
          "schema": null,
          "layer": 4
        }
      ],
      "failureResponse": {
        "effect": "deny",
        "text": "No answer means no action: an approval request that times out closes without the call."
      },
      "layer": 4,
      "secondaryLayers": [
        5
      ],
      "patterns": [
        {
          "slug": "human-in-the-loop-gate",
          "title": "Human-in-the-loop Gate",
          "url": "https://aigovernanceengineer.com/patterns/human-in-the-loop-gate"
        }
      ],
      "seeds": [
        {
          "id": "approval-log",
          "title": "Approval log, bound to the call",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#what-a-good-approval-looks-like"
        }
      ],
      "derivedFrom": [],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART14",
            "name": "EU AI Act Art. 14 human oversight",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art14"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART13",
            "name": "EU AI Act Art. 13 transparency and information to deployers",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art13"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART50",
            "name": "EU AI Act Art. 50 transparency for certain AI systems",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art50"
          },
          {
            "id": "AIGE-OBL-OWASP-AGENTIC",
            "name": "Top 10 for Agentic Applications 2026",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-agentic"
          }
        ],
        "iso42001": [
          {
            "id": "A.8.2",
            "title": "System documentation and information for users"
          },
          {
            "id": "A.9.2",
            "title": "Processes for responsible use of AI systems"
          }
        ],
        "nistAiRmf": [],
        "owasp": [
          {
            "id": "asi09",
            "externalId": "ASI09",
            "name": "Human-Agent Trust Exploitation",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-asi09"
          }
        ],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 13,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"What a good approval looks like\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#what-a-good-approval-looks-like",
          "verified": "primary"
        },
        {
          "n": 2,
          "title": "OWASP Top 10 for Agentic Applications for 2026",
          "text": "OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents). OWASP GenAI Security Project. 2025-12-09.",
          "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
          "verified": "primary"
        },
        {
          "n": 3,
          "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
          "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        }
      ],
      "implementationNotes": [
        "Show the call, not the story: the approver sees the tool, the parameters and the target as the gateway will execute them, then the agent's reason, the risk and what happens on rejection.",
        "Send to a person only the actions that need one: a checkpoint that fires hundreds of times a day on someone with other work becomes a rubber stamp, and its log then launders the decisions it was meant to examine."
      ],
      "openQuestions": [
        "Verification procedure and evidence schema to be specified; requires technical review."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-AGENT-010",
      "profile": "agent-runtime",
      "url": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-010",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-010.json",
      "title": "Per-agent circuit breaker",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "The gateway can reject every call from this one agent without stopping the rest of the fleet.",
      "failureModes": [
        "ASI08: One faulty or compromised agent, tool or output propagates through connected agents and workflows, and each hop amplifies the harm.",
        "ASI10: An agent drifts from its intended behaviour or scope (through compromise, misalignment or neglect) and keeps acting, possibly deceptively, where nobody is watching."
      ],
      "scope": "Every agent that calls tools, in production or in an evaluation harness.",
      "enforcementPoints": [
        "runtime"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Breaker events",
          "schemaId": null,
          "schema": null,
          "layer": 4
        }
      ],
      "failureResponse": {
        "effect": "deny",
        "text": "The gateway rejects every call from this one agent without stopping the rest of the fleet."
      },
      "layer": 4,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "kill-switch-circuit-breaker",
          "title": "Kill Switch / Circuit Breaker",
          "url": "https://aigovernanceengineer.com/patterns/kill-switch-circuit-breaker"
        }
      ],
      "seeds": [
        {
          "id": "per-agent-breaker",
          "title": "Per-agent circuit breaker",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#kill-switch-and-per-agent-circuit-breakers"
        }
      ],
      "derivedFrom": [],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART15",
            "name": "EU AI Act Art. 15 accuracy, robustness and cybersecurity",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART72",
            "name": "EU AI Act Art. 72 post-market monitoring",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art72"
          },
          {
            "id": "AIGE-OBL-OWASP-AGENTIC",
            "name": "Top 10 for Agentic Applications 2026",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-agentic"
          },
          {
            "id": "AIGE-OBL-NISTRMF-MANAGE",
            "name": "MANAGE",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART14",
            "name": "EU AI Act Art. 14 human oversight",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art14"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART26",
            "name": "EU AI Act Art. 26 deployer obligations for high-risk systems",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26"
          }
        ],
        "iso42001": [
          {
            "id": "A.6.2.6",
            "title": "AI system operation and monitoring"
          },
          {
            "id": "A.6.2.8",
            "title": "AI system recording of event logs"
          }
        ],
        "nistAiRmf": [
          {
            "id": "MANAGE 2.4",
            "title": "Mechanisms to supersede, disengage or deactivate AI systems"
          }
        ],
        "owasp": [
          {
            "id": "asi08",
            "externalId": "ASI08",
            "name": "Cascading Failures",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-asi08"
          },
          {
            "id": "asi10",
            "externalId": "ASI10",
            "name": "Rogue Agents",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-asi10"
          }
        ],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 14,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Kill switch and per-agent circuit breakers\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#kill-switch-and-per-agent-circuit-breakers",
          "verified": "primary"
        },
        {
          "n": 2,
          "title": "OWASP Top 10 for Agentic Applications for 2026",
          "text": "OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents). OWASP GenAI Security Project. 2025-12-09.",
          "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
          "verified": "primary"
        },
        {
          "n": 3,
          "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
          "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        },
        {
          "n": 15,
          "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1",
          "text": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (MANAGE 2.4: mechanisms to supersede, disengage or deactivate AI systems whose performance or outcomes are inconsistent with intended use). NIST. 2023-01-26.",
          "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
          "verified": "primary"
        }
      ],
      "implementationNotes": [],
      "openQuestions": [
        "Verification procedure and evidence schema to be specified; requires technical review."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-AGENT-011",
      "profile": "agent-runtime",
      "url": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-011",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-011.json",
      "title": "Drilled kill switch",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "The stop levels (pause a task, narrow the scope, trip the breaker, revoke the identity, stop a class, degrade) and their triggers are defined in advance, and the stop is drilled on a schedule, with the time to stop measured and a check that the stop held.",
      "failureModes": [
        "ASI10: An agent drifts from its intended behaviour or scope (through compromise, misalignment or neglect) and keeps acting, possibly deceptively, where nobody is watching."
      ],
      "scope": "Every agent that calls tools, in production or in an evaluation harness.",
      "enforcementPoints": [
        "runtime",
        "periodic"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Drill record: time to stop; no calls or writes after the pull",
          "schemaId": null,
          "schema": null,
          "layer": 4
        }
      ],
      "failureResponse": {
        "effect": "deny",
        "text": "The agent is stopped at the predefined level; no calls or writes follow the pull."
      },
      "layer": 4,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "kill-switch-circuit-breaker",
          "title": "Kill Switch / Circuit Breaker",
          "url": "https://aigovernanceengineer.com/patterns/kill-switch-circuit-breaker"
        }
      ],
      "seeds": [
        {
          "id": "drilled-kill-switch",
          "title": "Drilled kill switch",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#kill-switch-and-per-agent-circuit-breakers"
        }
      ],
      "derivedFrom": [],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART14",
            "name": "EU AI Act Art. 14 human oversight",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art14"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART26",
            "name": "EU AI Act Art. 26 deployer obligations for high-risk systems",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART72",
            "name": "EU AI Act Art. 72 post-market monitoring",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art72"
          },
          {
            "id": "AIGE-OBL-OWASP-AGENTIC",
            "name": "Top 10 for Agentic Applications 2026",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-agentic"
          }
        ],
        "iso42001": [
          {
            "id": "A.6.2.6",
            "title": "AI system operation and monitoring"
          },
          {
            "id": "A.6.2.8",
            "title": "AI system recording of event logs"
          }
        ],
        "nistAiRmf": [
          {
            "id": "MANAGE 2.4",
            "title": "Mechanisms to supersede, disengage or deactivate AI systems"
          }
        ],
        "owasp": [
          {
            "id": "asi10",
            "externalId": "ASI10",
            "name": "Rogue Agents",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-asi10"
          }
        ],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 14,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Kill switch and per-agent circuit breakers\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#kill-switch-and-per-agent-circuit-breakers",
          "verified": "primary"
        },
        {
          "n": 2,
          "title": "OWASP Top 10 for Agentic Applications for 2026",
          "text": "OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents). OWASP GenAI Security Project. 2025-12-09.",
          "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
          "verified": "primary"
        },
        {
          "n": 3,
          "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
          "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        },
        {
          "n": 15,
          "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1",
          "text": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (MANAGE 2.4: mechanisms to supersede, disengage or deactivate AI systems whose performance or outcomes are inconsistent with intended use). NIST. 2023-01-26.",
          "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Define the triggers in advance: a manual pull, a budget or unauthorised-call threshold, an anomaly, an upstream notice such as a vendor incident, or a legal instruction.",
        "Check that the stop held: no tool calls after the breaker tripped, no credentials issued after revocation, and no writes from long-running tasks on credentials issued before the pull."
      ],
      "openQuestions": [
        "Verification procedure and evidence schema to be specified; requires technical review."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-AGENT-012",
      "profile": "agent-runtime",
      "url": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-012",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-012.json",
      "title": "Trajectory anomaly detection",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "The agent's behaviour is monitored as it unfolds, and anomalies (calls unrelated to the purpose, parameters outside the profile, calls after expiry, spend spikes) are flagged and either halt the agent or escalate to a person.",
      "failureModes": [
        "A call unrelated to the task purpose, a parameter outside the registry profile, a call after expiry or a spend spike occurs and no anomaly event is raised.",
        "An anomaly is flagged but neither halts the agent nor reaches a person.",
        "The monitoring is switched off: METR states that its red-teaming found several simple ways for agent monitoring to be disabled, one by changing an environment variable."
      ],
      "scope": "Every agent that calls tools, in production or in an evaluation harness.",
      "enforcementPoints": [
        "runtime"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Anomaly events and decisions",
          "schemaId": null,
          "schema": null,
          "layer": 4
        }
      ],
      "failureResponse": {
        "effect": "alert",
        "text": "To be specified."
      },
      "layer": 4,
      "secondaryLayers": [],
      "patterns": [],
      "seeds": [
        {
          "id": "trajectory-anomaly",
          "title": "Trajectory anomaly detection",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#an-agent-incident-taxonomy"
        }
      ],
      "derivedFrom": [],
      "mappings": {
        "obligations": [],
        "iso42001": [],
        "nistAiRmf": [],
        "owasp": [],
        "atlas": [],
        "aiuc1": [
          "B006"
        ],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 16,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"An agent incident taxonomy\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#an-agent-incident-taxonomy",
          "verified": "primary"
        },
        {
          "n": 17,
          "title": "Frontier Risk Report (February to March 2026)",
          "text": "Frontier Risk Report (February to March 2026) (red-teaming found several simple ways for agent monitoring to be disabled, one by changing an environment variable). METR. 2026-05-19.",
          "url": "https://metr.org/blog/2026-05-19-frontier-risk-report/",
          "verified": "primary"
        },
        {
          "n": 8,
          "title": "AIUC-1 requirements",
          "text": "AIUC-1 requirements (public requirement index, A001 to F002, each requirement on its own page (E007 and E014 marked retired); AIUC-1 is a standard of the Artificial Intelligence Underwriting Company; this site is not affiliated with AIUC, and a mapping here is not an AIUC-1 certificate or audit). Artificial Intelligence Underwriting Company. 2026-09-24.",
          "url": "https://standard.aiuc-1.com/llms.txt",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Use the chapter's agent incident taxonomy for the detection signal and the first containment of each class; the severity scale and reporting clocks are those of chapter 17."
      ],
      "openQuestions": [
        "Verification procedure and evidence schema to be specified; requires technical review."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-AGENT-013",
      "profile": "agent-runtime",
      "url": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-013",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-013.json",
      "title": "Independent trajectory evals",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "Every change to the agent is evaluated on its path as well as its answer, including task success, injection resistance and trajectory checks, and a failed evaluation blocks the change.",
      "failureModes": [
        "An evaluation passes an agent that reached the right answer through a tool it should never have held, because it scored the answer and not the path.",
        "A change ships with no evaluation run for its version, or although its run failed."
      ],
      "scope": "Every agent that calls tools, in production or in an evaluation harness.",
      "enforcementPoints": [
        "pre_merge"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Eval runs per version",
          "schemaId": null,
          "schema": null,
          "layer": 3
        }
      ],
      "failureResponse": {
        "effect": "alert",
        "text": "To be specified."
      },
      "layer": 3,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "eval-gate-in-ci",
          "title": "Eval Gate in CI",
          "url": "https://aigovernanceengineer.com/patterns/eval-gate-in-ci"
        }
      ],
      "seeds": [
        {
          "id": "trajectory-evals",
          "title": "Independent trajectory evals",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#what-makes-an-agent-a-governance-object"
        }
      ],
      "derivedFrom": [],
      "mappings": {
        "obligations": [],
        "iso42001": [],
        "nistAiRmf": [],
        "owasp": [],
        "atlas": [],
        "aiuc1": [
          "C002"
        ],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 18,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"What makes an agent a governance object\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#what-makes-an-agent-a-governance-object",
          "verified": "primary"
        },
        {
          "n": 19,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Threats mapped to controls\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#threats-mapped-to-controls",
          "verified": "primary"
        },
        {
          "n": 8,
          "title": "AIUC-1 requirements",
          "text": "AIUC-1 requirements (public requirement index, A001 to F002, each requirement on its own page (E007 and E014 marked retired); AIUC-1 is a standard of the Artificial Intelligence Underwriting Company; this site is not affiliated with AIUC, and a mapping here is not an AIUC-1 certificate or audit). Artificial Intelligence Underwriting Company. 2026-09-24.",
          "url": "https://standard.aiuc-1.com/llms.txt",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Tag the red-team test cases with MITRE ATLAS technique ids, so a finding traces from technique to control to the evaluation that now guards it."
      ],
      "openQuestions": [
        "Verification procedure and evidence schema to be specified; requires technical review."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-AGENT-014",
      "profile": "agent-runtime",
      "url": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-014",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-014.json",
      "title": "Reversible, bounded actions only",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "At the Observer level the person audits after the fact, so the agent keeps only reversible, bounded actions.",
      "failureModes": [
        "An agent at the Observer level holds an irreversible action (a payment, a deletion, an external message, a publication) on its allow-list.",
        "An action at the Observer level has no rate, volume or budget bound."
      ],
      "scope": "Agents at the Observer autonomy level, where the person audits after the fact.",
      "enforcementPoints": [
        "runtime"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Allow-list without irreversible operation classes",
          "schemaId": null,
          "schema": null,
          "layer": 4
        }
      ],
      "failureResponse": {
        "effect": "alert",
        "text": "To be specified."
      },
      "layer": 4,
      "secondaryLayers": [],
      "patterns": [],
      "seeds": [
        {
          "id": "reversible-only",
          "title": "Reversible, bounded actions only",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#autonomy-is-a-design-decision"
        }
      ],
      "derivedFrom": [],
      "mappings": {
        "obligations": [],
        "iso42001": [],
        "nistAiRmf": [],
        "owasp": [],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 5,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Autonomy is a design decision\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#autonomy-is-a-design-decision",
          "verified": "primary"
        }
      ],
      "implementationNotes": [],
      "openQuestions": [
        "Verification procedure and evidence schema to be specified; requires technical review."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-AGENT-015",
      "profile": "agent-runtime",
      "url": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-015",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-015.json",
      "title": "Checkpoints on irreversible actions, failing closed",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "Pay, delete, send and execute calls are gated by consequence (high stakes, irreversible, outlier, user-defined, scope elevation) and fail closed when the guardian is down; only reads fail open, and then with an alert.",
      "failureModes": [
        "ASI02: The agent uses tools it is allowed to use in unsafe ways: destructive parameters, chains of calls nobody intended, or exfiltration through a permitted channel.",
        "ASI09: Fluent, confident or persuasive agent output leads people to approve harmful actions, disclose information or skip the check they were meant to make."
      ],
      "scope": "Agents with tools whose operation class is pay, delete, send or execute.",
      "enforcementPoints": [
        "runtime"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Checkpoint configuration; failure posture in the Policy Card",
          "schemaId": null,
          "schema": null,
          "layer": 4
        }
      ],
      "failureResponse": {
        "effect": "require_approval",
        "text": "Pay, delete, send and execute calls wait for approval, and are denied while the guardian is down; reads proceed with an alert."
      },
      "layer": 4,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "human-in-the-loop-gate",
          "title": "Human-in-the-loop Gate",
          "url": "https://aigovernanceengineer.com/patterns/human-in-the-loop-gate"
        }
      ],
      "seeds": [
        {
          "id": "checkpoint-irreversible",
          "title": "Checkpoints on irreversible actions, failing closed",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#where-to-put-a-checkpoint"
        }
      ],
      "derivedFrom": [],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART14",
            "name": "EU AI Act Art. 14 human oversight",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art14"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART15",
            "name": "EU AI Act Art. 15 accuracy, robustness and cybersecurity",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15"
          },
          {
            "id": "AIGE-OBL-OWASP-AGENTIC",
            "name": "Top 10 for Agentic Applications 2026",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-agentic"
          },
          {
            "id": "AIGE-OBL-CSA-AICM-AGENTIC",
            "name": "AICM agent controls with the CSA Agentic Trust Framework and AARM specification",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-csa-aicm-agentic"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART13",
            "name": "EU AI Act Art. 13 transparency and information to deployers",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art13"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART50",
            "name": "EU AI Act Art. 50 transparency for certain AI systems",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art50"
          }
        ],
        "iso42001": [
          {
            "id": "A.6.2.6",
            "title": "AI system operation and monitoring"
          },
          {
            "id": "A.9.2",
            "title": "Processes for responsible use of AI systems"
          },
          {
            "id": "A.8.2",
            "title": "System documentation and information for users"
          }
        ],
        "nistAiRmf": [],
        "owasp": [
          {
            "id": "asi02",
            "externalId": "ASI02",
            "name": "Tool Misuse and Exploitation",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-asi02"
          },
          {
            "id": "asi09",
            "externalId": "ASI09",
            "name": "Human-Agent Trust Exploitation",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-asi09"
          }
        ],
        "atlas": [],
        "aiuc1": [
          "D003"
        ],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 10,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Where to put a checkpoint\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#where-to-put-a-checkpoint",
          "verified": "primary"
        },
        {
          "n": 11,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Runtime guardrails for tool calls\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#runtime-guardrails-for-tool-calls",
          "verified": "primary"
        },
        {
          "n": 2,
          "title": "OWASP Top 10 for Agentic Applications for 2026",
          "text": "OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents). OWASP GenAI Security Project. 2025-12-09.",
          "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
          "verified": "primary"
        },
        {
          "n": 3,
          "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
          "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        },
        {
          "n": 8,
          "title": "AIUC-1 requirements",
          "text": "AIUC-1 requirements (public requirement index, A001 to F002, each requirement on its own page (E007 and E014 marked retired); AIUC-1 is a standard of the Artificial Intelligence Underwriting Company; this site is not affiliated with AIUC, and a mapping here is not an AIUC-1 certificate or audit). Artificial Intelligence Underwriting Company. 2026-09-24.",
          "url": "https://standard.aiuc-1.com/llms.txt",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Record the failure posture per operation class in the agent's Policy Card.",
        "Name who approves each class: a role with the authority to refuse for high stakes, the action's business owner for irreversible actions, the on-call owner for outliers, the user for user-defined limits and the agent's owner for scope elevation."
      ],
      "openQuestions": [
        "Verification procedure and evidence schema to be specified; requires technical review."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-AGENT-016",
      "profile": "agent-runtime",
      "url": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-016",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-016.json",
      "title": "Code runs only in a sandbox",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "Execute-class tools run generated code only in a sandbox; anything else is denied.",
      "failureModes": [
        "ASI05: Code the agent writes or runs, directly or through a tool, executes outside the bounds anyone intended and compromises the host or the environment around it.",
        "Code runs in a sandbox that still reaches the open internet: METR reports agents that gained code execution on an evaluation sandbox, which gave them more flexible access to the full internet."
      ],
      "scope": "Agents with execute-class tools that run generated code.",
      "enforcementPoints": [
        "runtime"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Sandbox policy; violation events",
          "schemaId": null,
          "schema": null,
          "layer": 4
        }
      ],
      "failureResponse": {
        "effect": "deny",
        "text": "Generated code that would run outside a sandbox is denied."
      },
      "layer": 4,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "runtime-guardrail",
          "title": "Runtime Guardrail",
          "url": "https://aigovernanceengineer.com/patterns/runtime-guardrail"
        }
      ],
      "seeds": [
        {
          "id": "sandbox",
          "title": "Code runs only in a sandbox",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#runtime-guardrails-for-tool-calls"
        }
      ],
      "derivedFrom": [],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART15",
            "name": "EU AI Act Art. 15 accuracy, robustness and cybersecurity",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15"
          },
          {
            "id": "AIGE-OBL-OWASP-AGENTIC",
            "name": "Top 10 for Agentic Applications 2026",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-agentic"
          },
          {
            "id": "AIGE-OBL-ETSI-304223",
            "name": "ETSI EN 304 223 baseline cyber-security for AI models and systems",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-etsi-304223"
          }
        ],
        "iso42001": [
          {
            "id": "A.6.2.5",
            "title": "AI system deployment"
          },
          {
            "id": "A.6.2.6",
            "title": "AI system operation and monitoring"
          }
        ],
        "nistAiRmf": [],
        "owasp": [
          {
            "id": "asi05",
            "externalId": "ASI05",
            "name": "Unexpected Code Execution (RCE)",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-asi05"
          }
        ],
        "atlas": [],
        "aiuc1": [
          "B006"
        ],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 11,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Runtime guardrails for tool calls\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#runtime-guardrails-for-tool-calls",
          "verified": "primary"
        },
        {
          "n": 2,
          "title": "OWASP Top 10 for Agentic Applications for 2026",
          "text": "OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents). OWASP GenAI Security Project. 2025-12-09.",
          "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
          "verified": "primary"
        },
        {
          "n": 3,
          "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
          "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        },
        {
          "n": 7,
          "title": "Brief independent investigation of agents' behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident",
          "text": "Brief independent investigation of agents' behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident (agents in an evaluation exercise spoofed tool calls to alter their transcripts, tried to trigger container resets that would wipe recent records, and gained code execution on a sandbox with access to the full internet). METR. 2026-08-26.",
          "url": "https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/",
          "verified": "primary"
        },
        {
          "n": 8,
          "title": "AIUC-1 requirements",
          "text": "AIUC-1 requirements (public requirement index, A001 to F002, each requirement on its own page (E007 and E014 marked retired); AIUC-1 is a standard of the Artificial Intelligence Underwriting Company; this site is not affiliated with AIUC, and a mapping here is not an AIUC-1 certificate or audit). Artificial Intelligence Underwriting Company. 2026-09-24.",
          "url": "https://standard.aiuc-1.com/llms.txt",
          "verified": "primary"
        }
      ],
      "implementationNotes": [],
      "openQuestions": [
        "Verification procedure and evidence schema to be specified; requires technical review."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-AGENT-017",
      "profile": "agent-runtime",
      "url": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-017",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-017.json",
      "title": "Output and egress filter",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "What leaves after each call is filtered for secrets, personal data and destinations, and every tool, including the ones nobody worries about, has a rate and an egress bound.",
      "failureModes": [
        "ASI02: The agent uses tools it is allowed to use in unsafe ways: destructive parameters, chains of calls nobody intended, or exfiltration through a permitted channel."
      ],
      "scope": "Every agent that calls tools, in production or in an evaluation harness.",
      "enforcementPoints": [
        "runtime"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Egress allow-list; redact and block events",
          "schemaId": null,
          "schema": null,
          "layer": 4
        }
      ],
      "failureResponse": {
        "effect": "deny",
        "text": "Output carrying secrets or personal data, or bound for a destination outside the egress allow-list, is redacted or blocked before the result returns."
      },
      "layer": 4,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "runtime-guardrail",
          "title": "Runtime Guardrail",
          "url": "https://aigovernanceengineer.com/patterns/runtime-guardrail"
        }
      ],
      "seeds": [
        {
          "id": "egress-filter",
          "title": "Output and egress filter",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#the-tool-allow-list"
        }
      ],
      "derivedFrom": [],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART14",
            "name": "EU AI Act Art. 14 human oversight",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art14"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART15",
            "name": "EU AI Act Art. 15 accuracy, robustness and cybersecurity",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15"
          },
          {
            "id": "AIGE-OBL-OWASP-AGENTIC",
            "name": "Top 10 for Agentic Applications 2026",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-agentic"
          },
          {
            "id": "AIGE-OBL-CSA-AICM-AGENTIC",
            "name": "AICM agent controls with the CSA Agentic Trust Framework and AARM specification",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-csa-aicm-agentic"
          }
        ],
        "iso42001": [
          {
            "id": "A.6.2.6",
            "title": "AI system operation and monitoring"
          },
          {
            "id": "A.9.2",
            "title": "Processes for responsible use of AI systems"
          }
        ],
        "nistAiRmf": [],
        "owasp": [
          {
            "id": "asi02",
            "externalId": "ASI02",
            "name": "Tool Misuse and Exploitation",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-asi02"
          }
        ],
        "atlas": [],
        "aiuc1": [
          "A006",
          "A008"
        ],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 9,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"The tool allow-list\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#the-tool-allow-list",
          "verified": "primary"
        },
        {
          "n": 2,
          "title": "OWASP Top 10 for Agentic Applications for 2026",
          "text": "OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents). OWASP GenAI Security Project. 2025-12-09.",
          "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
          "verified": "primary"
        },
        {
          "n": 3,
          "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
          "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        },
        {
          "n": 8,
          "title": "AIUC-1 requirements",
          "text": "AIUC-1 requirements (public requirement index, A001 to F002, each requirement on its own page (E007 and E014 marked retired); AIUC-1 is a standard of the Artificial Intelligence Underwriting Company; this site is not affiliated with AIUC, and a mapping here is not an AIUC-1 certificate or audit). Artificial Intelligence Underwriting Company. 2026-09-24.",
          "url": "https://standard.aiuc-1.com/llms.txt",
          "verified": "primary"
        }
      ],
      "implementationNotes": [],
      "openQuestions": [
        "Verification procedure and evidence schema to be specified; requires technical review."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-AGENT-018",
      "profile": "agent-runtime",
      "url": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-018",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-018.json",
      "title": "MCP server admission gate",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "Each MCP server is admitted as a supplier: its provenance is recorded in the AIBOM, its tool definitions are hashed and pinned with an alert on change, its authorisation conformance is checked, it is tested with poisoned descriptors and injected outputs, and it has an owner and a review date.",
      "failureModes": [
        "ASI04: Tools, MCP servers, plugins, prompt templates and models that an agent loads, often at run time, can be malicious or become malicious after they were trusted."
      ],
      "scope": "Agents that use MCP servers, and each server before any allow-list names it.",
      "enforcementPoints": [
        "deploy"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Admission record per server; definition hashes",
          "schemaId": null,
          "schema": null,
          "layer": 2
        }
      ],
      "failureResponse": {
        "effect": "alert",
        "text": "To be specified."
      },
      "layer": 2,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "aibom",
          "title": "AIBOM",
          "url": "https://aigovernanceengineer.com/patterns/aibom"
        }
      ],
      "seeds": [
        {
          "id": "mcp-admission",
          "title": "MCP server admission gate",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#admitting-an-mcp-server"
        }
      ],
      "derivedFrom": [],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART15",
            "name": "EU AI Act Art. 15 accuracy, robustness and cybersecurity",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART25",
            "name": "EU AI Act Art. 25 responsibilities along the AI value chain",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art25"
          },
          {
            "id": "AIGE-OBL-ISO42001-A10",
            "name": "A.10 Third-party and customer relationships",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a10"
          },
          {
            "id": "AIGE-OBL-OWASP-AIBOM",
            "name": "AIBOM",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-aibom"
          }
        ],
        "iso42001": [
          {
            "id": "A.10.3",
            "title": "Suppliers"
          },
          {
            "id": "A.7.5",
            "title": "Data provenance"
          }
        ],
        "nistAiRmf": [],
        "owasp": [
          {
            "id": "asi04",
            "externalId": "ASI04",
            "name": "Agentic Supply Chain Vulnerabilities",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-asi04"
          }
        ],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 20,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Admitting an MCP server\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#admitting-an-mcp-server",
          "verified": "primary"
        },
        {
          "n": 2,
          "title": "OWASP Top 10 for Agentic Applications for 2026",
          "text": "OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents). OWASP GenAI Security Project. 2025-12-09.",
          "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
          "verified": "primary"
        },
        {
          "n": 3,
          "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
          "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        }
      ],
      "implementationNotes": [
        "Record the publisher, the source repository and a signed release as provenance; hash tool names, descriptions and schemas at admission, because a changed description is a changed instruction.",
        "Run the tests with poisoned descriptors and injected tool outputs before any allow-list names the server; the vendor due-diligence gate covers who answers when it misbehaves and what notice comes before it changes."
      ],
      "openQuestions": [
        "Verification procedure and evidence schema to be specified; requires technical review."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-AGENT-019",
      "profile": "agent-runtime",
      "url": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-019",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-019.json",
      "title": "Local MCP servers sandboxed",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "A one-click local MCP server install shows the exact install command and waits for explicit approval; local servers run sandboxed with minimal privileges, and discovery sweeps reconcile them.",
      "failureModes": [
        "ASI04: Tools, MCP servers, plugins, prompt templates and models that an agent loads, often at run time, can be malicious or become malicious after they were trusted.",
        "ASI10: An agent drifts from its intended behaviour or scope (through compromise, misalignment or neglect) and keeps acting, possibly deceptively, where nobody is watching."
      ],
      "scope": "Agents that use MCP servers running on the same machine, including coding agents on developer laptops.",
      "enforcementPoints": [
        "runtime",
        "periodic"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Install approvals; discovery findings",
          "schemaId": null,
          "schema": null,
          "layer": 4
        }
      ],
      "failureResponse": {
        "effect": "alert",
        "text": "To be specified."
      },
      "layer": 4,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "shadow-ai-discovery",
          "title": "Shadow-AI Discovery",
          "url": "https://aigovernanceengineer.com/patterns/shadow-ai-discovery"
        }
      ],
      "seeds": [
        {
          "id": "mcp-local",
          "title": "Local MCP servers sandboxed",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#admitting-an-mcp-server"
        }
      ],
      "derivedFrom": [],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART15",
            "name": "EU AI Act Art. 15 accuracy, robustness and cybersecurity",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART25",
            "name": "EU AI Act Art. 25 responsibilities along the AI value chain",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art25"
          },
          {
            "id": "AIGE-OBL-ISO42001-A10",
            "name": "A.10 Third-party and customer relationships",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a10"
          },
          {
            "id": "AIGE-OBL-OWASP-AIBOM",
            "name": "AIBOM",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-aibom"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART14",
            "name": "EU AI Act Art. 14 human oversight",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art14"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART26",
            "name": "EU AI Act Art. 26 deployer obligations for high-risk systems",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART72",
            "name": "EU AI Act Art. 72 post-market monitoring",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art72"
          },
          {
            "id": "AIGE-OBL-OWASP-AGENTIC",
            "name": "Top 10 for Agentic Applications 2026",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-agentic"
          }
        ],
        "iso42001": [
          {
            "id": "A.10.3",
            "title": "Suppliers"
          },
          {
            "id": "A.7.5",
            "title": "Data provenance"
          },
          {
            "id": "A.6.2.6",
            "title": "AI system operation and monitoring"
          },
          {
            "id": "A.6.2.8",
            "title": "AI system recording of event logs"
          }
        ],
        "nistAiRmf": [],
        "owasp": [
          {
            "id": "asi04",
            "externalId": "ASI04",
            "name": "Agentic Supply Chain Vulnerabilities",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-asi04"
          },
          {
            "id": "asi10",
            "externalId": "ASI10",
            "name": "Rogue Agents",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-asi10"
          }
        ],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 20,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Admitting an MCP server\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#admitting-an-mcp-server",
          "verified": "primary"
        },
        {
          "n": 2,
          "title": "OWASP Top 10 for Agentic Applications for 2026",
          "text": "OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents). OWASP GenAI Security Project. 2025-12-09.",
          "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
          "verified": "primary"
        },
        {
          "n": 3,
          "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
          "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        }
      ],
      "implementationNotes": [],
      "openQuestions": [
        "Verification procedure and evidence schema to be specified; requires technical review."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-AGENT-020",
      "profile": "agent-runtime",
      "url": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-020",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-020.json",
      "title": "MCP authorisation (spec 2026-07-28)",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "Where a remote MCP server uses authorisation, discovery uses protected-resource metadata, token requests carry the resource parameter, the audience is validated and no token is passed through, the issuer is validated, and scopes are stepped up instead of granted as omnibus ones; the MCP version each server speaks is recorded.",
      "failureModes": [
        "ASI03: Delegated identities, inherited privileges and cached credentials let an agent (or whoever steers it) act with rights the requesting user never had."
      ],
      "scope": "Agents that call remote MCP servers over HTTP where the server uses authorisation.",
      "enforcementPoints": [
        "runtime"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Token requests naming the resource; audience-check alerts; MCP version in the registry",
          "schemaId": null,
          "schema": null,
          "layer": 4
        }
      ],
      "failureResponse": {
        "effect": "alert",
        "text": "To be specified."
      },
      "layer": 4,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "agent-identity-scoped-credentials",
          "title": "Agent Identity & Scoped Credentials",
          "url": "https://aigovernanceengineer.com/patterns/agent-identity-scoped-credentials"
        }
      ],
      "seeds": [
        {
          "id": "mcp-authorization",
          "title": "MCP authorisation (spec 2026-07-28)",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#mcp-authorization-as-of-2026-07-28"
        }
      ],
      "derivedFrom": [],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART15",
            "name": "EU AI Act Art. 15 accuracy, robustness and cybersecurity",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15"
          },
          {
            "id": "AIGE-OBL-OWASP-AGENTIC",
            "name": "Top 10 for Agentic Applications 2026",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-agentic"
          },
          {
            "id": "AIGE-OBL-CSA-AICM-AGENTIC",
            "name": "AICM agent controls with the CSA Agentic Trust Framework and AARM specification",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-csa-aicm-agentic"
          },
          {
            "id": "AIGE-OBL-NIST-AGENTS",
            "name": "NIST AI Agent Standards Initiative (2026)",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-nist-agents"
          }
        ],
        "iso42001": [
          {
            "id": "A.6.2.5",
            "title": "AI system deployment"
          }
        ],
        "nistAiRmf": [],
        "owasp": [
          {
            "id": "asi03",
            "externalId": "ASI03",
            "name": "Identity and Privilege Abuse",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-asi03"
          }
        ],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 21,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"MCP authorization as of 2026-07-28\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#mcp-authorization-as-of-2026-07-28",
          "verified": "primary"
        },
        {
          "n": 2,
          "title": "OWASP Top 10 for Agentic Applications for 2026",
          "text": "OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents). OWASP GenAI Security Project. 2025-12-09.",
          "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
          "verified": "primary"
        },
        {
          "n": 3,
          "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
          "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        }
      ],
      "implementationNotes": [
        "Prefer Client ID Metadata Documents to Dynamic Client Registration, which the 2026-07-28 specification deprecates, and keep the allowed client domains as policy.",
        "MCP secures the hop between one client and one server; which agent sits behind the client, and for whom, is the workload identity's job."
      ],
      "openQuestions": [
        "Verification procedure and evidence schema to be specified; requires technical review."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-AGENT-021",
      "profile": "agent-runtime",
      "url": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-021",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-021.json",
      "title": "Replace long-lived secrets with short-lived credentials",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "The agent holds no static key or long-lived secret: it acts on short-lived, attested credentials that expire in minutes and are revoked at the end of the task.",
      "failureModes": [
        "ASI03: Delegated identities, inherited privileges and cached credentials let an agent (or whoever steers it) act with rights the requesting user never had."
      ],
      "scope": "Agents that hold a static key or a long-lived secret.",
      "enforcementPoints": [
        "runtime"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Credential lifetime in the registry; no secrets in configuration",
          "schemaId": null,
          "schema": null,
          "layer": 4
        }
      ],
      "failureResponse": {
        "effect": "alert",
        "text": "To be specified."
      },
      "layer": 4,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "agent-identity-scoped-credentials",
          "title": "Agent Identity & Scoped Credentials",
          "url": "https://aigovernanceengineer.com/patterns/agent-identity-scoped-credentials"
        }
      ],
      "seeds": [
        {
          "id": "short-lived-credentials",
          "title": "Replace long-lived secrets with short-lived credentials",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#short-lived-attested-credentials"
        }
      ],
      "derivedFrom": [],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART15",
            "name": "EU AI Act Art. 15 accuracy, robustness and cybersecurity",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15"
          },
          {
            "id": "AIGE-OBL-OWASP-AGENTIC",
            "name": "Top 10 for Agentic Applications 2026",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-agentic"
          },
          {
            "id": "AIGE-OBL-CSA-AICM-AGENTIC",
            "name": "AICM agent controls with the CSA Agentic Trust Framework and AARM specification",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-csa-aicm-agentic"
          },
          {
            "id": "AIGE-OBL-NIST-AGENTS",
            "name": "NIST AI Agent Standards Initiative (2026)",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-nist-agents"
          }
        ],
        "iso42001": [
          {
            "id": "A.6.2.5",
            "title": "AI system deployment"
          }
        ],
        "nistAiRmf": [],
        "owasp": [
          {
            "id": "asi03",
            "externalId": "ASI03",
            "name": "Identity and Privilege Abuse",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-asi03"
          }
        ],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 22,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Short-lived, attested credentials\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#short-lived-attested-credentials",
          "verified": "primary"
        },
        {
          "n": 2,
          "title": "OWASP Top 10 for Agentic Applications for 2026",
          "text": "OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents). OWASP GenAI Security Project. 2025-12-09.",
          "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
          "verified": "primary"
        },
        {
          "n": 3,
          "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
          "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        }
      ],
      "implementationNotes": [
        "A credential that expires in minutes need not be hunted down after an incident, only not reissued; authorisations stay time- or session-bound, non-transferable and never greater than what the authorising person may do."
      ],
      "openQuestions": [
        "Verification procedure and evidence schema to be specified; requires technical review."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-AGENT-022",
      "profile": "agent-runtime",
      "url": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-022",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-022.json",
      "title": "Delegation, never impersonation",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "When the agent acts for a user, it holds a delegated token, exchanged for the user's, that names the agent, with a narrower scope and a short expiry; it never holds the user's own token.",
      "failureModes": [
        "ASI03: Delegated identities, inherited privileges and cached credentials let an agent (or whoever steers it) act with rights the requesting user never had."
      ],
      "scope": "Agents that act on behalf of a user.",
      "enforcementPoints": [
        "runtime"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Delegated tokens with an act claim; token-exchange log",
          "schemaId": null,
          "schema": null,
          "layer": 4
        }
      ],
      "failureResponse": {
        "effect": "alert",
        "text": "To be specified."
      },
      "layer": 4,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "agent-identity-scoped-credentials",
          "title": "Agent Identity & Scoped Credentials",
          "url": "https://aigovernanceengineer.com/patterns/agent-identity-scoped-credentials"
        }
      ],
      "seeds": [
        {
          "id": "delegated-token",
          "title": "Delegation, never impersonation",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#delegation-without-impersonation"
        }
      ],
      "derivedFrom": [],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART15",
            "name": "EU AI Act Art. 15 accuracy, robustness and cybersecurity",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15"
          },
          {
            "id": "AIGE-OBL-OWASP-AGENTIC",
            "name": "Top 10 for Agentic Applications 2026",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-agentic"
          },
          {
            "id": "AIGE-OBL-CSA-AICM-AGENTIC",
            "name": "AICM agent controls with the CSA Agentic Trust Framework and AARM specification",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-csa-aicm-agentic"
          },
          {
            "id": "AIGE-OBL-NIST-AGENTS",
            "name": "NIST AI Agent Standards Initiative (2026)",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-nist-agents"
          }
        ],
        "iso42001": [
          {
            "id": "A.6.2.5",
            "title": "AI system deployment"
          }
        ],
        "nistAiRmf": [],
        "owasp": [
          {
            "id": "asi03",
            "externalId": "ASI03",
            "name": "Identity and Privilege Abuse",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-asi03"
          }
        ],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 23,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Delegation without impersonation\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#delegation-without-impersonation",
          "verified": "primary"
        },
        {
          "n": 2,
          "title": "OWASP Top 10 for Agentic Applications for 2026",
          "text": "OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents). OWASP GenAI Security Project. 2025-12-09.",
          "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
          "verified": "primary"
        },
        {
          "n": 3,
          "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
          "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        }
      ],
      "implementationNotes": [
        "Keep both identities in the log: the user as the subject, the agent as the current actor in the act claim, and earlier actors in the chain as nested act claims."
      ],
      "openQuestions": [
        "Verification procedure and evidence schema to be specified; requires technical review."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-AGENT-023",
      "profile": "agent-runtime",
      "url": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-023",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-023.json",
      "title": "Memory write gate and rollback",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "Writes are events that carry their source; untrusted content cannot write to long-term memory without a gate; memory is isolated per user and per task; retention is code; memory can be rolled back to a known-good snapshot.",
      "failureModes": [
        "ASI06: Stored memory, retrieval stores or carried context are corrupted so the poison persists across sessions and shapes later decisions."
      ],
      "scope": "Agents with memory: context, conversation threads, long-term memory, retrieval corpora or memory shared with other agents.",
      "enforcementPoints": [
        "runtime"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Memory write events with provenance; retention jobs; rollback drills",
          "schemaId": null,
          "schema": null,
          "layer": 4
        }
      ],
      "failureResponse": {
        "effect": "alert",
        "text": "To be specified."
      },
      "layer": 4,
      "secondaryLayers": [
        3
      ],
      "patterns": [
        {
          "slug": "runtime-guardrail",
          "title": "Runtime Guardrail",
          "url": "https://aigovernanceengineer.com/patterns/runtime-guardrail"
        }
      ],
      "seeds": [
        {
          "id": "memory-governance",
          "title": "Memory write gate and rollback",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#memory-and-context-governance"
        }
      ],
      "derivedFrom": [],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART15",
            "name": "EU AI Act Art. 15 accuracy, robustness and cybersecurity",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART12",
            "name": "EU AI Act Art. 12 record-keeping and logging",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art12"
          },
          {
            "id": "AIGE-OBL-OWASP-AGENTIC",
            "name": "Top 10 for Agentic Applications 2026",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-agentic"
          }
        ],
        "iso42001": [
          {
            "id": "A.6.2.6",
            "title": "AI system operation and monitoring"
          },
          {
            "id": "A.6.2.8",
            "title": "AI system recording of event logs"
          }
        ],
        "nistAiRmf": [],
        "owasp": [
          {
            "id": "asi06",
            "externalId": "ASI06",
            "name": "Memory & Context Poisoning",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-asi06"
          }
        ],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 24,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Memory and context governance\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#memory-and-context-governance",
          "verified": "primary"
        },
        {
          "n": 2,
          "title": "OWASP Top 10 for Agentic Applications for 2026",
          "text": "OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents). OWASP GenAI Security Project. 2025-12-09.",
          "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
          "verified": "primary"
        },
        {
          "n": 3,
          "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
          "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        }
      ],
      "implementationNotes": [
        "Match the control to the memory: provenance tags for the context window, per-session isolation for threads, a write gate, per-user namespace, time to live and erasure path for long-term memory, source admission and entitlement checks for retrieval corpora, per-task isolation and attributed writes for shared memory."
      ],
      "openQuestions": [
        "Verification procedure and evidence schema to be specified; requires technical review."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-AGENT-024",
      "profile": "agent-runtime",
      "url": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-024",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-024.json",
      "title": "Retention and erasure for personal data in memory",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "Every memory store that holds personal data has retention windows and an erasure path, in line with the GDPR's minimisation and storage-limitation principles and the right to erasure, and no memory store holds credentials.",
      "failureModes": [
        "Personal data stays in a memory store past its retention window, or an erasure request cannot be carried out on the store.",
        "A credential is found in agent memory."
      ],
      "scope": "Agents with memory stores that hold personal data.",
      "enforcementPoints": [
        "runtime"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Retention schedule per memory class; erasure records",
          "schemaId": null,
          "schema": null,
          "layer": 4
        }
      ],
      "failureResponse": {
        "effect": "alert",
        "text": "To be specified."
      },
      "layer": 4,
      "secondaryLayers": [],
      "patterns": [],
      "seeds": [
        {
          "id": "memory-personal-data",
          "title": "Retention and erasure for personal data in memory",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#memory-and-context-governance"
        }
      ],
      "derivedFrom": [],
      "mappings": {
        "obligations": [],
        "iso42001": [],
        "nistAiRmf": [],
        "owasp": [],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 24,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Memory and context governance\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#memory-and-context-governance",
          "verified": "primary"
        }
      ],
      "implementationNotes": [],
      "openQuestions": [
        "Verification procedure and evidence schema to be specified; requires technical review."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-AGENT-025",
      "profile": "agent-runtime",
      "url": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-025",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-025.json",
      "title": "Accountability across hops",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "Every task carries its originating principal; each agent authenticates as itself; scope narrows or stays equal at each hop; the purpose travels and is checked; depth and fan-out are limited; one trace runs end to end; only registered peers with verified, signed cards are called.",
      "failureModes": [
        "ASI07: Messages between agents travel without authentication or integrity, so a peer can be spoofed, a message replayed or altered, and trust passes along a chain that nobody checked.",
        "ASI08: One faulty or compromised agent, tool or output propagates through connected agents and workflows, and each hop amplifies the harm."
      ],
      "scope": "Agents that delegate tasks to other agents or take tasks from them.",
      "enforcementPoints": [
        "runtime"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Delegation record; nested act claims; peer allow-list; trace ids",
          "schemaId": null,
          "schema": null,
          "layer": 4
        }
      ],
      "failureResponse": {
        "effect": "alert",
        "text": "To be specified."
      },
      "layer": 4,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "agent-identity-scoped-credentials",
          "title": "Agent Identity & Scoped Credentials",
          "url": "https://aigovernanceengineer.com/patterns/agent-identity-scoped-credentials"
        }
      ],
      "seeds": [
        {
          "id": "hop-accountability",
          "title": "Accountability across hops",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#accountability-across-hops"
        }
      ],
      "derivedFrom": [],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART15",
            "name": "EU AI Act Art. 15 accuracy, robustness and cybersecurity",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15"
          },
          {
            "id": "AIGE-OBL-OWASP-AGENTIC",
            "name": "Top 10 for Agentic Applications 2026",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-agentic"
          },
          {
            "id": "AIGE-OBL-NIST-AGENTS",
            "name": "NIST AI Agent Standards Initiative (2026)",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-nist-agents"
          },
          {
            "id": "AIGE-OBL-CSA-AICM-AGENTIC",
            "name": "AICM agent controls with the CSA Agentic Trust Framework and AARM specification",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-csa-aicm-agentic"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART72",
            "name": "EU AI Act Art. 72 post-market monitoring",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art72"
          },
          {
            "id": "AIGE-OBL-NISTRMF-MANAGE",
            "name": "MANAGE",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage"
          }
        ],
        "iso42001": [
          {
            "id": "A.6.2.5",
            "title": "AI system deployment"
          },
          {
            "id": "A.6.2.6",
            "title": "AI system operation and monitoring"
          }
        ],
        "nistAiRmf": [],
        "owasp": [
          {
            "id": "asi07",
            "externalId": "ASI07",
            "name": "Insecure Inter-Agent Communication",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-asi07"
          },
          {
            "id": "asi08",
            "externalId": "ASI08",
            "name": "Cascading Failures",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-asi08"
          }
        ],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 25,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Accountability across hops\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#accountability-across-hops",
          "verified": "primary"
        },
        {
          "n": 2,
          "title": "OWASP Top 10 for Agentic Applications for 2026",
          "text": "OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents). OWASP GenAI Security Project. 2025-12-09.",
          "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
          "verified": "primary"
        },
        {
          "n": 3,
          "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
          "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        }
      ],
      "implementationNotes": [
        "Enforce these properties at every gateway you control; a breach of the depth or fan-out limit raises a breaker event. Transaction Tokens and WIMSE address the same problem but are unfinished as of 2026-09-24."
      ],
      "openQuestions": [
        "Verification procedure and evidence schema to be specified; requires technical review."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-AGENT-026",
      "profile": "agent-runtime",
      "url": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-026",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-026.json",
      "title": "Stopping third-party agents at your boundary",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "A third-party agent, which cannot be stopped from outside, is cut off at your boundary: your agents can be stopped from calling it, what you issued to it can be revoked, and a contract names who answers for it.",
      "failureModes": [
        "ASI07: Messages between agents travel without authentication or integrity, so a peer can be spoofed, a message replayed or altered, and trust passes along a chain that nobody checked."
      ],
      "scope": "Agents that call, or delegate to, agents run by a third party.",
      "enforcementPoints": [
        "runtime"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Peer allow-list; revocation records; clause reference in the registry",
          "schemaId": null,
          "schema": null,
          "layer": 4
        }
      ],
      "failureResponse": {
        "effect": "alert",
        "text": "To be specified."
      },
      "layer": 4,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "kill-switch-circuit-breaker",
          "title": "Kill Switch / Circuit Breaker",
          "url": "https://aigovernanceengineer.com/patterns/kill-switch-circuit-breaker"
        }
      ],
      "seeds": [
        {
          "id": "remote-agents",
          "title": "Stopping third-party agents at your boundary",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#stopping-across-hops"
        }
      ],
      "derivedFrom": [],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART15",
            "name": "EU AI Act Art. 15 accuracy, robustness and cybersecurity",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15"
          },
          {
            "id": "AIGE-OBL-OWASP-AGENTIC",
            "name": "Top 10 for Agentic Applications 2026",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-agentic"
          },
          {
            "id": "AIGE-OBL-NIST-AGENTS",
            "name": "NIST AI Agent Standards Initiative (2026)",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-nist-agents"
          },
          {
            "id": "AIGE-OBL-CSA-AICM-AGENTIC",
            "name": "AICM agent controls with the CSA Agentic Trust Framework and AARM specification",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-csa-aicm-agentic"
          }
        ],
        "iso42001": [
          {
            "id": "A.6.2.5",
            "title": "AI system deployment"
          }
        ],
        "nistAiRmf": [],
        "owasp": [
          {
            "id": "asi07",
            "externalId": "ASI07",
            "name": "Insecure Inter-Agent Communication",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-asi07"
          }
        ],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 26,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Stopping across hops\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#stopping-across-hops",
          "verified": "primary"
        },
        {
          "n": 2,
          "title": "OWASP Top 10 for Agentic Applications for 2026",
          "text": "OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents). OWASP GenAI Security Project. 2025-12-09.",
          "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
          "verified": "primary"
        },
        {
          "n": 3,
          "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
          "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        }
      ],
      "implementationNotes": [
        "A remote cancel is not guaranteed to stop the task; short-lived delegated tokens bound the revocation by their lifetime, where long-lived ones make it a hope."
      ],
      "openQuestions": [
        "Verification procedure and evidence schema to be specified; requires technical review."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-AGENT-027",
      "profile": "agent-runtime",
      "url": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-027",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-027.json",
      "title": "Data classes recorded, with the DPIA linked",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "The registry entry records the agent's data classes and memory stores and links the DPIA and the records of processing, and each tool states which data classes may flow in and out (the chapter's example: no special-category data to external tools).",
      "failureModes": [
        "The registry entry names no data classes or memory stores, or links no DPIA or records of processing.",
        "A data class reaches a tool that may not receive it, such as special-category data sent to an external tool."
      ],
      "scope": "Every agent that calls tools, in production or in an evaluation harness.",
      "enforcementPoints": [
        "deploy"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Registry fields; DPIA and records-of-processing links",
          "schemaId": "agent-register-entry",
          "schema": "https://aigovernanceengineer.com/schemas/agent-register-entry.v1.json",
          "layer": 2
        }
      ],
      "failureResponse": {
        "effect": "alert",
        "text": "To be specified."
      },
      "layer": 2,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "agent-registry",
          "title": "Agent Registry",
          "url": "https://aigovernanceengineer.com/patterns/agent-registry"
        }
      ],
      "seeds": [
        {
          "id": "data-classes",
          "title": "Data classes recorded, with the DPIA linked",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#the-agent-registry"
        }
      ],
      "derivedFrom": [],
      "mappings": {
        "obligations": [],
        "iso42001": [],
        "nistAiRmf": [],
        "owasp": [],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 1,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"The agent registry\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#the-agent-registry",
          "verified": "primary"
        }
      ],
      "implementationNotes": [],
      "openQuestions": [
        "Verification procedure and evidence schema to be specified; requires technical review."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-AGENT-028",
      "profile": "agent-runtime",
      "url": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-028",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-028.json",
      "title": "Prompts under change control",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "The system prompt, tool descriptions and policy bundle are versioned and owned, hashed in the registry and in every trace, and changed only through the regression suite and a canary rollout with the previous hash ready to restore, with a check on whether the purpose changed.",
      "failureModes": [
        "The production prompt is edited outside the pipeline, for example in a vendor console, so the registry and the traces still name the old version and an incident replays a configuration that never ran.",
        "A prompt, tool description or policy bundle change ships with no passing regression run, or with no hash in the registry and the traces.",
        "A change alters what the system is for and no one asks whether the purpose changed."
      ],
      "scope": "Every agent that calls tools, in production or in an evaluation harness.",
      "enforcementPoints": [
        "pre_merge",
        "deploy"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Prompt manifest; eval run per change; rollout record",
          "schemaId": null,
          "schema": null,
          "layer": 4
        }
      ],
      "failureResponse": {
        "effect": "alert",
        "text": "To be specified."
      },
      "layer": 4,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "eval-gate-in-ci",
          "title": "Eval Gate in CI",
          "url": "https://aigovernanceengineer.com/patterns/eval-gate-in-ci"
        }
      ],
      "seeds": [
        {
          "id": "prompt-change-control",
          "title": "Prompts under change control",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#prompts-as-configuration-under-change-control"
        }
      ],
      "derivedFrom": [],
      "mappings": {
        "obligations": [],
        "iso42001": [],
        "nistAiRmf": [],
        "owasp": [],
        "atlas": [],
        "aiuc1": [
          "E004"
        ],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 27,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Prompts as configuration under change control\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#prompts-as-configuration-under-change-control",
          "verified": "primary"
        },
        {
          "n": 8,
          "title": "AIUC-1 requirements",
          "text": "AIUC-1 requirements (public requirement index, A001 to F002, each requirement on its own page (E007 and E014 marked retired); AIUC-1 is a standard of the Artificial Intelligence Underwriting Company; this site is not affiliated with AIUC, and a mapping here is not an AIUC-1 certificate or audit). Artificial Intelligence Underwriting Company. 2026-09-24.",
          "url": "https://standard.aiuc-1.com/llms.txt",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Keep prompts in the repository with a named owner and two reviewers, and let the pipeline refuse a prompt manifest whose named evaluation run has not passed.",
        "Treat the system prompt as configuration, not a secret and not a control: no credentials in it, and nothing that must hold enforced by it; that belongs in the gateway."
      ],
      "openQuestions": [
        "Verification procedure and evidence schema to be specified; requires technical review."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-AGENT-029",
      "profile": "agent-runtime",
      "url": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-029",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-029.json",
      "title": "Telemetry on the OpenTelemetry GenAI conventions",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "The agent emits agent and tool spans on the OpenTelemetry GenAI conventions (execute_tool, gen_ai.agent.id, gen_ai.agent.version), with registry id, workload identity, policy verdict, approval id and delegation chain in your own namespace, and argument capture has its own retention and access rules.",
      "failureModes": [
        "A tool call leaves no execute_tool span, or its span lacks the agent id and version.",
        "A span lacks the registry id, workload identity, policy verdict, approval id or delegation chain, so the action cannot be tied to its authority.",
        "Captured tool arguments and results, which may hold personal data, fall under the general trace retention and access rules."
      ],
      "scope": "Every agent that calls tools, in production or in an evaluation harness.",
      "enforcementPoints": [
        "runtime"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Spans per call; the fields in your namespace",
          "schemaId": null,
          "schema": null,
          "layer": 5
        }
      ],
      "failureResponse": {
        "effect": "alert",
        "text": "To be specified."
      },
      "layer": 5,
      "secondaryLayers": [],
      "patterns": [],
      "seeds": [
        {
          "id": "otel-telemetry",
          "title": "Telemetry on the OpenTelemetry GenAI conventions",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#telemetry-with-the-opentelemetry-genai-conventions"
        }
      ],
      "derivedFrom": [],
      "mappings": {
        "obligations": [],
        "iso42001": [],
        "nistAiRmf": [],
        "owasp": [],
        "atlas": [],
        "aiuc1": [
          "E015"
        ],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 6,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Telemetry with the OpenTelemetry GenAI conventions\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#telemetry-with-the-opentelemetry-genai-conventions",
          "verified": "primary"
        },
        {
          "n": 8,
          "title": "AIUC-1 requirements",
          "text": "AIUC-1 requirements (public requirement index, A001 to F002, each requirement on its own page (E007 and E014 marked retired); AIUC-1 is a standard of the Artificial Intelligence Underwriting Company; this site is not affiliated with AIUC, and a mapping here is not an AIUC-1 certificate or audit). Artificial Intelligence Underwriting Company. 2026-09-24.",
          "url": "https://standard.aiuc-1.com/llms.txt",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "The GenAI conventions are in Development status and names can still change; keep the governance fields in your own namespace and map them later."
      ],
      "openQuestions": [
        "Verification procedure and evidence schema to be specified; requires technical review."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-AGENT-030",
      "profile": "agent-runtime",
      "url": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-030",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-030.json",
      "title": "EU AI Act hooks for a high-risk purpose",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "An agent, classified by its intended purpose, that serves an Annex III purpose keeps event logs over its lifetime (Art. 12), has oversight commensurate with its autonomy level (Art. 14(3)-(4)) and competent overseers with authority (Art. 26(2)), and its logs stay under the deployer's control for at least six months (Art. 26(6)).",
      "failureModes": [
        "An agent with an Annex III purpose runs with no event log over its lifetime, or its logs are kept under the deployer's control for less than six months.",
        "Oversight is not matched to the autonomy level, or no overseer with the competence, training and authority is assigned."
      ],
      "scope": "Agents whose intended purpose falls under Annex III of the EU AI Act.",
      "enforcementPoints": [
        "runtime"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Traces; checkpoints and raw-call approvals; approver roster; log retention",
          "schemaId": null,
          "schema": null,
          "layer": 5
        }
      ],
      "failureResponse": {
        "effect": "alert",
        "text": "To be specified."
      },
      "layer": 5,
      "secondaryLayers": [],
      "patterns": [],
      "seeds": [
        {
          "id": "ai-act-high-risk",
          "title": "EU AI Act hooks for a high-risk purpose",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#eu-ai-act-hooks-for-agents"
        }
      ],
      "derivedFrom": [],
      "mappings": {
        "obligations": [],
        "iso42001": [],
        "nistAiRmf": [],
        "owasp": [],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 28,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"EU AI Act hooks for agents\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#eu-ai-act-hooks-for-agents",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Classify by intended purpose, not architecture: an agent that screens job applicants is high-risk through Annex III, and a scheduling assistant is not."
      ],
      "openQuestions": [
        "Verification procedure and evidence schema to be specified; requires technical review.",
        "Chapter 23 ties this control to the EU AI Act articles it names; the derivation carries obligations only through mapped OWASP Agentic threats, so the obligation mapping awaits review."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-AGENT-031",
      "profile": "agent-runtime",
      "url": "https://aigovernanceengineer.com/controls/agent-runtime#aige-ctl-agent-031",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-agent-031.json",
      "title": "Tell people they are dealing with an AI system",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "People who receive the messages, calls and chats the agent sends are told they are interacting with an AI system, unless that is obvious (Art. 50(1), from 2 Aug 2026).",
      "failureModes": [
        "A message, call or chat the agent sends to a person does not say it comes from an AI system, where that is not obvious."
      ],
      "scope": "Agents that send messages, calls or chats to people.",
      "enforcementPoints": [
        "runtime"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Disclosure text in message templates",
          "schemaId": null,
          "schema": null,
          "layer": 4
        }
      ],
      "failureResponse": {
        "effect": "alert",
        "text": "To be specified."
      },
      "layer": 4,
      "secondaryLayers": [],
      "patterns": [],
      "seeds": [
        {
          "id": "ai-disclosure",
          "title": "Tell people they are dealing with an AI system",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#eu-ai-act-hooks-for-agents"
        }
      ],
      "derivedFrom": [],
      "mappings": {
        "obligations": [],
        "iso42001": [],
        "nistAiRmf": [],
        "owasp": [],
        "atlas": [],
        "aiuc1": [
          "E016"
        ],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 28,
          "title": "Governing AI agents",
          "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"EU AI Act hooks for agents\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-agents#eu-ai-act-hooks-for-agents",
          "verified": "primary"
        },
        {
          "n": 8,
          "title": "AIUC-1 requirements",
          "text": "AIUC-1 requirements (public requirement index, A001 to F002, each requirement on its own page (E007 and E014 marked retired); AIUC-1 is a standard of the Artificial Intelligence Underwriting Company; this site is not affiliated with AIUC, and a mapping here is not an AIUC-1 certificate or audit). Artificial Intelligence Underwriting Company. 2026-09-24.",
          "url": "https://standard.aiuc-1.com/llms.txt",
          "verified": "primary"
        }
      ],
      "implementationNotes": [],
      "openQuestions": [
        "Verification procedure and evidence schema to be specified; requires technical review.",
        "Chapter 23 ties this control to the EU AI Act articles it names; the derivation carries obligations only through mapped OWASP Agentic threats, so the obligation mapping awaits review."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-DATA-001",
      "profile": "data-admission-and-privacy",
      "url": "https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-001",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-data-001.json",
      "title": "Dataset Admission Gate at Read Time",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "A training, fine-tuning, validation, testing, evaluation or retrieval-index job reads a dataset version only if a signed admission record for that version admits the job's pipeline for its use case and target system, and the rights, quality, representativeness, bias and integrity checks passed or were waived by someone entitled to waive them.",
      "failureModes": [
        "A job reads a dataset version that has no admission record for its pipeline, for example a training job pointed at a whole warehouse admitted for nothing.",
        "A model trains on data outside its consent scope, on a sample that misses the population it will serve, on labels nobody audited or on a snapshot someone altered, and the problem surfaces in production or in an audit, when the fix is a retrain.",
        "The person who wants the dataset used is the only person who decides it may be: the requester signs the admission, or a check is waived by someone not entitled to waive it.",
        "A missing admission field produces a reminder in a wiki instead of a failed run."
      ],
      "scope": "Every job that reads data to train, fine-tune, validate, test, evaluate or build a retrieval index, and the dataset versions it reads. The checks the gate runs are specified in AIGE-CTL-DATA-002 to 009; a sandbox pipeline with its own lighter admission is out of scope.",
      "enforcementPoints": [
        "runtime"
      ],
      "verification": [
        {
          "kind": "inspect",
          "text": "Each admission record validates against dataset-admission-record.v1 and carries what the pattern lists: subject, pipeline, target system, linked data card, decision, the checks with the obligation each enforces, the content hash of the admitted snapshot, the actor and a signature."
        },
        {
          "kind": "test",
          "text": "A job that presents a use-case id or a pipeline the record does not admit is denied the read."
        }
      ],
      "evidence": [
        {
          "artefact": "Admission record per dataset version and permitted pipeline, signed by the data owner",
          "schemaId": "dataset-admission-record",
          "schema": "https://aigovernanceengineer.com/schemas/dataset-admission-record.v1.json",
          "layer": 1
        },
        {
          "artefact": "Read-time verdicts of the gate: the use-case id presented and the admit or deny decision",
          "schemaId": null,
          "schema": null,
          "layer": 1
        }
      ],
      "failureResponse": {
        "effect": "deny",
        "text": "The policy denies the read unless the record admits that pipeline for that use; a job with no admitted dataset does not start. A new version, a new source, quality drift, a licence change, an erasure request or a new use case reopens admission."
      },
      "layer": 1,
      "secondaryLayers": [
        2
      ],
      "patterns": [
        {
          "slug": "dataset-admission-gate",
          "title": "Dataset Admission Gate",
          "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate"
        },
        {
          "slug": "policy-card",
          "title": "Policy Card",
          "url": "https://aigovernanceengineer.com/patterns/policy-card"
        }
      ],
      "seeds": [],
      "derivedFrom": [
        {
          "kind": "pattern",
          "ref": "dataset-admission-gate",
          "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate"
        },
        {
          "kind": "schema",
          "ref": "dataset-admission-record",
          "url": "https://aigovernanceengineer.com/resources/templates#schema-dataset-admission-record"
        },
        {
          "kind": "chapter",
          "ref": "governing-development",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        }
      ],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART10",
            "name": "EU AI Act Art. 10 data and data governance",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art10"
          },
          {
            "id": "AIGE-OBL-GDPR-ART5-1B",
            "name": "GDPR Art. 5(1)(b) and 6(4) purpose limitation",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art5-1b"
          },
          {
            "id": "AIGE-OBL-ISO42001-A7",
            "name": "A.7 Data for AI systems",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a7"
          }
        ],
        "iso42001": [
          {
            "id": "A.7.2",
            "title": "Data for development and enhancement of AI system"
          },
          {
            "id": "A.7.4",
            "title": "Quality of data for AI systems"
          },
          {
            "id": "A.7.5",
            "title": "Data provenance"
          }
        ],
        "nistAiRmf": [
          {
            "id": "MAP 2.3",
            "title": "Scientific integrity and TEVV considerations are identified and documented, including those related to experimental design, data collection and selection (e.g., availability, representativeness, suitability), system trustworthiness, and construct validation."
          },
          {
            "id": "MAP 4.1",
            "title": "Approaches for mapping AI technology and legal risks of its components – including the use of third-party data or software – are in place, followed, and documented, as are risks of infringement of a third party’s intellectual property or other rights."
          }
        ],
        "owasp": [
          {
            "id": "llm05-2026",
            "externalId": "LLM05:2026",
            "name": "Data and Model Poisoning",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-llm05-2026"
          }
        ],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 1,
          "title": "Dataset Admission Gate",
          "text": "Dataset Admission Gate (AI Governance Engineering Body of Knowledge v0.5.0, pattern catalogue (chapter 05): a job may read a dataset version only if a complete, signed admission record admits it for that use). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate",
          "verified": "primary"
        },
        {
          "n": 2,
          "title": "Governing AI development",
          "text": "Governing AI development (AI Governance Engineering Body of Knowledge v0.5.0, chapter 14, section \"Data for training and testing\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-development#data-for-training-and-testing",
          "verified": "primary"
        },
        {
          "n": 3,
          "title": "Governing AI development",
          "text": "Governing AI development (AI Governance Engineering Body of Knowledge v0.5.0, chapter 14, section \"Owners, stewards and the admission gate\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-development#owners-stewards-and-the-admission-gate",
          "verified": "primary"
        },
        {
          "n": 4,
          "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 10",
          "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 10 (data and data governance: 10(2) practices, including origin, preparation, bias examination and mitigation, and data gaps; 10(3) relevant, sufficiently representative, free of errors and complete; 10(4) specific setting of use). Publications Office of the EU (EUR-Lex). 2026-07-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_10",
          "verified": "primary"
        },
        {
          "n": 5,
          "title": "Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models",
          "text": "Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models (anonymity of models; legitimate interest; consequences of unlawful processing in development). European Data Protection Board. 2024-12.",
          "url": "https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-282024-on-certain-data-protection-aspects-related-to_en",
          "verified": "primary"
        },
        {
          "n": 6,
          "title": "OWASP GenAI LLM Top 10 2026",
          "text": "OWASP GenAI LLM Top 10 2026 (LLM01:2026 Prompt Injection to LLM10:2026 Improper Output Handling; resource page dated 3 Aug 2026). OWASP GenAI Security Project. 2026-08-03.",
          "url": "https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/",
          "verified": "primary"
        },
        {
          "n": 7,
          "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
          "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        },
        {
          "n": 8,
          "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1",
          "text": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (GOVERN 6.1 third-party risks incl. infringement of intellectual property or other rights; MAP 1.1 intended purposes documented; MAP 2.3 data collection and selection considerations identified and documented; MAP 3.3 targeted application scope; MAP 4.1 legal risks of components incl. third-party data; MEASURE 2.10 privacy risk examined and documented; MANAGE 1.4 negative residual risks to downstream acquirers and end users documented). NIST. 2023-01-26.",
          "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Write one admission record per dataset version and per permitted pipeline on the published dataset-admission-record schema, and make every data-reading job present its use-case id and target system at read time; the check is policy-as-code in the pipeline, not a reminder in a wiki.",
        "Separate the duties: the data owner is accountable and signs, the data steward operates the checks, and a small review board settles contested admissions. The minimum checklist lives as code, so adding a check is a reviewed change.",
        "Give waivers an owner and an expiry, or they become the norm; record conditions on the admission record (for example \"collect islands-region claims before the next retrain\") so the next retrain cannot start until they are closed."
      ],
      "openQuestions": [
        "What lighter admission should a sandbox pipeline for exploratory work carry, and how is data kept from leaving the sandbox into a training job?",
        "Which enforcement point fits a gate that decides at read time inside a data pipeline: the platform's access layer, the job scheduler or the storage policy engine?"
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-DATA-002",
      "profile": "data-admission-and-privacy",
      "url": "https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-002",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-data-002.json",
      "title": "Dataset Card for Every Admitted Version",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "Every dataset version that is admitted carries a dataset card that states its owner, purpose, provenance, lawful basis, licence and retention rule, and the admission gate checks the card is complete before it admits the version.",
      "failureModes": [
        "A dataset is admitted with a card that lacks a lawful basis, a provenance, a retention limit or a licence, so the rights and the deletion date cannot be read from it.",
        "The card describes a previous version: its composition, representativeness or quality checks no longer match the snapshot that was admitted.",
        "The card is written from memory after training instead of filled from the admission record and lineage."
      ],
      "scope": "Datasets admitted to training, fine-tuning, validation, testing, evaluation or retrieval-index pipelines, one card per version. The model card and the system card, which describe what was built from the data, are out of scope.",
      "enforcementPoints": [
        "deploy"
      ],
      "verification": [
        {
          "kind": "inspect",
          "text": "The card of each admitted version validates against dataset-card.v1 (dataset id, version, name, owner, description, provenance, lawful basis, licence and retention rule), and the admission record links to it."
        }
      ],
      "evidence": [
        {
          "artefact": "Dataset card per admitted version",
          "schemaId": "dataset-card",
          "schema": "https://aigovernanceengineer.com/schemas/dataset-card.v1.json",
          "layer": 2
        },
        {
          "artefact": "Card-completeness check on the admission record",
          "schemaId": "dataset-admission-record",
          "schema": "https://aigovernanceengineer.com/schemas/dataset-admission-record.v1.json",
          "layer": 1
        }
      ],
      "failureResponse": {
        "effect": "deny",
        "text": "A version whose card is missing or incomplete is not admitted; the admission record names the card that was checked."
      },
      "layer": 2,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "dataset-admission-gate",
          "title": "Dataset Admission Gate",
          "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate"
        },
        {
          "slug": "model-card-as-control-evidence",
          "title": "Model Card as Control Evidence",
          "url": "https://aigovernanceengineer.com/patterns/model-card-as-control-evidence"
        }
      ],
      "seeds": [],
      "derivedFrom": [
        {
          "kind": "schema",
          "ref": "dataset-card",
          "url": "https://aigovernanceengineer.com/resources/templates#schema-dataset-card"
        },
        {
          "kind": "pattern",
          "ref": "dataset-admission-gate",
          "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate"
        },
        {
          "kind": "chapter",
          "ref": "governing-development",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        }
      ],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART10",
            "name": "EU AI Act Art. 10 data and data governance",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art10"
          },
          {
            "id": "AIGE-OBL-ISO42001-A7",
            "name": "A.7 Data for AI systems",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a7"
          }
        ],
        "iso42001": [
          {
            "id": "A.7.2",
            "title": "Data for development and enhancement of AI system"
          },
          {
            "id": "A.7.5",
            "title": "Data provenance"
          }
        ],
        "nistAiRmf": [
          {
            "id": "MAP 2.3",
            "title": "Scientific integrity and TEVV considerations are identified and documented, including those related to experimental design, data collection and selection (e.g., availability, representativeness, suitability), system trustworthiness, and construct validation."
          }
        ],
        "owasp": [],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 2,
          "title": "Governing AI development",
          "text": "Governing AI development (AI Governance Engineering Body of Knowledge v0.5.0, chapter 14, section \"Data for training and testing\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-development#data-for-training-and-testing",
          "verified": "primary"
        },
        {
          "n": 9,
          "title": "Governing AI development",
          "text": "Governing AI development (AI Governance Engineering Body of Knowledge v0.5.0, chapter 14, section \"Model cards, system cards and datasheets\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-development#model-cards-system-cards-and-datasheets",
          "verified": "primary"
        },
        {
          "n": 1,
          "title": "Dataset Admission Gate",
          "text": "Dataset Admission Gate (AI Governance Engineering Body of Knowledge v0.5.0, pattern catalogue (chapter 05): a job may read a dataset version only if a complete, signed admission record admits it for that use). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate",
          "verified": "primary"
        },
        {
          "n": 10,
          "title": "Datasheets for Datasets (Gebru et al.; arXiv 1803.09010)",
          "text": "Datasheets for Datasets (Gebru et al.; arXiv 1803.09010) (motivation, composition, collection, preprocessing, uses, distribution and maintenance). arXiv. 2018-03-23.",
          "url": "https://arxiv.org/abs/1803.09010",
          "verified": "primary"
        },
        {
          "n": 4,
          "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 10",
          "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 10 (data and data governance: 10(2) practices, including origin, preparation, bias examination and mitigation, and data gaps; 10(3) relevant, sufficiently representative, free of errors and complete; 10(4) specific setting of use). Publications Office of the EU (EUR-Lex). 2026-07-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_10",
          "verified": "primary"
        },
        {
          "n": 7,
          "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
          "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        },
        {
          "n": 8,
          "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1",
          "text": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (GOVERN 6.1 third-party risks incl. infringement of intellectual property or other rights; MAP 1.1 intended purposes documented; MAP 2.3 data collection and selection considerations identified and documented; MAP 3.3 targeted application scope; MAP 4.1 legal risks of components incl. third-party data; MEASURE 2.10 privacy risk examined and documented; MANAGE 1.4 negative residual risks to downstream acquirers and end users documented). NIST. 2023-01-26.",
          "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Fill the card from the same records the gate reads (the admission record and lineage), so the datasheet travels with the admission record and covers motivation, composition, collection, preprocessing, uses, distribution and maintenance.",
        "Record in the card who the data does and does not represent (populations and known gaps) and the quality and bias checks run against this version, with their results."
      ],
      "openQuestions": [
        "Which optional card fields (composition, representativeness, quality checks, splits) should become mandatory for data admitted to a high-risk system?"
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-DATA-003",
      "profile": "data-admission-and-privacy",
      "url": "https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-003",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-data-003.json",
      "title": "Training-Data Rights Ledger Row per Source",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "Every training source has a ledger row, per source and not per merged dataset, that records its acquisition channel, licensor, licence terms for training, commercial use and distribution of derived models, the legal basis where the data is personal, the permitted uses and, for crawled content, the rights-reservation check with its method, result and date.",
      "failureModes": [
        "Nobody can say which sources trained which model version, or on what terms.",
        "A single unlicensed or unlawfully obtained source contaminates every model trained on it, and without per-source lineage the only safe response is to delete everything.",
        "Crawled content is used although the rightholder reserved its rights by machine-readable means, because the reservation check was not run, was not recorded or is stale."
      ],
      "scope": "Every source a provider trains or fine-tunes on: internal data, licensed corpora, open datasets, crawled web content and user data. The ledger records the organisation's position; it does not settle open legal questions.",
      "enforcementPoints": [
        "deploy"
      ],
      "verification": [
        {
          "kind": "test",
          "text": "The corpus build and the dataset admission gate fail on a source with no ledger row, on a source whose terms do not permit the declared use and on a source whose reservation check is missing or stale."
        }
      ],
      "evidence": [
        {
          "artefact": "Ledger row per source and version, with the reservation-check method, result and date for crawled content",
          "schemaId": null,
          "schema": null,
          "layer": 2
        },
        {
          "artefact": "Licence on the dataset card: name, whether training is allowed, whether text-and-data-mining reservations were checked",
          "schemaId": "dataset-card",
          "schema": "https://aigovernanceengineer.com/schemas/dataset-card.v1.json",
          "layer": 2
        },
        {
          "artefact": "Ledger check (rows present) on the admission record",
          "schemaId": "dataset-admission-record",
          "schema": "https://aigovernanceengineer.com/schemas/dataset-admission-record.v1.json",
          "layer": 1
        }
      ],
      "failureResponse": {
        "effect": "deny",
        "text": "A source with no row, with terms that do not permit the declared use or with a missing or stale reservation check fails the corpus build and admission."
      },
      "layer": 2,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "training-data-rights-ledger",
          "title": "Training-Data Rights Ledger",
          "url": "https://aigovernanceengineer.com/patterns/training-data-rights-ledger"
        },
        {
          "slug": "dataset-admission-gate",
          "title": "Dataset Admission Gate",
          "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate"
        },
        {
          "slug": "aibom",
          "title": "AIBOM",
          "url": "https://aigovernanceengineer.com/patterns/aibom"
        }
      ],
      "seeds": [],
      "derivedFrom": [
        {
          "kind": "pattern",
          "ref": "training-data-rights-ledger",
          "url": "https://aigovernanceengineer.com/patterns/training-data-rights-ledger"
        },
        {
          "kind": "schema",
          "ref": "dataset-card",
          "url": "https://aigovernanceengineer.com/resources/templates#schema-dataset-card"
        },
        {
          "kind": "chapter",
          "ref": "governing-development",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        }
      ],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART10",
            "name": "EU AI Act Art. 10 data and data governance",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art10"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART53-1C",
            "name": "EU AI Act Art. 53(1)(c) copyright policy honouring text-and-data-mining reservations",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art53-1c"
          },
          {
            "id": "AIGE-OBL-DSM-ART4-3",
            "name": "DSM Directive Art. 4(3) text-and-data-mining reservations",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-dsm-art4-3"
          },
          {
            "id": "AIGE-OBL-GDPR-ART5-1B",
            "name": "GDPR Art. 5(1)(b) and 6(4) purpose limitation",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art5-1b"
          }
        ],
        "iso42001": [
          {
            "id": "A.7.5",
            "title": "Data provenance"
          }
        ],
        "nistAiRmf": [
          {
            "id": "GOVERN 6.1",
            "title": "Policies and procedures are in place that address AI risks associated with third-party entities, including risks of infringement of a third-party’s intellectual property or other rights."
          },
          {
            "id": "MAP 4.1",
            "title": "Approaches for mapping AI technology and legal risks of its components – including the use of third-party data or software – are in place, followed, and documented, as are risks of infringement of a third party’s intellectual property or other rights."
          }
        ],
        "owasp": [],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 11,
          "title": "Training-Data Rights Ledger",
          "text": "Training-Data Rights Ledger (AI Governance Engineering Body of Knowledge v0.5.0, pattern catalogue (chapter 05): one ledger row per training source, joined to lineage so each model knows its sources). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/patterns/training-data-rights-ledger",
          "verified": "primary"
        },
        {
          "n": 12,
          "title": "Governing AI development",
          "text": "Governing AI development (AI Governance Engineering Body of Knowledge v0.5.0, chapter 14, section \"The right to use the data\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-development#the-right-to-use-the-data",
          "verified": "primary"
        },
        {
          "n": 13,
          "title": "Directive (EU) 2019/790 on copyright in the Digital Single Market, Art. 4",
          "text": "Directive (EU) 2019/790 on copyright in the Digital Single Market, Art. 4 (text and data mining exception; 4(3) reservation of rights by machine-readable means for content made publicly available online). Publications Office of the EU (EUR-Lex). 2019-05-17.",
          "url": "https://eur-lex.europa.eu/eli/dir/2019/790/oj/eng",
          "verified": "primary"
        },
        {
          "n": 14,
          "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 53",
          "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 53 (GPAI provider obligations: (c) copyright policy including reservations of rights; (d) public summary of training content on the AI Office template). Publications Office of the EU (EUR-Lex). 2026-07-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_53",
          "verified": "primary"
        },
        {
          "n": 4,
          "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 10",
          "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 10 (data and data governance: 10(2) practices, including origin, preparation, bias examination and mitigation, and data gaps; 10(3) relevant, sufficiently representative, free of errors and complete; 10(4) specific setting of use). Publications Office of the EU (EUR-Lex). 2026-07-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_10",
          "verified": "primary"
        },
        {
          "n": 15,
          "title": "In the Matter of Everalbum, Inc., Decision and Order",
          "text": "In the Matter of Everalbum, Inc., Decision and Order (\"Affected Work Product\": models or algorithms developed using users' biometric information, to be deleted within 90 days with a sworn statement). Federal Trade Commission. 2021-05-07.",
          "url": "https://www.ftc.gov/system/files/documents/cases/1923172_-_everalbum_decision_final.pdf",
          "verified": "primary"
        },
        {
          "n": 7,
          "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
          "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        },
        {
          "n": 8,
          "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1",
          "text": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (GOVERN 6.1 third-party risks incl. infringement of intellectual property or other rights; MAP 1.1 intended purposes documented; MAP 2.3 data collection and selection considerations identified and documented; MAP 3.3 targeted application scope; MAP 4.1 legal risks of components incl. third-party data; MEASURE 2.10 privacy risk examined and documented; MANAGE 1.4 negative residual risks to downstream acquirers and end users documented). NIST. 2023-01-26.",
          "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "For crawled content, record the crawler identity, the window and the reservation check: the method (for example robots.txt and page metadata read at fetch time), the result and the date. The crawl pipeline should write rows itself, since a row per source is real work for large crawls.",
        "Put the licence in the AIBOM as well, so a licence change surfaces in the next build.",
        "Generate the disclosures (the GPAI training-content summary under Art. 53(1)(d) and similar training-data documentation) as queries over the ledger, not as documents written from memory."
      ],
      "openQuestions": [
        "How fresh must a reservation check be before the gate treats it as stale, and should it be re-run at every corpus build?",
        "At what granularity should rows be kept when rights attach per record (opt-outs, per-record licences) rather than per source?"
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-DATA-004",
      "profile": "data-admission-and-privacy",
      "url": "https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-004",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-data-004.json",
      "title": "Lawful Basis and Assessment per Processing Stage",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "Each dataset carries, for each processing stage (training, fine-tuning, retrieval, inference, log monitoring), its lawful basis, its purpose and a pointer to the assessment behind it, and processing likely to result in a high risk has a versioned DPIA or a recorded decision that none was needed.",
      "failureModes": [
        "One basis is picked for \"the model\", although training, indexing and answering a live customer are different activities that each need their own basis.",
        "A training job runs on a dataset whose recorded basis does not cover training, or on data whose basis was never recorded.",
        "A legitimate-interest assessment points at mitigations that have been switched off, and the registry does not show that it went stale.",
        "No DPIA exists and no decision that one was not needed was recorded."
      ],
      "scope": "Personal data in datasets used for training, fine-tuning and retrieval, and the stages that process it. Transfers, automated decision-making and the rights path are outside this control; the fundamental rights impact assessment, which complements the DPIA rather than repeating it, is left to the FRIA-as-Code pattern.",
      "enforcementPoints": [
        "runtime",
        "periodic"
      ],
      "verification": [
        {
          "kind": "test",
          "text": "The training job reads the basis registry before it runs and refuses to run on a dataset whose basis does not cover training."
        }
      ],
      "evidence": [
        {
          "artefact": "Lawful basis for this purpose on the dataset card",
          "schemaId": "dataset-card",
          "schema": "https://aigovernanceengineer.com/schemas/dataset-card.v1.json",
          "layer": 2
        },
        {
          "artefact": "Basis registry entry per dataset and stage, with the reference of its assessment (for example a versioned LIA)",
          "schemaId": null,
          "schema": null,
          "layer": 2
        },
        {
          "artefact": "Versioned AI DPIA addendum, or the recorded decision that no DPIA was needed",
          "schemaId": "impact-assessment",
          "schema": "https://aigovernanceengineer.com/schemas/impact-assessment.v1.json",
          "layer": 2
        }
      ],
      "failureResponse": {
        "effect": "deny",
        "text": "The job refuses to run on a dataset whose basis does not cover the stage. Where the DPIA shows high residual risk, the controller consults the supervisory authority before the processing."
      },
      "layer": 2,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "dataset-admission-gate",
          "title": "Dataset Admission Gate",
          "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate"
        },
        {
          "slug": "training-data-rights-ledger",
          "title": "Training-Data Rights Ledger",
          "url": "https://aigovernanceengineer.com/patterns/training-data-rights-ledger"
        },
        {
          "slug": "fria-as-code",
          "title": "FRIA-as-Code",
          "url": "https://aigovernanceengineer.com/patterns/fria-as-code"
        }
      ],
      "seeds": [],
      "derivedFrom": [
        {
          "kind": "schema",
          "ref": "dataset-card",
          "url": "https://aigovernanceengineer.com/resources/templates#schema-dataset-card"
        },
        {
          "kind": "schema",
          "ref": "impact-assessment",
          "url": "https://aigovernanceengineer.com/resources/templates#schema-impact-assessment"
        },
        {
          "kind": "chapter",
          "ref": "privacy-and-ai",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai"
        }
      ],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-GDPR-ART6",
            "name": "GDPR Art. 6 lawful basis per processing moment",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art6"
          },
          {
            "id": "AIGE-OBL-GDPR-ART35-36",
            "name": "GDPR Arts. 35–36 DPIA and prior consultation",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art35-36"
          }
        ],
        "iso42001": [],
        "nistAiRmf": [
          {
            "id": "MEASURE 2.10",
            "title": "Privacy risk of the AI system – as identified in the MAP function – is examined and documented."
          }
        ],
        "owasp": [],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 16,
          "title": "Privacy and data protection law applied to AI",
          "text": "Privacy and data protection law applied to AI (AI Governance Engineering Body of Knowledge v0.5.0, chapter 19, section \"Lawful basis for training versus inference\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai#lawful-basis-for-training-versus-inference",
          "verified": "primary"
        },
        {
          "n": 17,
          "title": "Privacy and data protection law applied to AI",
          "text": "Privacy and data protection law applied to AI (AI Governance Engineering Body of Knowledge v0.5.0, chapter 19, section \"The DPIA for AI systems\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai#the-dpia-for-ai-systems",
          "verified": "primary"
        },
        {
          "n": 12,
          "title": "Governing AI development",
          "text": "Governing AI development (AI Governance Engineering Body of Knowledge v0.5.0, chapter 14, section \"The right to use the data\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-development#the-right-to-use-the-data",
          "verified": "primary"
        },
        {
          "n": 18,
          "title": "Regulation (EU) 2016/679 (GDPR)",
          "text": "Regulation (EU) 2016/679 (GDPR) (Art. 5 principles, incl. 5(1)(b) purpose limitation and 5(1)(c) minimisation; Art. 6 lawful basis and 6(4) compatibility; Art. 7 consent; Art. 9 special categories; Arts. 15 to 17 and 21 rights; Art. 25 data protection by design and by default; Art. 30 records of processing; Arts. 35 and 36 DPIA and prior consultation). Publications Office of the EU (EUR-Lex). 2016-04-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng",
          "verified": "primary"
        },
        {
          "n": 5,
          "title": "Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models",
          "text": "Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models (anonymity of models; legitimate interest; consequences of unlawful processing in development). European Data Protection Board. 2024-12.",
          "url": "https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-282024-on-certain-data-protection-aspects-related-to_en",
          "verified": "primary"
        },
        {
          "n": 8,
          "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1",
          "text": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (GOVERN 6.1 third-party risks incl. infringement of intellectual property or other rights; MAP 1.1 intended purposes documented; MAP 2.3 data collection and selection considerations identified and documented; MAP 3.3 targeted application scope; MAP 4.1 legal risks of components incl. third-party data; MEASURE 2.10 privacy risk examined and documented; MANAGE 1.4 negative residual risks to downstream acquirers and end users documented). NIST. 2023-01-26.",
          "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Keep the basis registry attached to the system's registry entry: each dataset and stage carries its basis, purpose and a pointer to the assessment behind it, and the training job reads it.",
        "Make the legitimate-interest assessment a versioned artefact that points each mitigation at the control implementing it (the opt-out endpoint, the filter rule id, the scraping allow-list); switch a mitigation off and the LIA goes stale.",
        "Generate most of the AI DPIA from the registry: processing moments from the registry, bases from the basis registry, with the DPO still writing and signing the risk judgement. The impact-assessment schema carries a dpia_addendum type for the AI-specific fields."
      ],
      "openQuestions": [
        "Should the admission gate itself refuse a dataset whose stage has no DPIA and no recorded \"no DPIA\" decision, or is that a periodic check over the registry?"
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-DATA-005",
      "profile": "data-admission-and-privacy",
      "url": "https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-005",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-data-005.json",
      "title": "Purpose Match Before Reuse of Data",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "A run that reads a dataset is denied when the purpose on the dataset's card differs from the purpose declared by the consuming system and no compatibility assessment is recorded.",
      "failureModes": [
        "Data is reused for a purpose incompatible with the one it was collected for: support transcripts reused to profile customers for sales, security footage reused for attendance, fraud features reused for credit limits.",
        "Consent to a service is treated as consent to train a model on the service's data.",
        "A purpose mismatch is caught by nobody because the purpose travels in a document, not as a tag on the data a rule can read."
      ],
      "scope": "Personal data further processed for training, fine-tuning or indexing by a system other than, or for a purpose other than, the one it was collected for.",
      "enforcementPoints": [
        "runtime"
      ],
      "verification": [
        {
          "kind": "test",
          "text": "A run whose declared purpose differs from the purpose on the dataset's card, with no compatibility assessment recorded, is denied, and the denial is filed against the dataset's registry entry."
        }
      ],
      "evidence": [
        {
          "artefact": "Purpose-match verdict per run",
          "schemaId": null,
          "schema": null,
          "layer": 1
        },
        {
          "artefact": "Compatibility and use-case checks on the admission record",
          "schemaId": "dataset-admission-record",
          "schema": "https://aigovernanceengineer.com/schemas/dataset-admission-record.v1.json",
          "layer": 1
        },
        {
          "artefact": "Art. 6(4) compatibility assessment filed against the dataset",
          "schemaId": null,
          "schema": null,
          "layer": 2
        }
      ],
      "failureResponse": {
        "effect": "deny",
        "text": "The run is denied; the request becomes an Art. 6(4) compatibility assessment, and the denied run and the assessment are both filed against the dataset's registry entry."
      },
      "layer": 1,
      "secondaryLayers": [
        2
      ],
      "patterns": [
        {
          "slug": "dataset-admission-gate",
          "title": "Dataset Admission Gate",
          "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate"
        },
        {
          "slug": "training-data-rights-ledger",
          "title": "Training-Data Rights Ledger",
          "url": "https://aigovernanceengineer.com/patterns/training-data-rights-ledger"
        },
        {
          "slug": "policy-card",
          "title": "Policy Card",
          "url": "https://aigovernanceengineer.com/patterns/policy-card"
        }
      ],
      "seeds": [],
      "derivedFrom": [
        {
          "kind": "pattern",
          "ref": "dataset-admission-gate",
          "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate"
        },
        {
          "kind": "schema",
          "ref": "dataset-admission-record",
          "url": "https://aigovernanceengineer.com/resources/templates#schema-dataset-admission-record"
        },
        {
          "kind": "chapter",
          "ref": "privacy-and-ai",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai"
        }
      ],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-GDPR-ART5-1B",
            "name": "GDPR Art. 5(1)(b) and 6(4) purpose limitation",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art5-1b"
          }
        ],
        "iso42001": [],
        "nistAiRmf": [],
        "owasp": [],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 19,
          "title": "Privacy and data protection law applied to AI",
          "text": "Privacy and data protection law applied to AI (AI Governance Engineering Body of Knowledge v0.5.0, chapter 19, section \"Purpose limitation and function creep\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai#purpose-limitation-and-function-creep",
          "verified": "primary"
        },
        {
          "n": 12,
          "title": "Governing AI development",
          "text": "Governing AI development (AI Governance Engineering Body of Knowledge v0.5.0, chapter 14, section \"The right to use the data\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-development#the-right-to-use-the-data",
          "verified": "primary"
        },
        {
          "n": 1,
          "title": "Dataset Admission Gate",
          "text": "Dataset Admission Gate (AI Governance Engineering Body of Knowledge v0.5.0, pattern catalogue (chapter 05): a job may read a dataset version only if a complete, signed admission record admits it for that use). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate",
          "verified": "primary"
        },
        {
          "n": 18,
          "title": "Regulation (EU) 2016/679 (GDPR)",
          "text": "Regulation (EU) 2016/679 (GDPR) (Art. 5 principles, incl. 5(1)(b) purpose limitation and 5(1)(c) minimisation; Art. 6 lawful basis and 6(4) compatibility; Art. 7 consent; Art. 9 special categories; Arts. 15 to 17 and 21 rights; Art. 25 data protection by design and by default; Art. 30 records of processing; Arts. 35 and 36 DPIA and prior consultation). Publications Office of the EU (EUR-Lex). 2016-04-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Use a purpose tag that travels with the data and a layer 01 rule that compares it with the purpose declared by the consuming system; a denied join is proof the purpose limit bit.",
        "The Art. 6(4) test weighs the link between purposes, the context, the nature of the data, the consequences and the safeguards, such as encryption or pseudonymisation; record the outcome, including a partial one (for example \"aggregated topic counts only\")."
      ],
      "openQuestions": [
        "How should purposes be named so that a rule can compare them: a controlled vocabulary per organisation, or the use-case ids of the registry?"
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-DATA-006",
      "profile": "data-admission-and-privacy",
      "url": "https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-006",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-data-006.json",
      "title": "Personal Data Screening and Minimisation",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "Personal and special-category data are screened on each snapshot before training, the filter log is kept with the snapshot, each input feature carries a reason and a measured contribution, and retention follows a rule enforced in code.",
      "failureModes": [
        "A snapshot enters training without a PII or special-category scan, or the scan ran and its log was not kept.",
        "Features with no reason and no measured contribution stay in the data, so minimisation is asserted once instead of argued feature by feature.",
        "Special-category fields are used with no documented condition.",
        "Retention follows the storage default rather than the obligation, and data is kept past its deletion date."
      ],
      "scope": "Snapshots and features admitted to training, fine-tuning, evaluation and retrieval pipelines, and their retention. Retrieval indexes and logs are covered for minimisation only; anonymity claims about trained models are outside this control.",
      "enforcementPoints": [
        "deploy",
        "periodic"
      ],
      "verification": [
        {
          "kind": "inspect",
          "text": "Each admitted snapshot has the log of the PII and special-category scan run on it, and its card records a retention rule as enforced in code."
        }
      ],
      "evidence": [
        {
          "artefact": "PII and special-category filter log kept with each snapshot",
          "schemaId": null,
          "schema": null,
          "layer": 1
        },
        {
          "artefact": "Personal-data flag and retention rule on the dataset card",
          "schemaId": "dataset-card",
          "schema": "https://aigovernanceengineer.com/schemas/dataset-card.v1.json",
          "layer": 2
        },
        {
          "artefact": "Retention-set check on the admission record",
          "schemaId": "dataset-admission-record",
          "schema": "https://aigovernanceengineer.com/schemas/dataset-admission-record.v1.json",
          "layer": 1
        }
      ],
      "failureResponse": {
        "effect": "deny",
        "text": "A snapshot with no scan log does not enter training; a feature with neither a reason nor a measured contribution is removed, and a special-category field needs a documented condition before it stays."
      },
      "layer": 1,
      "secondaryLayers": [
        3
      ],
      "patterns": [
        {
          "slug": "dataset-admission-gate",
          "title": "Dataset Admission Gate",
          "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate"
        }
      ],
      "seeds": [],
      "derivedFrom": [
        {
          "kind": "schema",
          "ref": "dataset-card",
          "url": "https://aigovernanceengineer.com/resources/templates#schema-dataset-card"
        },
        {
          "kind": "pattern",
          "ref": "dataset-admission-gate",
          "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate"
        },
        {
          "kind": "chapter",
          "ref": "privacy-and-ai",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai"
        }
      ],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-GDPR-ART25",
            "name": "GDPR Art. 5(1)(c) and 25 minimisation and data protection by design and by default",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art25"
          }
        ],
        "iso42001": [],
        "nistAiRmf": [],
        "owasp": [],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 20,
          "title": "Privacy and data protection law applied to AI",
          "text": "Privacy and data protection law applied to AI (AI Governance Engineering Body of Knowledge v0.5.0, chapter 19, section \"Minimisation, privacy by design and PETs\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai#minimisation-privacy-by-design-and-pets",
          "verified": "primary"
        },
        {
          "n": 21,
          "title": "Privacy and data protection law applied to AI",
          "text": "Privacy and data protection law applied to AI (AI Governance Engineering Body of Knowledge v0.5.0, chapter 19, section \"Obligation to artefact map\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai#obligation-to-artefact-map",
          "verified": "primary"
        },
        {
          "n": 18,
          "title": "Regulation (EU) 2016/679 (GDPR)",
          "text": "Regulation (EU) 2016/679 (GDPR) (Art. 5 principles, incl. 5(1)(b) purpose limitation and 5(1)(c) minimisation; Art. 6 lawful basis and 6(4) compatibility; Art. 7 consent; Art. 9 special categories; Arts. 15 to 17 and 21 rights; Art. 25 data protection by design and by default; Art. 30 records of processing; Arts. 35 and 36 DPIA and prior consultation). Publications Office of the EU (EUR-Lex). 2016-04-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng",
          "verified": "primary"
        },
        {
          "n": 5,
          "title": "Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models",
          "text": "Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models (anonymity of models; legitimate interest; consequences of unlawful processing in development). European Data Protection Board. 2024-12.",
          "url": "https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-282024-on-certain-data-protection-aspects-related-to_en",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Argue minimisation feature by feature in the data card; the EDPB lists source selection, preparation and filtering among the areas an authority examines.",
        "Hold only the fields answers need in retrieval indexes, and use synthetic or masked eval sets wherever a test does not depend on real identities.",
        "Treat a synthetic set as a dataset with its own admission record naming the generator, the seed data and the privacy method: synthetic data inherits the biases, gaps and, where the generator memorised, the source records of its generator."
      ],
      "openQuestions": [
        "What detection rate should a PII or special-category scan reach before its \"pass\" is accepted as evidence, and how is that rate measured?"
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-DATA-007",
      "profile": "data-admission-and-privacy",
      "url": "https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-007",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-data-007.json",
      "title": "Special-Category Data Conditions",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "Special-category data in a dataset is recorded with the Art. 9(2) condition relied on, and when it is processed for bias detection and correction under Art. 4a it is used only where other data would not do, pseudonymised, access-controlled, not transmitted onwards and deleted once the bias is corrected or its retention period ends, whichever comes first, with the records of processing stating why it was strictly necessary.",
      "failureModes": [
        "Special-category data is present in a dataset whose card says it is not, or with no condition recorded.",
        "Data admitted for bias detection is kept after the bias was corrected, used for another purpose or passed on.",
        "The records of processing do not say why special-category data was strictly necessary and why other data, including synthetic or anonymised data, would not do."
      ],
      "scope": "Datasets that contain special-category personal data, including data processed only to detect and correct bias. Sensitive data a model infers at runtime is covered by the proxy test and inference policy of chapter 19, not here.",
      "enforcementPoints": [
        "deploy",
        "periodic"
      ],
      "verification": [
        {
          "kind": "inspect",
          "text": "For each dataset processed under Art. 4a, the records of processing hold the strictly-necessary reason and a deletion log shows the data deleted once the bias was corrected or its retention period ended, whichever came first."
        }
      ],
      "evidence": [
        {
          "artefact": "Special-category block on the dataset card: presence, condition relied on, and whether it is processed only for bias detection",
          "schemaId": "dataset-card",
          "schema": "https://aigovernanceengineer.com/schemas/dataset-card.v1.json",
          "layer": 2
        },
        {
          "artefact": "Records-of-processing entry with the Art. 4a reason",
          "schemaId": null,
          "schema": null,
          "layer": 2
        },
        {
          "artefact": "Deletion log of the pseudonymised bias set",
          "schemaId": null,
          "schema": null,
          "layer": 1
        }
      ],
      "failureResponse": {
        "effect": "deny",
        "text": "A dataset with special-category data and no recorded condition is not admitted; an Art. 4a bias set without pseudonymisation or a deletion rule is not admitted for bias detection."
      },
      "layer": 1,
      "secondaryLayers": [
        2
      ],
      "patterns": [
        {
          "slug": "dataset-admission-gate",
          "title": "Dataset Admission Gate",
          "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate"
        },
        {
          "slug": "fairness-eval-suite",
          "title": "Fairness Eval Suite",
          "url": "https://aigovernanceengineer.com/patterns/fairness-eval-suite"
        }
      ],
      "seeds": [],
      "derivedFrom": [
        {
          "kind": "schema",
          "ref": "dataset-card",
          "url": "https://aigovernanceengineer.com/resources/templates#schema-dataset-card"
        },
        {
          "kind": "pattern",
          "ref": "dataset-admission-gate",
          "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate"
        },
        {
          "kind": "chapter",
          "ref": "privacy-and-ai",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai"
        }
      ],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-GDPR-ART9",
            "name": "GDPR Art. 9 special categories, incl. inferred sensitive data",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art9"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART4A",
            "name": "EU AI Act Art. 4a lawful basis for special-category data in bias detection",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art4a"
          },
          {
            "id": "AIGE-OBL-GDPR-ART30",
            "name": "GDPR Art. 30 records of processing activities",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art30"
          }
        ],
        "iso42001": [],
        "nistAiRmf": [],
        "owasp": [],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 22,
          "title": "Privacy and data protection law applied to AI",
          "text": "Privacy and data protection law applied to AI (AI Governance Engineering Body of Knowledge v0.5.0, chapter 19, section \"Special categories, inferred data and biometrics\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai#special-categories-inferred-data-and-biometrics",
          "verified": "primary"
        },
        {
          "n": 23,
          "title": "Privacy and data protection law applied to AI",
          "text": "Privacy and data protection law applied to AI (AI Governance Engineering Body of Knowledge v0.5.0, chapter 19, section \"Records of processing\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai#records-of-processing",
          "verified": "primary"
        },
        {
          "n": 12,
          "title": "Governing AI development",
          "text": "Governing AI development (AI Governance Engineering Body of Knowledge v0.5.0, chapter 14, section \"The right to use the data\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-development#the-right-to-use-the-data",
          "verified": "primary"
        },
        {
          "n": 1,
          "title": "Dataset Admission Gate",
          "text": "Dataset Admission Gate (AI Governance Engineering Body of Knowledge v0.5.0, pattern catalogue (chapter 05): a job may read a dataset version only if a complete, signed admission record admits it for that use). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate",
          "verified": "primary"
        },
        {
          "n": 24,
          "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Arts. 4a and 10",
          "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Arts. 4a and 10 (as amended by Reg. (EU) 2026/1744: Art. 10(5) deleted; Art. 4a inserted for special-category data in bias detection and correction). Publications Office of the EU (EUR-Lex). 2026-07-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_4a",
          "verified": "primary"
        },
        {
          "n": 18,
          "title": "Regulation (EU) 2016/679 (GDPR)",
          "text": "Regulation (EU) 2016/679 (GDPR) (Art. 5 principles, incl. 5(1)(b) purpose limitation and 5(1)(c) minimisation; Art. 6 lawful basis and 6(4) compatibility; Art. 7 consent; Art. 9 special categories; Arts. 15 to 17 and 21 rights; Art. 25 data protection by design and by default; Art. 30 records of processing; Arts. 35 and 36 DPIA and prior consultation). Publications Office of the EU (EUR-Lex). 2016-04-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "After the Digital Omnibus (Regulation (EU) 2026/1744, in force 27 July 2026), the narrow basis to process special-category data for bias detection sits in Art. 4a; Art. 10(5) was deleted, so a card that still names Art. 10(5) points at a basis that no longer exists.",
        "Generate the records-of-processing entries from the registry, the data cards and the basis registry, so the Art. 4a reason does not go stale with the next pipeline change."
      ],
      "openQuestions": [
        "What evidence shows that other data, including synthetic or anonymised data, would not have done for a given bias examination?"
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-DATA-008",
      "profile": "data-admission-and-privacy",
      "url": "https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-008",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-data-008.json",
      "title": "Fitness-for-Purpose Checks Before Admission",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "Before a dataset version is admitted, its quality (label accuracy, completeness, consistency, timeliness), its quantity per class and per group, its representativeness against the deployment population and a proxy and bias examination are checked and recorded, each passing or waived in writing by someone entitled to waive it.",
      "failureModes": [
        "A dataset large enough but drawn from the wrong population is admitted: quantity is taken for representativeness.",
        "A group falls below the minimum cell size in the test plan and nobody records it.",
        "No bias examination is recorded, or a failed check is waived with no signer, no condition and no expiry.",
        "The data measures a proxy rather than what the use case needs, and the assumption is never written down."
      ],
      "scope": "Training, validation and testing datasets for high-risk systems, where Art. 10 applies, and any dataset admitted under the organisation's own policy. Fairness testing of the trained model is covered by the Fairness Eval Suite pattern, not here.",
      "enforcementPoints": [
        "deploy"
      ],
      "verification": [
        {
          "kind": "inspect",
          "text": "The admission record holds a result for each quality, quantity, representativeness and bias check, with the obligation it enforces; every waived check names a waiver signed by the data owner and every condition is listed."
        }
      ],
      "evidence": [
        {
          "artefact": "Quality, representativeness and bias check results on the admission record, with waivers and conditions",
          "schemaId": "dataset-admission-record",
          "schema": "https://aigovernanceengineer.com/schemas/dataset-admission-record.v1.json",
          "layer": 1
        },
        {
          "artefact": "Quality checks, populations covered and known gaps on the dataset card",
          "schemaId": "dataset-card",
          "schema": "https://aigovernanceengineer.com/schemas/dataset-card.v1.json",
          "layer": 2
        }
      ],
      "failureResponse": {
        "effect": "require_approval",
        "text": "A failed check blocks admission unless someone entitled to waive it signs a waiver; the waiver and its conditions appear in the model card, and the next retrain cannot start until the conditions are closed."
      },
      "layer": 2,
      "secondaryLayers": [
        3
      ],
      "patterns": [
        {
          "slug": "dataset-admission-gate",
          "title": "Dataset Admission Gate",
          "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate"
        },
        {
          "slug": "fairness-eval-suite",
          "title": "Fairness Eval Suite",
          "url": "https://aigovernanceengineer.com/patterns/fairness-eval-suite"
        }
      ],
      "seeds": [],
      "derivedFrom": [
        {
          "kind": "pattern",
          "ref": "dataset-admission-gate",
          "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate"
        },
        {
          "kind": "schema",
          "ref": "dataset-admission-record",
          "url": "https://aigovernanceengineer.com/resources/templates#schema-dataset-admission-record"
        },
        {
          "kind": "chapter",
          "ref": "governing-development",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        }
      ],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART10",
            "name": "EU AI Act Art. 10 data and data governance",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art10"
          },
          {
            "id": "AIGE-OBL-ISO42001-A7",
            "name": "A.7 Data for AI systems",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a7"
          }
        ],
        "iso42001": [
          {
            "id": "A.7.4",
            "title": "Quality of data for AI systems"
          }
        ],
        "nistAiRmf": [
          {
            "id": "MAP 2.3",
            "title": "Scientific integrity and TEVV considerations are identified and documented, including those related to experimental design, data collection and selection (e.g., availability, representativeness, suitability), system trustworthiness, and construct validation."
          }
        ],
        "owasp": [],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 25,
          "title": "Governing AI development",
          "text": "Governing AI development (AI Governance Engineering Body of Knowledge v0.5.0, chapter 14, section \"Quality, quantity, representativeness and fitness for purpose\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-development#quality-quantity-representativeness-and-fitness-for-purpose",
          "verified": "primary"
        },
        {
          "n": 1,
          "title": "Dataset Admission Gate",
          "text": "Dataset Admission Gate (AI Governance Engineering Body of Knowledge v0.5.0, pattern catalogue (chapter 05): a job may read a dataset version only if a complete, signed admission record admits it for that use). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate",
          "verified": "primary"
        },
        {
          "n": 4,
          "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 10",
          "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 10 (data and data governance: 10(2) practices, including origin, preparation, bias examination and mitigation, and data gaps; 10(3) relevant, sufficiently representative, free of errors and complete; 10(4) specific setting of use). Publications Office of the EU (EUR-Lex). 2026-07-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_10",
          "verified": "primary"
        },
        {
          "n": 26,
          "title": "ISO/IEC 5259 series, Data quality for analytics and machine learning (ML)",
          "text": "ISO/IEC 5259 series, Data quality for analytics and machine learning (ML) (Part 1 overview, terminology and examples; Part 2 data quality measures; Part 3 data quality management requirements and guidelines; Part 4 data quality process framework; Part 5 data quality governance framework). ISO/IEC. 2024-2025.",
          "url": "https://www.iso.org/standard/81088.html",
          "verified": "primary"
        },
        {
          "n": 7,
          "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
          "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        },
        {
          "n": 8,
          "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1",
          "text": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (GOVERN 6.1 third-party risks incl. infringement of intellectual property or other rights; MAP 1.1 intended purposes documented; MAP 2.3 data collection and selection considerations identified and documented; MAP 3.3 targeted application scope; MAP 4.1 legal risks of components incl. third-party data; MEASURE 2.10 privacy risk examined and documented; MANAGE 1.4 negative residual risks to downstream acquirers and end users documented). NIST. 2023-01-26.",
          "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Use the vocabulary of the ISO/IEC 5259 series for the quality measures, and evidence each dimension with the test chapter 14 names: an audit of a labelled sample and inter-annotator agreement for labels, null rates per field and segment for completeness, cell counts against the minimum in the test plan for quantity, a distribution comparison against a reference for representativeness.",
        "Keep an assumption register for what the data is meant to measure (Art. 10(2)(d)) and a proxy analysis for fitness for purpose."
      ],
      "openQuestions": [
        "Who sets the thresholds each check is held to, and how are they reviewed when the deployment population changes?"
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-DATA-009",
      "profile": "data-admission-and-privacy",
      "url": "https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-009",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-data-009.json",
      "title": "Signed Snapshot Integrity",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "Only a content-addressed, signed snapshot is admitted, its hash is re-verified when a job reads it, and new or appended data is checked for anomalies before it is admitted.",
      "failureModes": [
        "A model trains on a snapshot someone altered after admission.",
        "Poisoned data enters through an appended batch that was never checked, so the model still looks functional while carrying a bias, a weakness or a backdoor.",
        "The admission record names a hash that no job ever compares with the data it reads."
      ],
      "scope": "Snapshots admitted to training, fine-tuning, validation, testing, evaluation and retrieval-index pipelines, and data appended to them. The integrity of the trained model artefact is covered by the Model Artefact Integrity pattern.",
      "enforcementPoints": [
        "deploy",
        "runtime"
      ],
      "verification": [
        {
          "kind": "test",
          "text": "When a job reads an admitted snapshot, the hash of what it reads is compared with the content hash on the admission record, and a mismatch stops the read."
        }
      ],
      "evidence": [
        {
          "artefact": "Content hash of the admitted snapshot and the signature over the admission record",
          "schemaId": "dataset-admission-record",
          "schema": "https://aigovernanceengineer.com/schemas/dataset-admission-record.v1.json",
          "layer": 1
        },
        {
          "artefact": "Read-time hash verification and anomaly-check results",
          "schemaId": null,
          "schema": null,
          "layer": 1
        }
      ],
      "failureResponse": {
        "effect": "deny",
        "text": "A snapshot whose hash does not match its admission record is not read; new or appended data that fails the anomaly checks is not admitted."
      },
      "layer": 2,
      "secondaryLayers": [
        1
      ],
      "patterns": [
        {
          "slug": "dataset-admission-gate",
          "title": "Dataset Admission Gate",
          "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate"
        },
        {
          "slug": "aibom",
          "title": "AIBOM",
          "url": "https://aigovernanceengineer.com/patterns/aibom"
        }
      ],
      "seeds": [],
      "derivedFrom": [
        {
          "kind": "pattern",
          "ref": "dataset-admission-gate",
          "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate"
        },
        {
          "kind": "schema",
          "ref": "dataset-admission-record",
          "url": "https://aigovernanceengineer.com/resources/templates#schema-dataset-admission-record"
        },
        {
          "kind": "chapter",
          "ref": "governing-development",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        }
      ],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART10",
            "name": "EU AI Act Art. 10 data and data governance",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art10"
          },
          {
            "id": "AIGE-OBL-OWASP-LLM",
            "name": "Top 10 for LLM Applications 2026",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-llm"
          }
        ],
        "iso42001": [
          {
            "id": "A.7.5",
            "title": "Data provenance"
          }
        ],
        "nistAiRmf": [],
        "owasp": [
          {
            "id": "llm05-2026",
            "externalId": "LLM05:2026",
            "name": "Data and Model Poisoning",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-llm05-2026"
          }
        ],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": [
          {
            "framework": "MITRE ATLAS",
            "ref": "AML.M0007",
            "note": "Sanitize Training Data (mitigation)"
          },
          {
            "framework": "MITRE ATLAS",
            "ref": "AML.M0025",
            "note": "Maintain AI Dataset Provenance (mitigation)"
          }
        ]
      },
      "references": [
        {
          "n": 1,
          "title": "Dataset Admission Gate",
          "text": "Dataset Admission Gate (AI Governance Engineering Body of Knowledge v0.5.0, pattern catalogue (chapter 05): a job may read a dataset version only if a complete, signed admission record admits it for that use). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate",
          "verified": "primary"
        },
        {
          "n": 25,
          "title": "Governing AI development",
          "text": "Governing AI development (AI Governance Engineering Body of Knowledge v0.5.0, chapter 14, section \"Quality, quantity, representativeness and fitness for purpose\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-development#quality-quantity-representativeness-and-fitness-for-purpose",
          "verified": "primary"
        },
        {
          "n": 6,
          "title": "OWASP GenAI LLM Top 10 2026",
          "text": "OWASP GenAI LLM Top 10 2026 (LLM01:2026 Prompt Injection to LLM10:2026 Improper Output Handling; resource page dated 3 Aug 2026). OWASP GenAI Security Project. 2026-08-03.",
          "url": "https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/",
          "verified": "primary"
        },
        {
          "n": 27,
          "title": "MITRE ATLAS data, release 2026.09",
          "text": "MITRE ATLAS data, release 2026.09 (modified 2026-09-15; AML.T0020 Training Data Poisoning; mitigations AML.M0007 Sanitize Training Data and AML.M0025 Maintain AI Dataset Provenance). MITRE (atlas-data repository). 2026-09-15.",
          "url": "https://github.com/mitre-atlas/atlas-data",
          "verified": "primary"
        },
        {
          "n": 7,
          "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
          "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        }
      ],
      "implementationNotes": [
        "Sign the admission record (for example \"ed25519:<base64>\") so it is tamper-evident in the evidence store, and record the digest of the snapshot that was checked in its input_hash.",
        "Training data is an attack surface: ATLAS catalogues training data poisoning (AML.T0020) and lists \"Sanitize Training Data\" (AML.M0007) and \"Maintain AI Dataset Provenance\" (AML.M0025) among its mitigations."
      ],
      "openQuestions": [
        "Which anomaly checks on appended data are strong enough to catch planted triggers, and which belong instead in the regression evals of the trained model?"
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-DATA-010",
      "profile": "data-admission-and-privacy",
      "url": "https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-010",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-data-010.json",
      "title": "Lineage from Training Runs to Admitted Sources",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "Each training run records the admission records and ledger rows (id and version) it read and the hashes of the admitted snapshots, so backward lineage answers \"what trained this model?\" and forward lineage answers \"which models used this source?\".",
      "failureModes": [
        "A licence withdrawal, an erasure request or an order names a source, and nobody can list the models trained on it.",
        "The model card lists datasets by name but not by version or snapshot hash, so the training cannot be reproduced.",
        "Lineage is kept at dataset level only where rights attach to records, so an opt-out cannot be traced to the runs it affects."
      ],
      "scope": "Training and fine-tuning runs and the datasets, snapshots and ledger rows they read. Evaluation runs are covered for the data they read, not for their results.",
      "enforcementPoints": [
        "deploy"
      ],
      "verification": [
        {
          "kind": "inspect",
          "text": "For a released model version, the run record names the admission records and ledger rows it read, and a forward-lineage query from one of those sources returns the model version."
        }
      ],
      "evidence": [
        {
          "artefact": "Datasets used to train, validate, test or fine-tune the model on the model card, each named by its dataset card id or linked to its data card, with its role",
          "schemaId": "model-card",
          "schema": "https://aigovernanceengineer.com/schemas/model-card.v1.json",
          "layer": 2
        },
        {
          "artefact": "Link to the lineage record (for example an OpenLineage or W3C PROV graph) on the dataset card",
          "schemaId": "dataset-card",
          "schema": "https://aigovernanceengineer.com/schemas/dataset-card.v1.json",
          "layer": 2
        },
        {
          "artefact": "Training run record with the code commit, the hashes of the admitted snapshots and the admission records and ledger rows read",
          "schemaId": null,
          "schema": null,
          "layer": 2
        }
      ],
      "failureResponse": {
        "effect": "alert",
        "text": "A training run that does not record the admission records and ledger rows it read has no backward lineage: until it is restored, a withdrawal or an order cannot be traced to that model version. Which response fits the gap is left to technical review."
      },
      "layer": 2,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "training-data-rights-ledger",
          "title": "Training-Data Rights Ledger",
          "url": "https://aigovernanceengineer.com/patterns/training-data-rights-ledger"
        },
        {
          "slug": "dataset-admission-gate",
          "title": "Dataset Admission Gate",
          "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate"
        },
        {
          "slug": "aibom",
          "title": "AIBOM",
          "url": "https://aigovernanceengineer.com/patterns/aibom"
        }
      ],
      "seeds": [],
      "derivedFrom": [
        {
          "kind": "pattern",
          "ref": "training-data-rights-ledger",
          "url": "https://aigovernanceengineer.com/patterns/training-data-rights-ledger"
        },
        {
          "kind": "pattern",
          "ref": "dataset-admission-gate",
          "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate"
        },
        {
          "kind": "schema",
          "ref": "model-card",
          "url": "https://aigovernanceengineer.com/resources/templates#schema-model-card"
        },
        {
          "kind": "chapter",
          "ref": "governing-development",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        }
      ],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART10",
            "name": "EU AI Act Art. 10 data and data governance",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art10"
          },
          {
            "id": "AIGE-OBL-ISO42001-A7",
            "name": "A.7 Data for AI systems",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a7"
          }
        ],
        "iso42001": [
          {
            "id": "A.7.5",
            "title": "Data provenance"
          }
        ],
        "nistAiRmf": [],
        "owasp": [],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 28,
          "title": "Governing AI development",
          "text": "Governing AI development (AI Governance Engineering Body of Knowledge v0.5.0, chapter 14, section \"Provenance versus lineage\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-development#provenance-versus-lineage",
          "verified": "primary"
        },
        {
          "n": 29,
          "title": "Governing AI development",
          "text": "Governing AI development (AI Governance Engineering Body of Knowledge v0.5.0, chapter 14, section \"Reproducibility and linked versioning\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-development#reproducibility-and-linked-versioning",
          "verified": "primary"
        },
        {
          "n": 11,
          "title": "Training-Data Rights Ledger",
          "text": "Training-Data Rights Ledger (AI Governance Engineering Body of Knowledge v0.5.0, pattern catalogue (chapter 05): one ledger row per training source, joined to lineage so each model knows its sources). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/patterns/training-data-rights-ledger",
          "verified": "primary"
        },
        {
          "n": 1,
          "title": "Dataset Admission Gate",
          "text": "Dataset Admission Gate (AI Governance Engineering Body of Knowledge v0.5.0, pattern catalogue (chapter 05): a job may read a dataset version only if a complete, signed admission record admits it for that use). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate",
          "verified": "primary"
        },
        {
          "n": 30,
          "title": "PROV Overview",
          "text": "PROV Overview (PROV-DM and PROV-O W3C Recommendations of 30 April 2013; provenance as information about entities, activities and people involved in producing data). W3C. 2013-04-30.",
          "url": "https://www.w3.org/TR/prov-overview/",
          "verified": "primary"
        },
        {
          "n": 31,
          "title": "OpenLineage: an open platform for collection and analysis of data lineage",
          "text": "OpenLineage: an open platform for collection and analysis of data lineage (standard API for lineage events over datasets, jobs and runs, with facets). OpenLineage project (The Linux Foundation). 2026.",
          "url": "https://openlineage.io/",
          "verified": "primary"
        },
        {
          "n": 7,
          "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
          "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        }
      ],
      "implementationNotes": [
        "Record provenance in W3C PROV terms (entities, activities and agents) and emit lineage events over datasets, jobs and runs, so each training run names the admission records it read.",
        "Choose granularity by where rights attach: dataset-level provenance by default, record-level where rights attach to records (personal data, per-source licences, opt-outs), feature-level lineage for sensitive derived features that can act as proxies.",
        "List the datasets by version in the AIBOM as well."
      ],
      "openQuestions": [
        "The site publishes no schema for a model training run (the published training-record schema covers AI literacy training): should one be published, or should the model card and AIBOM carry the run fields?",
        "Should a training run with no recorded lineage block the release of the model version it produced, or only raise an alert to its owner?"
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-DATA-011",
      "profile": "data-admission-and-privacy",
      "url": "https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-011",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-data-011.json",
      "title": "Rights Changes Propagated to Affected Models",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "A licence expiry or withdrawal, a new rights reservation, a consent withdrawal, an erasure request or an order marks the affected ledger rows and snapshots, forward lineage lists the affected models, and the remediation (retrain without the source, retire the model, or a documented decision to rely on another basis) is recorded against the same rows with a date and an approver.",
      "failureModes": [
        "An erasure request closes on time at the source system but the training snapshot, retrieval index, logs and models trained on the data are never reached.",
        "A consent withdrawal cannot be traced to the runs and model versions that inherited the consent.",
        "Remedies reach the model itself (an order to delete models developed using unlawfully used data) and, without per-source lineage, the only safe response is to delete everything.",
        "A change in rights does not reopen admission, and the next retrain reads the source again."
      ],
      "scope": "Changes in the right to use a training source or a person's data after admission, and the datasets, indexes and model versions they reach. The per-location response to a data-subject request is the Rights Requests Against Models pattern; this control covers the propagation from the data to the models.",
      "enforcementPoints": [
        "periodic"
      ],
      "verification": [
        {
          "kind": "test",
          "text": "Run a mock erasure request through the corpus, the snapshots, the retrieval index, the logs and the weights, write the fulfilment record, and time it against the one-month deadline."
        }
      ],
      "evidence": [
        {
          "artefact": "Re-admission record for the affected dataset versions",
          "schemaId": "dataset-admission-record",
          "schema": "https://aigovernanceengineer.com/schemas/dataset-admission-record.v1.json",
          "layer": 1
        },
        {
          "artefact": "Remediation recorded against the affected ledger rows, with the models forward lineage listed, a date and an approver",
          "schemaId": null,
          "schema": null,
          "layer": 2
        },
        {
          "artefact": "Fulfilment record: every location, the action in each, the model versions affected and when the gap closes",
          "schemaId": null,
          "schema": null,
          "layer": 5
        }
      ],
      "failureResponse": {
        "effect": "alert",
        "text": "The change marks the affected rows and reopens admission; the owners of every affected model are told, and each model is retrained without the source, retired or kept on a documented decision to rely on another basis."
      },
      "layer": 2,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "training-data-rights-ledger",
          "title": "Training-Data Rights Ledger",
          "url": "https://aigovernanceengineer.com/patterns/training-data-rights-ledger"
        },
        {
          "slug": "dataset-admission-gate",
          "title": "Dataset Admission Gate",
          "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate"
        },
        {
          "slug": "rights-requests-against-models",
          "title": "Rights Requests Against Models",
          "url": "https://aigovernanceengineer.com/patterns/rights-requests-against-models"
        }
      ],
      "seeds": [],
      "derivedFrom": [
        {
          "kind": "pattern",
          "ref": "training-data-rights-ledger",
          "url": "https://aigovernanceengineer.com/patterns/training-data-rights-ledger"
        },
        {
          "kind": "pattern",
          "ref": "rights-requests-against-models",
          "url": "https://aigovernanceengineer.com/patterns/rights-requests-against-models"
        },
        {
          "kind": "schema",
          "ref": "dataset-admission-record",
          "url": "https://aigovernanceengineer.com/resources/templates#schema-dataset-admission-record"
        },
        {
          "kind": "chapter",
          "ref": "privacy-and-ai",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai"
        }
      ],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-GDPR-ART15-17-21",
            "name": "GDPR Arts. 15–17 and 21 data subject rights against trained models",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art15-17-21"
          },
          {
            "id": "AIGE-OBL-GDPR-ART7",
            "name": "GDPR Art. 7 conditions for consent and its withdrawal",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art7"
          },
          {
            "id": "AIGE-OBL-DSM-ART4-3",
            "name": "DSM Directive Art. 4(3) text-and-data-mining reservations",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-dsm-art4-3"
          }
        ],
        "iso42001": [],
        "nistAiRmf": [],
        "owasp": [],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 11,
          "title": "Training-Data Rights Ledger",
          "text": "Training-Data Rights Ledger (AI Governance Engineering Body of Knowledge v0.5.0, pattern catalogue (chapter 05): one ledger row per training source, joined to lineage so each model knows its sources). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/patterns/training-data-rights-ledger",
          "verified": "primary"
        },
        {
          "n": 32,
          "title": "Privacy and data protection law applied to AI",
          "text": "Privacy and data protection law applied to AI (AI Governance Engineering Body of Knowledge v0.5.0, chapter 19, section \"Where a request has to reach\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai#where-a-request-has-to-reach",
          "verified": "primary"
        },
        {
          "n": 33,
          "title": "Privacy and data protection law applied to AI",
          "text": "Privacy and data protection law applied to AI (AI Governance Engineering Body of Knowledge v0.5.0, chapter 19, section \"The limits of consent\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai#the-limits-of-consent",
          "verified": "primary"
        },
        {
          "n": 34,
          "title": "Rights Requests Against Models",
          "text": "Rights Requests Against Models (AI Governance Engineering Body of Knowledge v0.5.0, pattern catalogue (chapter 05): each data-subject request routed to every place the data sits and closed with a fulfilment record). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/patterns/rights-requests-against-models",
          "verified": "primary"
        },
        {
          "n": 28,
          "title": "Governing AI development",
          "text": "Governing AI development (AI Governance Engineering Body of Knowledge v0.5.0, chapter 14, section \"Provenance versus lineage\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-development#provenance-versus-lineage",
          "verified": "primary"
        },
        {
          "n": 18,
          "title": "Regulation (EU) 2016/679 (GDPR)",
          "text": "Regulation (EU) 2016/679 (GDPR) (Art. 5 principles, incl. 5(1)(b) purpose limitation and 5(1)(c) minimisation; Art. 6 lawful basis and 6(4) compatibility; Art. 7 consent; Art. 9 special categories; Arts. 15 to 17 and 21 rights; Art. 25 data protection by design and by default; Art. 30 records of processing; Arts. 35 and 36 DPIA and prior consultation). Publications Office of the EU (EUR-Lex). 2016-04-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng",
          "verified": "primary"
        },
        {
          "n": 15,
          "title": "In the Matter of Everalbum, Inc., Decision and Order",
          "text": "In the Matter of Everalbum, Inc., Decision and Order (\"Affected Work Product\": models or algorithms developed using users' biometric information, to be deleted within 90 days with a sworn statement). Federal Trade Commission. 2021-05-07.",
          "url": "https://www.ftc.gov/system/files/documents/cases/1923172_-_everalbum_decision_final.pdf",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Keep a consent-purpose log joining each consent to the datasets and model versions that inherited it; without that join a withdrawal cannot be traced to the runs it affects.",
        "For data inside the weights, choose on the ladder chapter 19 sets out (output suppression, retraining without the data, machine unlearning) and record the choice and its reason per request, with the date the next retrain closes the gap."
      ],
      "openQuestions": [
        "How long may a model stay in production on output suppression before retraining without the data is due, and who decides?"
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-DATA-012",
      "profile": "data-admission-and-privacy",
      "url": "https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-012",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-data-012.json",
      "title": "Registered Downstream Consumers of Outputs",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "Every consumer of a system's outputs (a system, a team, a partner or a training pipeline) is registered against the producing system with its purpose, its approval and the re-test that cleared the outputs for that context; access to the outputs is granted per registered consumer, and the intended and prohibited uses are rules on a Policy Card.",
      "failureModes": [
        "A risk score approved to prioritise manual review becomes an automatic decline in another team's pipeline, and nobody assessed that use.",
        "A model's outputs are harvested as training data for another model, and the feedback loop is invisible.",
        "A partner receives outputs under a contract nobody connected to the registry, and is not told when the model changes or retires."
      ],
      "scope": "Consumers of the outputs of AI systems, internal and external, including training pipelines that read those outputs. Registration binds internal consumers; external ones depend on contract terms and audit rights.",
      "enforcementPoints": [
        "deploy",
        "runtime"
      ],
      "verification": [
        {
          "kind": "test",
          "text": "A consumer with no registration has no credential to the output API or table, and a registration whose declared use meets a prohibited-use rule on the card goes to review as a new purpose instead of receiving a credential."
        }
      ],
      "evidence": [
        {
          "artefact": "Intended and prohibited uses as rules on the system's Policy Card",
          "schemaId": "policy-card",
          "schema": "https://aigovernanceengineer.com/schemas/policy-card.v1.json",
          "layer": 1
        },
        {
          "artefact": "Downstream use register entry: each consumer with its use, approval, re-test, credential or contract, and the feedback-loop check",
          "schemaId": null,
          "schema": null,
          "layer": 2
        }
      ],
      "failureResponse": {
        "effect": "deny",
        "text": "An unregistered consumer gets no credential; a declared use outside the card fails registration and reopens classification and the impact assessments as a new purpose. A model change, an incident or a retirement notifies every registered consumer."
      },
      "layer": 2,
      "secondaryLayers": [
        1
      ],
      "patterns": [
        {
          "slug": "downstream-use-register",
          "title": "Downstream Use Register",
          "url": "https://aigovernanceengineer.com/patterns/downstream-use-register"
        },
        {
          "slug": "policy-card",
          "title": "Policy Card",
          "url": "https://aigovernanceengineer.com/patterns/policy-card"
        },
        {
          "slug": "agent-registry",
          "title": "Agent Registry",
          "url": "https://aigovernanceengineer.com/patterns/agent-registry"
        },
        {
          "slug": "disclosure-notification-pipeline",
          "title": "Disclosure & Notification Pipeline",
          "url": "https://aigovernanceengineer.com/patterns/disclosure-notification-pipeline"
        }
      ],
      "seeds": [],
      "derivedFrom": [
        {
          "kind": "pattern",
          "ref": "downstream-use-register",
          "url": "https://aigovernanceengineer.com/patterns/downstream-use-register"
        },
        {
          "kind": "schema",
          "ref": "policy-card",
          "url": "https://aigovernanceengineer.com/resources/templates#schema-policy-card"
        },
        {
          "kind": "chapter",
          "ref": "governing-development",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        }
      ],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART9",
            "name": "EU AI Act Art. 9 risk management system",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art9"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART25",
            "name": "EU AI Act Art. 25 responsibilities along the AI value chain",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art25"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART50",
            "name": "EU AI Act Art. 50 transparency for certain AI systems",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art50"
          },
          {
            "id": "AIGE-OBL-ISO42001-A8",
            "name": "A.8 Information for interested parties",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a8"
          },
          {
            "id": "AIGE-OBL-ISO42001-A9",
            "name": "A.9 Use of AI systems",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a9"
          }
        ],
        "iso42001": [
          {
            "id": "A.8.2",
            "title": "System documentation and information for users"
          },
          {
            "id": "A.9.4",
            "title": "Intended use of the AI system"
          }
        ],
        "nistAiRmf": [
          {
            "id": "MAP 1.1",
            "title": "Intended purposes, potentially beneficial uses, context-specific laws, norms and expectations, and prospective settings in which the AI system will be deployed are understood and documented."
          },
          {
            "id": "MAP 3.3",
            "title": "Targeted application scope is specified and documented based on the system’s capability, established context, and AI system categorization."
          },
          {
            "id": "MANAGE 1.4",
            "title": "Negative residual risks (defined as the sum of all unmitigated risks) to both downstream acquirers of AI systems and end users are documented."
          }
        ],
        "owasp": [
          {
            "id": "llm10-2026",
            "externalId": "LLM10:2026",
            "name": "Improper Output Handling",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-llm10-2026"
          },
          {
            "id": "asi08",
            "externalId": "ASI08",
            "name": "Cascading Failures",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-asi08"
          }
        ],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 35,
          "title": "Downstream Use Register",
          "text": "Downstream Use Register (AI Governance Engineering Body of Knowledge v0.5.0, pattern catalogue (chapter 05): intended and prohibited uses as a Policy Card and every consumer of the outputs recorded against the registry entry). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/patterns/downstream-use-register",
          "verified": "primary"
        },
        {
          "n": 36,
          "title": "Governing AI development",
          "text": "Governing AI development (AI Governance Engineering Body of Knowledge v0.5.0, chapter 14, section \"Function creep\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-development#function-creep",
          "verified": "primary"
        },
        {
          "n": 37,
          "title": "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), of 13 June 2024; OJ L, 2024/1689, 12.7.2024",
          "text": "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), of 13 June 2024; OJ L, 2024/1689, 12.7.2024 (Art. 3(13) reasonably foreseeable misuse; Art. 9(2)(b) risks under reasonably foreseeable misuse; Art. 25(1)(c) changed intended purpose; Art. 50(2) machine-readable marking of synthetic outputs). Publications Office of the EU (EUR-Lex). 2024-07-12.",
          "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng",
          "verified": "primary"
        },
        {
          "n": 6,
          "title": "OWASP GenAI LLM Top 10 2026",
          "text": "OWASP GenAI LLM Top 10 2026 (LLM01:2026 Prompt Injection to LLM10:2026 Improper Output Handling; resource page dated 3 Aug 2026). OWASP GenAI Security Project. 2026-08-03.",
          "url": "https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/",
          "verified": "primary"
        },
        {
          "n": 38,
          "title": "OWASP Top 10 for Agentic Applications for 2026",
          "text": "OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents). OWASP GenAI Security Project. 2025-12-09.",
          "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
          "verified": "primary"
        },
        {
          "n": 7,
          "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
          "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        },
        {
          "n": 8,
          "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1",
          "text": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (GOVERN 6.1 third-party risks incl. infringement of intellectual property or other rights; MAP 1.1 intended purposes documented; MAP 2.3 data collection and selection considerations identified and documented; MAP 3.3 targeted application scope; MAP 4.1 legal risks of components incl. third-party data; MEASURE 2.10 privacy risk examined and documented; MANAGE 1.4 negative residual risks to downstream acquirers and end users documented). NIST. 2023-01-26.",
          "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Forecast misuse before go-live with a premortem, abuse cases written next to the user stories and a stakeholder impact map that includes people who never touch the interface; each plausible misuse becomes a prohibited-use rule or a monitor.",
        "Stamp outputs with the producing system and version, the intended use and a caveat, as metadata a consumer can read; for generative content, this is the machine-readable marking Art. 50(2) requires of providers.",
        "Classify consumer requests against the negative space of the card, alert on what falls outside it, and watch for outputs that return as training data."
      ],
      "openQuestions": [
        "How is a registered external consumer held to its declared use when the outputs leave the organisation's access controls?"
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-ASSURE-001",
      "profile": "assurance-and-evidence",
      "url": "https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-001",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-assure-001.json",
      "title": "Test Plan Frozen Before Evaluation",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "The test plan (suites, metrics, thresholds with their link to the error appetite, datasets, subgroups, sample sizes and the number of repeated runs) is frozen in the repository before evaluation starts, and a change to it after results are known is a diff with an approver.",
      "failureModes": [
        "Evaluation starts before the plan's metrics, thresholds, datasets, subgroups, sample sizes and number of repeated runs are fixed.",
        "A metric or threshold changes after the results are known with no approved diff: metric shopping, choosing the metric that passes after seeing all of them.",
        "A planned suite names no failure mode, or its threshold has no link to the error appetite.",
        "A test category is missing from the plan with no reason given in its scope."
      ],
      "scope": "Every system or model tested before a release, and every change to its test plan. The suites themselves, and whether a result is valid, are covered by AIGE-CTL-ASSURE-002 and AIGE-CTL-EVAL-009.",
      "enforcementPoints": [
        "pre_merge"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Test plan frozen in the repository before the first run: suites with metric, threshold, failure mode and whether a failure blocks, exit criteria, owner and approver",
          "schemaId": "test-plan",
          "schema": "https://aigovernanceengineer.com/schemas/test-plan.v1.json",
          "layer": 3
        }
      ],
      "failureResponse": {
        "effect": "require_approval",
        "text": "A change to the plan after results are known is a diff that needs an approver before it takes effect."
      },
      "layer": 3,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "eval-gate-in-ci",
          "title": "Eval Gate in CI",
          "url": "https://aigovernanceengineer.com/patterns/eval-gate-in-ci"
        }
      ],
      "seeds": [],
      "derivedFrom": [
        {
          "kind": "schema",
          "ref": "test-plan",
          "url": "https://aigovernanceengineer.com/resources/templates#schema-test-plan"
        },
        {
          "kind": "pattern",
          "ref": "eval-gate-in-ci",
          "url": "https://aigovernanceengineer.com/patterns/eval-gate-in-ci"
        },
        {
          "kind": "chapter",
          "ref": "governing-development",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        }
      ],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART9",
            "name": "EU AI Act Art. 9 risk management system",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art9"
          },
          {
            "id": "AIGE-OBL-NISTRMF-MEASURE",
            "name": "MEASURE",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure"
          },
          {
            "id": "AIGE-OBL-ISO42001-A6",
            "name": "A.6 AI system life cycle",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a6"
          }
        ],
        "iso42001": [
          {
            "id": "A.6.2.4",
            "title": "AI system verification and validation"
          }
        ],
        "nistAiRmf": [
          {
            "id": "MEASURE 2.1",
            "title": "Test sets, metrics, and details about the tools used during TEVV are documented."
          }
        ],
        "owasp": [],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 1,
          "title": "Governing AI development",
          "text": "Governing AI development (AI Governance Engineering Body of Knowledge v0.5.0, chapter 14, section \"A test plan before the first run\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-development#a-test-plan-before-the-first-run",
          "verified": "primary"
        },
        {
          "n": 2,
          "title": "Pattern: Eval Gate in CI",
          "text": "Pattern: Eval Gate in CI (AI Governance Engineering Body of Knowledge v0.5.0, chapter 05 pattern catalogue). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/patterns/eval-gate-in-ci",
          "verified": "primary"
        },
        {
          "n": 3,
          "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744",
          "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744 (the articles each control maps to, as chapters 14 and 18 restate them). Publications Office of the EU (EUR-Lex). 2026-07-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng",
          "verified": "primary"
        },
        {
          "n": 4,
          "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1",
          "text": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (MEASURE and MANAGE subcategories cited by id, mapped only where the official text matches the control). NIST. 2023-01-26.",
          "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
          "verified": "primary"
        },
        {
          "n": 5,
          "title": "ISO/IEC 42001:2023, AI management systems",
          "text": "ISO/IEC 42001:2023, AI management systems (Annex A control ids and clause numbers cited by number and short title only; the text of the standard was not opened). ISO/IEC. 2023-12.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        }
      ],
      "implementationNotes": [
        "The EU AI Act asks for testing against \"prior defined metrics and probabilistic thresholds\" (Art. 9(8)); chapter 14 reads the operative words as prior defined and freezes the plan before evaluation starts.",
        "Build the plan from the chapter's test-type matrix: one suite per test type the system needs (validation, robustness, security and adversarial, bias and fairness, regression and the rest), each behind the eval gate; the schema asks for a reason in the scope for any category left out."
      ],
      "openQuestions": [
        "Verification procedure to be specified: the derivation adds no check its source material does not state; requires technical review.",
        "Which changes to a frozen plan (a new suite, a larger sample, a stricter threshold) may proceed without a new approval, and which reopen the plan?"
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-ASSURE-002",
      "profile": "assurance-and-evidence",
      "url": "https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-002",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-assure-002.json",
      "title": "Release Blocked Below the Eval Threshold",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "A model or agent ships only after a versioned eval suite, with at least one capability and one adversarial eval, passes in the pipeline above a documented threshold that traces to a named failure mode or obligation, and every run leaves a structured result filed against the registry entry of the version tested.",
      "failureModes": [
        "A model or agent is retrained, re-prompted or given a new tool and ships with no eval run for its version.",
        "A result below the threshold does not fail the pipeline, so the release ships and a finding is filed instead.",
        "A threshold traces to no named failure mode or obligation.",
        "A result exists only as a pasted score or a slide, not as a structured record (suite id, model version, score, threshold, result, timestamp) filed against the registry entry."
      ],
      "scope": "Models and agents that change (retrained, re-prompted or given a new tool) and ship through a pipeline that already runs functional tests. The trajectory evals of an agent are AIGE-CTL-AGENT-013, and the checks that a result is valid enough to gate a release are AIGE-CTL-EVAL-009.",
      "enforcementPoints": [
        "pre_merge"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Eval result of each run: suite id, model version, score, threshold, pass or fail and timestamp, filed against the registry entry",
          "schemaId": "eval-result",
          "schema": "https://aigovernanceengineer.com/schemas/eval-result.v1.json",
          "layer": 3
        }
      ],
      "failureResponse": {
        "effect": "deny",
        "text": "A result below the threshold fails the pipeline, and the release does not ship until it is fixed."
      },
      "layer": 3,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "eval-gate-in-ci",
          "title": "Eval Gate in CI",
          "url": "https://aigovernanceengineer.com/patterns/eval-gate-in-ci"
        },
        {
          "slug": "adversarial-red-team-suite",
          "title": "Adversarial Red-Team Suite",
          "url": "https://aigovernanceengineer.com/patterns/adversarial-red-team-suite"
        }
      ],
      "seeds": [],
      "derivedFrom": [
        {
          "kind": "pattern",
          "ref": "eval-gate-in-ci",
          "url": "https://aigovernanceengineer.com/patterns/eval-gate-in-ci"
        },
        {
          "kind": "schema",
          "ref": "eval-result",
          "url": "https://aigovernanceengineer.com/resources/templates#schema-eval-result"
        },
        {
          "kind": "chapter",
          "ref": "governing-development",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        }
      ],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART15",
            "name": "EU AI Act Art. 15 accuracy, robustness and cybersecurity",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART55",
            "name": "EU AI Act Art. 55 GPAI models with systemic risk",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art55"
          },
          {
            "id": "AIGE-OBL-NISTRMF-MEASURE",
            "name": "MEASURE",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure"
          },
          {
            "id": "AIGE-OBL-OWASP-AGENTIC",
            "name": "Top 10 for Agentic Applications 2026",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-agentic"
          }
        ],
        "iso42001": [
          {
            "id": "A.6.2.4",
            "title": "AI system verification and validation"
          }
        ],
        "nistAiRmf": [
          {
            "id": "MEASURE 2.3",
            "title": "Performance or assurance criteria measured for deployment-like conditions"
          }
        ],
        "owasp": [
          {
            "id": "asi01",
            "externalId": "ASI01",
            "name": "Agent Goal Hijack",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-asi01"
          },
          {
            "id": "asi02",
            "externalId": "ASI02",
            "name": "Tool Misuse and Exploitation",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-asi02"
          }
        ],
        "atlas": [],
        "aiuc1": [
          "C002"
        ],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 2,
          "title": "Pattern: Eval Gate in CI",
          "text": "Pattern: Eval Gate in CI (AI Governance Engineering Body of Knowledge v0.5.0, chapter 05 pattern catalogue). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/patterns/eval-gate-in-ci",
          "verified": "primary"
        },
        {
          "n": 6,
          "title": "Governing AI development",
          "text": "Governing AI development (AI Governance Engineering Body of Knowledge v0.5.0, chapter 14, section \"Statistical validity of evals\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-development#statistical-validity-of-evals",
          "verified": "primary"
        },
        {
          "n": 7,
          "title": "Governing AI development",
          "text": "Governing AI development (AI Governance Engineering Body of Knowledge v0.5.0, chapter 14, section \"Reproducibility and linked versioning\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-development#reproducibility-and-linked-versioning",
          "verified": "primary"
        },
        {
          "n": 8,
          "title": "OWASP Top 10 for Agentic Applications for 2026",
          "text": "OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents). OWASP GenAI Security Project. 2025-12-09.",
          "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
          "verified": "primary"
        },
        {
          "n": 3,
          "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744",
          "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744 (the articles each control maps to, as chapters 14 and 18 restate them). Publications Office of the EU (EUR-Lex). 2026-07-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng",
          "verified": "primary"
        },
        {
          "n": 4,
          "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1",
          "text": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (MEASURE and MANAGE subcategories cited by id, mapped only where the official text matches the control). NIST. 2023-01-26.",
          "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
          "verified": "primary"
        },
        {
          "n": 5,
          "title": "ISO/IEC 42001:2023, AI management systems",
          "text": "ISO/IEC 42001:2023, AI management systems (Annex A control ids and clause numbers cited by number and short title only; the text of the standard was not opened). ISO/IEC. 2023-12.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        },
        {
          "n": 9,
          "title": "AIUC-1 requirements",
          "text": "AIUC-1 requirements (public requirement index, A001 to F002, each requirement on its own page (E007 and E014 marked retired); AIUC-1 is a standard of the Artificial Intelligence Underwriting Company; this site is not affiliated with AIUC, and a mapping here is not an AIUC-1 certificate or audit). Artificial Intelligence Underwriting Company. 2026-09-24.",
          "url": "https://standard.aiuc-1.com/llms.txt",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Version the suite alongside the model and run it in CI (for example with Inspect, promptfoo, Garak or Giskard; illustrative); the security suite is the Adversarial Red-Team Suite.",
        "Size the suite from the threshold, not from the time available: chapter 14 shows a 0.96 pass rate on 200 cases with a 95% interval of about 0.933 to 0.987, which a 0.95 threshold sits inside, so the gate cannot tell a pass from a fail.",
        "Link the records both ways: model version to training record to eval results to release tag to the risk approvals that let it ship."
      ],
      "openQuestions": [
        "Verification procedure to be specified: the derivation adds no check its source material does not state; requires technical review.",
        "How should the gate treat a suite whose repeated runs straddle the threshold: rerun, enlarge the sample or block, given that the pattern warns against flaky gates?"
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-ASSURE-003",
      "profile": "assurance-and-evidence",
      "url": "https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-003",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-assure-003.json",
      "title": "Signed Test Report Against the Plan",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "Each test campaign ends in a dated, signed test report that sets the eval result of every planned suite against the frozen plan, records deviations and waivers, and concludes against the plan's exit criteria; the release gate does not open without a current one.",
      "failureModes": [
        "A release goes ahead with no test report against the frozen plan, or with a stale one.",
        "A planned suite has no result in the report, or a deviation from the plan is not recorded.",
        "A failed suite is waived with no approving role recorded.",
        "The report is not signed off by the responsible role, or its conclusion does not follow from the results against the exit criteria."
      ],
      "scope": "Test campaigns whose results feed a release decision. The go/no-go record the release gate writes, and what else it reads, are out of scope; runs excluded or re-scored after validity checks are reported under AIGE-CTL-EVAL-009.",
      "enforcementPoints": [
        "deploy"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Test report: the test plan executed, the eval result per planned suite, counts passed, failed and waived, deviations and waivers, conclusion and a dated sign-off by role",
          "schemaId": "test-report",
          "schema": "https://aigovernanceengineer.com/schemas/test-report.v1.json",
          "layer": 3
        }
      ],
      "failureResponse": {
        "effect": "deny",
        "text": "The release gate refuses to open while the test report against the frozen plan is missing or stale."
      },
      "layer": 3,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "eval-gate-in-ci",
          "title": "Eval Gate in CI",
          "url": "https://aigovernanceengineer.com/patterns/eval-gate-in-ci"
        }
      ],
      "seeds": [],
      "derivedFrom": [
        {
          "kind": "schema",
          "ref": "test-report",
          "url": "https://aigovernanceengineer.com/resources/templates#schema-test-report"
        },
        {
          "kind": "pattern",
          "ref": "eval-gate-in-ci",
          "url": "https://aigovernanceengineer.com/patterns/eval-gate-in-ci"
        },
        {
          "kind": "chapter",
          "ref": "governing-development",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        }
      ],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART9",
            "name": "EU AI Act Art. 9 risk management system",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art9"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART11",
            "name": "EU AI Act Art. 11 technical documentation (Annex IV)",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art11"
          },
          {
            "id": "AIGE-OBL-ISO42001-A6",
            "name": "A.6 AI system life cycle",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a6"
          },
          {
            "id": "AIGE-OBL-NISTRMF-MEASURE",
            "name": "MEASURE",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure"
          }
        ],
        "iso42001": [
          {
            "id": "A.6.2.4",
            "title": "AI system verification and validation"
          }
        ],
        "nistAiRmf": [
          {
            "id": "MEASURE 2.3",
            "title": "Performance or assurance criteria measured for deployment-like conditions"
          }
        ],
        "owasp": [],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 10,
          "title": "Governing AI development",
          "text": "Governing AI development (AI Governance Engineering Body of Knowledge v0.5.0, chapter 14, section \"The go/no-go gate\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-development#the-gono-go-gate",
          "verified": "primary"
        },
        {
          "n": 1,
          "title": "Governing AI development",
          "text": "Governing AI development (AI Governance Engineering Body of Knowledge v0.5.0, chapter 14, section \"A test plan before the first run\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-development#a-test-plan-before-the-first-run",
          "verified": "primary"
        },
        {
          "n": 2,
          "title": "Pattern: Eval Gate in CI",
          "text": "Pattern: Eval Gate in CI (AI Governance Engineering Body of Knowledge v0.5.0, chapter 05 pattern catalogue). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/patterns/eval-gate-in-ci",
          "verified": "primary"
        },
        {
          "n": 3,
          "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744",
          "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744 (the articles each control maps to, as chapters 14 and 18 restate them). Publications Office of the EU (EUR-Lex). 2026-07-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng",
          "verified": "primary"
        },
        {
          "n": 4,
          "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1",
          "text": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (MEASURE and MANAGE subcategories cited by id, mapped only where the official text matches the control). NIST. 2023-01-26.",
          "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
          "verified": "primary"
        },
        {
          "n": 5,
          "title": "ISO/IEC 42001:2023, AI management systems",
          "text": "ISO/IEC 42001:2023, AI management systems (Annex A control ids and clause numbers cited by number and short title only; the text of the standard was not opened). ISO/IEC. 2023-12.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        }
      ],
      "implementationNotes": [
        "The release gate reads the records the earlier gates produced; a test report against the frozen plan is one of them, and the gate writes a signed go/no-go record with its conditions, filed against the registry entry.",
        "Sign off by role, not by personal name, as the schema asks, and release in stages (shadow, canary, limited pilot, general availability), each with exit criteria from the test plan."
      ],
      "openQuestions": [
        "Verification procedure to be specified: the derivation adds no check its source material does not state; requires technical review.",
        "When a waiver in the report expires after release, is the release gated again or only the waived suite rerun?"
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-ASSURE-004",
      "profile": "assurance-and-evidence",
      "url": "https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-004",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-assure-004.json",
      "title": "Common Signed Evidence Record",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "Every control writes a timestamped, signed record on one common schema (control id; subject as registry id and version; decision; metric, value and threshold; failure mode or obligation; input hash; actor; timestamp; signature) to one assurance store keyed on the registry id, and other tools' outputs are normalised into that shape on ingest.",
      "failureModes": [
        "A control's decision leaves no record in the assurance store, or its record lacks the control id, the subject's registry id and version, the decision, the actor, the timestamp or the signature.",
        "Records from different tools keep their own shapes and cannot be joined on the registry id.",
        "A record cannot be shown to be unchanged, because it carries no signature, or to come from a given input, because it carries no input hash."
      ],
      "scope": "Every control of an AI system that decides something (policy verdicts, eval results, guardrail actions, identity events, admissions, go/no-go decisions), whatever tool runs it. What each control decides is set by the control itself.",
      "enforcementPoints": [
        "runtime"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Evidence record of each control decision, signed and filed in the assurance store under the registry id",
          "schemaId": "evidence-record",
          "schema": "https://aigovernanceengineer.com/schemas/evidence-record.v1.json",
          "layer": 5
        }
      ],
      "failureResponse": {
        "effect": "alert",
        "text": "To be specified: the source material states no failure response for this control."
      },
      "layer": 5,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "continuous-assurance-telemetry",
          "title": "Continuous Assurance Telemetry",
          "url": "https://aigovernanceengineer.com/patterns/continuous-assurance-telemetry"
        }
      ],
      "seeds": [],
      "derivedFrom": [
        {
          "kind": "pattern",
          "ref": "continuous-assurance-telemetry",
          "url": "https://aigovernanceengineer.com/patterns/continuous-assurance-telemetry"
        },
        {
          "kind": "schema",
          "ref": "evidence-record",
          "url": "https://aigovernanceengineer.com/resources/templates#schema-evidence-record"
        },
        {
          "kind": "chapter",
          "ref": "patterns",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        }
      ],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART12",
            "name": "EU AI Act Art. 12 record-keeping and logging",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art12"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART17",
            "name": "EU AI Act Art. 17 quality management system",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art17"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART72",
            "name": "EU AI Act Art. 72 post-market monitoring",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art72"
          },
          {
            "id": "AIGE-OBL-NISTRMF-MANAGE",
            "name": "MANAGE",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage"
          }
        ],
        "iso42001": [],
        "nistAiRmf": [],
        "owasp": [],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": [
          {
            "framework": "ISO/IEC 42001:2023",
            "ref": "9.1",
            "note": "Performance evaluation: monitoring and measurement (cited by the evidence-record and control-observation schemas)"
          }
        ]
      },
      "references": [
        {
          "n": 11,
          "title": "Pattern: Continuous Assurance Telemetry",
          "text": "Pattern: Continuous Assurance Telemetry (AI Governance Engineering Body of Knowledge v0.5.0, chapter 05 pattern catalogue). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/patterns/continuous-assurance-telemetry",
          "verified": "primary"
        },
        {
          "n": 3,
          "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744",
          "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744 (the articles each control maps to, as chapters 14 and 18 restate them). Publications Office of the EU (EUR-Lex). 2026-07-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng",
          "verified": "primary"
        },
        {
          "n": 5,
          "title": "ISO/IEC 42001:2023, AI management systems",
          "text": "ISO/IEC 42001:2023, AI management systems (Annex A control ids and clause numbers cited by number and short title only; the text of the standard was not opened). ISO/IEC. 2023-12.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        }
      ],
      "implementationNotes": [
        "Fix the schema first, then normalise every tool's output into it on ingest, so heterogeneous sources compose into one store queryable by registry id.",
        "Where a record is a normalised copy of a fuller one (an eval result, a go/no-go record, an incident record), link the original with record_ref; keep evidence-bearing fields in the core record, not in extensions."
      ],
      "openQuestions": [
        "Verification procedure to be specified: the derivation adds no check its source material does not state; requires technical review.",
        "Which key signs a record that a third-party tool produced and the ingest pipeline normalised: the tool's, the pipeline's or both?"
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-ASSURE-005",
      "profile": "assurance-and-evidence",
      "url": "https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-005",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-assure-005.json",
      "title": "Live Control Status from the Assurance Store",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "The status of each control is a live query over the records it emits to the assurance store, not a point-in-time attestation, so a control that stops firing or starts failing is visible as it happens, not at the next audit.",
      "failureModes": [
        "A control's status rests on an attestation made when someone looked, although the model has since been retrained or an agent has gained a tool.",
        "A control stops firing and its status still shows it working until the next audit.",
        "The post-market monitoring plan of a high-risk system is a document, not the versioned configuration of the telemetry that collects the data."
      ],
      "scope": "Controls of AI systems in production whose decisions reach the assurance store, and, for high-risk systems, the post-market monitoring their provider runs under Art. 72. What a control decides, and the monitoring of model performance itself, are out of scope: the monitoring plan with its thresholds, owners and consequences is AIGE-CTL-DEPLOY-008.",
      "enforcementPoints": [
        "runtime",
        "periodic"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Evidence records each control emits to the assurance store, which the live status query of that control reads",
          "schemaId": "evidence-record",
          "schema": "https://aigovernanceengineer.com/schemas/evidence-record.v1.json",
          "layer": 5
        }
      ],
      "failureResponse": {
        "effect": "alert",
        "text": "A control that stops firing shows as failing within minutes (the pattern's illustrative dashboard tile goes red), not at the next audit."
      },
      "layer": 5,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "continuous-assurance-telemetry",
          "title": "Continuous Assurance Telemetry",
          "url": "https://aigovernanceengineer.com/patterns/continuous-assurance-telemetry"
        }
      ],
      "seeds": [],
      "derivedFrom": [
        {
          "kind": "pattern",
          "ref": "continuous-assurance-telemetry",
          "url": "https://aigovernanceengineer.com/patterns/continuous-assurance-telemetry"
        },
        {
          "kind": "schema",
          "ref": "evidence-record",
          "url": "https://aigovernanceengineer.com/resources/templates#schema-evidence-record"
        },
        {
          "kind": "chapter",
          "ref": "eu-ai-act",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART72",
            "name": "EU AI Act Art. 72 post-market monitoring",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art72"
          },
          {
            "id": "AIGE-OBL-NISTRMF-MANAGE",
            "name": "MANAGE",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage"
          },
          {
            "id": "AIGE-OBL-NISTRMF-GOVERN",
            "name": "GOVERN",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-govern"
          },
          {
            "id": "AIGE-OBL-CSA-AICM",
            "name": "AICM v1.1: 247 control objectives across 18 domains",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-csa-aicm"
          }
        ],
        "iso42001": [],
        "nistAiRmf": [
          {
            "id": "MANAGE 4.1",
            "title": "Post-deployment monitoring plans are implemented"
          }
        ],
        "owasp": [],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 11,
          "title": "Pattern: Continuous Assurance Telemetry",
          "text": "Pattern: Continuous Assurance Telemetry (AI Governance Engineering Body of Knowledge v0.5.0, chapter 05 pattern catalogue). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/patterns/continuous-assurance-telemetry",
          "verified": "primary"
        },
        {
          "n": 12,
          "title": "The EU AI Act in one pass",
          "text": "The EU AI Act in one pass (AI Governance Engineering Body of Knowledge v0.5.0, chapter 18, section \"Post-market monitoring and serious incidents (Articles 72 and 73)\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act#post-market-monitoring-and-serious-incidents-articles-72-and-73",
          "verified": "primary"
        },
        {
          "n": 3,
          "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744",
          "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744 (the articles each control maps to, as chapters 14 and 18 restate them). Publications Office of the EU (EUR-Lex). 2026-07-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng",
          "verified": "primary"
        },
        {
          "n": 4,
          "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1",
          "text": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (MEASURE and MANAGE subcategories cited by id, mapped only where the official text matches the control). NIST. 2023-01-26.",
          "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Expose the current status of each control as a query over the store, for example a dashboard tile backed by a live query over the decisions the control emitted.",
        "For a high-risk system, chapter 18 treats Continuous Assurance Telemetry as the post-market monitoring system and the plan as its versioned configuration; the Commission's guidance and template for the plan are due by 2 Sep 2027 (Art. 72(3))."
      ],
      "openQuestions": [
        "Verification procedure to be specified: the derivation adds no check its source material does not state; requires technical review.",
        "How long may a control go without emitting a record before its status turns to failing, and should that window differ by control?"
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-ASSURE-006",
      "profile": "assurance-and-evidence",
      "url": "https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-006",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-assure-006.json",
      "title": "Control Observations Filed Against Control Ids",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "Each observation of a reference control is filed as a record naming the control id and version, the subject and its kind, what the control expects, what was observed, whether it held and when, and the evidence records it rests on, so a third party can check it without trusting the observer.",
      "failureModes": [
        "An observation lists no evidence, so a third party has to trust the observer.",
        "An observation does not name the control version it was made against, so it cannot be read once the control changes.",
        "The observer is recorded as a person's name rather than a system or a role.",
        "A control that does not apply to a subject is recorded as passing, instead of not applicable with the reason in the notes."
      ],
      "scope": "Observations of the controls of the open control profiles on this site, whether an adapter, a test or a reviewer makes them.",
      "enforcementPoints": [
        "runtime",
        "periodic"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Control observation: control id and version, subject and kind, expected, observed, status, timestamp and the evidence it rests on",
          "schemaId": "control-observation",
          "schema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
          "layer": 5
        }
      ],
      "failureResponse": {
        "effect": "alert",
        "text": "To be specified: the source material states no failure response for this control."
      },
      "layer": 5,
      "secondaryLayers": [
        4
      ],
      "patterns": [
        {
          "slug": "continuous-assurance-telemetry",
          "title": "Continuous Assurance Telemetry",
          "url": "https://aigovernanceengineer.com/patterns/continuous-assurance-telemetry"
        },
        {
          "slug": "machine-readable-evidence-oscal",
          "title": "Machine-Readable Evidence (OSCAL)",
          "url": "https://aigovernanceengineer.com/patterns/machine-readable-evidence-oscal"
        }
      ],
      "seeds": [],
      "derivedFrom": [
        {
          "kind": "schema",
          "ref": "control-observation",
          "url": "https://aigovernanceengineer.com/resources/templates#schema-control-observation"
        },
        {
          "kind": "pattern",
          "ref": "continuous-assurance-telemetry",
          "url": "https://aigovernanceengineer.com/patterns/continuous-assurance-telemetry"
        }
      ],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART12",
            "name": "EU AI Act Art. 12 record-keeping and logging",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art12"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART15",
            "name": "EU AI Act Art. 15 accuracy, robustness and cybersecurity",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART17",
            "name": "EU AI Act Art. 17 quality management system",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art17"
          }
        ],
        "iso42001": [],
        "nistAiRmf": [],
        "owasp": [],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": [
          {
            "framework": "ISO/IEC 42001:2023",
            "ref": "9.1",
            "note": "Performance evaluation: monitoring and measurement (cited by the evidence-record and control-observation schemas)"
          }
        ]
      },
      "references": [
        {
          "n": 11,
          "title": "Pattern: Continuous Assurance Telemetry",
          "text": "Pattern: Continuous Assurance Telemetry (AI Governance Engineering Body of Knowledge v0.5.0, chapter 05 pattern catalogue). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/patterns/continuous-assurance-telemetry",
          "verified": "primary"
        },
        {
          "n": 13,
          "title": "Pattern: Machine-Readable Evidence (OSCAL)",
          "text": "Pattern: Machine-Readable Evidence (OSCAL) (AI Governance Engineering Body of Knowledge v0.5.0, chapter 05 pattern catalogue). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/patterns/machine-readable-evidence-oscal",
          "verified": "primary"
        },
        {
          "n": 3,
          "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744",
          "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744 (the articles each control maps to, as chapters 14 and 18 restate them). Publications Office of the EU (EUR-Lex). 2026-07-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng",
          "verified": "primary"
        },
        {
          "n": 5,
          "title": "ISO/IEC 42001:2023, AI management systems",
          "text": "ISO/IEC 42001:2023, AI management systems (Annex A control ids and clause numbers cited by number and short title only; the text of the standard was not opened). ISO/IEC. 2023-12.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        }
      ],
      "implementationNotes": [
        "Make each piece of evidence checkable: where it is kept, a digest prefixed with the algorithm, and the schema it validates against when it is a structured record (for example evidence-record or eval-result).",
        "Sign the observation with a detached signature so it is tamper-evident in the evidence store; the evaluation environment profile publishes illustrative pass and fail observations of its specified controls."
      ],
      "openQuestions": [
        "Verification procedure to be specified: the derivation adds no check its source material does not state; requires technical review.",
        "Should an observation an adapter emits and one a reviewer records weigh the same when the status of a control is computed from them?"
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-ASSURE-007",
      "profile": "assurance-and-evidence",
      "url": "https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-007",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-assure-007.json",
      "title": "Machine-Readable Evidence in OSCAL",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "Control results are emitted in a machine-readable standard format, OSCAL first (component-definition and assessment-results artefacts that trace each result back to the control it tested), and stored so that an auditor's question is answered by a query, not by collecting the evidence again.",
      "failureModes": [
        "Evidence reaches an audit as a screenshot or as a document a person formatted and filed by hand.",
        "An assessment result cannot be traced back to the control it tested.",
        "Each audit collects the evidence again from scratch."
      ],
      "scope": "The results of the controls of an AI stack that already produces structured records, and the assurance function that answers auditors from them. The choice of AI-specific OSCAL extensions is left open.",
      "enforcementPoints": [
        "runtime",
        "periodic"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "OSCAL assessment-results for each control result, with component definitions of the controls that produced them",
          "schemaId": null,
          "schema": null,
          "layer": 5
        },
        {
          "artefact": "Structured records the controls already produce, the starting point the pattern assumes (for example evidence records)",
          "schemaId": "evidence-record",
          "schema": "https://aigovernanceengineer.com/schemas/evidence-record.v1.json",
          "layer": 5
        }
      ],
      "failureResponse": {
        "effect": "alert",
        "text": "To be specified: the source material states no failure response for this control."
      },
      "layer": 5,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "machine-readable-evidence-oscal",
          "title": "Machine-Readable Evidence (OSCAL)",
          "url": "https://aigovernanceengineer.com/patterns/machine-readable-evidence-oscal"
        },
        {
          "slug": "continuous-assurance-telemetry",
          "title": "Continuous Assurance Telemetry",
          "url": "https://aigovernanceengineer.com/patterns/continuous-assurance-telemetry"
        }
      ],
      "seeds": [],
      "derivedFrom": [
        {
          "kind": "pattern",
          "ref": "machine-readable-evidence-oscal",
          "url": "https://aigovernanceengineer.com/patterns/machine-readable-evidence-oscal"
        },
        {
          "kind": "chapter",
          "ref": "patterns",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        }
      ],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART12",
            "name": "EU AI Act Art. 12 record-keeping and logging",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art12"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART17",
            "name": "EU AI Act Art. 17 quality management system",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art17"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART72",
            "name": "EU AI Act Art. 72 post-market monitoring",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art72"
          },
          {
            "id": "AIGE-OBL-NISTRMF-MANAGE",
            "name": "MANAGE",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage"
          },
          {
            "id": "AIGE-OBL-NISTRMF-GOVERN",
            "name": "GOVERN",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-govern"
          }
        ],
        "iso42001": [],
        "nistAiRmf": [],
        "owasp": [],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 13,
          "title": "Pattern: Machine-Readable Evidence (OSCAL)",
          "text": "Pattern: Machine-Readable Evidence (OSCAL) (AI Governance Engineering Body of Knowledge v0.5.0, chapter 05 pattern catalogue). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/patterns/machine-readable-evidence-oscal",
          "verified": "primary"
        },
        {
          "n": 14,
          "title": "OSCAL Layers and Models",
          "text": "OSCAL Layers and Models (control layer (catalog, profile), implementation layer (component-definition, system-security-plan) and assessment layer (assessment-plan, assessment-results, POA&M), with traceability from a result to the control it tested). NIST. 2026.",
          "url": "https://pages.nist.gov/OSCAL/learn/concepts/layer/",
          "verified": "primary"
        },
        {
          "n": 15,
          "title": "Making AI Compliance Evidence Machine-Readable (arXiv 2604.13767)",
          "text": "Making AI Compliance Evidence Machine-Readable (arXiv 2604.13767) (one proposed approach, a single preprint: OSCAL with sixteen property extensions for AI). UC3M. 2026-04-15.",
          "url": "https://arxiv.org/abs/2604.13767",
          "verified": "primary"
        },
        {
          "n": 3,
          "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744",
          "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744 (the articles each control maps to, as chapters 14 and 18 restate them). Publications Office of the EU (EUR-Lex). 2026-07-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Build on OSCAL's native model first: the control layer (catalog, profile), the implementation layer (component-definition, system-security-plan) and the assessment layer (assessment-plan, assessment-results, POA&M), which traces a result back to the control it tested.",
        "AI-specific extensions are still forming: one 2026 preprint proposes sixteen property extensions; adopt them only where they fit, since the native assessment models carry most of the load today.",
        "An eval gate that writes an OSCAL assessment result on every run turns a request such as \"all robustness evidence in Q3\" into a filter over the store (the pattern's illustrative example)."
      ],
      "openQuestions": [
        "Verification procedure to be specified: the derivation adds no check its source material does not state; requires technical review.",
        "Which OSCAL model should carry the result of an AI-specific control that no published catalogue defines: a local catalogue of these reference controls, or a property extension?"
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-ASSURE-008",
      "profile": "assurance-and-evidence",
      "url": "https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-008",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-assure-008.json",
      "title": "Evidence Retention as Code",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "Each evidence class carries a retention rule keyed to its obligation (for a high-risk system, the technical documentation, QMS documentation and EU declaration for 10 years after placing on the market, and logs under the provider's control for at least six months, set by intended purpose); signed records go to write-once storage and a legal hold overrides deletion.",
      "failureModes": [
        "An evidence class has no retention rule, or its rule is not keyed to the obligation it evidences.",
        "Automatically generated logs are deleted before six months, or the six-month floor is applied as a default whatever the intended purpose.",
        "A signed record sits on storage where it can be overwritten, or is deleted while a legal hold applies.",
        "Personal data in the logs is kept without reconciling the log retention rule with the GDPR's storage limitation."
      ],
      "scope": "Evidence records, logs and documentation of AI systems, above all high-risk systems whose provider keeps documentation under Art. 18 and logs under Art. 19. The deployer's parallel log duty (Art. 26(6), chapter 15) is AIGE-CTL-DEPLOY-010.",
      "enforcementPoints": [
        "periodic"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Retention rule per evidence class, keyed to its obligation, with its storage and any legal hold",
          "schemaId": null,
          "schema": null,
          "layer": 5
        },
        {
          "artefact": "Signed evidence records kept on write-once storage",
          "schemaId": "evidence-record",
          "schema": "https://aigovernanceengineer.com/schemas/evidence-record.v1.json",
          "layer": 5
        }
      ],
      "failureResponse": {
        "effect": "deny",
        "text": "A legal hold overrides deletion: a record under hold is not deleted when its retention period ends."
      },
      "layer": 5,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "machine-readable-evidence-oscal",
          "title": "Machine-Readable Evidence (OSCAL)",
          "url": "https://aigovernanceengineer.com/patterns/machine-readable-evidence-oscal"
        }
      ],
      "seeds": [],
      "derivedFrom": [
        {
          "kind": "schema",
          "ref": "evidence-record",
          "url": "https://aigovernanceengineer.com/resources/templates#schema-evidence-record"
        },
        {
          "kind": "chapter",
          "ref": "governing-development",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        },
        {
          "kind": "chapter",
          "ref": "eu-ai-act",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART18",
            "name": "EU AI Act Art. 18 documentation keeping",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art18"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART19",
            "name": "EU AI Act Art. 19 automatically generated logs kept by the provider",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art19"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART12",
            "name": "EU AI Act Art. 12 record-keeping and logging",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art12"
          }
        ],
        "iso42001": [],
        "nistAiRmf": [],
        "owasp": [],
        "atlas": [],
        "aiuc1": [
          "E015"
        ],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 16,
          "title": "Governing AI development",
          "text": "Governing AI development (AI Governance Engineering Body of Knowledge v0.5.0, chapter 14, section \"Record keeping\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-development#record-keeping",
          "verified": "primary"
        },
        {
          "n": 17,
          "title": "The EU AI Act in one pass",
          "text": "The EU AI Act in one pass (AI Governance Engineering Body of Knowledge v0.5.0, chapter 18, section \"Conformity assessment, declaration, marking and registration\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act#conformity-assessment-declaration-marking-and-registration",
          "verified": "primary"
        },
        {
          "n": 3,
          "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744",
          "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744 (the articles each control maps to, as chapters 14 and 18 restate them). Publications Office of the EU (EUR-Lex). 2026-07-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng",
          "verified": "primary"
        },
        {
          "n": 9,
          "title": "AIUC-1 requirements",
          "text": "AIUC-1 requirements (public requirement index, A001 to F002, each requirement on its own page (E007 and E014 marked retired); AIUC-1 is a standard of the Artificial Intelligence Underwriting Company; this site is not affiliated with AIUC, and a mapping here is not an AIUC-1 certificate or audit). Artificial Intelligence Underwriting Company. 2026-09-24.",
          "url": "https://standard.aiuc-1.com/llms.txt",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Keep evidence in open formats (JSON, OSCAL): a 10-year horizon outlives most tools.",
        "Financial institutions keep the logs within their financial-services documentation (Art. 19); other law can set a period other than six months."
      ],
      "openQuestions": [
        "Verification procedure to be specified: the derivation adds no check its source material does not state; requires technical review.",
        "How should a write-once evidence store honour an erasure request for personal data inside a signed record without breaking the record's signature?"
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-ASSURE-009",
      "profile": "assurance-and-evidence",
      "url": "https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-009",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-assure-009.json",
      "title": "Internal Audit Answered from the Evidence Store",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "Internal audit of the AI management system is answered from one evidence store, the same one that answers internal audit for any management system run alongside ISO/IEC 42001, and each Annex A control listed as applicable points at the running control and the evidence stream that implement it.",
      "failureModes": [
        "Internal audit collects evidence by hand for each management system instead of querying one evidence store.",
        "An Annex A control listed as applicable in the Statement of Applicability points at no running control or evidence stream, or an exclusion carries no justification or owner.",
        "The internal audit programme does not cover the AI controls."
      ],
      "scope": "Organisations that run an AI management system to ISO/IEC 42001, alone or with ISO/IEC 27001, ISO/IEC 27701 or ISO 9001. What internal audit tests and how management review runs are not derived here: chapter 22 names clause 9 only as one evidence store answering internal audit.",
      "enforcementPoints": [
        "periodic"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Statement of Applicability generated from control metadata, each applicable control linked to its evidence stream, each exclusion with its justification and owner",
          "schemaId": null,
          "schema": null,
          "layer": 5
        },
        {
          "artefact": "Evidence records internal audit queries, filed under the registry id",
          "schemaId": "evidence-record",
          "schema": "https://aigovernanceengineer.com/schemas/evidence-record.v1.json",
          "layer": 5
        }
      ],
      "failureResponse": {
        "effect": "alert",
        "text": "To be specified: the source material states no failure response for this control."
      },
      "layer": 5,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "continuous-assurance-telemetry",
          "title": "Continuous Assurance Telemetry",
          "url": "https://aigovernanceengineer.com/patterns/continuous-assurance-telemetry"
        },
        {
          "slug": "machine-readable-evidence-oscal",
          "title": "Machine-Readable Evidence (OSCAL)",
          "url": "https://aigovernanceengineer.com/patterns/machine-readable-evidence-oscal"
        }
      ],
      "seeds": [],
      "derivedFrom": [
        {
          "kind": "pattern",
          "ref": "continuous-assurance-telemetry",
          "url": "https://aigovernanceengineer.com/patterns/continuous-assurance-telemetry"
        },
        {
          "kind": "pattern",
          "ref": "machine-readable-evidence-oscal",
          "url": "https://aigovernanceengineer.com/patterns/machine-readable-evidence-oscal"
        },
        {
          "kind": "chapter",
          "ref": "principles-and-standards",
          "url": "https://aigovernanceengineer.com/bok/principles-and-standards"
        }
      ],
      "mappings": {
        "obligations": [],
        "iso42001": [],
        "nistAiRmf": [],
        "owasp": [],
        "atlas": [],
        "aiuc1": [
          "E008"
        ],
        "csaAicm": [],
        "other": [
          {
            "framework": "ISO/IEC 42001:2023",
            "ref": "9",
            "note": "Performance evaluation: one evidence store answering internal audit (clause heading as chapter 22 names it)"
          }
        ]
      },
      "references": [
        {
          "n": 18,
          "title": "Principles, soft law and standards",
          "text": "Principles, soft law and standards (AI Governance Engineering Body of Knowledge v0.5.0, chapter 22, section \"Integrating with 27001, 27701 and 9001\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/principles-and-standards#integrating-with-27001-27701-and-9001",
          "verified": "primary"
        },
        {
          "n": 19,
          "title": "Principles, soft law and standards",
          "text": "Principles, soft law and standards (AI Governance Engineering Body of Knowledge v0.5.0, chapter 22, section \"The management-system trio\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/principles-and-standards#the-management-system-trio",
          "verified": "primary"
        },
        {
          "n": 11,
          "title": "Pattern: Continuous Assurance Telemetry",
          "text": "Pattern: Continuous Assurance Telemetry (AI Governance Engineering Body of Knowledge v0.5.0, chapter 05 pattern catalogue). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/patterns/continuous-assurance-telemetry",
          "verified": "primary"
        },
        {
          "n": 13,
          "title": "Pattern: Machine-Readable Evidence (OSCAL)",
          "text": "Pattern: Machine-Readable Evidence (OSCAL) (AI Governance Engineering Body of Knowledge v0.5.0, chapter 05 pattern catalogue). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/patterns/machine-readable-evidence-oscal",
          "verified": "primary"
        },
        {
          "n": 5,
          "title": "ISO/IEC 42001:2023, AI management systems",
          "text": "ISO/IEC 42001:2023, AI management systems (Annex A control ids and clause numbers cited by number and short title only; the text of the standard was not opened). ISO/IEC. 2023-12.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        },
        {
          "n": 9,
          "title": "AIUC-1 requirements",
          "text": "AIUC-1 requirements (public requirement index, A001 to F002, each requirement on its own page (E007 and E014 marked retired); AIUC-1 is a standard of the Artificial Intelligence Underwriting Company; this site is not affiliated with AIUC, and a mapping here is not an AIUC-1 certificate or audit). Artificial Intelligence Underwriting Company. 2026-09-24.",
          "url": "https://standard.aiuc-1.com/llms.txt",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Treat the Statement of Applicability as a generated file, not a document: each applicable Annex A control points at the running control and its evidence stream, and each exclusion carries its justification and an owner.",
        "Map each shared clause of the Harmonized Structure to one artefact serving every management system; for clause 9 that is one evidence store answering internal audit. In chapter 22's illustrative case, a team that held ISO/IEC 27001 added AI controls to its internal audit programme and generated the 42001 Statement of Applicability from the same control metadata."
      ],
      "openQuestions": [
        "Verification procedure to be specified: the derivation adds no check its source material does not state; requires technical review.",
        "Chapter 22 names clause 9 only at heading level: which inputs and outputs of internal audit and management review should this control cover once they are read against the standard?"
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-ASSURE-010",
      "profile": "assurance-and-evidence",
      "url": "https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-010",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-assure-010.json",
      "title": "Model Artefacts Signed at Build and Verified Before Load",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "Every model artefact is signed at build through a manifest of each file and its digest and carries build provenance (what built it, by what process, from which inputs), and a runtime loads it only after verifying the signature, the signer, the digests and the provenance against the registry entry of the version deployed, writing an evidence record either way.",
      "failureModes": [
        "A tampered or malicious model file loads with the privileges of the serving process.",
        "A model that skipped the eval gate reaches production through a manual copy or a moved tag.",
        "After an incident, nobody can prove which weights produced the outputs in question.",
        "A model is allowed or refused at load and no evidence record of the verification is written."
      ],
      "scope": "Model weights and their companion files, from training jobs to registries to serving clusters, including fine-tunes of bases pulled from public hubs. The artefacts an evaluation run loads are covered by AIGE-CTL-EVAL-008, and the admission of MCP servers by AIGE-CTL-AGENT-018.",
      "enforcementPoints": [
        "deploy",
        "runtime"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Signed manifest of every model file and its digest, with SLSA build provenance, recorded in the registry entry",
          "schemaId": null,
          "schema": null,
          "layer": 2
        },
        {
          "artefact": "Verification at load: signature, signer, file digests and provenance checked against the registry entry, with the decision",
          "schemaId": "evidence-record",
          "schema": "https://aigovernanceengineer.com/schemas/evidence-record.v1.json",
          "layer": 4
        }
      ],
      "failureResponse": {
        "effect": "deny",
        "text": "The serving platform's admission control refuses a model whose signature, signer identity, file digests or provenance do not match the registry entry, and writes an evidence record either way."
      },
      "layer": 2,
      "secondaryLayers": [
        4
      ],
      "patterns": [
        {
          "slug": "model-artefact-integrity",
          "title": "Model Artefact Integrity",
          "url": "https://aigovernanceengineer.com/patterns/model-artefact-integrity"
        },
        {
          "slug": "aibom",
          "title": "AIBOM",
          "url": "https://aigovernanceengineer.com/patterns/aibom"
        }
      ],
      "seeds": [],
      "derivedFrom": [
        {
          "kind": "pattern",
          "ref": "model-artefact-integrity",
          "url": "https://aigovernanceengineer.com/patterns/model-artefact-integrity"
        },
        {
          "kind": "schema",
          "ref": "evidence-record",
          "url": "https://aigovernanceengineer.com/resources/templates#schema-evidence-record"
        },
        {
          "kind": "chapter",
          "ref": "governing-development",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        }
      ],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART15",
            "name": "EU AI Act Art. 15 accuracy, robustness and cybersecurity",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART55",
            "name": "EU AI Act Art. 55 GPAI models with systemic risk",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art55"
          },
          {
            "id": "AIGE-OBL-ISO42001-A6",
            "name": "A.6 AI system life cycle",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a6"
          },
          {
            "id": "AIGE-OBL-ISO42001-A10",
            "name": "A.10 Third-party and customer relationships",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a10"
          },
          {
            "id": "AIGE-OBL-NISTRMF-MANAGE",
            "name": "MANAGE",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage"
          },
          {
            "id": "AIGE-OBL-OWASP-LLM",
            "name": "Top 10 for LLM Applications 2026",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-llm"
          },
          {
            "id": "AIGE-OBL-OWASP-AGENTIC",
            "name": "Top 10 for Agentic Applications 2026",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-agentic"
          }
        ],
        "iso42001": [
          {
            "id": "A.6.2.5",
            "title": "AI system deployment"
          },
          {
            "id": "A.10.3",
            "title": "Suppliers"
          }
        ],
        "nistAiRmf": [
          {
            "id": "MANAGE 3.2",
            "title": "Pre-trained models which are used for development are monitored as part of AI system regular monitoring and maintenance."
          },
          {
            "id": "MEASURE 2.7",
            "title": "Security and resilience are evaluated and documented"
          }
        ],
        "owasp": [
          {
            "id": "llm04-2026",
            "externalId": "LLM04:2026",
            "name": "Supply Chain",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-llm04-2026"
          },
          {
            "id": "asi04",
            "externalId": "ASI04",
            "name": "Agentic Supply Chain Vulnerabilities",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-asi04"
          }
        ],
        "atlas": [
          {
            "id": "aml-t0010",
            "externalId": "AML.T0010",
            "name": "AI Supply Chain Compromise",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-aml-t0010"
          }
        ],
        "aiuc1": [],
        "csaAicm": [],
        "other": [
          {
            "framework": "MITRE ATLAS mitigation",
            "ref": "AML.M0013",
            "note": "Code Signing"
          },
          {
            "framework": "MITRE ATLAS mitigation",
            "ref": "AML.M0014",
            "note": "Verify AI Artifacts"
          }
        ]
      },
      "references": [
        {
          "n": 20,
          "title": "Pattern: Model Artefact Integrity",
          "text": "Pattern: Model Artefact Integrity (AI Governance Engineering Body of Knowledge v0.5.0, chapter 05 pattern catalogue). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/patterns/model-artefact-integrity",
          "verified": "primary"
        },
        {
          "n": 7,
          "title": "Governing AI development",
          "text": "Governing AI development (AI Governance Engineering Body of Knowledge v0.5.0, chapter 14, section \"Reproducibility and linked versioning\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-development#reproducibility-and-linked-versioning",
          "verified": "primary"
        },
        {
          "n": 21,
          "title": "An Introduction to the OpenSSF Model Signing (OMS) Specification",
          "text": "An Introduction to the OpenSSF Model Signing (OMS) Specification (detached signature over a manifest of file hashes, in the Sigstore bundle format; PKI-agnostic). OpenSSF. 2025-06-25.",
          "url": "https://openssf.org/blog/2025/06/25/an-introduction-to-the-openssf-model-signing-oms-specification/",
          "verified": "primary"
        },
        {
          "n": 22,
          "title": "model-transparency: supply chain security for ML",
          "text": "model-transparency: supply chain security for ML (signs a statement of file paths and digests through Sigstore or conventional keys; verification recomputes the hashes). Sigstore (GitHub). 2026.",
          "url": "https://github.com/sigstore/model-transparency",
          "verified": "primary"
        },
        {
          "n": 23,
          "title": "SLSA specification v1.2, Build track basics",
          "text": "SLSA specification v1.2, Build track basics (Build L1 provenance exists, L2 hosted build platform, L3 hardened builds; provenance describes what built the artefact, by what process and from which top-level inputs). OpenSSF SLSA project. n.d. (accessed 2026-09-24).",
          "url": "https://slsa.dev/spec/v1.2/build-track-basics",
          "verified": "primary"
        },
        {
          "n": 24,
          "title": "OWASP GenAI LLM Top 10 2026",
          "text": "OWASP GenAI LLM Top 10 2026 (LLM01:2026 Prompt Injection to LLM10:2026 Improper Output Handling; resource page dated 3 Aug 2026). OWASP GenAI Security Project. 2026-08-03.",
          "url": "https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/",
          "verified": "primary"
        },
        {
          "n": 8,
          "title": "OWASP Top 10 for Agentic Applications for 2026",
          "text": "OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents). OWASP GenAI Security Project. 2025-12-09.",
          "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
          "verified": "primary"
        },
        {
          "n": 25,
          "title": "MITRE ATLAS data, release v2026.09",
          "text": "MITRE ATLAS data, release v2026.09 (16 tactics, 120 techniques, 88 sub-techniques, 40 mitigations; technique names and technique-to-mitigation links read from dist/v6/ATLAS-2026.09.yaml). MITRE. 2026-09-15.",
          "url": "https://github.com/mitre-atlas/atlas-data/releases/tag/v2026.09",
          "verified": "primary"
        },
        {
          "n": 4,
          "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1",
          "text": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (MEASURE and MANAGE subcategories cited by id, mapped only where the official text matches the control). NIST. 2023-01-26.",
          "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
          "verified": "primary"
        },
        {
          "n": 5,
          "title": "ISO/IEC 42001:2023, AI management systems",
          "text": "ISO/IEC 42001:2023, AI management systems (Annex A control ids and clause numbers cited by number and short title only; the text of the standard was not opened). ISO/IEC. 2023-12.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        },
        {
          "n": 3,
          "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744",
          "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744 (the articles each control maps to, as chapters 14 and 18 restate them). Publications Office of the EU (EUR-Lex). 2026-07-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Sign a manifest of file digests at build: the OpenSSF Model Signing (OMS) specification puts a detached signature over such a manifest in the Sigstore bundle format and is PKI-agnostic; its reference implementation, model-signing, recomputes the hashes on verification.",
        "Record provenance as SLSA provenance (https://slsa.dev/provenance/v1): Build L1 means provenance exists, L2 a hosted build platform and L3 hardened builds. Include the base model digest and the dataset admission records among the inputs, and list the same artefacts in the AIBOM.",
        "Budget for the verification latency at load, small next to model load times but real for fast scale-out; the pattern's example found a hand-copied model that had never passed the current eval gate, refused on a digest mismatch."
      ],
      "openQuestions": [
        "Verification procedure to be specified: the derivation adds no check its source material does not state; requires technical review.",
        "Which SLSA Build level should a model build reach before its provenance is trusted at load, and should that depend on the risk tier of the system?"
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-ASSURE-011",
      "profile": "assurance-and-evidence",
      "url": "https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-011",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-assure-011.json",
      "title": "Safe Model Formats and Digest-Pinned Third-Party Models",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "Model weights are stored in a format that cannot execute code on load (safetensors); every file in a code-executing format is scanned for code-executing imports before it reaches a registry and quarantined if it fails; third-party models are pulled by content digest, not by tag, re-hosted internally and recorded with their upstream source and digest in the registry entry.",
      "failureModes": [
        "A pickle file runs code when it is loaded: the Python documentation warns that the pickle module is not secure.",
        "A file in a code-executing format reaches a registry unscanned, or after a failed scan.",
        "A third-party model is pulled by name or tag, and the tag has since moved."
      ],
      "scope": "Every serialised model file admitted to an internal registry, and every third-party model or base model pulled from outside. Signature and provenance checks at load are AIGE-CTL-ASSURE-010.",
      "enforcementPoints": [
        "deploy"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Scan result for code-executing imports per serialised file, with the quarantine decision",
          "schemaId": "evidence-record",
          "schema": "https://aigovernanceengineer.com/schemas/evidence-record.v1.json",
          "layer": 2
        },
        {
          "artefact": "Upstream source and content digest of each third-party model, recorded in its registry entry",
          "schemaId": null,
          "schema": null,
          "layer": 2
        }
      ],
      "failureResponse": {
        "effect": "deny",
        "text": "A serialised file that fails the scan for code-executing imports is quarantined and does not reach the registry."
      },
      "layer": 2,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "model-artefact-integrity",
          "title": "Model Artefact Integrity",
          "url": "https://aigovernanceengineer.com/patterns/model-artefact-integrity"
        }
      ],
      "seeds": [],
      "derivedFrom": [
        {
          "kind": "pattern",
          "ref": "model-artefact-integrity",
          "url": "https://aigovernanceengineer.com/patterns/model-artefact-integrity"
        },
        {
          "kind": "chapter",
          "ref": "governing-development",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        }
      ],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART15",
            "name": "EU AI Act Art. 15 accuracy, robustness and cybersecurity",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15"
          },
          {
            "id": "AIGE-OBL-ISO42001-A10",
            "name": "A.10 Third-party and customer relationships",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a10"
          },
          {
            "id": "AIGE-OBL-OWASP-LLM",
            "name": "Top 10 for LLM Applications 2026",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-llm"
          }
        ],
        "iso42001": [
          {
            "id": "A.10.3",
            "title": "Suppliers"
          }
        ],
        "nistAiRmf": [],
        "owasp": [
          {
            "id": "llm04-2026",
            "externalId": "LLM04:2026",
            "name": "Supply Chain",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-llm04-2026"
          },
          {
            "id": "asi04",
            "externalId": "ASI04",
            "name": "Agentic Supply Chain Vulnerabilities",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-asi04"
          }
        ],
        "atlas": [
          {
            "id": "aml-t0010",
            "externalId": "AML.T0010",
            "name": "AI Supply Chain Compromise",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-aml-t0010"
          }
        ],
        "aiuc1": [],
        "csaAicm": [],
        "other": [
          {
            "framework": "MITRE ATLAS mitigation",
            "ref": "AML.M0016",
            "note": "Vulnerability Scanning"
          }
        ]
      },
      "references": [
        {
          "n": 20,
          "title": "Pattern: Model Artefact Integrity",
          "text": "Pattern: Model Artefact Integrity (AI Governance Engineering Body of Knowledge v0.5.0, chapter 05 pattern catalogue). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/patterns/model-artefact-integrity",
          "verified": "primary"
        },
        {
          "n": 7,
          "title": "Governing AI development",
          "text": "Governing AI development (AI Governance Engineering Body of Knowledge v0.5.0, chapter 14, section \"Reproducibility and linked versioning\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-development#reproducibility-and-linked-versioning",
          "verified": "primary"
        },
        {
          "n": 26,
          "title": "pickle: Python object serialization",
          "text": "pickle: Python object serialization (\"The pickle module is not secure. Only unpickle data you trust.\"). Python Software Foundation. 2026.",
          "url": "https://docs.python.org/3/library/pickle.html",
          "verified": "primary"
        },
        {
          "n": 27,
          "title": "Pickle Scanning",
          "text": "Pickle Scanning (arbitrary code execution when loading pickle files; the Hub's pickle-import scan \"is not 100% foolproof\"). Hugging Face Hub documentation. n.d. (accessed 2026-09-24).",
          "url": "https://huggingface.co/docs/hub/security-pickle",
          "verified": "primary"
        },
        {
          "n": 28,
          "title": "Safetensors",
          "text": "Safetensors (\"a new simple format for storing tensors safely (as opposed to pickle)\"). Hugging Face documentation. n.d. (accessed 2026-09-24).",
          "url": "https://huggingface.co/docs/safetensors/index",
          "verified": "primary"
        },
        {
          "n": 29,
          "title": "torch.load",
          "text": "torch.load (default weights_only=True; \"Never load data from an untrusted source\"). PyTorch documentation (2.14). n.d. (accessed 2026-09-24).",
          "url": "https://docs.pytorch.org/docs/stable/generated/torch.load.html",
          "verified": "primary"
        },
        {
          "n": 24,
          "title": "OWASP GenAI LLM Top 10 2026",
          "text": "OWASP GenAI LLM Top 10 2026 (LLM01:2026 Prompt Injection to LLM10:2026 Improper Output Handling; resource page dated 3 Aug 2026). OWASP GenAI Security Project. 2026-08-03.",
          "url": "https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/",
          "verified": "primary"
        },
        {
          "n": 8,
          "title": "OWASP Top 10 for Agentic Applications for 2026",
          "text": "OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents). OWASP GenAI Security Project. 2025-12-09.",
          "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
          "verified": "primary"
        },
        {
          "n": 25,
          "title": "MITRE ATLAS data, release v2026.09",
          "text": "MITRE ATLAS data, release v2026.09 (16 tactics, 120 techniques, 88 sub-techniques, 40 mitigations; technique names and technique-to-mitigation links read from dist/v6/ATLAS-2026.09.yaml). MITRE. 2026-09-15.",
          "url": "https://github.com/mitre-atlas/atlas-data/releases/tag/v2026.09",
          "verified": "primary"
        },
        {
          "n": 5,
          "title": "ISO/IEC 42001:2023, AI management systems",
          "text": "ISO/IEC 42001:2023, AI management systems (Annex A control ids and clause numbers cited by number and short title only; the text of the standard was not opened). ISO/IEC. 2023-12.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        },
        {
          "n": 3,
          "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744",
          "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744 (the articles each control maps to, as chapters 14 and 18 restate them). Publications Office of the EU (EUR-Lex). 2026-07-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Where a framework still loads pickle, keep its restrictions on: torch.load defaults to weights_only=True in its current documentation and warns \"Never load data from an untrusted source\".",
        "Do not rely on the scan alone: Hugging Face says of its own pickle-import scanner that it \"is not 100% foolproof\". Convert legacy checkpoints to safetensors, and verify the publisher's signature on a third-party model where one exists."
      ],
      "openQuestions": [
        "Verification procedure to be specified: the derivation adds no check its source material does not state; requires technical review.",
        "How should a legacy checkpoint that cannot be converted to safetensors be handled: blocked, or admitted after a scan with a named acceptor of the risk?"
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-ASSURE-012",
      "profile": "assurance-and-evidence",
      "url": "https://aigovernanceengineer.com/controls/assurance-and-evidence#aige-ctl-assure-012",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-assure-012.json",
      "title": "AI Bill of Materials per Build",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "Each AI system has an AI bill of materials generated at build in a standard format (CycloneDX ML-BOM or the SPDX 3.0 AI profile), recording its models, datasets and weights with their provenance and licences, attached to its registry entry and regenerated on each build so it never drifts from the deployed system.",
      "failureModes": [
        "Nobody can say which model version, from which provenance, trained on which data, is inside a given system.",
        "The AIBOM was written once and no longer matches the deployed system.",
        "A licence or provenance change in a model or dataset does not show in the next build's AIBOM.",
        "The registry entry of the system links no AIBOM."
      ],
      "scope": "AI systems assembled from foundation models, fine-tunes, third-party datasets and libraries. The software dependencies a classic SBOM already captures are out of scope.",
      "enforcementPoints": [
        "deploy"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "AIBOM of each build (CycloneDX ML-BOM or SPDX 3.0 AI profile), linked from the registry entry",
          "schemaId": "ai-system-register-entry",
          "schema": "https://aigovernanceengineer.com/schemas/ai-system-register-entry.v1.json",
          "layer": 2
        }
      ],
      "failureResponse": {
        "effect": "alert",
        "text": "To be specified: the source material states no failure response for this control."
      },
      "layer": 2,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "aibom",
          "title": "AIBOM",
          "url": "https://aigovernanceengineer.com/patterns/aibom"
        }
      ],
      "seeds": [],
      "derivedFrom": [
        {
          "kind": "pattern",
          "ref": "aibom",
          "url": "https://aigovernanceengineer.com/patterns/aibom"
        },
        {
          "kind": "schema",
          "ref": "ai-system-register-entry",
          "url": "https://aigovernanceengineer.com/resources/templates#schema-ai-system-register-entry"
        },
        {
          "kind": "chapter",
          "ref": "governing-development",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        }
      ],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART11",
            "name": "EU AI Act Art. 11 technical documentation (Annex IV)",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art11"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART53",
            "name": "EU AI Act Art. 53 GPAI provider obligations",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art53"
          },
          {
            "id": "AIGE-OBL-OWASP-AIBOM",
            "name": "AIBOM",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-aibom"
          },
          {
            "id": "AIGE-OBL-NISTRMF-MAP",
            "name": "MAP",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-map"
          },
          {
            "id": "AIGE-OBL-CSA-AICM",
            "name": "AICM v1.1: 247 control objectives across 18 domains",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-csa-aicm"
          }
        ],
        "iso42001": [
          {
            "id": "A.7.5",
            "title": "Data provenance"
          },
          {
            "id": "A.10.3",
            "title": "Suppliers"
          }
        ],
        "nistAiRmf": [],
        "owasp": [
          {
            "id": "llm04-2026",
            "externalId": "LLM04:2026",
            "name": "Supply Chain",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-llm04-2026"
          }
        ],
        "atlas": [
          {
            "id": "aml-t0010",
            "externalId": "AML.T0010",
            "name": "AI Supply Chain Compromise",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-aml-t0010"
          }
        ],
        "aiuc1": [],
        "csaAicm": [],
        "other": [
          {
            "framework": "MITRE ATLAS mitigation",
            "ref": "AML.M0023",
            "note": "AI Bill of Materials"
          }
        ]
      },
      "references": [
        {
          "n": 30,
          "title": "Pattern: AIBOM",
          "text": "Pattern: AIBOM (AI Governance Engineering Body of Knowledge v0.5.0, chapter 05 pattern catalogue). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/patterns/aibom",
          "verified": "primary"
        },
        {
          "n": 31,
          "title": "Governing AI development",
          "text": "Governing AI development (AI Governance Engineering Body of Knowledge v0.5.0, chapter 14, section \"Annex IV, element by element\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-development#annex-iv-element-by-element",
          "verified": "primary"
        },
        {
          "n": 32,
          "title": "Evolving AI Transparency: the AIBOM generator's new home at OWASP",
          "text": "Evolving AI Transparency: the AIBOM generator's new home at OWASP (OWASP AIBOM generator, CycloneDX output). OWASP GenAI Security Project. 2025-12-18.",
          "url": "https://genai.owasp.org/2025/12/18/evolving-ai-transparency-the-journey-of-the-aibom-generator-and-its-new-home-at-owasp/",
          "verified": "primary"
        },
        {
          "n": 24,
          "title": "OWASP GenAI LLM Top 10 2026",
          "text": "OWASP GenAI LLM Top 10 2026 (LLM01:2026 Prompt Injection to LLM10:2026 Improper Output Handling; resource page dated 3 Aug 2026). OWASP GenAI Security Project. 2026-08-03.",
          "url": "https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/",
          "verified": "primary"
        },
        {
          "n": 25,
          "title": "MITRE ATLAS data, release v2026.09",
          "text": "MITRE ATLAS data, release v2026.09 (16 tactics, 120 techniques, 88 sub-techniques, 40 mitigations; technique names and technique-to-mitigation links read from dist/v6/ATLAS-2026.09.yaml). MITRE. 2026-09-15.",
          "url": "https://github.com/mitre-atlas/atlas-data/releases/tag/v2026.09",
          "verified": "primary"
        },
        {
          "n": 5,
          "title": "ISO/IEC 42001:2023, AI management systems",
          "text": "ISO/IEC 42001:2023, AI management systems (Annex A control ids and clause numbers cited by number and short title only; the text of the standard was not opened). ISO/IEC. 2023-12.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        },
        {
          "n": 3,
          "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744",
          "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744 (the articles each control maps to, as chapters 14 and 18 restate them). Publications Office of the EU (EUR-Lex). 2026-07-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Generate the AIBOM in the build, for example with the OWASP AIBOM generator (illustrative), covering models, datasets and weights with their provenance and licences.",
        "Transparency documents can be generated from the AIBOM, as the pattern notes; chapter 14 draws Annex IV items 1(b) and 1(c) (interaction with other systems; software versions) from it."
      ],
      "openQuestions": [
        "Verification procedure to be specified: the derivation adds no check its source material does not state; requires technical review.",
        "Should a build fail when its AIBOM changes in a way nobody approved (a new model, dataset or licence), or only flag the difference for review?"
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-DEPLOY-001",
      "profile": "deployment-and-monitoring",
      "url": "https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-001",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-deploy-001.json",
      "title": "Deployment decision record before use",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "Before an AI system is put to use in a context, a Deployment Decision Record states the objective, what the system is not for (its negative space), the risk tier and obligations, the performance floors including per group, the retirement conditions and the owner, checks the deployer duties one by one, records the decision and who took it, and is referenced from the registry entry.",
      "failureModes": [
        "A system serves in production with no decision record, or with one that no registry entry references.",
        "The record names no negative space, so a new use (the chapter's example: HR queries routed to a customer-service assistant) arrives as a quiet configuration change instead of a new intake.",
        "Performance floors are set after a vendor demonstration, or only as an average, so a good overall figure hides a group the system fails."
      ],
      "scope": "Every AI system an organisation puts to use in a given context, built or procured. A new use of an existing system is a new decision.",
      "enforcementPoints": [
        "deploy"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Signed Deployment Decision Record, committed next to the system and linked from its registry entry",
          "schemaId": "deployment-decision-record",
          "schema": "https://aigovernanceengineer.com/schemas/deployment-decision-record.v1.json",
          "layer": 2
        }
      ],
      "failureResponse": {
        "effect": "require_approval",
        "text": "A proposed use that the record does not cover, or that falls in its negative space, goes back through intake and classification before it proceeds."
      },
      "layer": 2,
      "secondaryLayers": [
        1
      ],
      "patterns": [],
      "seeds": [],
      "derivedFrom": [
        {
          "kind": "schema",
          "ref": "deployment-decision-record",
          "url": "https://aigovernanceengineer.com/resources/templates#schema-deployment-decision-record"
        },
        {
          "kind": "chapter",
          "ref": "governing-deployment",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        }
      ],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART26",
            "name": "EU AI Act Art. 26 deployer obligations for high-risk systems",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26"
          }
        ],
        "iso42001": [
          {
            "id": "A.6.2.5",
            "title": "AI system deployment"
          },
          {
            "id": "A.9.4",
            "title": "Intended use of the AI system"
          }
        ],
        "nistAiRmf": [
          {
            "id": "MAP 1.1",
            "title": "Intended purposes, potentially beneficial uses, context-specific laws, norms and expectations, and prospective settings in which the AI system will be deployed are understood and documented."
          },
          {
            "id": "MANAGE 1.1",
            "title": "A determination is made as to whether the AI system achieves its intended purposes and stated objectives and whether its development or deployment should proceed."
          }
        ],
        "owasp": [],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 1,
          "title": "Governing deployment and use",
          "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"The Deployment Decision Record\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment#the-deployment-decision-record",
          "verified": "primary"
        },
        {
          "n": 2,
          "title": "Governing deployment and use",
          "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"Start from the use case, not the model\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment#start-from-the-use-case-not-the-model",
          "verified": "primary"
        },
        {
          "n": 3,
          "title": "Governing deployment and use",
          "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"Set performance and explainability requirements first\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment#set-performance-and-explainability-requirements-first",
          "verified": "primary"
        },
        {
          "n": 4,
          "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 26",
          "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 26 (deployer obligations: 26(1) use per the instructions; 26(2) oversight by competent persons with authority; 26(5) monitor, suspend and inform, serious incidents to the provider first; 26(6) logs kept at least six months). Publications Office of the EU (EUR-Lex). 2026-07-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_26",
          "verified": "primary"
        },
        {
          "n": 5,
          "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
          "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        },
        {
          "n": 6,
          "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1",
          "text": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (subcategories cited by id: GOVERN 1.6, 1.7, 2.2, 6.1; MAP 1.1, 3.5; MEASURE 2.3, 2.4, 2.11, 3.1; MANAGE 1.1, 2.4, 3.1, 4.1, 4.3). NIST. 2023-01-26.",
          "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "The record's floors become the thresholds of the eval gate (layer 03) and its negative space becomes the scope the runtime watches (layer 04).",
        "Set the requirements before looking at candidates: metrics that match the harm, a floor per population the system acts on, go/no-go thresholds each traced to the failure mode it stands for, and the explanation the use needs."
      ],
      "openQuestions": [
        "Verification procedure to be specified: the source material states what the control produces, not how a third party checks it; requires technical review.",
        "The deployment decision record schema has no dedicated field for the negative space or the retirement conditions the chapter puts in the record; whether they belong in the deployment context, the conditions or extensions awaits review."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-DEPLOY-002",
      "profile": "deployment-and-monitoring",
      "url": "https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-002",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-deploy-002.json",
      "title": "Instructions for use held and followed",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "The deployer holds the provider's instructions for use for the version it runs, records the gaps it finds in them and what it could not verify, and uses the system in line with them: its monitoring hooks, oversight measures, input data and log collection follow what the instructions state, and its maintenance calendar starts from the lifetime and maintenance they declare.",
      "failureModes": [
        "The system runs with no instructions for use on record for the version in production.",
        "The go-live review accepts the provider's own evidence without recording what the deployer could not verify.",
        "A metric the instructions name has no monitoring hook, or the system receives input data the instructions say it must not receive."
      ],
      "scope": "Deployers of AI systems supplied with instructions for use, in particular high-risk systems, whose providers must supply them. Writing the instructions is the provider's side and out of scope, except where the deployer is also the provider.",
      "enforcementPoints": [
        "deploy"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Instructions for use on record for the running version, referenced from the deployment decision record with the gaps found in them",
          "schemaId": "instructions-for-use",
          "schema": "https://aigovernanceengineer.com/schemas/instructions-for-use.v1.json",
          "layer": 2
        }
      ],
      "failureResponse": {
        "effect": "require_approval",
        "text": "Gaps in the instructions, and what the deployer could not verify, are recorded and go to the go-live review, which decides on them explicitly."
      },
      "layer": 2,
      "secondaryLayers": [],
      "patterns": [],
      "seeds": [],
      "derivedFrom": [
        {
          "kind": "schema",
          "ref": "instructions-for-use",
          "url": "https://aigovernanceengineer.com/resources/templates#schema-instructions-for-use"
        },
        {
          "kind": "schema",
          "ref": "deployment-decision-record",
          "url": "https://aigovernanceengineer.com/resources/templates#schema-deployment-decision-record"
        },
        {
          "kind": "chapter",
          "ref": "governing-deployment",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        },
        {
          "kind": "chapter",
          "ref": "incidents",
          "url": "https://aigovernanceengineer.com/bok/incidents"
        }
      ],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART26",
            "name": "EU AI Act Art. 26 deployer obligations for high-risk systems",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART13",
            "name": "EU AI Act Art. 13 transparency and information to deployers",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art13"
          }
        ],
        "iso42001": [
          {
            "id": "A.8.2",
            "title": "System documentation and information for users"
          }
        ],
        "nistAiRmf": [],
        "owasp": [],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 7,
          "title": "Governing deployment and use",
          "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"What the review reads\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment#what-the-review-reads",
          "verified": "primary"
        },
        {
          "n": 8,
          "title": "Governing deployment and use",
          "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"Maintenance calendar and retraining governance\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment#maintenance-calendar-and-retraining-governance",
          "verified": "primary"
        },
        {
          "n": 9,
          "title": "Incidents, issues and root causes",
          "text": "Incidents, issues and root causes (AI Governance Engineering Body of Knowledge v0.5.0, chapter 17, section \"Deployer duties: inform the provider, suspend use\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/incidents#deployer-duties-inform-the-provider-suspend-use",
          "verified": "primary"
        },
        {
          "n": 4,
          "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 26",
          "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 26 (deployer obligations: 26(1) use per the instructions; 26(2) oversight by competent persons with authority; 26(5) monitor, suspend and inform, serious incidents to the provider first; 26(6) logs kept at least six months). Publications Office of the EU (EUR-Lex). 2026-07-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_26",
          "verified": "primary"
        },
        {
          "n": 10,
          "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 13",
          "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 13 (instructions for use: capabilities and limitations of performance; pre-determined changes; human oversight measures; expected lifetime and maintenance; log collection). Publications Office of the EU (EUR-Lex). 2026-07-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_13",
          "verified": "primary"
        },
        {
          "n": 5,
          "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
          "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        }
      ],
      "implementationNotes": [
        "When the evidence is the provider's own, run the go-live review in review mode: assess the supplier's assessment and record, explicitly, what the deployer could not verify.",
        "Build a monitoring hook, with its threshold as code, for each metric the provider's instructions name (layer 04)."
      ],
      "openQuestions": [
        "Verification procedure to be specified: the source material states what the control produces, not how a third party checks it; requires technical review.",
        "Whether a revised version of the instructions re-opens the go-live review, or only the gaps it changes, is not settled by the source material."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-DEPLOY-003",
      "profile": "deployment-and-monitoring",
      "url": "https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-003",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-deploy-003.json",
      "title": "Oversight by trained people with authority to stop",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "Oversight of the deployed system is assigned to named people with the competence, training and authority it needs, and the support to use it: role-based training (what the system is for, the limitations its instructions declare, when to override it, how to report a problem) is a condition of access, and an operator who sees the system misbehave may stop it without first asking permission.",
      "failureModes": [
        "The decision record names no oversight roles, or names roles with no training record behind them.",
        "A person gets or keeps access to the system with no current training record for the role.",
        "An operator who sees the system misbehave has to ask for permission before pausing it.",
        "Oversight is undifferentiated: every output waits for review, which destroys the value of the system, or none does, which removes the oversight the risk requires."
      ],
      "scope": "Deployed AI systems whose outputs inform or take decisions that people oversee, in particular high-risk systems. For AI agents, the checkpoint and approval controls of the Agent Runtime profile apply as well, and for an agent with an Annex III purpose AIGE-CTL-AGENT-030 restates the same oversight duty.",
      "enforcementPoints": [
        "deploy",
        "runtime"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Role-based training records whose grants field the access check reads",
          "schemaId": "training-record",
          "schema": "https://aigovernanceengineer.com/schemas/training-record.v1.json",
          "layer": 4
        },
        {
          "artefact": "Oversight roles and the ids of their training records in the deployment decision record",
          "schemaId": "deployment-decision-record",
          "schema": "https://aigovernanceengineer.com/schemas/deployment-decision-record.v1.json",
          "layer": 2
        }
      ],
      "failureResponse": {
        "effect": "deny",
        "text": "Access to the system is refused while the person holds no current training record for the role."
      },
      "layer": 4,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "human-in-the-loop-gate",
          "title": "Human-in-the-loop Gate",
          "url": "https://aigovernanceengineer.com/patterns/human-in-the-loop-gate"
        }
      ],
      "seeds": [],
      "derivedFrom": [
        {
          "kind": "pattern",
          "ref": "human-in-the-loop-gate",
          "url": "https://aigovernanceengineer.com/patterns/human-in-the-loop-gate"
        },
        {
          "kind": "schema",
          "ref": "training-record",
          "url": "https://aigovernanceengineer.com/resources/templates#schema-training-record"
        },
        {
          "kind": "schema",
          "ref": "deployment-decision-record",
          "url": "https://aigovernanceengineer.com/resources/templates#schema-deployment-decision-record"
        },
        {
          "kind": "chapter",
          "ref": "governing-deployment",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        }
      ],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART26-2",
            "name": "EU AI Act Art. 26(2) human oversight assigned to persons with competence, training and authority",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26-2"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART14",
            "name": "EU AI Act Art. 14 human oversight",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art14"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART4",
            "name": "EU AI Act Art. 4 AI literacy",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art4"
          }
        ],
        "iso42001": [
          {
            "id": "A.9.2",
            "title": "Processes for responsible use of AI systems"
          }
        ],
        "nistAiRmf": [
          {
            "id": "MAP 3.5",
            "title": "Processes for human oversight are defined, assessed, and documented in accordance with organizational policies from the GOVERN function."
          }
        ],
        "owasp": [],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 11,
          "title": "Governing deployment and use",
          "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"Check the data and the people\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment#check-the-data-and-the-people",
          "verified": "primary"
        },
        {
          "n": 12,
          "title": "Governing deployment and use",
          "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"Policies at go-live\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment#policies-at-go-live",
          "verified": "primary"
        },
        {
          "n": 13,
          "title": "Pattern: Human-in-the-loop Gate",
          "text": "Pattern: Human-in-the-loop Gate (AI Governance Engineering Body of Knowledge v0.5.0, pattern catalogue (chapter 05)). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/patterns/human-in-the-loop-gate",
          "verified": "primary"
        },
        {
          "n": 4,
          "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 26",
          "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 26 (deployer obligations: 26(1) use per the instructions; 26(2) oversight by competent persons with authority; 26(5) monitor, suspend and inform, serious incidents to the provider first; 26(6) logs kept at least six months). Publications Office of the EU (EUR-Lex). 2026-07-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_26",
          "verified": "primary"
        },
        {
          "n": 14,
          "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 14",
          "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 14 (human oversight of high-risk systems). Publications Office of the EU (EUR-Lex). 2026-07-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_14",
          "verified": "primary"
        },
        {
          "n": 15,
          "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 4",
          "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 4 (providers and deployers take measures to support the AI literacy of their staff). Publications Office of the EU (EUR-Lex). 2026-07-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_4",
          "verified": "primary"
        },
        {
          "n": 5,
          "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
          "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        },
        {
          "n": 6,
          "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1",
          "text": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (subcategories cited by id: GOVERN 1.6, 1.7, 2.2, 6.1; MAP 1.1, 3.5; MEASURE 2.3, 2.4, 2.11, 3.1; MANAGE 1.1, 2.4, 3.1, 4.1, 4.3). NIST. 2023-01-26.",
          "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Classify outputs or actions by consequence: gate the high-consequence class behind a person with enough context to decide, keep the routine class autonomous under guardrails, and log the approver, the context and the decision as evidence.",
        "Pair the training with interface aids that support judgement rather than replace it: sources shown, confidence where it is meaningful, and a visible way to reach a person."
      ],
      "openQuestions": [
        "Verification procedure to be specified: the source material states what the control produces, not how a third party checks it; requires technical review.",
        "The training record carries an expiry, but the source material sets no refresher interval per oversight role."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-DEPLOY-004",
      "profile": "deployment-and-monitoring",
      "url": "https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-004",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-deploy-004.json",
      "title": "Go-live decision with conditions as code",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "A go-live review reads an evidence pack and records one of three outcomes (approve, approve with conditions, reject) with the approver and the residual risk, accepted by an authority that matches the risk tier; each condition is a check with an owner and a deadline, the approval lapses when a check has not passed in time, and any member of the review can attach named dissent to the decision record.",
      "failureModes": [
        "A condition is granted and forgotten: its deadline passes with no check, and the approval keeps running.",
        "Residual risk is accepted by the team that wants to ship rather than by an authority that matches the risk tier.",
        "A checklist item is marked met with no link to the record that answers it, or a management override is not recorded.",
        "Dissent raised in the review is not attached to the decision, so the incident review cannot tell whether anyone saw the problem coming."
      ],
      "scope": "Every release that takes an AI system, or a new version of it, into use: a new system, a major or minor change, a retrain or a rollback, the change types the go/no-go record distinguishes.",
      "enforcementPoints": [
        "deploy"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Go/no-go record: checklist items linked to the records that answer them, reviewers' decisions by role, overrides, conditions, residual risk and the rollout plan",
          "schemaId": "go-no-go",
          "schema": "https://aigovernanceengineer.com/schemas/go-no-go.v1.json",
          "layer": 5
        }
      ],
      "failureResponse": {
        "effect": "deny",
        "text": "A rejected release is blocked and its registry status reads rejected; when a condition's check has not passed by its deadline, the approval lapses and the feature flag closes."
      },
      "layer": 5,
      "secondaryLayers": [
        1
      ],
      "patterns": [],
      "seeds": [],
      "derivedFrom": [
        {
          "kind": "schema",
          "ref": "go-no-go",
          "url": "https://aigovernanceengineer.com/resources/templates#schema-go-no-go"
        },
        {
          "kind": "chapter",
          "ref": "governing-deployment",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        }
      ],
      "mappings": {
        "obligations": [],
        "iso42001": [
          {
            "id": "A.6.2.5",
            "title": "AI system deployment"
          }
        ],
        "nistAiRmf": [
          {
            "id": "MANAGE 1.1",
            "title": "A determination is made as to whether the AI system achieves its intended purposes and stated objectives and whether its development or deployment should proceed."
          }
        ],
        "owasp": [],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 7,
          "title": "Governing deployment and use",
          "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"What the review reads\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment#what-the-review-reads",
          "verified": "primary"
        },
        {
          "n": 16,
          "title": "Governing deployment and use",
          "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"Three outcomes\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment#three-outcomes",
          "verified": "primary"
        },
        {
          "n": 17,
          "title": "Governing deployment and use",
          "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"Recorded dissent\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment#recorded-dissent",
          "verified": "primary"
        },
        {
          "n": 5,
          "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
          "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        },
        {
          "n": 6,
          "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1",
          "text": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (subcategories cited by id: GOVERN 1.6, 1.7, 2.2, 6.1; MAP 1.1, 3.5; MEASURE 2.3, 2.4, 2.11, 3.1; MANAGE 1.1, 2.4, 3.1, 4.1, 4.3). NIST. 2023-01-26.",
          "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Make each condition code: a feature flag caps exposure while the condition holds, and the approval carries an expiry.",
        "Review recorded dissent at the first monitoring review after go-live, and close it with the evidence that answered it."
      ],
      "openQuestions": [
        "Verification procedure to be specified: the source material states what the control produces, not how a third party checks it; requires technical review.",
        "The go/no-go schema has no field of its own for dissent; whether it belongs in the reviewers list, the overrides or extensions awaits review.",
        "No EU AI Act obligation is mapped: the go-live review is chapter 15 practice rather than a single article, and the mapping awaits review."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-DEPLOY-005",
      "profile": "deployment-and-monitoring",
      "url": "https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-005",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-deploy-005.json",
      "title": "Staged rollout with pre-registered rollback criteria",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "Every change to a deployed AI system (a new model, a retrain, a prompt or corpus change, a new vendor model version) reaches production through shadow, pilot, canary and general availability stages, each with rollback criteria signed before it starts and evaluated by the pipeline, which writes a promote, hold or roll-back verdict per stage to the assurance store.",
      "failureModes": [
        "A change goes from the eval harness to all traffic at once, so the first evidence about live behaviour is the harm itself.",
        "A rollback criterion is written or loosened after the metric moved, or a threshold is edited on a dashboard rather than through a reviewed diff with an approver.",
        "A criterion trips and the rollback waits for a meeting instead of the pipeline acting on it.",
        "Criteria are checked only in aggregate, so a regression for one group (the pattern's example: one language) passes the canary."
      ],
      "scope": "Changes to deployed AI systems that can move quality, safety or fairness, including changes that touch no line of the deployer's code. At general availability the criteria stay on as live monitors.",
      "enforcementPoints": [
        "deploy",
        "runtime"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Rollout plan registered before the first stage, stage verdicts and rollback events in the assurance store, summarised in the rollout field of the go/no-go record",
          "schemaId": "go-no-go",
          "schema": "https://aigovernanceengineer.com/schemas/go-no-go.v1.json",
          "layer": 4
        }
      ],
      "failureResponse": {
        "effect": "deny",
        "text": "A tripped criterion stops promotion and returns the exposed cohort to the baseline; the stage verdict and the rollback event are recorded before anyone meets."
      },
      "layer": 4,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "staged-rollout-rollback-criteria",
          "title": "Staged Rollout with Rollback Criteria",
          "url": "https://aigovernanceengineer.com/patterns/staged-rollout-rollback-criteria"
        }
      ],
      "seeds": [],
      "derivedFrom": [
        {
          "kind": "pattern",
          "ref": "staged-rollout-rollback-criteria",
          "url": "https://aigovernanceengineer.com/patterns/staged-rollout-rollback-criteria"
        },
        {
          "kind": "schema",
          "ref": "go-no-go",
          "url": "https://aigovernanceengineer.com/resources/templates#schema-go-no-go"
        },
        {
          "kind": "chapter",
          "ref": "governing-deployment",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        }
      ],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART26-5",
            "name": "EU AI Act Art. 26(5) deployer monitoring, suspension and informing the provider",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26-5"
          }
        ],
        "iso42001": [
          {
            "id": "A.6.2.5",
            "title": "AI system deployment"
          },
          {
            "id": "A.6.2.6",
            "title": "AI system operation and monitoring"
          }
        ],
        "nistAiRmf": [
          {
            "id": "MANAGE 1.1",
            "title": "A determination is made as to whether the AI system achieves its intended purposes and stated objectives and whether its development or deployment should proceed."
          },
          {
            "id": "MEASURE 2.3",
            "title": "Performance or assurance criteria measured for deployment-like conditions"
          },
          {
            "id": "MANAGE 2.4",
            "title": "Mechanisms to supersede, disengage or deactivate AI systems"
          }
        ],
        "owasp": [],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 18,
          "title": "Pattern: Staged Rollout with Rollback Criteria",
          "text": "Pattern: Staged Rollout with Rollback Criteria (AI Governance Engineering Body of Knowledge v0.5.0, pattern catalogue (chapter 05)). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/patterns/staged-rollout-rollback-criteria",
          "verified": "primary"
        },
        {
          "n": 19,
          "title": "Governing deployment and use",
          "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"Progressive delivery as a control\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment#progressive-delivery-as-a-control",
          "verified": "primary"
        },
        {
          "n": 20,
          "title": "The Site Reliability Workbook, ch. 16 \"Canarying Releases\"",
          "text": "The Site Reliability Workbook, ch. 16 \"Canarying Releases\" (\"a partial and time-limited deployment of a change in a service and its evaluation\"). Google (O'Reilly). 2018.",
          "url": "https://sre.google/workbook/canarying-releases/",
          "verified": "primary"
        },
        {
          "n": 4,
          "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 26",
          "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 26 (deployer obligations: 26(1) use per the instructions; 26(2) oversight by competent persons with authority; 26(5) monitor, suspend and inform, serious incidents to the provider first; 26(6) logs kept at least six months). Publications Office of the EU (EUR-Lex). 2026-07-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_26",
          "verified": "primary"
        },
        {
          "n": 21,
          "title": "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)",
          "text": "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) (Art. 49 and 71 registration in the EU database; Art. 60 testing of high-risk AI systems in real-world conditions outside sandboxes). Publications Office of the EU (EUR-Lex). 2024-07-12.",
          "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng",
          "verified": "primary"
        },
        {
          "n": 5,
          "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
          "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        },
        {
          "n": 6,
          "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1",
          "text": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (subcategories cited by id: GOVERN 1.6, 1.7, 2.2, 6.1; MAP 1.1, 3.5; MEASURE 2.3, 2.4, 2.11, 3.1; MANAGE 1.1, 2.4, 3.1, 4.1, 4.3). NIST. 2023-01-26.",
          "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Give each stage a purpose: shadow proves behaviour on real traffic, a pilot with trained users proves oversight works, and a canary against a control group proves no regression at scale.",
        "Each stage lists metric, comparison, threshold, window and the group breakdowns that matter; where outcome labels arrive after the stage ends, lean on proxies such as disagreement, overrides, complaints and groundedness.",
        "Review the criteria with their owners on the maintenance calendar: criteria that are too tight produce rollback fatigue.",
        "A provider or prospective provider that pilots an Annex III system with real users before placing it on the market is testing in real-world conditions, which Art. 60 governs; that pre-market pilot is outside this control, which covers changes to systems already in use."
      ],
      "openQuestions": [
        "Verification procedure to be specified: the source material states what the control produces, not how a third party checks it; requires technical review.",
        "How long each stage runs and how much exposure it takes are left to the plan; the source material gives illustrative values only and no method to size a stage for a per-group regression."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-DEPLOY-006",
      "profile": "deployment-and-monitoring",
      "url": "https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-006",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-deploy-006.json",
      "title": "Pinned versions and a tested path back",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "The registry pins the model, prompt, retrieval corpus and guardrail versions of the baseline and the candidate; an unpinned change detected at runtime is a rollback trigger; a new provider model version runs in shadow and canary against the pinned version before it takes traffic; and the path back, a blue-green switch or a feature flag, is exercised in the shadow stage before anyone depends on it.",
      "failureModes": [
        "A vendor model update that nobody treated as a release reaches users without passing any stage.",
        "The model, prompt, corpus or guardrail version that served a request cannot be told, because the registry did not pin it.",
        "The path back is used for the first time during an incident, untested."
      ],
      "scope": "Deployed AI systems with versioned components, including models reached through a provider's API, whose versions change on the provider's schedule. Verifying a model artefact's signature and provenance before load is AIGE-CTL-ASSURE-010.",
      "enforcementPoints": [
        "deploy",
        "runtime"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Registry diff of the pinned versions of baseline and candidate, and switch events from the exercised path back",
          "schemaId": null,
          "schema": null,
          "layer": 4
        }
      ],
      "failureResponse": {
        "effect": "deny",
        "text": "An unpinned change detected at runtime triggers a rollback to the pinned baseline; a new vendor version takes no traffic until it has passed shadow and canary."
      },
      "layer": 4,
      "secondaryLayers": [
        2
      ],
      "patterns": [
        {
          "slug": "staged-rollout-rollback-criteria",
          "title": "Staged Rollout with Rollback Criteria",
          "url": "https://aigovernanceengineer.com/patterns/staged-rollout-rollback-criteria"
        }
      ],
      "seeds": [],
      "derivedFrom": [
        {
          "kind": "pattern",
          "ref": "staged-rollout-rollback-criteria",
          "url": "https://aigovernanceengineer.com/patterns/staged-rollout-rollback-criteria"
        },
        {
          "kind": "chapter",
          "ref": "governing-deployment",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        }
      ],
      "mappings": {
        "obligations": [],
        "iso42001": [
          {
            "id": "A.6.2.5",
            "title": "AI system deployment"
          }
        ],
        "nistAiRmf": [
          {
            "id": "MANAGE 2.4",
            "title": "Mechanisms to supersede, disengage or deactivate AI systems"
          },
          {
            "id": "MANAGE 3.1",
            "title": "AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented."
          }
        ],
        "owasp": [],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 18,
          "title": "Pattern: Staged Rollout with Rollback Criteria",
          "text": "Pattern: Staged Rollout with Rollback Criteria (AI Governance Engineering Body of Knowledge v0.5.0, pattern catalogue (chapter 05)). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/patterns/staged-rollout-rollback-criteria",
          "verified": "primary"
        },
        {
          "n": 19,
          "title": "Governing deployment and use",
          "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"Progressive delivery as a control\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment#progressive-delivery-as-a-control",
          "verified": "primary"
        },
        {
          "n": 22,
          "title": "Governing deployment and use",
          "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"Monitoring third parties while you run\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment#monitoring-third-parties-while-you-run",
          "verified": "primary"
        },
        {
          "n": 23,
          "title": "\"BlueGreenDeployment\"",
          "text": "\"BlueGreenDeployment\" (two identical production environments; switch back on failure). Martin Fowler. 2010-03-01.",
          "url": "https://martinfowler.com/bliki/BlueGreenDeployment.html",
          "verified": "primary"
        },
        {
          "n": 24,
          "title": "\"Feature Toggles (aka Feature Flags)\"",
          "text": "\"Feature Toggles (aka Feature Flags)\" (release, experiment, ops and permissioning toggles; ops kill switches for graceful degradation). Pete Hodgson, martinfowler.com. 2017-10-09.",
          "url": "https://martinfowler.com/articles/feature-toggles.html",
          "verified": "primary"
        },
        {
          "n": 5,
          "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
          "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        },
        {
          "n": 6,
          "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1",
          "text": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (subcategories cited by id: GOVERN 1.6, 1.7, 2.2, 6.1; MAP 1.1, 3.5; MEASURE 2.3, 2.4, 2.11, 3.1; MANAGE 1.1, 2.4, 3.1, 4.1, 4.3). NIST. 2023-01-26.",
          "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "File every provider change and deprecation notice against the registry entry, and keep an alternative model warm in the eval harness so a forced migration starts from evidence rather than from a standing start.",
        "A retrain, a fine-tune, a prompt change, a corpus refresh and a vendor model update are all releases: each bumps the version in the registry."
      ],
      "openQuestions": [
        "Verification procedure to be specified: the source material states what the control produces, not how a third party checks it; requires technical review.",
        "Where a provider changes the model behind a stable name and exposes no version, the pin cannot be checked directly; how to detect such a change beyond the canary awaits review."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-DEPLOY-007",
      "profile": "deployment-and-monitoring",
      "url": "https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-007",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-deploy-007.json",
      "title": "Re-assessment when a change goes beyond what was foreseen",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "Each change is classified in CI against the pre-determined changes in the provider's instructions for use; a change beyond them, a changed intended purpose, or a new population, jurisdiction, autonomy level or vendor version triggers a re-assessment, an amended deployment decision record and a role decision in the registry entry on whether the deployer has become the provider.",
      "failureModes": [
        "A retrain, a new data source or a threshold moved beyond the provider's pre-determined changes ships as routine, and the deployer takes on provider duties without knowing it.",
        "A general-purpose assistant is put to work on hiring or credit through a configuration change, with no re-classification.",
        "A system reaches a new population, jurisdiction or autonomy level with no re-assessment trigger record."
      ],
      "scope": "Changes to a deployed AI system, its intended purpose or its context of use, whether the deployer built the system or procured it.",
      "enforcementPoints": [
        "pre_merge",
        "deploy"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Change record classified against the pre-determined changes, and the amended deployment decision record with its role assessment",
          "schemaId": "deployment-decision-record",
          "schema": "https://aigovernanceengineer.com/schemas/deployment-decision-record.v1.json",
          "layer": 2
        }
      ],
      "failureResponse": {
        "effect": "require_approval",
        "text": "A change classified as beyond the pre-determined changes, or as a new purpose, goes back through classification and a new decision before it ships."
      },
      "layer": 2,
      "secondaryLayers": [
        1
      ],
      "patterns": [],
      "seeds": [],
      "derivedFrom": [
        {
          "kind": "schema",
          "ref": "instructions-for-use",
          "url": "https://aigovernanceengineer.com/resources/templates#schema-instructions-for-use"
        },
        {
          "kind": "schema",
          "ref": "deployment-decision-record",
          "url": "https://aigovernanceengineer.com/resources/templates#schema-deployment-decision-record"
        },
        {
          "kind": "chapter",
          "ref": "governing-deployment",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        }
      ],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART25",
            "name": "EU AI Act Art. 25 responsibilities along the AI value chain",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art25"
          }
        ],
        "iso42001": [],
        "nistAiRmf": [],
        "owasp": [],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 25,
          "title": "Governing deployment and use",
          "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"When a deployer becomes a provider\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment#when-a-deployer-becomes-a-provider",
          "verified": "primary"
        },
        {
          "n": 8,
          "title": "Governing deployment and use",
          "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"Maintenance calendar and retraining governance\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment#maintenance-calendar-and-retraining-governance",
          "verified": "primary"
        },
        {
          "n": 26,
          "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 25",
          "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 25 (value chain: name or trademark, substantial modification or changed intended purpose makes a deployer the provider). Publications Office of the EU (EUR-Lex). 2026-07-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_25",
          "verified": "primary"
        },
        {
          "n": 10,
          "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 13",
          "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 13 (instructions for use: capabilities and limitations of performance; pre-determined changes; human oversight measures; expected lifetime and maintenance; log collection). Publications Office of the EU (EUR-Lex). 2026-07-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_13",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Detect each trigger where it happens: a brand check in the release checklist for a name or trademark, change classification in CI for a substantial modification, and intake and the downstream use register for a changed purpose.",
        "Log the compute of every fine-tune of a general-purpose model as an artefact filed with the AIBOM: whether the modifier becomes a provider turns on an indicative criterion of one third of the original training compute."
      ],
      "openQuestions": [
        "Verification procedure to be specified: the source material states what the control produces, not how a third party checks it; requires technical review.",
        "Whether a given change is a substantial modification is a legal call the source material leaves to counsel; who signs off the classification in CI awaits review."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-DEPLOY-008",
      "profile": "deployment-and-monitoring",
      "url": "https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-008",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-deploy-008.json",
      "title": "Monitoring plan with thresholds, owners and consequences",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "A monitoring plan kept as data names the drift classes that apply to the system and a statistic for each, and gives every metric a threshold, a window, a named owner who can be paged and the action a breach fires; each check writes an evidence record, pass or fail, and the plan and its findings are reviewed on a stated cadence.",
      "failureModes": [
        "A dashboard has no thresholds, or a breach pages no one, so drift is watched by nobody.",
        "A signal has no owner who can be paged for it.",
        "A generative system degrades (more ungrounded answers, more refusals in one language) while every infrastructure metric stays green.",
        "Checks that pass leave no record, so the absence of breaches cannot be shown."
      ],
      "scope": "Every AI system in production, built or procured: providers of high-risk systems keep a post-market monitoring plan, and deployers monitor operation on the basis of the instructions for use. Whether each check is still firing is the live control status of AIGE-CTL-ASSURE-005.",
      "enforcementPoints": [
        "runtime",
        "periodic"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Monitoring plan with data sources, metrics, thresholds, triggers, owner and review cadence",
          "schemaId": "post-market-monitoring-plan",
          "schema": "https://aigovernanceengineer.com/schemas/post-market-monitoring-plan.v1.json",
          "layer": 4
        },
        {
          "artefact": "Evidence record per check, pass or fail, in the assurance store",
          "schemaId": "evidence-record",
          "schema": "https://aigovernanceengineer.com/schemas/evidence-record.v1.json",
          "layer": 5
        }
      ],
      "failureResponse": {
        "effect": "alert",
        "text": "A breach fires the action the plan sets for it (an issue, a retrain, a degraded mode, an incident or a tripped breaker) and pages the named owner."
      },
      "layer": 4,
      "secondaryLayers": [
        5
      ],
      "patterns": [
        {
          "slug": "drift-fairness-monitor",
          "title": "Drift & Fairness Monitor",
          "url": "https://aigovernanceengineer.com/patterns/drift-fairness-monitor"
        }
      ],
      "seeds": [],
      "derivedFrom": [
        {
          "kind": "pattern",
          "ref": "drift-fairness-monitor",
          "url": "https://aigovernanceengineer.com/patterns/drift-fairness-monitor"
        },
        {
          "kind": "schema",
          "ref": "post-market-monitoring-plan",
          "url": "https://aigovernanceengineer.com/resources/templates#schema-post-market-monitoring-plan"
        },
        {
          "kind": "chapter",
          "ref": "governing-deployment",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        }
      ],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART72",
            "name": "EU AI Act Art. 72 post-market monitoring",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art72"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART26-5",
            "name": "EU AI Act Art. 26(5) deployer monitoring, suspension and informing the provider",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26-5"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART9",
            "name": "EU AI Act Art. 9 risk management system",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art9"
          }
        ],
        "iso42001": [
          {
            "id": "A.6.2.6",
            "title": "AI system operation and monitoring"
          }
        ],
        "nistAiRmf": [
          {
            "id": "MEASURE 2.4",
            "title": "The functionality and behavior of the AI system and its components – as identified in the MAP function – are monitored when in production."
          },
          {
            "id": "MEASURE 3.1",
            "title": "Existing, unanticipated and emergent risks are tracked"
          },
          {
            "id": "MANAGE 4.1",
            "title": "Post-deployment monitoring plans are implemented"
          }
        ],
        "owasp": [],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 27,
          "title": "Pattern: Drift & Fairness Monitor",
          "text": "Pattern: Drift & Fairness Monitor (AI Governance Engineering Body of Knowledge v0.5.0, pattern catalogue (chapter 05)). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/patterns/drift-fairness-monitor",
          "verified": "primary"
        },
        {
          "n": 28,
          "title": "Governing deployment and use",
          "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"Drift: what moves and how to see it\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment#drift-what-moves-and-how-to-see-it",
          "verified": "primary"
        },
        {
          "n": 29,
          "title": "Governing deployment and use",
          "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"Who owns the signal\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment#who-owns-the-signal",
          "verified": "primary"
        },
        {
          "n": 30,
          "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 72",
          "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 72 (post-market monitoring system and plan). Publications Office of the EU (EUR-Lex). 2026-07-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_72",
          "verified": "primary"
        },
        {
          "n": 4,
          "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 26",
          "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 26 (deployer obligations: 26(1) use per the instructions; 26(2) oversight by competent persons with authority; 26(5) monitor, suspend and inform, serious incidents to the provider first; 26(6) logs kept at least six months). Publications Office of the EU (EUR-Lex). 2026-07-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_26",
          "verified": "primary"
        },
        {
          "n": 31,
          "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 9",
          "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 9 (risk management system across the lifecycle of a high-risk system). Publications Office of the EU (EUR-Lex). 2026-07-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_9",
          "verified": "primary"
        },
        {
          "n": 5,
          "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
          "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        },
        {
          "n": 6,
          "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1",
          "text": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (subcategories cited by id: GOVERN 1.6, 1.7, 2.2, 6.1; MAP 1.1, 3.5; MEASURE 2.3, 2.4, 2.11, 3.1; MANAGE 1.1, 2.4, 3.1, 4.1, 4.3). NIST. 2023-01-26.",
          "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Name what can move (data, label, concept, pipeline, vendor model and usage drift) and pick a statistic per class: a stability index or two-sample test against a reference window, predicted against observed positive rate, performance on fresh labels, data contracts, version-pin checks, topic classification of traffic against the negative space.",
        "Labels often arrive late or never: pair input-drift statistics with a delayed performance check, and for generative systems sample outputs for groundedness scoring and human review.",
        "A threshold change is a change to a control: a reviewed diff with an approver, not an edit on a dashboard."
      ],
      "openQuestions": [
        "Verification procedure to be specified: the source material states what the control produces, not how a third party checks it; requires technical review.",
        "Provider and deployer each monitor part of the system and see different data; how the deployer's findings reach the provider's post-market monitoring is not settled here."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-DEPLOY-009",
      "profile": "deployment-and-monitoring",
      "url": "https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-009",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-deploy-009.json",
      "title": "Fairness monitored by group in production",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "Fairness keeps being measured after go-live: selection or approval rates by group against the eval baseline, error and calibration rates by group once outcomes arrive, override, complaint and appeal rates by group, groundedness and refusal rates by topic and language for generative systems, and feedback-loop checks where outputs shape future training data; a breach opens a ticket with an owner.",
      "failureModes": [
        "A system that passed its fairness evals at go-live drifts into unfairness without any code change, and nothing measures it.",
        "The group attribute is absent at runtime and no consented sample, periodic audit or secured join replaces it, so no per-group rate exists.",
        "Reviewers override one group more often than others and the signal is never read.",
        "Outputs shape the data the next version learns from, and no feedback-loop check runs."
      ],
      "scope": "AI systems in production that make or inform decisions about people, or serve groups that can be served unequally, such as speakers of different languages. A disparity that caused harm is an incident and follows the incident controls.",
      "enforcementPoints": [
        "runtime",
        "periodic"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Per-group metrics in the monitoring plan, with the label delay stated, thresholds and owners, and an evidence record per check",
          "schemaId": "post-market-monitoring-plan",
          "schema": "https://aigovernanceengineer.com/schemas/post-market-monitoring-plan.v1.json",
          "layer": 4
        }
      ],
      "failureResponse": {
        "effect": "alert",
        "text": "A per-group breach opens a ticket with an owner, not a chart nobody reads; a disparity that caused harm is opened as an incident."
      },
      "layer": 4,
      "secondaryLayers": [
        5
      ],
      "patterns": [
        {
          "slug": "drift-fairness-monitor",
          "title": "Drift & Fairness Monitor",
          "url": "https://aigovernanceengineer.com/patterns/drift-fairness-monitor"
        }
      ],
      "seeds": [],
      "derivedFrom": [
        {
          "kind": "pattern",
          "ref": "drift-fairness-monitor",
          "url": "https://aigovernanceengineer.com/patterns/drift-fairness-monitor"
        },
        {
          "kind": "chapter",
          "ref": "fairness-and-explainability",
          "url": "https://aigovernanceengineer.com/bok/fairness-and-explainability"
        },
        {
          "kind": "chapter",
          "ref": "governing-deployment",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        }
      ],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART15-4",
            "name": "EU AI Act Art. 15(4) feedback loops in systems that continue to learn",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15-4"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART4A",
            "name": "EU AI Act Art. 4a lawful basis for special-category data in bias detection",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art4a"
          }
        ],
        "iso42001": [
          {
            "id": "A.6.2.6",
            "title": "AI system operation and monitoring"
          }
        ],
        "nistAiRmf": [
          {
            "id": "MEASURE 2.11",
            "title": "Fairness and bias – as identified in the MAP function – are evaluated and results are documented."
          }
        ],
        "owasp": [],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 32,
          "title": "Fairness and explainability for practitioners",
          "text": "Fairness and explainability for practitioners (AI Governance Engineering Body of Knowledge v0.5.0, chapter 16, section \"Monitoring fairness in production\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/fairness-and-explainability#monitoring-fairness-in-production",
          "verified": "primary"
        },
        {
          "n": 33,
          "title": "Governing deployment and use",
          "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"Fairness and quality in production\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment#fairness-and-quality-in-production",
          "verified": "primary"
        },
        {
          "n": 27,
          "title": "Pattern: Drift & Fairness Monitor",
          "text": "Pattern: Drift & Fairness Monitor (AI Governance Engineering Body of Knowledge v0.5.0, pattern catalogue (chapter 05)). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/patterns/drift-fairness-monitor",
          "verified": "primary"
        },
        {
          "n": 34,
          "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 15",
          "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 15 (15(4): systems that continue to learn reduce the risk of biased outputs feeding future input, \"feedback loops\"). Publications Office of the EU (EUR-Lex). 2026-07-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_15",
          "verified": "primary"
        },
        {
          "n": 35,
          "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Arts. 4a and 10",
          "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Arts. 4a and 10 (as amended by Reg. (EU) 2026/1744: Art. 10(5) deleted; Art. 4a inserted for special-category data in bias detection and correction). Publications Office of the EU (EUR-Lex). 2026-07-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_4a",
          "verified": "primary"
        },
        {
          "n": 5,
          "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
          "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        },
        {
          "n": 6,
          "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1",
          "text": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (subcategories cited by id: GOVERN 1.6, 1.7, 2.2, 6.1; MAP 1.1, 3.5; MEASURE 2.3, 2.4, 2.11, 3.1; MANAGE 1.1, 2.4, 3.1, 4.1, 4.3). NIST. 2023-01-26.",
          "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Where the group attribute is not held at runtime, choose between a consented sample or panel, periodic audits under the Art. 4a conditions, or outcome-free rates with the attribute joined in a secured environment.",
        "The contest channel is a sensor: complaints, appeals and explanation requests by group, with their outcomes, feed the same threshold and issue path as every other signal.",
        "Where law requires a periodic bias audit, as New York City's Local Law 144 does for automated employment decision tools, the production telemetry is what makes the audit cheap."
      ],
      "openQuestions": [
        "Verification procedure to be specified: the source material states what the control produces, not how a third party checks it; requires technical review.",
        "Per-group metrics on small groups are noisy; the source material names the problem but sets no minimum group size or window."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-DEPLOY-010",
      "profile": "deployment-and-monitoring",
      "url": "https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-010",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-deploy-010.json",
      "title": "Deployer log retention",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "Logs a high-risk system generates automatically, to the extent they are under the deployer's control, are kept for at least six months unless other law says otherwise, and longer while an incident is open; retention is code: a schedule per record type, tamper-evident storage, a legal hold that overrides deletion, and the ceiling data protection law sets for the personal data inside them.",
      "failureModes": [
        "Logs under the deployer's control are deleted before six months, or while an incident they bear on is still open.",
        "Logs are overwritten while the decision to stop the system is still being taken.",
        "Everything is kept indefinitely, so the personal data in the logs outlives the storage-limitation ceiling."
      ],
      "scope": "Deployers of high-risk AI systems, for the logs under their control; the same schedule covers the deployer's decision records (decision record, go-live decision, conditions and dissent), kept for the life of the system plus the limitation period counsel sets. For an agent with an Annex III purpose AIGE-CTL-AGENT-030 carries the same six-month floor, and the provider's retention of documentation and logs is AIGE-CTL-ASSURE-008.",
      "enforcementPoints": [
        "runtime",
        "periodic"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Retention schedule per record type, and the log retention period in days in the deployment decision record",
          "schemaId": "deployment-decision-record",
          "schema": "https://aigovernanceengineer.com/schemas/deployment-decision-record.v1.json",
          "layer": 5
        }
      ],
      "failureResponse": {
        "effect": "deny",
        "text": "A legal hold overrides deletion: logs under hold, or tied to an open incident, cannot be deleted."
      },
      "layer": 5,
      "secondaryLayers": [
        4
      ],
      "patterns": [
        {
          "slug": "incident-pipeline",
          "title": "Incident Pipeline",
          "url": "https://aigovernanceengineer.com/patterns/incident-pipeline"
        }
      ],
      "seeds": [],
      "derivedFrom": [
        {
          "kind": "pattern",
          "ref": "incident-pipeline",
          "url": "https://aigovernanceengineer.com/patterns/incident-pipeline"
        },
        {
          "kind": "schema",
          "ref": "deployment-decision-record",
          "url": "https://aigovernanceengineer.com/resources/templates#schema-deployment-decision-record"
        },
        {
          "kind": "chapter",
          "ref": "governing-deployment",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        }
      ],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART26-6",
            "name": "EU AI Act Art. 26(6) deployer retention of automatically generated logs",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26-6"
          }
        ],
        "iso42001": [
          {
            "id": "A.6.2.8",
            "title": "AI system recording of event logs"
          }
        ],
        "nistAiRmf": [],
        "owasp": [],
        "atlas": [],
        "aiuc1": [
          "E015"
        ],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 36,
          "title": "Governing deployment and use",
          "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"Records retention\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment#records-retention",
          "verified": "primary"
        },
        {
          "n": 9,
          "title": "Incidents, issues and root causes",
          "text": "Incidents, issues and root causes (AI Governance Engineering Body of Knowledge v0.5.0, chapter 17, section \"Deployer duties: inform the provider, suspend use\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/incidents#deployer-duties-inform-the-provider-suspend-use",
          "verified": "primary"
        },
        {
          "n": 37,
          "title": "Pattern: Incident Pipeline",
          "text": "Pattern: Incident Pipeline (AI Governance Engineering Body of Knowledge v0.5.0, pattern catalogue (chapter 05)). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/patterns/incident-pipeline",
          "verified": "primary"
        },
        {
          "n": 4,
          "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 26",
          "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 26 (deployer obligations: 26(1) use per the instructions; 26(2) oversight by competent persons with authority; 26(5) monitor, suspend and inform, serious incidents to the provider first; 26(6) logs kept at least six months). Publications Office of the EU (EUR-Lex). 2026-07-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_26",
          "verified": "primary"
        },
        {
          "n": 5,
          "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
          "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        },
        {
          "n": 38,
          "title": "AIUC-1 requirements",
          "text": "AIUC-1 requirements (public requirement index, A001 to F002, each requirement on its own page (E007 and E014 marked retired); AIUC-1 is a standard of the Artificial Intelligence Underwriting Company; this site is not affiliated with AIUC, and a mapping here is not an AIUC-1 certificate or audit). Artificial Intelligence Underwriting Company. 2026-09-24.",
          "url": "https://standard.aiuc-1.com/llms.txt",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Reconcile the six-month floor for logs with the data protection ceiling per data type, not by keeping everything; keep archive formats someone can still read in ten years.",
        "Where the provider holds the logs, its own six-month floor applies (Art. 19(1)); record who holds which logs."
      ],
      "openQuestions": [
        "Verification procedure to be specified: the source material states what the control produces, not how a third party checks it; requires technical review.",
        "How long past the six-month floor logs should be kept for a given intended purpose is left to the deployer; the source material gives no default."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-DEPLOY-011",
      "profile": "deployment-and-monitoring",
      "url": "https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-011",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-deploy-011.json",
      "title": "Serious incident reporting clocks",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "Each incident record keeps severity and reportability in separate fields set by named people with timestamps, and records when the organisation became aware and one entry per regime assessed; a deployer that identifies a serious incident informs the provider first, then the importer or distributor and the authority, and starts the Art. 73 timers on its own record when the provider cannot be reached.",
      "failureModes": [
        "A single priority field is read one way by engineering and another by legal, so the reportability decision is never taken.",
        "A deadline is missed because detection, triage and reporting are disconnected manual steps.",
        "A \"not applicable\" decision leaves no rationale or owner, so the organisation cannot show later why it did not report.",
        "The provider does not answer and no clock starts on the deployer's own record."
      ],
      "scope": "Incidents in deployed AI systems, whoever built them. The AI Act clocks bind providers of high-risk systems and, when the provider cannot be reached, their deployers; a personal data breach inside an AI incident adds the GDPR clock.",
      "enforcementPoints": [
        "runtime"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Incident record with its reporting block (awareness time, one entry per regime with rationale, deadline and submission) and the timestamp of each notification",
          "schemaId": "incident-record",
          "schema": "https://aigovernanceengineer.com/schemas/incident-record.v1.json",
          "layer": 5
        }
      ],
      "failureResponse": {
        "effect": "alert",
        "text": "The pipeline alerts on the nearest reporting deadline and pages the system owner and legal; a person can override the first classification, and the override is logged with a reason."
      },
      "layer": 5,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "incident-pipeline",
          "title": "Incident Pipeline",
          "url": "https://aigovernanceengineer.com/patterns/incident-pipeline"
        }
      ],
      "seeds": [],
      "derivedFrom": [
        {
          "kind": "pattern",
          "ref": "incident-pipeline",
          "url": "https://aigovernanceengineer.com/patterns/incident-pipeline"
        },
        {
          "kind": "schema",
          "ref": "incident-record",
          "url": "https://aigovernanceengineer.com/resources/templates#schema-incident-record"
        },
        {
          "kind": "chapter",
          "ref": "incidents",
          "url": "https://aigovernanceengineer.com/bok/incidents"
        }
      ],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART73",
            "name": "EU AI Act Art. 73 serious-incident reporting",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art73"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART26-5",
            "name": "EU AI Act Art. 26(5) deployer monitoring, suspension and informing the provider",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26-5"
          },
          {
            "id": "AIGE-OBL-GDPR-ART33-34",
            "name": "GDPR Arts. 33–34 personal data breach notification",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art33-34"
          }
        ],
        "iso42001": [
          {
            "id": "A.8.4",
            "title": "Communication of incidents"
          }
        ],
        "nistAiRmf": [
          {
            "id": "MANAGE 4.3",
            "title": "Incidents and errors are communicated to relevant AI actors, including affected communities."
          }
        ],
        "owasp": [],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 39,
          "title": "Incidents, issues and root causes",
          "text": "Incidents, issues and root causes (AI Governance Engineering Body of Knowledge v0.5.0, chapter 17, section \"The overlapping clocks\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/incidents#the-overlapping-clocks",
          "verified": "primary"
        },
        {
          "n": 9,
          "title": "Incidents, issues and root causes",
          "text": "Incidents, issues and root causes (AI Governance Engineering Body of Knowledge v0.5.0, chapter 17, section \"Deployer duties: inform the provider, suspend use\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/incidents#deployer-duties-inform-the-provider-suspend-use",
          "verified": "primary"
        },
        {
          "n": 40,
          "title": "Incidents, issues and root causes",
          "text": "Incidents, issues and root causes (AI Governance Engineering Body of Knowledge v0.5.0, chapter 17, section \"A severity scale mapped to the clocks\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/incidents#a-severity-scale-mapped-to-the-clocks",
          "verified": "primary"
        },
        {
          "n": 41,
          "title": "Incidents, issues and root causes",
          "text": "Incidents, issues and root causes (AI Governance Engineering Body of Knowledge v0.5.0, chapter 17, section \"The incident record\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/incidents#the-incident-record",
          "verified": "primary"
        },
        {
          "n": 37,
          "title": "Pattern: Incident Pipeline",
          "text": "Pattern: Incident Pipeline (AI Governance Engineering Body of Knowledge v0.5.0, pattern catalogue (chapter 05)). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/patterns/incident-pipeline",
          "verified": "primary"
        },
        {
          "n": 42,
          "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 73",
          "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 73 (reporting of serious incidents: no later than 2, 10 or 15 days from awareness). Publications Office of the EU (EUR-Lex). 2026-07-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_73",
          "verified": "primary"
        },
        {
          "n": 4,
          "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 26",
          "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 26 (deployer obligations: 26(1) use per the instructions; 26(2) oversight by competent persons with authority; 26(5) monitor, suspend and inform, serious incidents to the provider first; 26(6) logs kept at least six months). Publications Office of the EU (EUR-Lex). 2026-07-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_26",
          "verified": "primary"
        },
        {
          "n": 43,
          "title": "Regulation (EU) 2016/679 (GDPR), Art. 33",
          "text": "Regulation (EU) 2016/679 (GDPR), Art. 33 (notification of a personal data breach to the supervisory authority without undue delay and, where feasible, within 72 hours). Publications Office of the EU (EUR-Lex). 2016-04-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng#art_33",
          "verified": "primary"
        },
        {
          "n": 5,
          "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
          "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        },
        {
          "n": 6,
          "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1",
          "text": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (subcategories cited by id: GOVERN 1.6, 1.7, 2.2, 6.1; MAP 1.1, 3.5; MEASURE 2.3, 2.4, 2.11, 3.1; MANAGE 1.1, 2.4, 3.1, 4.1, 4.3). NIST. 2023-01-26.",
          "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Classify up and downgrade with evidence: the deadlines run from awareness, and a reasonable likelihood of a causal link is enough to start them.",
        "Hold the facts once and render each regime's report from the record, never retyped; keep the provider's incident contact and channel on the registry entry and test the notification terms in drills."
      ],
      "openQuestions": [
        "Verification procedure to be specified: the source material states what the control produces, not how a third party checks it; requires technical review.",
        "Which regimes count as equivalent for a given system, which narrows Art. 73 reporting to fundamental-rights infringements, is a legal call the source material says to record per system; who records it awaits review."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-DEPLOY-012",
      "profile": "deployment-and-monitoring",
      "url": "https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-012",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-deploy-012.json",
      "title": "Deactivation triggers, degraded modes and suspension",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "A runbook kept with the registry entry names the threshold and legal triggers for stopping the system, each with the role that decides and the time allowed; every path first freezes the logs, applies a legal hold and snapshots the pinned versions; degraded modes short of shutdown, and a suspension path for systems the deployer does not own, are built as tested toggles and drilled at least yearly.",
      "failureModes": [
        "A trigger fires and nobody knows who may decide, so the system keeps serving while a meeting runs.",
        "Logs are overwritten before the evidence is frozen.",
        "The only available action is to turn everything off, everywhere, which is often worse than the fault.",
        "A classifier embedded in a vendor product has no switch, so a deployer with reason to consider that it presents a risk cannot suspend its use.",
        "A degraded mode or the suspension path fails the first time it is used, because it was never drilled."
      ],
      "scope": "Every deployed AI system that a breached floor, an incident or a legal duty could force to stop, including systems embedded in a supplier's product. For agents, the kill switch and circuit breaker controls of the Agent Runtime profile (AIGE-CTL-AGENT-011 and AIGE-CTL-AGENT-010) are the instant form.",
      "enforcementPoints": [
        "runtime",
        "periodic"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Runbook with triggers, deciding roles and times allowed; toggle change log; drill records with the time to decide, to the degraded mode and to off",
          "schemaId": null,
          "schema": null,
          "layer": 4
        }
      ],
      "failureResponse": {
        "effect": "deny",
        "text": "On a trigger the decision owner switches the system to a degraded mode or off within the time allowed, after the evidence is frozen; under Art. 26(5) the deployer suspends use and informs the provider or distributor and the authority."
      },
      "layer": 4,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "deactivation-localisation-retirement-runbook",
          "title": "Deactivation, Localisation & Retirement Runbook",
          "url": "https://aigovernanceengineer.com/patterns/deactivation-localisation-retirement-runbook"
        },
        {
          "slug": "incident-pipeline",
          "title": "Incident Pipeline",
          "url": "https://aigovernanceengineer.com/patterns/incident-pipeline"
        }
      ],
      "seeds": [],
      "derivedFrom": [
        {
          "kind": "pattern",
          "ref": "deactivation-localisation-retirement-runbook",
          "url": "https://aigovernanceengineer.com/patterns/deactivation-localisation-retirement-runbook"
        },
        {
          "kind": "pattern",
          "ref": "incident-pipeline",
          "url": "https://aigovernanceengineer.com/patterns/incident-pipeline"
        },
        {
          "kind": "chapter",
          "ref": "governing-deployment",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        },
        {
          "kind": "chapter",
          "ref": "incidents",
          "url": "https://aigovernanceengineer.com/bok/incidents"
        }
      ],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART26-5",
            "name": "EU AI Act Art. 26(5) deployer monitoring, suspension and informing the provider",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26-5"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART20",
            "name": "EU AI Act Art. 20 corrective actions and duty of information",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art20"
          },
          {
            "id": "AIGE-OBL-EUAIA-ART5",
            "name": "EU AI Act Art. 5 prohibited practices (incl. new NCII and CSAM bans)",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art5"
          }
        ],
        "iso42001": [
          {
            "id": "A.6.2.6",
            "title": "AI system operation and monitoring"
          }
        ],
        "nistAiRmf": [
          {
            "id": "MANAGE 2.4",
            "title": "Mechanisms to supersede, disengage or deactivate AI systems"
          }
        ],
        "owasp": [],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 44,
          "title": "Pattern: Deactivation, Localisation & Retirement Runbook",
          "text": "Pattern: Deactivation, Localisation & Retirement Runbook (AI Governance Engineering Body of Knowledge v0.5.0, pattern catalogue (chapter 05)). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/patterns/deactivation-localisation-retirement-runbook",
          "verified": "primary"
        },
        {
          "n": 45,
          "title": "Governing deployment and use",
          "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"A deactivation policy someone can execute\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment#a-deactivation-policy-someone-can-execute",
          "verified": "primary"
        },
        {
          "n": 46,
          "title": "Governing deployment and use",
          "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"Graduated degradation\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment#graduated-degradation",
          "verified": "primary"
        },
        {
          "n": 9,
          "title": "Incidents, issues and root causes",
          "text": "Incidents, issues and root causes (AI Governance Engineering Body of Knowledge v0.5.0, chapter 17, section \"Deployer duties: inform the provider, suspend use\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/incidents#deployer-duties-inform-the-provider-suspend-use",
          "verified": "primary"
        },
        {
          "n": 24,
          "title": "\"Feature Toggles (aka Feature Flags)\"",
          "text": "\"Feature Toggles (aka Feature Flags)\" (release, experiment, ops and permissioning toggles; ops kill switches for graceful degradation). Pete Hodgson, martinfowler.com. 2017-10-09.",
          "url": "https://martinfowler.com/articles/feature-toggles.html",
          "verified": "primary"
        },
        {
          "n": 4,
          "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 26",
          "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 26 (deployer obligations: 26(1) use per the instructions; 26(2) oversight by competent persons with authority; 26(5) monitor, suspend and inform, serious incidents to the provider first; 26(6) logs kept at least six months). Publications Office of the EU (EUR-Lex). 2026-07-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_26",
          "verified": "primary"
        },
        {
          "n": 47,
          "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 20",
          "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 20 (providers take corrective action: bring into conformity, withdraw, disable or recall; inform distributors and deployers). Publications Office of the EU (EUR-Lex). 2026-07-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_20",
          "verified": "primary"
        },
        {
          "n": 48,
          "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 5",
          "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 5 (prohibited practices, binding on deployers as well as providers). Publications Office of the EU (EUR-Lex). 2026-07-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_5",
          "verified": "primary"
        },
        {
          "n": 5,
          "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
          "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        },
        {
          "n": 6,
          "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1",
          "text": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (subcategories cited by id: GOVERN 1.6, 1.7, 2.2, 6.1; MAP 1.1, 3.5; MEASURE 2.3, 2.4, 2.11, 3.1; MANAGE 1.1, 2.4, 3.1, 4.1, 4.3). NIST. 2023-01-26.",
          "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Build the intermediate modes in advance: advice-only, raised thresholds with abstention to a person, grounded-only answers, scoped off for one group, language, region or function, back to the pilot cohort, and off with the fallback process.",
        "Suspension is a kill switch for a system you do not own: you cannot revoke a vendor's weights, but you can stop sending it traffic; test that you can, and how long it takes.",
        "Keep the jurisdiction as a policy input, with flags by region, so one market can be switched off without touching the others."
      ],
      "openQuestions": [
        "Verification procedure to be specified: the source material states what the control produces, not how a third party checks it; requires technical review.",
        "Where the model sits inside a supplier's product the switch depends on the contract; which terms give the deployer a switch is not settled here."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-DEPLOY-013",
      "profile": "deployment-and-monitoring",
      "url": "https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-013",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-deploy-013.json",
      "title": "Shadow AI discovery and registry reconciliation",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "Discovery runs continuously against the places AI appears (identity providers, cloud accounts, network egress, code repositories and SaaS integrations); each finding is reconciled against the registry, an unknown system gets an entry and an owner asked to claim it, the unclaimed are escalated, and the result feeds the registry drift check.",
      "failureModes": [
        "The registry is fed only by voluntary declaration and lags production: models, agents and AI-enabled tools run with no entry.",
        "A finding is logged but never registered, claimed or escalated.",
        "A retired system keeps a copy serving because no sweep checks for it."
      ],
      "scope": "The environments where staff and systems can run or reach AI: identity, cloud, network, code and SaaS. Local models and personal devices stay a discovery problem that the sanctioned gateway does not cover.",
      "enforcementPoints": [
        "periodic"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Discovery findings reconciled against the registry, with the entries opened, claimed and escalated",
          "schemaId": null,
          "schema": null,
          "layer": 2
        }
      ],
      "failureResponse": {
        "effect": "alert",
        "text": "An unknown system is registered as unclaimed, its owner is asked to claim it and the unclaimed are escalated; in the pattern's example its scope is frozen until claimed."
      },
      "layer": 2,
      "secondaryLayers": [],
      "patterns": [
        {
          "slug": "shadow-ai-discovery",
          "title": "Shadow-AI Discovery",
          "url": "https://aigovernanceengineer.com/patterns/shadow-ai-discovery"
        }
      ],
      "seeds": [],
      "derivedFrom": [
        {
          "kind": "pattern",
          "ref": "shadow-ai-discovery",
          "url": "https://aigovernanceengineer.com/patterns/shadow-ai-discovery"
        },
        {
          "kind": "chapter",
          "ref": "governing-deployment",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        }
      ],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART49-71",
            "name": "EU AI Act Art. 49/71 registration of high-risk systems in the EU database",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art49-71"
          }
        ],
        "iso42001": [],
        "nistAiRmf": [
          {
            "id": "GOVERN 1.6",
            "title": "Mechanisms are in place to inventory AI systems and are resourced according to organizational risk priorities."
          }
        ],
        "owasp": [
          {
            "id": "asi10",
            "externalId": "ASI10",
            "name": "Rogue Agents",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-asi10"
          }
        ],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 49,
          "title": "Pattern: Shadow-AI Discovery",
          "text": "Pattern: Shadow-AI Discovery (AI Governance Engineering Body of Knowledge v0.5.0, pattern catalogue (chapter 05)). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/patterns/shadow-ai-discovery",
          "verified": "primary"
        },
        {
          "n": 50,
          "title": "Governing deployment and use",
          "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"Retirement and decommissioning\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment#retirement-and-decommissioning",
          "verified": "primary"
        },
        {
          "n": 51,
          "title": "OWASP Top 10 for Agentic Applications for 2026",
          "text": "OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents). OWASP GenAI Security Project. 2025-12-09.",
          "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
          "verified": "primary"
        },
        {
          "n": 21,
          "title": "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)",
          "text": "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) (Art. 49 and 71 registration in the EU database; Art. 60 testing of high-risk AI systems in real-world conditions outside sandboxes). Publications Office of the EU (EUR-Lex). 2024-07-12.",
          "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng",
          "verified": "primary"
        },
        {
          "n": 6,
          "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1",
          "text": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (subcategories cited by id: GOVERN 1.6, 1.7, 2.2, 6.1; MAP 1.1, 3.5; MEASURE 2.3, 2.4, 2.11, 3.1; MANAGE 1.1, 2.4, 3.1, 4.1, 4.3). NIST. 2023-01-26.",
          "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Turn each find into an intake request (register, tier, approve or replace) before it becomes a sanction; identity, network and expense data show the tools used outside the sanctioned gateway."
      ],
      "openQuestions": [
        "Verification procedure to be specified: the source material states what the control produces, not how a third party checks it; requires technical review.",
        "The source material sets no cadence for discovery sweeps beyond the pattern's illustrative weekly sweep, and no deadline for an owner to claim a finding."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-DEPLOY-014",
      "profile": "deployment-and-monitoring",
      "url": "https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-014",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-deploy-014.json",
      "title": "Sanctioned AI gateway for staff use",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "Staff reach approved AI tools and model APIs through single sign-on and one gateway that applies the acceptable-use policy as code: a catalogue names each tool, its contract terms and allowed data classes; each request is tagged by data class and allowed, redacted or blocked; access needs a current acceptable-use attestation; and each call writes a signed evidence record with the input's hash, not the input.",
      "failureModes": [
        "Someone pastes a customer file into a public tool, and the acceptable-use policy, read once in a handbook, is never evaluated at that moment.",
        "An approved tool is used on terms that changed after its approval, such as training on customer inputs.",
        "Every public tool is blocked, and use moves onto personal devices where nothing is seen.",
        "The gateway keeps full staff prompts, beyond what the control needs."
      ],
      "scope": "Staff use of AI tools and model APIs, in the browser or through an API. Local models and personal devices are outside the gateway and left to discovery.",
      "enforcementPoints": [
        "runtime"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Signed gateway decision event per call: decision, data class, tool, redactions and a hash of the input",
          "schemaId": "evidence-record",
          "schema": "https://aigovernanceengineer.com/schemas/evidence-record.v1.json",
          "layer": 4
        },
        {
          "artefact": "Current acceptable-use attestation and training module on record for each user",
          "schemaId": "training-record",
          "schema": "https://aigovernanceengineer.com/schemas/training-record.v1.json",
          "layer": 4
        }
      ],
      "failureResponse": {
        "effect": "deny",
        "text": "A request carrying a data class the tool is not approved for is redacted or blocked with a reason and a route to the right tool; without a current attestation the gateway role is not granted."
      },
      "layer": 4,
      "secondaryLayers": [
        2
      ],
      "patterns": [
        {
          "slug": "sanctioned-ai-gateway",
          "title": "Sanctioned AI Gateway",
          "url": "https://aigovernanceengineer.com/patterns/sanctioned-ai-gateway"
        }
      ],
      "seeds": [],
      "derivedFrom": [
        {
          "kind": "pattern",
          "ref": "sanctioned-ai-gateway",
          "url": "https://aigovernanceengineer.com/patterns/sanctioned-ai-gateway"
        },
        {
          "kind": "schema",
          "ref": "evidence-record",
          "url": "https://aigovernanceengineer.com/resources/templates#schema-evidence-record"
        },
        {
          "kind": "schema",
          "ref": "training-record",
          "url": "https://aigovernanceengineer.com/resources/templates#schema-training-record"
        }
      ],
      "mappings": {
        "obligations": [
          {
            "id": "AIGE-OBL-EUAIA-ART4",
            "name": "EU AI Act Art. 4 AI literacy",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art4"
          }
        ],
        "iso42001": [
          {
            "id": "A.9.2",
            "title": "Processes for responsible use of AI systems"
          },
          {
            "id": "A.10.3",
            "title": "Suppliers"
          }
        ],
        "nistAiRmf": [
          {
            "id": "GOVERN 2.2",
            "title": "The organization’s personnel and partners receive AI risk management training to enable them to perform their duties and responsibilities consistent with related policies, procedures, and agreements."
          },
          {
            "id": "GOVERN 6.1",
            "title": "Policies and procedures are in place that address AI risks associated with third-party entities, including risks of infringement of a third-party’s intellectual property or other rights."
          },
          {
            "id": "MANAGE 3.1",
            "title": "AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented."
          }
        ],
        "owasp": [
          {
            "id": "llm02-2026",
            "externalId": "LLM02:2026",
            "name": "Sensitive Information Disclosure",
            "url": "https://aigovernanceengineer.com/resources/threats#threat-llm02-2026"
          }
        ],
        "atlas": [],
        "aiuc1": [
          "E010"
        ],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 52,
          "title": "Pattern: Sanctioned AI Gateway",
          "text": "Pattern: Sanctioned AI Gateway (AI Governance Engineering Body of Knowledge v0.5.0, pattern catalogue (chapter 05)). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/patterns/sanctioned-ai-gateway",
          "verified": "primary"
        },
        {
          "n": 15,
          "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 4",
          "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 4 (providers and deployers take measures to support the AI literacy of their staff). Publications Office of the EU (EUR-Lex). 2026-07-27.",
          "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_4",
          "verified": "primary"
        },
        {
          "n": 53,
          "title": "OWASP GenAI LLM Top 10 2026",
          "text": "OWASP GenAI LLM Top 10 2026 (LLM01:2026 Prompt Injection to LLM10:2026 Improper Output Handling; resource page dated 3 Aug 2026). OWASP GenAI Security Project. 2026-08-03.",
          "url": "https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/",
          "verified": "primary"
        },
        {
          "n": 5,
          "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
          "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
          "url": "https://www.iso.org/standard/81230.html",
          "verified": "secondary"
        },
        {
          "n": 6,
          "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1",
          "text": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (subcategories cited by id: GOVERN 1.6, 1.7, 2.2, 6.1; MAP 1.1, 3.5; MEASURE 2.3, 2.4, 2.11, 3.1; MANAGE 1.1, 2.4, 3.1, 4.1, 4.3). NIST. 2023-01-26.",
          "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
          "verified": "primary"
        },
        {
          "n": 38,
          "title": "AIUC-1 requirements",
          "text": "AIUC-1 requirements (public requirement index, A001 to F002, each requirement on its own page (E007 and E014 marked retired); AIUC-1 is a standard of the Artificial Intelligence Underwriting Company; this site is not affiliated with AIUC, and a mapping here is not an AIUC-1 certificate or audit). Artificial Intelligence Underwriting Company. 2026-09-24.",
          "url": "https://standard.aiuc-1.com/llms.txt",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Make the gateway the fastest route: every extra step on the approved path sends people back to the unapproved one; replace personal accounts on approved tools with enterprise tenancies.",
        "Feed the catalogue from the Vendor / Model Due-Diligence Gate and review each entry on its review date, because supplier terms change."
      ],
      "openQuestions": [
        "Verification procedure to be specified: the source material states what the control produces, not how a third party checks it; requires technical review.",
        "Logging staff prompts is itself processing of employees' personal data; how much the gateway keeps, and for how long, awaits review with the DPO and employee representatives."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    },
    {
      "id": "AIGE-CTL-DEPLOY-015",
      "profile": "deployment-and-monitoring",
      "url": "https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-015",
      "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-deploy-015.json",
      "title": "Retirement runbook with access and data removal",
      "version": "0.1",
      "status": "draft",
      "reviewerStatus": "open",
      "depth": "derived",
      "objective": "An AI system is retired through a runbook, not a deletion: dependencies are analysed, users move to the fallback, sunset notices go out before the date, a final evidence snapshot is archived, weights, corpora and logs are kept or destroyed as licence, lawful basis and retention decide, every identity and credential is revoked, the registry entry is set to retired rather than deleted, and discovery confirms no copy still runs.",
      "failureModes": [
        "The registry entry is deleted while a copy keeps serving.",
        "A service account or API key of the retired system stays live.",
        "The evidence that the system was ever governed is lost with it.",
        "Consumers of the outputs learn of the retirement after the date, because nobody analysed dependencies or sent sunset notices."
      ],
      "scope": "Every AI system or agent retired, replaced or withdrawn: at end of life, on replacement, for unacceptable risk, for a regulatory reason, on a vendor exit or after an incident.",
      "enforcementPoints": [
        "deploy"
      ],
      "verification": [],
      "evidence": [
        {
          "artefact": "Decommissioning runbook: reason, decision reference, dependencies, notifications, steps with owners and evidence, data disposition, evidence archive and sign-off",
          "schemaId": "decommissioning-runbook",
          "schema": "https://aigovernanceengineer.com/schemas/decommissioning-runbook.v1.json",
          "layer": 4
        }
      ],
      "failureResponse": {
        "effect": "require_approval",
        "text": "The runbook closes only with a final sign-off, once every step is done or skipped with a reason."
      },
      "layer": 4,
      "secondaryLayers": [
        2
      ],
      "patterns": [
        {
          "slug": "deactivation-localisation-retirement-runbook",
          "title": "Deactivation, Localisation & Retirement Runbook",
          "url": "https://aigovernanceengineer.com/patterns/deactivation-localisation-retirement-runbook"
        },
        {
          "slug": "shadow-ai-discovery",
          "title": "Shadow-AI Discovery",
          "url": "https://aigovernanceengineer.com/patterns/shadow-ai-discovery"
        }
      ],
      "seeds": [],
      "derivedFrom": [
        {
          "kind": "pattern",
          "ref": "deactivation-localisation-retirement-runbook",
          "url": "https://aigovernanceengineer.com/patterns/deactivation-localisation-retirement-runbook"
        },
        {
          "kind": "schema",
          "ref": "decommissioning-runbook",
          "url": "https://aigovernanceengineer.com/resources/templates#schema-decommissioning-runbook"
        },
        {
          "kind": "chapter",
          "ref": "governing-deployment",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        }
      ],
      "mappings": {
        "obligations": [],
        "iso42001": [],
        "nistAiRmf": [
          {
            "id": "GOVERN 1.7",
            "title": "Decommissioning and phasing out AI systems safely"
          }
        ],
        "owasp": [],
        "atlas": [],
        "aiuc1": [],
        "csaAicm": [],
        "other": []
      },
      "references": [
        {
          "n": 50,
          "title": "Governing deployment and use",
          "text": "Governing deployment and use (AI Governance Engineering Body of Knowledge v0.5.0, chapter 15, section \"Retirement and decommissioning\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment#retirement-and-decommissioning",
          "verified": "primary"
        },
        {
          "n": 44,
          "title": "Pattern: Deactivation, Localisation & Retirement Runbook",
          "text": "Pattern: Deactivation, Localisation & Retirement Runbook (AI Governance Engineering Body of Knowledge v0.5.0, pattern catalogue (chapter 05)). AI Governance Engineer (Jorge García Aibar). 2026-09.",
          "url": "https://aigovernanceengineer.com/patterns/deactivation-localisation-retirement-runbook",
          "verified": "primary"
        },
        {
          "n": 6,
          "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1",
          "text": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (subcategories cited by id: GOVERN 1.6, 1.7, 2.2, 6.1; MAP 1.1, 3.5; MEASURE 2.3, 2.4, 2.11, 3.1; MANAGE 1.1, 2.4, 3.1, 4.1, 4.3). NIST. 2023-01-26.",
          "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
          "verified": "primary"
        }
      ],
      "implementationNotes": [
        "Design retirement in from the start: the deployment decision record already names the conditions under which the system is retired.",
        "Irregular or indiscriminate termination can itself increase risk, so retirement moves users to a fallback before traffic stops; the downstream use register lists the consumers to warn."
      ],
      "openQuestions": [
        "Verification procedure to be specified: the source material states what the control produces, not how a third party checks it; requires technical review.",
        "The source material leaves the length of the evidence archive to the retention schedule and maps retirement to several record-keeping articles; the obligation mapping of this control awaits review."
      ],
      "observation": null,
      "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
      "examples": []
    }
  ],
  "crosswalk": {
    "frameworks": [
      {
        "id": "obligations-eu-ai-act",
        "name": "EU AI Act (post-Omnibus)",
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng",
        "note": "Rows of this site's obligation register (AIGE-OBL-*) for EU AI Act; each links to its register page.",
        "rows": [
          {
            "ref": "AIGE-OBL-EUAIA-ART4",
            "name": "EU AI Act Art. 4 AI literacy",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art4",
            "note": null,
            "controls": [
              "AIGE-CTL-DEPLOY-003",
              "AIGE-CTL-DEPLOY-014"
            ]
          },
          {
            "ref": "AIGE-OBL-EUAIA-ART4A",
            "name": "EU AI Act Art. 4a lawful basis for special-category data in bias detection",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art4a",
            "note": null,
            "controls": [
              "AIGE-CTL-DATA-007",
              "AIGE-CTL-DEPLOY-009"
            ]
          },
          {
            "ref": "AIGE-OBL-EUAIA-ART5",
            "name": "EU AI Act Art. 5 prohibited practices (incl. new NCII and CSAM bans)",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art5",
            "note": null,
            "controls": [
              "AIGE-CTL-DEPLOY-012"
            ]
          },
          {
            "ref": "AIGE-OBL-EUAIA-ART9",
            "name": "EU AI Act Art. 9 risk management system",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art9",
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-009",
              "AIGE-CTL-DATA-012",
              "AIGE-CTL-ASSURE-001",
              "AIGE-CTL-ASSURE-003",
              "AIGE-CTL-DEPLOY-008"
            ]
          },
          {
            "ref": "AIGE-OBL-EUAIA-ART10",
            "name": "EU AI Act Art. 10 data and data governance",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art10",
            "note": null,
            "controls": [
              "AIGE-CTL-DATA-001",
              "AIGE-CTL-DATA-002",
              "AIGE-CTL-DATA-003",
              "AIGE-CTL-DATA-008",
              "AIGE-CTL-DATA-009",
              "AIGE-CTL-DATA-010"
            ]
          },
          {
            "ref": "AIGE-OBL-EUAIA-ART11",
            "name": "EU AI Act Art. 11 technical documentation (Annex IV)",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art11",
            "note": null,
            "controls": [
              "AIGE-CTL-ASSURE-003",
              "AIGE-CTL-ASSURE-012"
            ]
          },
          {
            "ref": "AIGE-OBL-EUAIA-ART12",
            "name": "EU AI Act Art. 12 record-keeping and logging",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art12",
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-005",
              "AIGE-CTL-EVAL-007",
              "AIGE-CTL-AGENT-023",
              "AIGE-CTL-ASSURE-004",
              "AIGE-CTL-ASSURE-006",
              "AIGE-CTL-ASSURE-007",
              "AIGE-CTL-ASSURE-008"
            ]
          },
          {
            "ref": "AIGE-OBL-EUAIA-ART13",
            "name": "EU AI Act Art. 13 transparency and information to deployers",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art13",
            "note": null,
            "controls": [
              "AIGE-CTL-AGENT-009",
              "AIGE-CTL-AGENT-015",
              "AIGE-CTL-DEPLOY-002"
            ]
          },
          {
            "ref": "AIGE-OBL-EUAIA-ART14",
            "name": "EU AI Act Art. 14 human oversight",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art14",
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-001",
              "AIGE-CTL-EVAL-004",
              "AIGE-CTL-EVAL-006",
              "AIGE-CTL-AGENT-001",
              "AIGE-CTL-AGENT-005",
              "AIGE-CTL-AGENT-007",
              "AIGE-CTL-AGENT-009",
              "AIGE-CTL-AGENT-010",
              "AIGE-CTL-AGENT-011",
              "AIGE-CTL-AGENT-015",
              "AIGE-CTL-AGENT-017",
              "AIGE-CTL-AGENT-019",
              "AIGE-CTL-DEPLOY-003"
            ]
          },
          {
            "ref": "AIGE-OBL-EUAIA-ART15",
            "name": "EU AI Act Art. 15 accuracy, robustness and cybersecurity",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15",
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-002",
              "AIGE-CTL-EVAL-003",
              "AIGE-CTL-EVAL-008",
              "AIGE-CTL-EVAL-009",
              "AIGE-CTL-AGENT-002",
              "AIGE-CTL-AGENT-005",
              "AIGE-CTL-AGENT-007",
              "AIGE-CTL-AGENT-008",
              "AIGE-CTL-AGENT-010",
              "AIGE-CTL-AGENT-015",
              "AIGE-CTL-AGENT-016",
              "AIGE-CTL-AGENT-017",
              "AIGE-CTL-AGENT-018",
              "AIGE-CTL-AGENT-019",
              "AIGE-CTL-AGENT-020",
              "AIGE-CTL-AGENT-021",
              "AIGE-CTL-AGENT-022",
              "AIGE-CTL-AGENT-023",
              "AIGE-CTL-AGENT-025",
              "AIGE-CTL-AGENT-026",
              "AIGE-CTL-ASSURE-002",
              "AIGE-CTL-ASSURE-006",
              "AIGE-CTL-ASSURE-010",
              "AIGE-CTL-ASSURE-011"
            ]
          },
          {
            "ref": "AIGE-OBL-EUAIA-ART15-4",
            "name": "EU AI Act Art. 15(4) feedback loops in systems that continue to learn",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15-4",
            "note": null,
            "controls": [
              "AIGE-CTL-DEPLOY-009"
            ]
          },
          {
            "ref": "AIGE-OBL-EUAIA-ART17",
            "name": "EU AI Act Art. 17 quality management system",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art17",
            "note": null,
            "controls": [
              "AIGE-CTL-ASSURE-004",
              "AIGE-CTL-ASSURE-006",
              "AIGE-CTL-ASSURE-007"
            ]
          },
          {
            "ref": "AIGE-OBL-EUAIA-ART18",
            "name": "EU AI Act Art. 18 documentation keeping",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art18",
            "note": null,
            "controls": [
              "AIGE-CTL-ASSURE-008"
            ]
          },
          {
            "ref": "AIGE-OBL-EUAIA-ART19",
            "name": "EU AI Act Art. 19 automatically generated logs kept by the provider",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art19",
            "note": null,
            "controls": [
              "AIGE-CTL-ASSURE-008"
            ]
          },
          {
            "ref": "AIGE-OBL-EUAIA-ART20",
            "name": "EU AI Act Art. 20 corrective actions and duty of information",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art20",
            "note": null,
            "controls": [
              "AIGE-CTL-DEPLOY-012"
            ]
          },
          {
            "ref": "AIGE-OBL-EUAIA-ART25",
            "name": "EU AI Act Art. 25 responsibilities along the AI value chain",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art25",
            "note": null,
            "controls": [
              "AIGE-CTL-AGENT-018",
              "AIGE-CTL-AGENT-019",
              "AIGE-CTL-DATA-012",
              "AIGE-CTL-DEPLOY-007"
            ]
          },
          {
            "ref": "AIGE-OBL-EUAIA-ART26",
            "name": "EU AI Act Art. 26 deployer obligations for high-risk systems",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26",
            "note": null,
            "controls": [
              "AIGE-CTL-AGENT-001",
              "AIGE-CTL-AGENT-010",
              "AIGE-CTL-AGENT-011",
              "AIGE-CTL-AGENT-019",
              "AIGE-CTL-DEPLOY-001",
              "AIGE-CTL-DEPLOY-002"
            ]
          },
          {
            "ref": "AIGE-OBL-EUAIA-ART26-2",
            "name": "EU AI Act Art. 26(2) human oversight assigned to persons with competence, training and authority",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26-2",
            "note": null,
            "controls": [
              "AIGE-CTL-DEPLOY-003"
            ]
          },
          {
            "ref": "AIGE-OBL-EUAIA-ART26-5",
            "name": "EU AI Act Art. 26(5) deployer monitoring, suspension and informing the provider",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26-5",
            "note": null,
            "controls": [
              "AIGE-CTL-DEPLOY-005",
              "AIGE-CTL-DEPLOY-008",
              "AIGE-CTL-DEPLOY-011",
              "AIGE-CTL-DEPLOY-012"
            ]
          },
          {
            "ref": "AIGE-OBL-EUAIA-ART26-6",
            "name": "EU AI Act Art. 26(6) deployer retention of automatically generated logs",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26-6",
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-007",
              "AIGE-CTL-DEPLOY-010"
            ]
          },
          {
            "ref": "AIGE-OBL-EUAIA-ART49-71",
            "name": "EU AI Act Art. 49/71 registration of high-risk systems in the EU database",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art49-71",
            "note": null,
            "controls": [
              "AIGE-CTL-DEPLOY-013"
            ]
          },
          {
            "ref": "AIGE-OBL-EUAIA-ART50",
            "name": "EU AI Act Art. 50 transparency for certain AI systems",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art50",
            "note": null,
            "controls": [
              "AIGE-CTL-AGENT-009",
              "AIGE-CTL-AGENT-015",
              "AIGE-CTL-DATA-012"
            ]
          },
          {
            "ref": "AIGE-OBL-EUAIA-ART53",
            "name": "EU AI Act Art. 53 GPAI provider obligations",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art53",
            "note": null,
            "controls": [
              "AIGE-CTL-ASSURE-012"
            ]
          },
          {
            "ref": "AIGE-OBL-EUAIA-ART53-1C",
            "name": "EU AI Act Art. 53(1)(c) copyright policy honouring text-and-data-mining reservations",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art53-1c",
            "note": null,
            "controls": [
              "AIGE-CTL-DATA-003"
            ]
          },
          {
            "ref": "AIGE-OBL-EUAIA-ART55",
            "name": "EU AI Act Art. 55 GPAI models with systemic risk",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art55",
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-009",
              "AIGE-CTL-ASSURE-002",
              "AIGE-CTL-ASSURE-010"
            ]
          },
          {
            "ref": "AIGE-OBL-EUAIA-ART72",
            "name": "EU AI Act Art. 72 post-market monitoring",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art72",
            "note": null,
            "controls": [
              "AIGE-CTL-AGENT-001",
              "AIGE-CTL-AGENT-008",
              "AIGE-CTL-AGENT-010",
              "AIGE-CTL-AGENT-011",
              "AIGE-CTL-AGENT-019",
              "AIGE-CTL-AGENT-025",
              "AIGE-CTL-ASSURE-004",
              "AIGE-CTL-ASSURE-005",
              "AIGE-CTL-ASSURE-007",
              "AIGE-CTL-DEPLOY-008"
            ]
          },
          {
            "ref": "AIGE-OBL-EUAIA-ART73",
            "name": "EU AI Act Art. 73 serious-incident reporting",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art73",
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-007",
              "AIGE-CTL-DEPLOY-011"
            ]
          }
        ]
      },
      {
        "id": "obligations-gpai-code-of-practice",
        "name": "GPAI Code of Practice",
        "url": "https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai",
        "note": "Rows of this site's obligation register (AIGE-OBL-*) for GPAI Code; each links to its register page.",
        "rows": [
          {
            "ref": "AIGE-OBL-GPAICOP-SAFETY-C9",
            "name": "Safety and Security Commitment 9: serious-incident reporting",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-gpaicop-safety-c9",
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-007"
            ]
          }
        ]
      },
      {
        "id": "obligations-gdpr",
        "name": "General Data Protection Regulation (EU) 2016/679",
        "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng",
        "note": "Rows of this site's obligation register (AIGE-OBL-*) for GDPR; each links to its register page.",
        "rows": [
          {
            "ref": "AIGE-OBL-GDPR-ART5-1B",
            "name": "GDPR Art. 5(1)(b) and 6(4) purpose limitation",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art5-1b",
            "note": null,
            "controls": [
              "AIGE-CTL-DATA-001",
              "AIGE-CTL-DATA-003",
              "AIGE-CTL-DATA-005"
            ]
          },
          {
            "ref": "AIGE-OBL-GDPR-ART6",
            "name": "GDPR Art. 6 lawful basis per processing moment",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art6",
            "note": null,
            "controls": [
              "AIGE-CTL-DATA-004"
            ]
          },
          {
            "ref": "AIGE-OBL-GDPR-ART7",
            "name": "GDPR Art. 7 conditions for consent and its withdrawal",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art7",
            "note": null,
            "controls": [
              "AIGE-CTL-DATA-011"
            ]
          },
          {
            "ref": "AIGE-OBL-GDPR-ART9",
            "name": "GDPR Art. 9 special categories, incl. inferred sensitive data",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art9",
            "note": null,
            "controls": [
              "AIGE-CTL-DATA-007"
            ]
          },
          {
            "ref": "AIGE-OBL-GDPR-ART15-17-21",
            "name": "GDPR Arts. 15–17 and 21 data subject rights against trained models",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art15-17-21",
            "note": null,
            "controls": [
              "AIGE-CTL-DATA-011"
            ]
          },
          {
            "ref": "AIGE-OBL-GDPR-ART25",
            "name": "GDPR Art. 5(1)(c) and 25 minimisation and data protection by design and by default",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art25",
            "note": null,
            "controls": [
              "AIGE-CTL-DATA-006"
            ]
          },
          {
            "ref": "AIGE-OBL-GDPR-ART30",
            "name": "GDPR Art. 30 records of processing activities",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art30",
            "note": null,
            "controls": [
              "AIGE-CTL-DATA-007"
            ]
          },
          {
            "ref": "AIGE-OBL-GDPR-ART33-34",
            "name": "GDPR Arts. 33–34 personal data breach notification",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art33-34",
            "note": null,
            "controls": [
              "AIGE-CTL-DEPLOY-011"
            ]
          },
          {
            "ref": "AIGE-OBL-GDPR-ART35-36",
            "name": "GDPR Arts. 35–36 DPIA and prior consultation",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art35-36",
            "note": null,
            "controls": [
              "AIGE-CTL-DATA-004"
            ]
          }
        ]
      },
      {
        "id": "obligations-eu-dsm",
        "name": "Directive (EU) 2019/790 on copyright in the Digital Single Market",
        "url": "https://eur-lex.europa.eu/eli/dir/2019/790/oj/eng",
        "note": "Rows of this site's obligation register (AIGE-OBL-*) for DSM Directive; each links to its register page.",
        "rows": [
          {
            "ref": "AIGE-OBL-DSM-ART4-3",
            "name": "DSM Directive Art. 4(3) text-and-data-mining reservations",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-dsm-art4-3",
            "note": null,
            "controls": [
              "AIGE-CTL-DATA-003",
              "AIGE-CTL-DATA-011"
            ]
          }
        ]
      },
      {
        "id": "obligations-iso-42001",
        "name": "ISO/IEC 42001",
        "url": null,
        "note": "Rows of this site's obligation register (AIGE-OBL-*) for ISO 42001; each links to its register page.",
        "rows": [
          {
            "ref": "AIGE-OBL-ISO42001-A6",
            "name": "A.6 AI system life cycle",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a6",
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-008",
              "AIGE-CTL-EVAL-009",
              "AIGE-CTL-ASSURE-001",
              "AIGE-CTL-ASSURE-003",
              "AIGE-CTL-ASSURE-010"
            ]
          },
          {
            "ref": "AIGE-OBL-ISO42001-A7",
            "name": "A.7 Data for AI systems",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a7",
            "note": null,
            "controls": [
              "AIGE-CTL-DATA-001",
              "AIGE-CTL-DATA-002",
              "AIGE-CTL-DATA-008",
              "AIGE-CTL-DATA-010"
            ]
          },
          {
            "ref": "AIGE-OBL-ISO42001-A8",
            "name": "A.8 Information for interested parties",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a8",
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-007",
              "AIGE-CTL-DATA-012"
            ]
          },
          {
            "ref": "AIGE-OBL-ISO42001-A9",
            "name": "A.9 Use of AI systems",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a9",
            "note": null,
            "controls": [
              "AIGE-CTL-DATA-012"
            ]
          },
          {
            "ref": "AIGE-OBL-ISO42001-A10",
            "name": "A.10 Third-party and customer relationships",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a10",
            "note": null,
            "controls": [
              "AIGE-CTL-AGENT-018",
              "AIGE-CTL-AGENT-019",
              "AIGE-CTL-ASSURE-010",
              "AIGE-CTL-ASSURE-011"
            ]
          }
        ]
      },
      {
        "id": "obligations-nist-ai-rmf",
        "name": "NIST AI RMF",
        "url": "https://www.nist.gov/itl/ai-risk-management-framework",
        "note": "Rows of this site's obligation register (AIGE-OBL-*) for NIST AI RMF; each links to its register page.",
        "rows": [
          {
            "ref": "AIGE-OBL-NISTRMF-GOVERN",
            "name": "GOVERN",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-govern",
            "note": null,
            "controls": [
              "AIGE-CTL-ASSURE-005",
              "AIGE-CTL-ASSURE-007"
            ]
          },
          {
            "ref": "AIGE-OBL-NISTRMF-MANAGE",
            "name": "MANAGE",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage",
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-006",
              "AIGE-CTL-AGENT-008",
              "AIGE-CTL-AGENT-010",
              "AIGE-CTL-AGENT-025",
              "AIGE-CTL-ASSURE-004",
              "AIGE-CTL-ASSURE-005",
              "AIGE-CTL-ASSURE-007",
              "AIGE-CTL-ASSURE-010"
            ]
          },
          {
            "ref": "AIGE-OBL-NISTRMF-MAP",
            "name": "MAP",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-map",
            "note": null,
            "controls": [
              "AIGE-CTL-ASSURE-012"
            ]
          },
          {
            "ref": "AIGE-OBL-NISTRMF-MEASURE",
            "name": "MEASURE",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure",
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-005",
              "AIGE-CTL-EVAL-009",
              "AIGE-CTL-ASSURE-001",
              "AIGE-CTL-ASSURE-002",
              "AIGE-CTL-ASSURE-003"
            ]
          }
        ]
      },
      {
        "id": "obligations-nist-ai-agent-standards",
        "name": "NIST AI Agent Standards Initiative",
        "url": "https://www.nist.gov/news-events/news/2026/02/announcing-ai-agent-standards-initiative-interoperable-and-secure",
        "note": "Rows of this site's obligation register (AIGE-OBL-*) for NIST Agents; each links to its register page.",
        "rows": [
          {
            "ref": "AIGE-OBL-NIST-AGENTS",
            "name": "NIST AI Agent Standards Initiative (2026)",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-nist-agents",
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-003",
              "AIGE-CTL-AGENT-002",
              "AIGE-CTL-AGENT-007",
              "AIGE-CTL-AGENT-020",
              "AIGE-CTL-AGENT-021",
              "AIGE-CTL-AGENT-022",
              "AIGE-CTL-AGENT-025",
              "AIGE-CTL-AGENT-026"
            ]
          }
        ]
      },
      {
        "id": "obligations-nist-ai-600-1",
        "name": "NIST AI 600-1 Generative AI Profile",
        "url": "https://doi.org/10.6028/NIST.AI.600-1",
        "note": "Rows of this site's obligation register (AIGE-OBL-*) for NIST AI 600-1; each links to its register page.",
        "rows": [
          {
            "ref": "AIGE-OBL-NIST-AI600-1",
            "name": "NIST AI 600-1 Generative AI Profile",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-nist-ai600-1",
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-009"
            ]
          }
        ]
      },
      {
        "id": "obligations-csa-aicm",
        "name": "CSA AI Controls Matrix (AICM) v1.1",
        "url": "https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1",
        "note": "Rows of this site's obligation register (AIGE-OBL-*) for CSA AICM; each links to its register page.",
        "rows": [
          {
            "ref": "AIGE-OBL-CSA-AICM",
            "name": "AICM v1.1: 247 control objectives across 18 domains",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-csa-aicm",
            "note": null,
            "controls": [
              "AIGE-CTL-ASSURE-005",
              "AIGE-CTL-ASSURE-012"
            ]
          },
          {
            "ref": "AIGE-OBL-CSA-AICM-AGENTIC",
            "name": "AICM agent controls with the CSA Agentic Trust Framework and AARM specification",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-csa-aicm-agentic",
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-001",
              "AIGE-CTL-AGENT-002",
              "AIGE-CTL-AGENT-005",
              "AIGE-CTL-AGENT-007",
              "AIGE-CTL-AGENT-015",
              "AIGE-CTL-AGENT-017",
              "AIGE-CTL-AGENT-020",
              "AIGE-CTL-AGENT-021",
              "AIGE-CTL-AGENT-022",
              "AIGE-CTL-AGENT-025",
              "AIGE-CTL-AGENT-026"
            ]
          }
        ]
      },
      {
        "id": "obligations-owasp-agentic-top-10",
        "name": "OWASP Top 10 for Agentic Applications 2026",
        "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
        "note": "Rows of this site's obligation register (AIGE-OBL-*) for OWASP Agentic; each links to its register page.",
        "rows": [
          {
            "ref": "AIGE-OBL-OWASP-AGENTIC",
            "name": "Top 10 for Agentic Applications 2026",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-agentic",
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-001",
              "AIGE-CTL-EVAL-002",
              "AIGE-CTL-EVAL-003",
              "AIGE-CTL-EVAL-004",
              "AIGE-CTL-EVAL-006",
              "AIGE-CTL-AGENT-001",
              "AIGE-CTL-AGENT-002",
              "AIGE-CTL-AGENT-005",
              "AIGE-CTL-AGENT-007",
              "AIGE-CTL-AGENT-008",
              "AIGE-CTL-AGENT-009",
              "AIGE-CTL-AGENT-010",
              "AIGE-CTL-AGENT-011",
              "AIGE-CTL-AGENT-015",
              "AIGE-CTL-AGENT-016",
              "AIGE-CTL-AGENT-017",
              "AIGE-CTL-AGENT-019",
              "AIGE-CTL-AGENT-020",
              "AIGE-CTL-AGENT-021",
              "AIGE-CTL-AGENT-022",
              "AIGE-CTL-AGENT-023",
              "AIGE-CTL-AGENT-025",
              "AIGE-CTL-AGENT-026",
              "AIGE-CTL-ASSURE-002",
              "AIGE-CTL-ASSURE-010"
            ]
          }
        ]
      },
      {
        "id": "obligations-owasp-llm-top-10",
        "name": "OWASP Top 10 for LLM Applications 2026",
        "url": "https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/",
        "note": "Rows of this site's obligation register (AIGE-OBL-*) for OWASP LLM; each links to its register page.",
        "rows": [
          {
            "ref": "AIGE-OBL-OWASP-LLM",
            "name": "Top 10 for LLM Applications 2026",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-llm",
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-002",
              "AIGE-CTL-DATA-009",
              "AIGE-CTL-ASSURE-010",
              "AIGE-CTL-ASSURE-011"
            ]
          }
        ]
      },
      {
        "id": "obligations-owasp-acs",
        "name": "OWASP Agent Control Standard (ACS)",
        "url": "https://genai.owasp.org/resource/agent-control-standard-acs/",
        "note": "Rows of this site's obligation register (AIGE-OBL-*) for OWASP ACS; each links to its register page.",
        "rows": [
          {
            "ref": "AIGE-OBL-OWASP-ACS",
            "name": "Agent Control Standard (ACS)",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-acs",
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-004"
            ]
          }
        ]
      },
      {
        "id": "obligations-owasp-aibom",
        "name": "OWASP AIBOM",
        "url": "https://genai.owasp.org/initiatives/ai-sbom-initiative/",
        "note": "Rows of this site's obligation register (AIGE-OBL-*) for OWASP AIBOM; each links to its register page.",
        "rows": [
          {
            "ref": "AIGE-OBL-OWASP-AIBOM",
            "name": "AIBOM",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-aibom",
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-008",
              "AIGE-CTL-AGENT-018",
              "AIGE-CTL-AGENT-019",
              "AIGE-CTL-ASSURE-012"
            ]
          }
        ]
      },
      {
        "id": "obligations-sg-agentic-framework",
        "name": "Singapore Model AI Governance Framework for Agentic AI",
        "url": "https://www.imda.gov.sg/-/media/imda/files/about/emerging-tech-and-research/artificial-intelligence/mgf-for-agentic-ai.pdf",
        "note": "Rows of this site's obligation register (AIGE-OBL-*) for Singapore Agentic; each links to its register page.",
        "rows": [
          {
            "ref": "AIGE-OBL-SG-AGENTIC-CHECKPOINTS",
            "name": "Singapore IMDA Model AI Governance Framework for Agentic AI: human checkpoints for significant actions (voluntary)",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-sg-agentic-checkpoints",
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-004"
            ]
          },
          {
            "ref": "AIGE-OBL-SG-AGENTIC-IDENTITY",
            "name": "Singapore IMDA Model AI Governance Framework for Agentic AI: agent identity and scoped authorisations (voluntary)",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-sg-agentic-identity",
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-001",
              "AIGE-CTL-EVAL-003"
            ]
          }
        ]
      },
      {
        "id": "obligations-cn-tc260-framework",
        "name": "TC260 AI Safety Governance Framework 3.0",
        "url": "https://www.cac.gov.cn/rootimages/uploadimg/1791137114683961/1791137114683961.pdf",
        "note": "Rows of this site's obligation register (AIGE-OBL-*) for TC260 Framework 3.0; each links to its register page.",
        "rows": [
          {
            "ref": "AIGE-OBL-CN-TC260-AGENTS",
            "name": "TC260 Framework 3.0 Appendix 2: agentic AI risk management (voluntary; 2026-09-14)",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-cn-tc260-agents",
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-006"
            ]
          }
        ]
      },
      {
        "id": "obligations-etsi-en-304-223",
        "name": "ETSI EN 304 223",
        "url": "https://www.etsi.org/newsroom/press-releases/2627-etsi-releases-world-leading-standard-for-securing-ai/",
        "note": "Rows of this site's obligation register (AIGE-OBL-*) for ETSI EN 304 223; each links to its register page.",
        "rows": [
          {
            "ref": "AIGE-OBL-ETSI-304223",
            "name": "ETSI EN 304 223 baseline cyber-security for AI models and systems",
            "url": "https://aigovernanceengineer.com/obligations/aige-obl-etsi-304223",
            "note": null,
            "controls": [
              "AIGE-CTL-AGENT-016"
            ]
          }
        ]
      },
      {
        "id": "iso42001",
        "name": "ISO/IEC 42001:2023 Annex A",
        "url": "https://www.iso.org/standard/81230.html",
        "note": "Annex A reference controls, by their short titles.",
        "rows": [
          {
            "ref": "A.6.2.2",
            "name": "AI system requirements and specification",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-001"
            ]
          },
          {
            "ref": "A.6.2.4",
            "name": "AI system verification and validation",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-008",
              "AIGE-CTL-EVAL-009",
              "AIGE-CTL-AGENT-007",
              "AIGE-CTL-ASSURE-001",
              "AIGE-CTL-ASSURE-002",
              "AIGE-CTL-ASSURE-003"
            ]
          },
          {
            "ref": "A.6.2.5",
            "name": "AI system deployment",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-AGENT-002",
              "AIGE-CTL-AGENT-016",
              "AIGE-CTL-AGENT-020",
              "AIGE-CTL-AGENT-021",
              "AIGE-CTL-AGENT-022",
              "AIGE-CTL-AGENT-025",
              "AIGE-CTL-AGENT-026",
              "AIGE-CTL-ASSURE-010",
              "AIGE-CTL-DEPLOY-001",
              "AIGE-CTL-DEPLOY-004",
              "AIGE-CTL-DEPLOY-005",
              "AIGE-CTL-DEPLOY-006"
            ]
          },
          {
            "ref": "A.6.2.6",
            "name": "AI system operation and monitoring",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-002",
              "AIGE-CTL-EVAL-003",
              "AIGE-CTL-EVAL-005",
              "AIGE-CTL-EVAL-006",
              "AIGE-CTL-AGENT-001",
              "AIGE-CTL-AGENT-005",
              "AIGE-CTL-AGENT-007",
              "AIGE-CTL-AGENT-008",
              "AIGE-CTL-AGENT-010",
              "AIGE-CTL-AGENT-011",
              "AIGE-CTL-AGENT-015",
              "AIGE-CTL-AGENT-016",
              "AIGE-CTL-AGENT-017",
              "AIGE-CTL-AGENT-019",
              "AIGE-CTL-AGENT-023",
              "AIGE-CTL-AGENT-025",
              "AIGE-CTL-DEPLOY-005",
              "AIGE-CTL-DEPLOY-008",
              "AIGE-CTL-DEPLOY-009",
              "AIGE-CTL-DEPLOY-012"
            ]
          },
          {
            "ref": "A.6.2.8",
            "name": "AI system recording of event logs",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-005",
              "AIGE-CTL-EVAL-007",
              "AIGE-CTL-AGENT-001",
              "AIGE-CTL-AGENT-010",
              "AIGE-CTL-AGENT-011",
              "AIGE-CTL-AGENT-019",
              "AIGE-CTL-AGENT-023",
              "AIGE-CTL-DEPLOY-010"
            ]
          },
          {
            "ref": "A.7.2",
            "name": "Data for development and enhancement of AI system",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-DATA-001",
              "AIGE-CTL-DATA-002"
            ]
          },
          {
            "ref": "A.7.4",
            "name": "Quality of data for AI systems",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-DATA-001",
              "AIGE-CTL-DATA-008"
            ]
          },
          {
            "ref": "A.7.5",
            "name": "Data provenance",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-AGENT-018",
              "AIGE-CTL-AGENT-019",
              "AIGE-CTL-DATA-001",
              "AIGE-CTL-DATA-002",
              "AIGE-CTL-DATA-003",
              "AIGE-CTL-DATA-009",
              "AIGE-CTL-DATA-010",
              "AIGE-CTL-ASSURE-012"
            ]
          },
          {
            "ref": "A.8.2",
            "name": "System documentation and information for users",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-AGENT-009",
              "AIGE-CTL-AGENT-015",
              "AIGE-CTL-DATA-012",
              "AIGE-CTL-DEPLOY-002"
            ]
          },
          {
            "ref": "A.8.4",
            "name": "Communication of incidents",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-007",
              "AIGE-CTL-DEPLOY-011"
            ]
          },
          {
            "ref": "A.9.2",
            "name": "Processes for responsible use of AI systems",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-001",
              "AIGE-CTL-EVAL-003",
              "AIGE-CTL-EVAL-004",
              "AIGE-CTL-AGENT-005",
              "AIGE-CTL-AGENT-007",
              "AIGE-CTL-AGENT-009",
              "AIGE-CTL-AGENT-015",
              "AIGE-CTL-AGENT-017",
              "AIGE-CTL-DEPLOY-003",
              "AIGE-CTL-DEPLOY-014"
            ]
          },
          {
            "ref": "A.9.4",
            "name": "Intended use of the AI system",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-DATA-012",
              "AIGE-CTL-DEPLOY-001"
            ]
          },
          {
            "ref": "A.10.3",
            "name": "Suppliers",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-AGENT-018",
              "AIGE-CTL-AGENT-019",
              "AIGE-CTL-ASSURE-010",
              "AIGE-CTL-ASSURE-011",
              "AIGE-CTL-ASSURE-012",
              "AIGE-CTL-DEPLOY-014"
            ]
          }
        ]
      },
      {
        "id": "nist-ai-rmf",
        "name": "NIST AI Risk Management Framework (AI RMF 1.0)",
        "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
        "note": "Subcategories, with their text as NIST AI 100-1 prints it.",
        "rows": [
          {
            "ref": "GOVERN 1.6",
            "name": "Mechanisms are in place to inventory AI systems and are resourced according to organizational risk priorities.",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-DEPLOY-013"
            ]
          },
          {
            "ref": "GOVERN 1.7",
            "name": "Processes and procedures are in place for decommissioning and phasing out AI systems safely and in a manner that does not increase risks or decrease the organization’s trustworthiness.",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-DEPLOY-015"
            ]
          },
          {
            "ref": "GOVERN 2.2",
            "name": "The organization’s personnel and partners receive AI risk management training to enable them to perform their duties and responsibilities consistent with related policies, procedures, and agreements.",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-DEPLOY-014"
            ]
          },
          {
            "ref": "GOVERN 6.1",
            "name": "Policies and procedures are in place that address AI risks associated with third-party entities, including risks of infringement of a third-party’s intellectual property or other rights.",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-DATA-003",
              "AIGE-CTL-DEPLOY-014"
            ]
          },
          {
            "ref": "MAP 1.1",
            "name": "Intended purposes, potentially beneficial uses, context-specific laws, norms and expectations, and prospective settings in which the AI system will be deployed are understood and documented. Considerations include: the specific set or types of users along with their expectations; potential positive and negative impacts of system uses to individuals, communities, organizations, society, and the planet; assumptions and related limitations about AI system purposes, uses, and risks across the development or product AI lifecycle; and related TEVV and system metrics.",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-DATA-012",
              "AIGE-CTL-DEPLOY-001"
            ]
          },
          {
            "ref": "MAP 2.3",
            "name": "Scientific integrity and TEVV considerations are identified and documented, including those related to experimental design, data collection and selection (e.g., availability, representativeness, suitability), system trustworthiness, and construct validation.",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-DATA-001",
              "AIGE-CTL-DATA-002",
              "AIGE-CTL-DATA-008"
            ]
          },
          {
            "ref": "MAP 3.3",
            "name": "Targeted application scope is specified and documented based on the system’s capability, established context, and AI system categorization.",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-DATA-012"
            ]
          },
          {
            "ref": "MAP 3.5",
            "name": "Processes for human oversight are defined, assessed, and documented in accordance with organizational policies from the GOVERN function.",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-DEPLOY-003"
            ]
          },
          {
            "ref": "MAP 4.1",
            "name": "Approaches for mapping AI technology and legal risks of its components – including the use of third-party data or software – are in place, followed, and documented, as are risks of infringement of a third party’s intellectual property or other rights.",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-DATA-001",
              "AIGE-CTL-DATA-003"
            ]
          },
          {
            "ref": "MAP 4.2",
            "name": "Internal risk controls for components of the AI system, including third-party AI technologies, are identified and documented.",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-001",
              "AIGE-CTL-EVAL-004"
            ]
          },
          {
            "ref": "MEASURE 2.1",
            "name": "Test sets, metrics, and details about the tools used during TEVV are documented.",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-008",
              "AIGE-CTL-ASSURE-001"
            ]
          },
          {
            "ref": "MEASURE 2.3",
            "name": "AI system performance or assurance criteria are measured qualitatively or quantitatively and demonstrated for conditions similar to deployment setting(s). Measures are documented.",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-009",
              "AIGE-CTL-ASSURE-002",
              "AIGE-CTL-ASSURE-003",
              "AIGE-CTL-DEPLOY-005"
            ]
          },
          {
            "ref": "MEASURE 2.4",
            "name": "The functionality and behavior of the AI system and its components – as identified in the MAP function – are monitored when in production.",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-DEPLOY-008"
            ]
          },
          {
            "ref": "MEASURE 2.7",
            "name": "AI system security and resilience – as identified in the MAP function – are evaluated and documented.",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-002",
              "AIGE-CTL-EVAL-003",
              "AIGE-CTL-ASSURE-010"
            ]
          },
          {
            "ref": "MEASURE 2.10",
            "name": "Privacy risk of the AI system – as identified in the MAP function – is examined and documented.",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-DATA-004"
            ]
          },
          {
            "ref": "MEASURE 2.11",
            "name": "Fairness and bias – as identified in the MAP function – are evaluated and results are documented.",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-DEPLOY-009"
            ]
          },
          {
            "ref": "MEASURE 2.13",
            "name": "Effectiveness of the employed TEVV metrics and processes in the MEASURE function are evaluated and documented.",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-009"
            ]
          },
          {
            "ref": "MEASURE 3.1",
            "name": "Approaches, personnel, and documentation are in place to regularly identify and track existing, unanticipated, and emergent AI risks based on factors such as intended and actual performance in deployed contexts.",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-005",
              "AIGE-CTL-DEPLOY-008"
            ]
          },
          {
            "ref": "MANAGE 1.1",
            "name": "A determination is made as to whether the AI system achieves its intended purposes and stated objectives and whether its development or deployment should proceed.",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-DEPLOY-001",
              "AIGE-CTL-DEPLOY-004",
              "AIGE-CTL-DEPLOY-005"
            ]
          },
          {
            "ref": "MANAGE 1.4",
            "name": "Negative residual risks (defined as the sum of all unmitigated risks) to both downstream acquirers of AI systems and end users are documented.",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-DATA-012"
            ]
          },
          {
            "ref": "MANAGE 2.4",
            "name": "Mechanisms are in place and applied, and responsibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use.",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-006",
              "AIGE-CTL-AGENT-010",
              "AIGE-CTL-AGENT-011",
              "AIGE-CTL-DEPLOY-005",
              "AIGE-CTL-DEPLOY-006",
              "AIGE-CTL-DEPLOY-012"
            ]
          },
          {
            "ref": "MANAGE 3.1",
            "name": "AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented.",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-DEPLOY-006",
              "AIGE-CTL-DEPLOY-014"
            ]
          },
          {
            "ref": "MANAGE 3.2",
            "name": "Pre-trained models which are used for development are monitored as part of AI system regular monitoring and maintenance.",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-ASSURE-010"
            ]
          },
          {
            "ref": "MANAGE 4.1",
            "name": "Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing and evaluating input from users and other relevant AI actors, appeal and override, decommissioning, incident response, recovery, and change management.",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-ASSURE-005",
              "AIGE-CTL-DEPLOY-008"
            ]
          },
          {
            "ref": "MANAGE 4.3",
            "name": "Incidents and errors are communicated to relevant AI actors, including affected communities. Processes for tracking, responding to, and recovering from incidents and errors are followed and documented.",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-007",
              "AIGE-CTL-DEPLOY-011"
            ]
          }
        ]
      },
      {
        "id": "owasp-llm",
        "name": "OWASP Top 10 for LLM Applications 2026",
        "url": "https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/",
        "note": "Version 2026 (published 3 Aug 2026); ids as the catalogue prints them.",
        "rows": [
          {
            "ref": "LLM02:2026",
            "name": "Sensitive Information Disclosure",
            "url": "https://github.com/GenAI-Security-Project/GenAI-LLM-Top10/blob/main/2026/final/LLM02_SensitiveInformationDisclosure.md",
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-002",
              "AIGE-CTL-DEPLOY-014"
            ]
          },
          {
            "ref": "LLM03:2026",
            "name": "Excessive Agency",
            "url": "https://github.com/GenAI-Security-Project/GenAI-LLM-Top10/blob/main/2026/final/LLM03_ExcessiveAgency.md",
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-001"
            ]
          },
          {
            "ref": "LLM04:2026",
            "name": "Supply Chain",
            "url": "https://github.com/GenAI-Security-Project/GenAI-LLM-Top10/blob/main/2026/final/LLM04_SupplyChain.md",
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-008",
              "AIGE-CTL-ASSURE-010",
              "AIGE-CTL-ASSURE-011",
              "AIGE-CTL-ASSURE-012"
            ]
          },
          {
            "ref": "LLM05:2026",
            "name": "Data and Model Poisoning",
            "url": "https://github.com/GenAI-Security-Project/GenAI-LLM-Top10/blob/main/2026/final/LLM05_DataModelPoisoning.md",
            "note": null,
            "controls": [
              "AIGE-CTL-DATA-001",
              "AIGE-CTL-DATA-009"
            ]
          },
          {
            "ref": "LLM06:2026",
            "name": "Unbounded Consumption",
            "url": "https://github.com/GenAI-Security-Project/GenAI-LLM-Top10/blob/main/2026/final/LLM06_UnboundedConsumption.md",
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-006"
            ]
          },
          {
            "ref": "LLM10:2026",
            "name": "Improper Output Handling",
            "url": "https://github.com/GenAI-Security-Project/GenAI-LLM-Top10/blob/main/2026/final/LLM10_ImproperOutputHandling.md",
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-004",
              "AIGE-CTL-DATA-012"
            ]
          }
        ]
      },
      {
        "id": "owasp-asi",
        "name": "OWASP Top 10 for Agentic Applications 2026",
        "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
        "note": "Version 2026 (published 9 Dec 2025); ids as the catalogue prints them.",
        "rows": [
          {
            "ref": "ASI01",
            "name": "Agent Goal Hijack",
            "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-004",
              "AIGE-CTL-AGENT-007",
              "AIGE-CTL-ASSURE-002"
            ]
          },
          {
            "ref": "ASI02",
            "name": "Tool Misuse and Exploitation",
            "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-001",
              "AIGE-CTL-EVAL-002",
              "AIGE-CTL-EVAL-004",
              "AIGE-CTL-AGENT-005",
              "AIGE-CTL-AGENT-007",
              "AIGE-CTL-AGENT-015",
              "AIGE-CTL-AGENT-017",
              "AIGE-CTL-ASSURE-002"
            ]
          },
          {
            "ref": "ASI03",
            "name": "Identity and Privilege Abuse",
            "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-001",
              "AIGE-CTL-EVAL-003",
              "AIGE-CTL-AGENT-002",
              "AIGE-CTL-AGENT-020",
              "AIGE-CTL-AGENT-021",
              "AIGE-CTL-AGENT-022"
            ]
          },
          {
            "ref": "ASI04",
            "name": "Agentic Supply Chain Vulnerabilities",
            "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-008",
              "AIGE-CTL-AGENT-018",
              "AIGE-CTL-AGENT-019",
              "AIGE-CTL-ASSURE-010",
              "AIGE-CTL-ASSURE-011"
            ]
          },
          {
            "ref": "ASI05",
            "name": "Unexpected Code Execution (RCE)",
            "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-004",
              "AIGE-CTL-AGENT-016"
            ]
          },
          {
            "ref": "ASI06",
            "name": "Memory & Context Poisoning",
            "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
            "note": null,
            "controls": [
              "AIGE-CTL-AGENT-023"
            ]
          },
          {
            "ref": "ASI07",
            "name": "Insecure Inter-Agent Communication",
            "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
            "note": null,
            "controls": [
              "AIGE-CTL-AGENT-025",
              "AIGE-CTL-AGENT-026"
            ]
          },
          {
            "ref": "ASI08",
            "name": "Cascading Failures",
            "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-006",
              "AIGE-CTL-AGENT-008",
              "AIGE-CTL-AGENT-010",
              "AIGE-CTL-AGENT-025",
              "AIGE-CTL-DATA-012"
            ]
          },
          {
            "ref": "ASI09",
            "name": "Human-Agent Trust Exploitation",
            "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-004",
              "AIGE-CTL-AGENT-009",
              "AIGE-CTL-AGENT-015"
            ]
          },
          {
            "ref": "ASI10",
            "name": "Rogue Agents",
            "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-005",
              "AIGE-CTL-EVAL-006",
              "AIGE-CTL-AGENT-001",
              "AIGE-CTL-AGENT-010",
              "AIGE-CTL-AGENT-011",
              "AIGE-CTL-AGENT-019",
              "AIGE-CTL-DEPLOY-013"
            ]
          }
        ]
      },
      {
        "id": "mitre-atlas",
        "name": "MITRE ATLAS techniques",
        "url": "https://atlas.mitre.org/",
        "note": "Version data release v2026.09 (15 Sep 2026); ids as the catalogue prints them.",
        "rows": [
          {
            "ref": "AML.M0007",
            "name": "Sanitize Training Data (mitigation)",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-DATA-009"
            ]
          },
          {
            "ref": "AML.M0025",
            "name": "Maintain AI Dataset Provenance (mitigation)",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-DATA-009"
            ]
          },
          {
            "ref": "AML.T0010",
            "name": "AI Supply Chain Compromise",
            "url": "https://atlas.mitre.org/techniques/AML.T0010",
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-008",
              "AIGE-CTL-ASSURE-010",
              "AIGE-CTL-ASSURE-011",
              "AIGE-CTL-ASSURE-012"
            ]
          },
          {
            "ref": "AML.T0034",
            "name": "Cost Harvesting",
            "url": "https://atlas.mitre.org/techniques/AML.T0034",
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-006"
            ]
          },
          {
            "ref": "AML.T0083",
            "name": "Credentials from AI Agent Configuration (not yet a row of the threat bridge)",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-003"
            ]
          },
          {
            "ref": "AML.T0086",
            "name": "Exfiltration via AI Agent Tool Invocation",
            "url": "https://atlas.mitre.org/techniques/AML.T0086",
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-002"
            ]
          },
          {
            "ref": "AML.T0110",
            "name": "AI Agent Tool Poisoning",
            "url": "https://atlas.mitre.org/techniques/AML.T0110",
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-008"
            ]
          }
        ]
      },
      {
        "id": "nist-sp-800-53",
        "name": "NIST SP 800-53 Rev. 5",
        "url": "https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final",
        "note": "One row per control family; each row names the specific controls cited from it.",
        "rows": [
          {
            "ref": "AC",
            "name": "AC-3 Access Enforcement; AC-6 Least Privilege",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-001",
              "AIGE-CTL-EVAL-003"
            ]
          },
          {
            "ref": "AU",
            "name": "AU-2 Event Logging; AU-9 Protection of Audit Information; AU-12 Audit Record Generation",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-005",
              "AIGE-CTL-EVAL-007"
            ]
          },
          {
            "ref": "CM",
            "name": "CM-2 Baseline Configuration; CM-3 Configuration Change Control; CM-6 Configuration Settings",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-008"
            ]
          },
          {
            "ref": "IA",
            "name": "IA-5 Authenticator Management",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-003"
            ]
          },
          {
            "ref": "IR",
            "name": "IR-4 Incident Handling",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-007"
            ]
          },
          {
            "ref": "SA",
            "name": "SA-11 Developer Testing and Evaluation",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-009"
            ]
          },
          {
            "ref": "SC",
            "name": "SC-7 Boundary Protection; SC-7(5) Deny by default, allow by exception",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-002"
            ]
          },
          {
            "ref": "SI",
            "name": "SI-4 System Monitoring",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-005"
            ]
          }
        ]
      },
      {
        "id": "aiuc1",
        "name": "AIUC-1",
        "url": "https://standard.aiuc-1.com/",
        "note": "This site is not affiliated with AIUC and holds no AIUC certificate; ids read on AIUC-1's public pages. Each mapping is this project's reading of the requirement text, not AIUC's.",
        "rows": [
          {
            "ref": "A006",
            "name": "Prevent PII leakage",
            "url": "https://standard.aiuc-1.com/data-and-privacy/prevent-pii-leakage",
            "note": "Read on its public AIUC-1 page on 2026-09-26; not affiliated with AIUC.",
            "controls": [
              "AIGE-CTL-AGENT-017"
            ]
          },
          {
            "ref": "A008",
            "name": "Prevent leakage of credentials and secrets",
            "url": "https://standard.aiuc-1.com/data-and-privacy/prevent-secrets-leakage",
            "note": "Read on its public AIUC-1 page on 2026-09-26; not affiliated with AIUC.",
            "controls": [
              "AIGE-CTL-EVAL-003",
              "AIGE-CTL-AGENT-017"
            ]
          },
          {
            "ref": "B006",
            "name": "Prevent unauthorized AI agent actions",
            "url": "https://standard.aiuc-1.com/security/enforce-contextual-access-controls",
            "note": "Read on its public AIUC-1 page on 2026-09-26; not affiliated with AIUC.",
            "controls": [
              "AIGE-CTL-EVAL-001",
              "AIGE-CTL-EVAL-002",
              "AIGE-CTL-EVAL-004",
              "AIGE-CTL-AGENT-005",
              "AIGE-CTL-AGENT-012",
              "AIGE-CTL-AGENT-016"
            ]
          },
          {
            "ref": "C002",
            "name": "Conduct pre-deployment testing",
            "url": "https://standard.aiuc-1.com/safety/conduct-pre-deployment-testing",
            "note": "Read on its public AIUC-1 page on 2026-09-26; not affiliated with AIUC.",
            "controls": [
              "AIGE-CTL-AGENT-013",
              "AIGE-CTL-ASSURE-002"
            ]
          },
          {
            "ref": "D003",
            "name": "Restrict unsafe tool calls",
            "url": "https://standard.aiuc-1.com/reliability/restrict-unsafe-tool-calls",
            "note": "Read on its public AIUC-1 page on 2026-09-26; not affiliated with AIUC.",
            "controls": [
              "AIGE-CTL-EVAL-004",
              "AIGE-CTL-AGENT-005",
              "AIGE-CTL-AGENT-007",
              "AIGE-CTL-AGENT-008",
              "AIGE-CTL-AGENT-015"
            ]
          },
          {
            "ref": "E004",
            "name": "Assign accountability",
            "url": "https://standard.aiuc-1.com/accountability/assign-accountability",
            "note": "Read on its public AIUC-1 page on 2026-09-26; not affiliated with AIUC.",
            "controls": [
              "AIGE-CTL-AGENT-028"
            ]
          },
          {
            "ref": "E008",
            "name": "Review internal processes",
            "url": "https://standard.aiuc-1.com/accountability/review-internal-processes",
            "note": "Read on its public AIUC-1 page on 2026-09-26; not affiliated with AIUC.",
            "controls": [
              "AIGE-CTL-ASSURE-009"
            ]
          },
          {
            "ref": "E010",
            "name": "Establish AI acceptable use policy",
            "url": "https://standard.aiuc-1.com/accountability/establish-ai-acceptable-use-policy",
            "note": "Read on its public AIUC-1 page on 2026-09-26; not affiliated with AIUC.",
            "controls": [
              "AIGE-CTL-DEPLOY-014"
            ]
          },
          {
            "ref": "E015",
            "name": "Log AI system activity",
            "url": "https://standard.aiuc-1.com/accountability/log-model-activity",
            "note": "Read on its public AIUC-1 page on 2026-09-26; not affiliated with AIUC.",
            "controls": [
              "AIGE-CTL-EVAL-005",
              "AIGE-CTL-EVAL-007",
              "AIGE-CTL-AGENT-004",
              "AIGE-CTL-AGENT-029",
              "AIGE-CTL-ASSURE-008",
              "AIGE-CTL-DEPLOY-010"
            ]
          },
          {
            "ref": "E016",
            "name": "Implement AI disclosure mechanisms",
            "url": "https://standard.aiuc-1.com/accountability/implement-ai-disclosure-mechanisms",
            "note": "Read on its public AIUC-1 page on 2026-09-26; not affiliated with AIUC.",
            "controls": [
              "AIGE-CTL-AGENT-031"
            ]
          }
        ]
      },
      {
        "id": "other-eu-ai-act",
        "name": "EU AI Act",
        "url": null,
        "note": "Named in the controls' other mappings; this site keeps no index of it.",
        "rows": [
          {
            "ref": "Art. 14(4)(e)",
            "name": "stop procedure",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-006"
            ]
          }
        ]
      },
      {
        "id": "other-ietf-rfc-8693",
        "name": "IETF RFC 8693",
        "url": null,
        "note": "Named in the controls' other mappings; this site keeps no index of it.",
        "rows": [
          {
            "ref": "act claim",
            "name": "delegation names the acting party; never impersonation",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-003"
            ]
          }
        ]
      },
      {
        "id": "other-iso-iec-42001-2023",
        "name": "ISO/IEC 42001:2023",
        "url": null,
        "note": "Named in the controls' other mappings; this site keeps no index of it.",
        "rows": [
          {
            "ref": "9",
            "name": "Performance evaluation: one evidence store answering internal audit (clause heading as chapter 22 names it)",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-ASSURE-009"
            ]
          },
          {
            "ref": "9.1",
            "name": "Performance evaluation: monitoring and measurement (cited by the evidence-record and control-observation schemas)",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-ASSURE-004",
              "AIGE-CTL-ASSURE-006"
            ]
          }
        ]
      },
      {
        "id": "other-mcp-specification-2026-07-28",
        "name": "MCP specification 2026-07-28",
        "url": null,
        "note": "Named in the controls' other mappings; this site keeps no index of it.",
        "rows": [
          {
            "ref": "Authorization, Token Handling",
            "name": "audience validation; no token passthrough",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-003"
            ]
          }
        ]
      },
      {
        "id": "other-mitre-atlas-mitigation",
        "name": "MITRE ATLAS mitigation",
        "url": null,
        "note": "Named in the controls' other mappings; this site keeps no index of it.",
        "rows": [
          {
            "ref": "AML.M0013",
            "name": "Code Signing",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-ASSURE-010"
            ]
          },
          {
            "ref": "AML.M0014",
            "name": "Verify AI Artifacts",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-008",
              "AIGE-CTL-ASSURE-010"
            ]
          },
          {
            "ref": "AML.M0016",
            "name": "Vulnerability Scanning",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-ASSURE-011"
            ]
          },
          {
            "ref": "AML.M0023",
            "name": "AI Bill of Materials",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-008",
              "AIGE-CTL-ASSURE-012"
            ]
          },
          {
            "ref": "AML.M0024",
            "name": "AI Telemetry Logging",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-005"
            ]
          },
          {
            "ref": "AML.M0028",
            "name": "AI Agent Tools Permissions Configuration",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-004"
            ]
          },
          {
            "ref": "AML.M0029",
            "name": "Human In-the-Loop for AI Agent Actions",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-004"
            ]
          },
          {
            "ref": "AML.M0030",
            "name": "Restrict AI Agent Tool Invocation on Untrusted Data",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-004"
            ]
          },
          {
            "ref": "AML.M0032",
            "name": "Segmentation of AI Agent Components",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-002"
            ]
          },
          {
            "ref": "AML.M0036",
            "name": "Limit AI Workload Resource Consumption",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-006"
            ]
          }
        ]
      },
      {
        "id": "other-nist-sp-800-218a",
        "name": "NIST SP 800-218A",
        "url": null,
        "note": "Named in the controls' other mappings; this site keeps no index of it.",
        "rows": [
          {
            "ref": "PS.1.3",
            "name": "Protect model weights and configuration parameters",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-008"
            ]
          },
          {
            "ref": "PS.3.2",
            "name": "Keep provenance data for every component of a release",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-008"
            ]
          }
        ]
      },
      {
        "id": "other-spiffe",
        "name": "SPIFFE",
        "url": null,
        "note": "Named in the controls' other mappings; this site keeps no index of it.",
        "rows": [
          {
            "ref": "SVID",
            "name": "short-lived workload identity documents",
            "url": null,
            "note": null,
            "controls": [
              "AIGE-CTL-EVAL-003"
            ]
          }
        ]
      }
    ]
  }
}
