{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/control.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-data-012.json",
  "source": "https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-012",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "control": {
    "id": "AIGE-CTL-DATA-012",
    "profile": "data-admission-and-privacy",
    "url": "https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-012",
    "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-data-012.json",
    "title": "Registered Downstream Consumers of Outputs",
    "version": "0.1",
    "status": "draft",
    "reviewerStatus": "open",
    "depth": "derived",
    "objective": "Every consumer of a system's outputs (a system, a team, a partner or a training pipeline) is registered against the producing system with its purpose, its approval and the re-test that cleared the outputs for that context; access to the outputs is granted per registered consumer, and the intended and prohibited uses are rules on a Policy Card.",
    "failureModes": [
      "A risk score approved to prioritise manual review becomes an automatic decline in another team's pipeline, and nobody assessed that use.",
      "A model's outputs are harvested as training data for another model, and the feedback loop is invisible.",
      "A partner receives outputs under a contract nobody connected to the registry, and is not told when the model changes or retires."
    ],
    "scope": "Consumers of the outputs of AI systems, internal and external, including training pipelines that read those outputs. Registration binds internal consumers; external ones depend on contract terms and audit rights.",
    "enforcementPoints": [
      "deploy",
      "runtime"
    ],
    "verification": [
      {
        "kind": "test",
        "text": "A consumer with no registration has no credential to the output API or table, and a registration whose declared use meets a prohibited-use rule on the card goes to review as a new purpose instead of receiving a credential."
      }
    ],
    "evidence": [
      {
        "artefact": "Intended and prohibited uses as rules on the system's Policy Card",
        "schemaId": "policy-card",
        "schema": "https://aigovernanceengineer.com/schemas/policy-card.v1.json",
        "layer": 1
      },
      {
        "artefact": "Downstream use register entry: each consumer with its use, approval, re-test, credential or contract, and the feedback-loop check",
        "schemaId": null,
        "schema": null,
        "layer": 2
      }
    ],
    "failureResponse": {
      "effect": "deny",
      "text": "An unregistered consumer gets no credential; a declared use outside the card fails registration and reopens classification and the impact assessments as a new purpose. A model change, an incident or a retirement notifies every registered consumer."
    },
    "layer": 2,
    "secondaryLayers": [
      1
    ],
    "patterns": [
      {
        "slug": "downstream-use-register",
        "title": "Downstream Use Register",
        "url": "https://aigovernanceengineer.com/patterns/downstream-use-register"
      },
      {
        "slug": "policy-card",
        "title": "Policy Card",
        "url": "https://aigovernanceengineer.com/patterns/policy-card"
      },
      {
        "slug": "agent-registry",
        "title": "Agent Registry",
        "url": "https://aigovernanceengineer.com/patterns/agent-registry"
      },
      {
        "slug": "disclosure-notification-pipeline",
        "title": "Disclosure & Notification Pipeline",
        "url": "https://aigovernanceengineer.com/patterns/disclosure-notification-pipeline"
      }
    ],
    "seeds": [],
    "derivedFrom": [
      {
        "kind": "pattern",
        "ref": "downstream-use-register",
        "url": "https://aigovernanceengineer.com/patterns/downstream-use-register"
      },
      {
        "kind": "schema",
        "ref": "policy-card",
        "url": "https://aigovernanceengineer.com/resources/templates#schema-policy-card"
      },
      {
        "kind": "chapter",
        "ref": "governing-development",
        "url": "https://aigovernanceengineer.com/bok/governing-development"
      }
    ],
    "mappings": {
      "obligations": [
        {
          "id": "AIGE-OBL-EUAIA-ART9",
          "name": "EU AI Act Art. 9 risk management system",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art9"
        },
        {
          "id": "AIGE-OBL-EUAIA-ART25",
          "name": "EU AI Act Art. 25 responsibilities along the AI value chain",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art25"
        },
        {
          "id": "AIGE-OBL-EUAIA-ART50",
          "name": "EU AI Act Art. 50 transparency for certain AI systems",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art50"
        },
        {
          "id": "AIGE-OBL-ISO42001-A8",
          "name": "A.8 Information for interested parties",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a8"
        },
        {
          "id": "AIGE-OBL-ISO42001-A9",
          "name": "A.9 Use of AI systems",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a9"
        }
      ],
      "iso42001": [
        {
          "id": "A.8.2",
          "title": "System documentation and information for users"
        },
        {
          "id": "A.9.4",
          "title": "Intended use of the AI system"
        }
      ],
      "nistAiRmf": [
        {
          "id": "MAP 1.1",
          "title": "Intended purposes, potentially beneficial uses, context-specific laws, norms and expectations, and prospective settings in which the AI system will be deployed are understood and documented."
        },
        {
          "id": "MAP 3.3",
          "title": "Targeted application scope is specified and documented based on the system’s capability, established context, and AI system categorization."
        },
        {
          "id": "MANAGE 1.4",
          "title": "Negative residual risks (defined as the sum of all unmitigated risks) to both downstream acquirers of AI systems and end users are documented."
        }
      ],
      "owasp": [
        {
          "id": "llm10-2026",
          "externalId": "LLM10:2026",
          "name": "Improper Output Handling",
          "url": "https://aigovernanceengineer.com/resources/threats#threat-llm10-2026"
        },
        {
          "id": "asi08",
          "externalId": "ASI08",
          "name": "Cascading Failures",
          "url": "https://aigovernanceengineer.com/resources/threats#threat-asi08"
        }
      ],
      "atlas": [],
      "aiuc1": [],
      "csaAicm": [],
      "other": []
    },
    "references": [
      {
        "n": 35,
        "title": "Downstream Use Register",
        "text": "Downstream Use Register (AI Governance Engineering Body of Knowledge v0.5.0, pattern catalogue (chapter 05): intended and prohibited uses as a Policy Card and every consumer of the outputs recorded against the registry entry). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/patterns/downstream-use-register",
        "verified": "primary"
      },
      {
        "n": 36,
        "title": "Governing AI development",
        "text": "Governing AI development (AI Governance Engineering Body of Knowledge v0.5.0, chapter 14, section \"Function creep\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-development#function-creep",
        "verified": "primary"
      },
      {
        "n": 37,
        "title": "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), of 13 June 2024; OJ L, 2024/1689, 12.7.2024",
        "text": "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), of 13 June 2024; OJ L, 2024/1689, 12.7.2024 (Art. 3(13) reasonably foreseeable misuse; Art. 9(2)(b) risks under reasonably foreseeable misuse; Art. 25(1)(c) changed intended purpose; Art. 50(2) machine-readable marking of synthetic outputs). Publications Office of the EU (EUR-Lex). 2024-07-12.",
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng",
        "verified": "primary"
      },
      {
        "n": 6,
        "title": "OWASP GenAI LLM Top 10 2026",
        "text": "OWASP GenAI LLM Top 10 2026 (LLM01:2026 Prompt Injection to LLM10:2026 Improper Output Handling; resource page dated 3 Aug 2026). OWASP GenAI Security Project. 2026-08-03.",
        "url": "https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/",
        "verified": "primary"
      },
      {
        "n": 38,
        "title": "OWASP Top 10 for Agentic Applications for 2026",
        "text": "OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents). OWASP GenAI Security Project. 2025-12-09.",
        "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
        "verified": "primary"
      },
      {
        "n": 7,
        "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
        "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
        "url": "https://www.iso.org/standard/81230.html",
        "verified": "secondary"
      },
      {
        "n": 8,
        "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1",
        "text": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (GOVERN 6.1 third-party risks incl. infringement of intellectual property or other rights; MAP 1.1 intended purposes documented; MAP 2.3 data collection and selection considerations identified and documented; MAP 3.3 targeted application scope; MAP 4.1 legal risks of components incl. third-party data; MEASURE 2.10 privacy risk examined and documented; MANAGE 1.4 negative residual risks to downstream acquirers and end users documented). NIST. 2023-01-26.",
        "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
        "verified": "primary"
      }
    ],
    "implementationNotes": [
      "Forecast misuse before go-live with a premortem, abuse cases written next to the user stories and a stakeholder impact map that includes people who never touch the interface; each plausible misuse becomes a prohibited-use rule or a monitor.",
      "Stamp outputs with the producing system and version, the intended use and a caveat, as metadata a consumer can read; for generative content, this is the machine-readable marking Art. 50(2) requires of providers.",
      "Classify consumer requests against the negative space of the card, alert on what falls outside it, and watch for outputs that return as training data."
    ],
    "openQuestions": [
      "How is a registered external consumer held to its declared use when the outputs leave the organisation's access controls?"
    ],
    "observation": null,
    "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
    "examples": []
  }
}
