{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/control.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-deploy-014.json",
  "source": "https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-014",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "control": {
    "id": "AIGE-CTL-DEPLOY-014",
    "profile": "deployment-and-monitoring",
    "url": "https://aigovernanceengineer.com/controls/deployment-and-monitoring#aige-ctl-deploy-014",
    "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-deploy-014.json",
    "title": "Sanctioned AI gateway for staff use",
    "version": "0.1",
    "status": "draft",
    "reviewerStatus": "open",
    "depth": "derived",
    "objective": "Staff reach approved AI tools and model APIs through single sign-on and one gateway that applies the acceptable-use policy as code: a catalogue names each tool, its contract terms and allowed data classes; each request is tagged by data class and allowed, redacted or blocked; access needs a current acceptable-use attestation; and each call writes a signed evidence record with the input's hash, not the input.",
    "failureModes": [
      "Someone pastes a customer file into a public tool, and the acceptable-use policy, read once in a handbook, is never evaluated at that moment.",
      "An approved tool is used on terms that changed after its approval, such as training on customer inputs.",
      "Every public tool is blocked, and use moves onto personal devices where nothing is seen.",
      "The gateway keeps full staff prompts, beyond what the control needs."
    ],
    "scope": "Staff use of AI tools and model APIs, in the browser or through an API. Local models and personal devices are outside the gateway and left to discovery.",
    "enforcementPoints": [
      "runtime"
    ],
    "verification": [],
    "evidence": [
      {
        "artefact": "Signed gateway decision event per call: decision, data class, tool, redactions and a hash of the input",
        "schemaId": "evidence-record",
        "schema": "https://aigovernanceengineer.com/schemas/evidence-record.v1.json",
        "layer": 4
      },
      {
        "artefact": "Current acceptable-use attestation and training module on record for each user",
        "schemaId": "training-record",
        "schema": "https://aigovernanceengineer.com/schemas/training-record.v1.json",
        "layer": 4
      }
    ],
    "failureResponse": {
      "effect": "deny",
      "text": "A request carrying a data class the tool is not approved for is redacted or blocked with a reason and a route to the right tool; without a current attestation the gateway role is not granted."
    },
    "layer": 4,
    "secondaryLayers": [
      2
    ],
    "patterns": [
      {
        "slug": "sanctioned-ai-gateway",
        "title": "Sanctioned AI Gateway",
        "url": "https://aigovernanceengineer.com/patterns/sanctioned-ai-gateway"
      }
    ],
    "seeds": [],
    "derivedFrom": [
      {
        "kind": "pattern",
        "ref": "sanctioned-ai-gateway",
        "url": "https://aigovernanceengineer.com/patterns/sanctioned-ai-gateway"
      },
      {
        "kind": "schema",
        "ref": "evidence-record",
        "url": "https://aigovernanceengineer.com/resources/templates#schema-evidence-record"
      },
      {
        "kind": "schema",
        "ref": "training-record",
        "url": "https://aigovernanceengineer.com/resources/templates#schema-training-record"
      }
    ],
    "mappings": {
      "obligations": [
        {
          "id": "AIGE-OBL-EUAIA-ART4",
          "name": "EU AI Act Art. 4 AI literacy",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art4"
        }
      ],
      "iso42001": [
        {
          "id": "A.9.2",
          "title": "Processes for responsible use of AI systems"
        },
        {
          "id": "A.10.3",
          "title": "Suppliers"
        }
      ],
      "nistAiRmf": [
        {
          "id": "GOVERN 2.2",
          "title": "The organization’s personnel and partners receive AI risk management training to enable them to perform their duties and responsibilities consistent with related policies, procedures, and agreements."
        },
        {
          "id": "GOVERN 6.1",
          "title": "Policies and procedures are in place that address AI risks associated with third-party entities, including risks of infringement of a third-party’s intellectual property or other rights."
        },
        {
          "id": "MANAGE 3.1",
          "title": "AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented."
        }
      ],
      "owasp": [
        {
          "id": "llm02-2026",
          "externalId": "LLM02:2026",
          "name": "Sensitive Information Disclosure",
          "url": "https://aigovernanceengineer.com/resources/threats#threat-llm02-2026"
        }
      ],
      "atlas": [],
      "aiuc1": [
        "E010"
      ],
      "csaAicm": [],
      "other": []
    },
    "references": [
      {
        "n": 52,
        "title": "Pattern: Sanctioned AI Gateway",
        "text": "Pattern: Sanctioned AI Gateway (AI Governance Engineering Body of Knowledge v0.5.0, pattern catalogue (chapter 05)). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/patterns/sanctioned-ai-gateway",
        "verified": "primary"
      },
      {
        "n": 15,
        "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 4",
        "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 4 (providers and deployers take measures to support the AI literacy of their staff). Publications Office of the EU (EUR-Lex). 2026-07-27.",
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_4",
        "verified": "primary"
      },
      {
        "n": 53,
        "title": "OWASP GenAI LLM Top 10 2026",
        "text": "OWASP GenAI LLM Top 10 2026 (LLM01:2026 Prompt Injection to LLM10:2026 Improper Output Handling; resource page dated 3 Aug 2026). OWASP GenAI Security Project. 2026-08-03.",
        "url": "https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/",
        "verified": "primary"
      },
      {
        "n": 5,
        "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
        "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
        "url": "https://www.iso.org/standard/81230.html",
        "verified": "secondary"
      },
      {
        "n": 6,
        "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1",
        "text": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (subcategories cited by id: GOVERN 1.6, 1.7, 2.2, 6.1; MAP 1.1, 3.5; MEASURE 2.3, 2.4, 2.11, 3.1; MANAGE 1.1, 2.4, 3.1, 4.1, 4.3). NIST. 2023-01-26.",
        "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
        "verified": "primary"
      },
      {
        "n": 38,
        "title": "AIUC-1 requirements",
        "text": "AIUC-1 requirements (public requirement index, A001 to F002, each requirement on its own page (E007 and E014 marked retired); AIUC-1 is a standard of the Artificial Intelligence Underwriting Company; this site is not affiliated with AIUC, and a mapping here is not an AIUC-1 certificate or audit). Artificial Intelligence Underwriting Company. 2026-09-24.",
        "url": "https://standard.aiuc-1.com/llms.txt",
        "verified": "primary"
      }
    ],
    "implementationNotes": [
      "Make the gateway the fastest route: every extra step on the approved path sends people back to the unapproved one; replace personal accounts on approved tools with enterprise tenancies.",
      "Feed the catalogue from the Vendor / Model Due-Diligence Gate and review each entry on its review date, because supplier terms change."
    ],
    "openQuestions": [
      "Verification procedure to be specified: the source material states what the control produces, not how a third party checks it; requires technical review.",
      "Logging staff prompts is itself processing of employees' personal data; how much the gateway keeps, and for how long, awaits review with the DPO and employee representatives."
    ],
    "observation": null,
    "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
    "examples": []
  }
}
