Implement safeguards to prevent cross-customer data exposure when combining customer data from multiple sources for AI model training
Establishing explicit consent and disclosure for combined data usage. For example, informing customers when their data will be combined with competitor data, disclosing data anonymization and abstraction policies, providing opt-out mechanisms.
Implementing customer data isolation controls. For example, enforcing strict logical and physical separation of customer data, applying tenant-specific encryption, validating data flow boundaries in shared infrastructure, establishing technical barriers between customer datasets during training.
Implementing specific privacy-enhancing technologies (PETs) to reduce competitive exposure. For example, applying differential privacy to obfuscate customer contributions, using federated learning to avoid centralizing raw data, generating task-relevant synthetic datasets to simulate real data scenarios.
Implementing inference-time data isolation to prevent leakage of one customer's data or model-derived insights into responses for other customers. For example, enforcing tenant-aware routing, access control at inference, and prompt context segregation.
Adapting safeguards to industry-specific competitive risks. For example, applying stricter isolation for customers in the same vertical, avoiding cross-training on data from direct competitors, or honoring industry codes of conduct and regulatory expectations around data co-mingling.
Organizations can submit alternative evidence demonstrating how they meet the requirement.
"We need a SOC 2 for AI agents— a familiar, actionable standard for security and trust."
"Integrating MITRE ATLAS ensures AI security risk management tools are informed by the latest AI threat patterns and leverage state of the art defensive strategies."
"Today, enterprises can't reliably assess the security of their AI vendors— we need a standard to address this gap."
"Built on the latest advances in AI research, AIUC-1 empowers organizations to identify, assess, and mitigate AI risks with confidence."
"AIUC-1 standardizes how AI is adopted. That's powerful."
"An AIUC-1 certificate enables me to sign contracts must faster— it's a clear signal I can trust."