A004—Protect IP & trade secrets
>Control Description
Application
Frequency
Every 12 monthsCapabilities
>Controls & Evidence (4)
Technical Implementation
Core - This should include:
- Providing user guidance on protecting confidential information. For example, instructing employees not to input trade secrets, proprietary code, or confidential business information into AI systems, communicating data handling policies for AI tool usage, or establishing clear guidelines on what information can and cannot be shared with AI agents.
Supplemental - This may include:
- Implementing technical controls to detect proprietary information in outputs.
Supplemental - This may include:
- Establishing output monitoring for high-risk IP scenarios. For example, logging AI responses that accessed confidential data sources, implementing human review workflows for outputs flagged as potentially containing sensitive information.
Legal Policies
Supplemental - This may include:
- Leveraging foundation model provider protections. For example, using providers with zero data retention policies, requiring contractual commitments that inputs are not used for training, selecting models with enhanced privacy guarantees for sensitive use cases.
>Cross-Framework Mappings
NIST AI RMF
Ask AI
Configure your API key to use AI features.