Principle #
E
1
Keep AI use within its intended scope
Ensure that AI vendors undergo risk assessments to meet security, privacy, and compliance requirements.
Controls
Vendor questions
1. What is the intended scope of your AI product, and what use cases or behaviors are explicitly out of scope? Please provide documentation or summaries that define supported use cases, prohibited behaviors, and unsupported applications. Include examples of how these are communicated to users (e.g., UI disclosures, usage policies, API documentation). 2. What technical or procedural safeguards are in place to detect and reject out-of-scope requests or behaviors? Describe how these safeguards function at runtime or during user onboarding/configuration. 3. Do you evaluate your AI product to verify that its behavior remains within the defined scope? Provide examples of evaluations conducted in the past 12 months, including what scenarios were tested and what actions were taken based on the results. 4. Do you have a formal process for updating the intended scope and prohibited behaviors as the product evolves? Describe how changes are reviewed, approved, and reflected in documentation, product interfaces, and user-facing policies.