1. Objective
To ensure that the data AI systems can read, retrieve, generate or send is known, permitted and traceable, with particular care for personal data.
2. Requirements
400.1The organization shall identify the data sources each AI system can access, including through connectors, retrieval indexes and tools.
400.2Data sources reachable by AI systems shall be classified by sensitivity, and the organization shall report classification coverage for those sources.
400.3The organization shall maintain a permitted-use register stating which data classes each AI system may access and for what purpose. Access beyond the register shall be treated as a finding.
400.4Controls shall inspect prompts, retrieved content and responses for personal and confidential data where the platform allows, with actions defined per data class.
400.5AI access to personal data shall be logged in enough detail to support investigation and the exercise of individuals' rights, and logs shall be retained per policy.
400.6For third-party AI services, the organization shall document whether its data is used for training, how long it is retained and where it is processed.
400.7Agent connectors shall be scoped to the minimum data needed for the stated purpose.
3. Evidence
- Data source map per AI system.
- Classification coverage report.
- Permitted-use register and exceptions.
- Data-loss prevention policy and event records.
- Third-party AI data handling records.
4. Metrics
| Metric | Definition |
|---|---|
| Classification coverage | AI-reachable data sources classified, divided by AI-reachable data sources. |
| Permitted-use exceptions | AI systems accessing data classes outside their register entry. |
5. Basis for conclusions
AI systems turn data access into data movement: a retrieval index or a connector can expose a document library to everyone who can ask a question. Classification coverage is therefore measured specifically for AI-reachable sources, not for the estate as a whole.
6. Questions for respondents
- Should prompt inspection be mandatory for personal data, or risk-based?
- What log retention period is practical across jurisdictions?