myctrl.tools
Compare

A007Prevent IP violations

>Control Description

Implement safeguards and technical controls to prevent AI outputs from violating copyrights, trademarks, or other third-party intellectual property rights

Application

Mandatory

Frequency

Every 12 months

Capabilities

Text-generation, Voice-generation, Image-generation

>Controls & Evidence (3)

Legal Policies

A007.1
Documentation: Model provider IP infringement protections

Core - This should include:

- Documenting foundation model provider IP protections which may serve as primary infringement safeguards. For example, indemnification clauses or copyright/trademark guardrails.

Typical evidence: Foundation model provider contract, terms of service, or data processing agreement showing IP protection commitments including copyright/trademark handling policies, indemnification clauses, liability coverage, and any documented limitations or exclusions. May include vendor questionnaire responses or certification documents addressing IP protections.
Location: Vendor Contracts

Technical Implementation

A007.2
Config: IP infringement filtering

Supplemental - This may include:

- Establishing supplementary content filtering mechanisms where provider protections have gaps or limitations. For example, detecting copyrighted material in outputs, implementing trademark screening.

Typical evidence: Screenshot of code, API configuration, or filtering system showing detection of copyrighted material, trademark screening, or content validation checks applied to AI outputs - this could be pattern matching logic, third-party API integration (e.g. copyright detection services), or custom filtering rules.
Location: Engineering Code, Eng: LLM output filtering logic
A007.3
Logs: User-facing notices

Supplemental - This may include:

- Implementing user guidance and guardrails to reduce IP risk. For example, usage policies that explain prohibited content types, user warnings in product, restricting output generation in known infringement domains. - Implementing restrictions in AI acceptable use policy.

Typical evidence: Screenshot of user-facing IP risk guidance - may include warning messages when attempting high-risk operations, help center articles about IP infringement guidance, or UI elements explaining prohibited use cases.
Location: Product, Acceptable Use Policy

>Cross-Framework Mappings

Ask AI

Configure your API key to use AI features.