Appendixes
-
Appendix A: Implementation Considerations
- Access Controls
- Sandboxing
- Limiting Execution Depth and Incorporating Human Oversight
- Requiring Strong Authentication, Signed Data Exchange, and Integrity Checks Between Model, Retriever, and Tools
- Memory Management, Delete When Able, Encrypt or Purge Stored Prompts and Results
- Data Provenance
- Recording Agent and Model Activity, Tool Invocation, and Prompt Chains and Analyzing for Dual-Use Patterns
- Supply Chain Security
- Confidential Computing, Secure Enclaves, and Attestation
- AI-Assisted Red-Teaming
- Misuse-Resilience Testing
- Appendix B: Extended Security Control Tables
- Appendix C: Security Control Sources
- Appendix D: Key Sources and Recommended Reading
- Appendix E: Guide Methodology
Note: Reference links in the guide and appendixes were accurate as of the date of publication.