unified
UC-AI-17 — Define customer data-use and output-rights policies for AI services
Publish and maintain customer-facing policies for AI services that state how customer inputs are used for model training and inference, how long inputs and outputs are retained, who owns and may use generated outputs, and how customers can opt in or out, request deletion, or exercise other data rights. Communicate the policies before onboarding, version them, and retain customer acknowledgements and periodic review records as evidence.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- AI Governance
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-AI-17
- title
- Define customer data-use and output-rights policies for AI services
- statement
- Publish and maintain customer-facing policies for AI services that state how customer inputs are used for model training and inference, how long inputs and outputs are retained, who owns and may use generated outputs, and how customers can opt in or out, request deletion, or exercise other data rights. Communicate the policies before onboarding, version them, and retain customer acknowledgements and periodic review records as evidence.
- domain
- AI Governance
- control_type
- preventive
- control_category
- administrative
- members
- framework
- aiuc-1
- control_id
- A001
- coverage
- full
- relationship
- superset_of
- framework
- aiuc-1
- control_id
- A002
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-AI-17 — Define customer data-use and output-rights policies for AI services maps_to A002 — Establish output data policy
- framework
- aiuc-1
- control_id
- A002
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- July 15, 2026 release (quarterly update cadence)
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-AI-17 — Define customer data-use and output-rights policies for AI services mitigates Privacy-program non-compliance (GDPR, CCPA, state laws)
- strength
- primary
- rationale
- Customer-facing input and output data policies (training use, retention, ownership, opt-out, deletion) are the notice-and-consent backbone of a privacy program for AI services.
- UC-AI-17 — Define customer data-use and output-rights policies for AI services mitigates AI accountability gaps and organizational liability
- strength
- related
- rationale
- Clear ownership and usage terms for outputs pre-empt the liability disputes that arise when rights to generated content are undefined.
- UC-AI-17 — Define customer data-use and output-rights policies for AI services mitigates AI privacy leakage and re-identification
- strength
- related
- rationale
- Declared training-use and retention limits reduce the volume of customer data an AI system can later leak, but the operative defenses are the output and isolation controls.
- UC-AI-17 — Define customer data-use and output-rights policies for AI services mitigates Lack of AI explainability, documentation and disclosure
- strength
- related
- rationale
- Published data-use and output-rights terms are part of the transparency customers rely on to understand how the AI service treats their data.
- AI Service Data Policy & Quality Management Cycle operates UC-AI-17 — Define customer data-use and output-rights policies for AI services
- UC-AI-17 — Define customer data-use and output-rights policies for AI services maps_to A001 — Establish input data policy
- framework
- aiuc-1
- control_id
- A001
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- July 15, 2026 release (quarterly update cadence)
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.