{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"AI Governance","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AI-18","description":"Protect the inference and agent interfaces of AI systems with layered input defenses: screen prompts, uploaded content, retrieved data, and tool results for prompt-injection and jailbreak patterns before they reach the model or trigger actions; detect and alert on adversarial-input campaigns; and rate-limit, authenticate, and monitor endpoints to prevent scraping, model extraction, and resource-exhaustion abuse. Tune detections from evaluation findings and retain filter configurations and detection logs as evidence.","details":{"control_category":"technical","control_type":"preventive","domain":"AI Governance","guidance":[{"propositionId":"NIST-AGI-06","propositionTitle":"Prompt-injection prevention and limits on resulting harm","source":"nist-ai-agent-identity","sourcePages":"Concept paper p. 4: Prompt Injection prevention and mitigation","sourceTitle":"NIST NCCoE: Software and AI Agent Identity and Authorization"},{"propositionId":"NIST-TEVV-05","propositionTitle":"Test direct and indirect prompt injection","source":"nist-ai-tevv-athlon","sourcePages":"NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Integrity attacks","sourceTitle":"NIST AI 200-2: TEVV-Athlon Framework for Evaluating AI Systems"}],"members":[{"control_id":"B002","coverage":"full","framework":"aiuc-1","relationship":"superset_of"},{"control_id":"B004","coverage":"full","framework":"aiuc-1","relationship":"superset_of"},{"control_id":"B005","coverage":"full","framework":"aiuc-1","relationship":"superset_of"}],"statement":"Protect the inference and agent interfaces of AI systems with layered input defenses: screen prompts, uploaded content, retrieved data, and tool results for prompt-injection and jailbreak patterns before they reach the model or trigger actions; detect and alert on adversarial-input campaigns; and rate-limit, authenticate, and monitor endpoints to prevent scraping, model extraction, and resource-exhaustion abuse. Tune detections from evaluation findings and retain filter configurations and detection logs as evidence.","title":"Defend AI interfaces against adversarial input, injection, and endpoint abuse","unified_id":"UC-AI-18"},"id":"uc:UC-AI-18","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AI-18","sourceIds":["aiuc-1","nist-ai-agent-identity","nist-ai-tevv-athlon"],"sourceUrl":null,"title":"UC-AI-18 — Defend AI interfaces against adversarial input, injection, and endpoint abuse","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:78f1281c5bb694c0085788552e2319c57a19b1ae8e513f96b70d4dace3262c93","properties":{"rationale":"Screening prompts, retrieved content, and tool results for injection and jailbreak patterns, plus adversarial-input detection, is the inference-time defense against prompt injection.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-18-f15ac93a.json","sourceId":"uc:UC-AI-18","targetDetailPath":"/data/v1/records/risk-ai-adversarial-poisoning-attacks-ea7df068.json","targetId":"risk:ai-adversarial-poisoning-attacks","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:79bdeeae194462215e7108e8a2a23905c4f758e1e096c1379e4396865b2e1f2f","properties":{"control_id":"NIST-AGI-06","coverage":"guidance","delta":null,"framework":"nist-ai-agent-identity","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"Concept paper p. 4: Prompt Injection prevention and mitigation","source_version":"February 2026 draft concept paper"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-18-f15ac93a.json","sourceId":"uc:UC-AI-18","targetDetailPath":"/data/v1/records/ctrl-nist-ai-agent-identity-nist-agi-06-e6b81ea1.json","targetId":"ctrl:nist-ai-agent-identity:NIST-AGI-06","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7f84867ba5c5b81b99aad66d6bce3b76b84b2554cf87e3359f2fedb1d44fac7b","properties":{"rationale":"Input screening is where pasted credentials can be caught before they reach the model or its logs.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-18-f15ac93a.json","sourceId":"uc:UC-AI-18","targetDetailPath":"/data/v1/records/risk-ai-secrets-credential-leakage-abf1bf77.json","targetId":"risk:ai-secrets-credential-leakage","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:80e9af26c29453059d89e2aba17000c854a1989c3ce1528c70e9d7bc1db36e64","properties":{},"sourceDetailPath":"/data/v1/records/wf-c67-2d6bb2c2.json","sourceId":"wf:C67","targetDetailPath":"/data/v1/records/uc-uc-ai-18-f15ac93a.json","targetId":"uc:UC-AI-18","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:908c341aa078ce102be83a656c1dbff4928a9841491d3385d0d228153e5925dc","properties":{"control_id":"B005","coverage":"full","delta":null,"framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-18-f15ac93a.json","sourceId":"uc:UC-AI-18","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-b005-fe985c7b.json","targetId":"ctrl:aiuc-1:B005","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a340fde6d9d4f7a36559a15043c17bac883b57bf6dd7bb715a1212a87782ced2","properties":{"rationale":"Rate limiting, authentication, and monitoring of inference endpoints directly stop scraping, extraction, and unbounded-consumption abuse.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-18-f15ac93a.json","sourceId":"uc:UC-AI-18","targetDetailPath":"/data/v1/records/risk-ai-endpoint-abuse-model-extraction-a3c97c52.json","targetId":"risk:ai-endpoint-abuse-model-extraction","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c59b52e616b08f549f872fb76832769ea6adad3fb38cb731b2fde42e7437b8e3","properties":{"rationale":"Blocking injected instructions that try to exfiltrate context reduces one avenue for personal-data leakage.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-18-f15ac93a.json","sourceId":"uc:UC-AI-18","targetDetailPath":"/data/v1/records/risk-ai-privacy-leakage-9aa8d83c.json","targetId":"risk:ai-privacy-leakage","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cac87c52f8cad781925ff1df93d3ecdcadc88de1e2481e2c5f6ec35ca0f68006","properties":{"control_id":"B004","coverage":"full","delta":null,"framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-18-f15ac93a.json","sourceId":"uc:UC-AI-18","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-b004-d4ff3b14.json","targetId":"ctrl:aiuc-1:B004","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d8b80f08aebb53818d702d4d99d8c67750cac06da57d362f51268c30edd793ac","properties":{"control_id":"NIST-TEVV-05","coverage":"guidance","delta":null,"framework":"nist-ai-tevv-athlon","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Integrity attacks","source_version":"NIST AI 200-2 ipd (Initial Public Draft), August 2026"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-18-f15ac93a.json","sourceId":"uc:UC-AI-18","targetDetailPath":"/data/v1/records/ctrl-nist-ai-tevv-athlon-nist-tevv-05-f9e22b30.json","targetId":"ctrl:nist-ai-tevv-athlon:NIST-TEVV-05","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:dd6e424d14cc32172c325fc0c83ce251db91de1d64582e194ee680e4e84c4f96","properties":{},"sourceDetailPath":"/data/v1/records/wf-c66-26a4ed19.json","sourceId":"wf:C66","targetDetailPath":"/data/v1/records/uc-uc-ai-18-f15ac93a.json","targetId":"uc:UC-AI-18","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:dfe4a2f352199a3a665ddddedaf3a66dee1ff1c8687930b9b84f4439e5433a9a","properties":{"control_id":"B002","coverage":"full","delta":null,"framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-18-f15ac93a.json","sourceId":"uc:UC-AI-18","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-b002-07a4b0e1.json","targetId":"ctrl:aiuc-1:B002","type":"maps_to"}],"schemaVersion":1}
