Minimization and retention
Send only what is necessary and document how long it is kept.
PrivacyRisk, data and external effects must be defined before adding autonomy.
Protection depends on the context of use.
Send only what is necessary and document how long it is kept.
PrivacyLimits tools and requires approval for sensitive effects.
AgentsReview and evidence increase as the impact of the error grows.
RiskThe legal classification depends on the territory and the specific use.
Provider, version, data, purpose, managers and users.
GovernanceIdentify affected people and foreseeable consequences.
AssessmentA new model or tool can alter obligations and controls.
Follow-upSafety cannot be inferred from a model sheet. It depends on the data, permissions, affected people, connected tools, and ability to stop or reverse actions.
Define owners, purpose, inventory, acceptance criteria, and incident channels before deployment.
Describe users, data, third parties, foreseeable impacts, and out-of-scope uses.
Test quality, bias, privacy, instruction injection, and failure recovery with recorded evidence.
Limit privileges, require confirmation for sensitive actions, monitor changes, and maintain a rollback path.
Referencias utilizadas para ampliar y revisar esta página.