OECD Recommendation on Artificial Intelligence (2024 Update)
Security, IP, Environment

OECD Recommendation on Artificial Intelligence (2024 Update) OECDAI24-6: Security, Model and Data Protection, Intellectual Property, and Environmental Sustainability

Adhere to OECD 2024 Update security + model and data protection + IP + environmental sustainability. Security including model and data protection must (a) protect AI models against extraction + theft + tampering + with model signing + cryptographic protection + access control + (b) protect training and inference data against unauthorised access + tampering + extraction + including model inference attacks + (c) implement security per emerging AI security frameworks (NIST AI 100-3 + ISO/IEC TS 27091 + MITRE ATLAS + OWASP LLM Top 10 + similar), (d) coordinate AI security with broader cybersecurity governance. Intellectual property and training data must (a) respect IP rights in training data including copyright + trademark + database rights + sui generis protections + (b) maintain training data provenance + licensing + opt-out + with reproducible data trails, (c) navigate emerging case law and statutory developments (US fair use cases + EU AI Act Article 53 + UK CDPA + China + Japan + Singapore guidance), (d) support content creator rights including remuneration + attribution + opt-out where applicable. Environmental sustainability considerations must (a) assess AI training and inference energy + water + carbon footprint + with disclosure proportionate to material impact, (b) implement efficiency measures + renewable energy + lifecycle assessment + (c) consider AI use for environmental benefit (climate modelling + biodiversity + circular economy + efficient grids) and balance against direct environmental costs, (d) align with broader environmental reporting (TCFD + ESRS E1 + ISSB S2 + similar).

What else in your programme already covers this

This control maps to 5 controls across 3 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • AIDA-9 Robustness and Validation

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 5 it maps to, and the evidence behind each claim, over MCP and REST.