Firms using AI must safeguard private and confidential data, including personal data, by storing it securely (for example encryption, backups), limiting access to staff who strictly need it, training those staff at least annually on AI privacy and confidentiality risks, preparing data in privacy-protecting ways such as anonymisation, and not uploading such data to AI systems unless affected stakeholders have given express written consent in advance and the firm has reasonably satisfied itself that the upload carries no unacceptable risk.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.