Control Packs · AI-002 · v1.0.0

Model Output Validation

Treat model output as untrusted data until it passes schema, policy, and consequence-aware validation.

Status: review · Review: not independent. This is design guidance; review status does not establish independent verification or compliance.

What this safeguard addresses

Validate model output against a strict contract, apply policy checks, preserve provenance, and reject unsafe or ambiguous output.

  • Model output crosses a boundary without validationGenerated content is exported, stored, or acted upon before structural, policy, and destination checks are complete.
Versioned applicability rule
{
  "all": [
    {
      "characteristic": "AI_CONTROLLED",
      "equals": true
    },
    {
      "characteristic": "DATA_EXPORT",
      "equals": true
    }
  ]
}

Decisions for the project owner

Leave a decision open when its value is unknown. Suggested values become confirmed only through an explicit user decision.

  • Which model outputs require validation or human review before export?The system must not infer that a well-formed output is safe for its destination.AI-002-Q1 · confirmation

Requirements for the coding agent

  • AI-002-R1Validate model output against a schema and policy, preserve provenance, reject ambiguity, and require confirmed review before material export.

Tests and evidence to retain

  • MODEL_OUTPUT_VALIDATION_TESTVerify valid output, malformed output, policy rejection, prompt injection content, ambiguity, and review escalation.
  • configuration_or_policy
  • implementation_location
  • test_result
  • telemetry_definition

Passing a published example shows that example's behavior. A coding agent's implementation report remains a claim until its evidence is independently checked.

Related guidance

  • SI-10 · Information Input ValidationNIST_SP_800_53_5_2_0 · partially addressesSchema and policy validation operationalize a bounded slice of input validation; they do not establish control compliance.
  • SA-11 · Developer Testing and EvaluationNIST_SP_800_53_5_2_0 · partially addressesThe required malformed, ambiguous, and injection test cases support focused evaluation; they are not a complete developer testing program.
  • AU-10 · Non-repudiationNIST_SP_800_53_5_2_0 · informsProvenance preservation informs attribution and reconstruction needs without asserting non-repudiation coverage.

Mappings indicate contextual relevance or partial support. They do not establish equivalence, certification, government endorsement, or complete framework implementation.

Continue your review