Pre-deployment Red Teaming Controls
Gate deployments on a qualifying red teaming risk assessment.
Pre-deployment red teaming controls gate deployment on a recent red teaming risk assessment. Use them to require security and safety testing before an AI application is released.
When should you use pre-deployment red teaming controls?
- When a release must be backed by a recent, qualifying security and safety assessment.
- When you need to verify that the intended application, model, and attack configuration were tested against adversarial risks.
- When deployment should be blocked unless the release has current red teaming evidence.
Which risk assessment is assessed
The control assesses the project's latest completed risk assessment.
If you mark risk assessments as official, the control assesses the latest official risk assessment instead. Use official assessments when your security or governance team promotes specific assessments as the source of truth for release decisions, so scratch runs can't become the evidence a release is gated on.
Apply filters
You can add filters to further define which risk assessment qualifies. The selected assessment must match every configured filter.
Filters let you scope the requirement to the application, model, attack configuration, or other attributes relevant to the release.
Example requirements
- Require the latest risk assessment to pass before a release can ship.
- Require the latest official risk assessment as the source of truth for gating.
- Require the gating assessment to match the approved model and attack configuration.
Last updated on