Pre-deployment Red Teaming Controls
Gate deployments on a qualifying red teaming risk assessment.
Pre-deployment red teaming controls gate deployment on a recent red teaming risk assessment. Use them to require security and safety testing before an AI application is released.
When should you use pre-deployment red teaming controls?
- When a release must be backed by a recent, qualifying security and safety assessment.
- When you need to verify that the intended application, model, and attack configuration were tested against adversarial risks.
- When deployment should be blocked unless the release has current red teaming evidence.
Select the gating risk assessment
Choose one of two selection methods:
Latest official assessment
The control selects the most recent risk assessment marked official in the project. Use this method when your security or governance team explicitly promotes one assessment as the source of truth for release decisions.
Identifier and window
The control selects the latest completed risk assessment that:
- matches the configured identifier, and
- completed within a rolling window of 7, 14, 30, or 90 days.
Use this method when a stable identifier represents a release pipeline or red teaming campaign and the result must stay current.
Apply filters
You can add filters to further define which risk assessment qualifies. The selected assessment must match every configured filter.
Filters let you scope the requirement to the application, model, attack configuration, or other attributes relevant to the release.
Example requirements
- Require the latest official risk assessment before a release can ship.
- Require a release-candidate red teaming assessment from the last 14 days.
- Require the gating assessment to match the approved model and attack configuration.
Last updated on