CC6.7 (Trust Services Criteria, common criteria)
Restrict the movement and transmission of information
CC6.7 requires the organization to restrict the transmission, movement, and removal of information to authorized users and processes, protecting it during transmission outside system boundaries. It is the criterion covering data leaving controlled channels.
An employee prompt carrying customer data to an external AI tool is a transmission outside the system boundary through a channel the control set never contemplated. If the organization cannot show a control governing that path, CC6.7 has a gap regardless of how good its encryption and DLP story is elsewhere. IBM found in 2025 that only 17% of organizations have technical controls that redact or block sensitive data at the point of entry, so most CC6.7 narratives are silent exactly where auditors are now looking.
CC6.1 (logical access security)
Logical access controls over information assets
CC6.1 requires logical access security software, infrastructure, and architectures over protected information assets, so that only authorized users, processes, and devices reach them.
Shadow AI inverts CC6.1: instead of unauthorized users reaching protected data, authorized users carry protected data out to unauthorized systems. LayerX measured in 2025 that 71% of GenAI connections use personal, non-corporate accounts, access paths that provisioning, SSO, and offboarding never touch. A defensible CC6.1 position needs to account for browser-based AI tools as destinations, not just for who can log in to production.
CC7.2 (system monitoring)
Monitor systems for anomalies and security events
CC7.2 requires monitoring of system components for anomalies indicative of malicious acts, natural disasters, and errors, with events analyzed to determine whether they represent security incidents.
Monitoring that does not see AI-bound data flows cannot classify them as events, and LayerX found in 2025 that organizations have no insight into roughly 89% of AI usage. In a Type II audit, the question is not whether an incident occurred but whether your monitoring would have detected it during the review period. Visibility into which AI tools are used, and what categories of sensitive data were caught heading to them, turns an unanswerable question into an evidence request you can satisfy.
C1.1-C1.2 (Confidentiality criteria)
Identify, maintain, and dispose of confidential information
The Confidentiality category requires identifying and maintaining confidential information to meet the entity's confidentiality objectives and commitments, and disposing of it when no longer needed. Most B2B contracts make these commitments explicit.
Customer data pasted into an external AI tool sits outside every retention and disposal control the confidentiality commitments rely on: the organization can neither maintain nor dispose of what it no longer holds. Since most SaaS contracts promise confidentiality to customers, one careless prompt can put the company out of conformity with both its report and its contracts. Keeping confidential identifiers out of prompts is the control that keeps the commitment true.
P4.0-P6.0 (Privacy criteria); CC9.2 (vendor management)
Privacy criteria and management of vendors and business partners
The Privacy category imposes criteria on use, retention, disposal, and disclosure of personal information, including disclosure only to authorized third parties. CC9.2 requires the organization to assess and manage risks associated with vendors and business partners, the criterion auditors apply to subprocessors.
An AI tool that receives personal information is a disclosure recipient and, functionally, a subprocessor, whether or not procurement ever saw it. Auditors increasingly ask for the AI usage policy, the approved-tools list, and evidence that AI vendors passed vendor risk review; 63% of organizations have no AI governance policy at all (IBM, 2025). Unapproved AI tools receiving personal data are undocumented third-party disclosures under P6 and unmanaged vendors under CC9.2 at the same time.