Protect test sets from exposure or contamination
Counts the explicit approaches or boundaries identified in this passage. Categories can overlap; the stated clinical scope still applies.
Read the source passage
Question 10 raises data contamination, saturation, and limited real-world representativeness in publicly available benchmarking assets. The concern is acute for the Safety elements specifically. Public Comment, Docket FDA-2026-N-7874 | Polina Moshenets, SichGate Page 6 Because the provenance of training, instruction-tuning, and safety-tuning corpora is generally incomplete or undisclosed, public adversarial benchmarks should be treated as potentially exposed rather than presumed sequestered. A model may decline a prompt drawn from a well-known adversarial dataset because that prompt or a near neighbor was present during alignment training, rather than because the underlying behavior generalizes. Measured resistance on public adversarial assets therefore tends to overstate resistance to novel constructions within the same attack class, and the overstatement grows as an asset ages and circulates. This interacts with Question 16. Sponsor-developed adversarial assets are less likely to be exposed but carry an evident independence problem, since the same party selects both the attacks and the acceptance criteria. One available balance is to publish the attack category taxonomy and scoring methodology while retaining the specific probe payloads, which preserves reviewability of the construct without publishing a reproduction recipe. Sequestered assets held by a qualified independent party would address both concerns more completely, at the cost of the program design considerations raised in Question 16. Recommendation: For the S-series elements, a sponsor's construct validity argument should address exposure specifically, including whether assets post-date the model's training data and whether they appear in public alignment datasets. Where sponsor-developed adversarial assets are used, the taxonomy of attack classes and the scoring rubric should be prespecified and disclosed even where individual payloads are not. 8. Agentic systems: tie acceptance criteria to the action surface (Question 26) Element A.1 appropriately includes resistance to prompt injection through user inputs, retrieved content, and tool outputs, which reflects the established finding that indirect injection through retrieved content is a distinct attack surface from direct user input (Greshake et al., AISec 2023). I would add one consideration about how the elements interact for agentic devices. A boundary failure under S.2 in a non-agentic informational device produces an inappropriate output that a user may or may not rely upon. The same failure in a device with tool access produces an action. The consequences axis in Figure 1 captures the severity of relying on an incorrect output, but for agentic systems the relevant quantity is closer to the severity of an action taken without any opportunity for reliance to be withheld. Recommendation: For devices in the action-taking columns, acceptance criteria should account not only for the likelihood of unsafe generation but also for the action surface exposed to the model, the reversibility of available actions, the authorization scope granted to the device, the availability of independent confirmation before high-consequence or irreversible actions, and the capability to halt or roll back an in-progress action sequence. Where meaningful autonomous action is possible, S.2 and A.1 should be evaluated as jointly interacting controls rather than as independent checklist items, since the human review that moderates risk elsewhere in the framework is absent by construction. Closing The discussion paper is correct that the range of possible inputs to a GenAI-enabled device may be too large for exhaustive testing to be practical, and the competency-based structure is a sound response to that constraint. My comments concern the durability of that structure across the device lifecycle: that the artifact evaluated at Public Comment, Docket FDA-2026-N-7874 | Polina Moshenets, SichGate Page 7 premarket is the artifact that reaches the patient, that changes to it are enumerated in a way that prompts characterization, that the safety elements are re-measured actively rather than inferred from observational use, and that results are compared at a resolution fine enough to make a regression visible. I would be glad to provide further detail on any of the above if it would be useful to the Center. Respectfully submitted, Polina Moshenets Founder, SichGate Polina.Moshenets@sichgate.com Public Comment, Docket FDA-2026-N-7874 | Polina Moshenets, SichGate Page 8
Original source ↗