Join our Newsletter — 33% off our NHI Course

LLM Addendum

An LLM Addendum is an assessment layer that extends a privacy review to large language model risks. It captures issues such as prompts, generated outputs, training data, model behavior, vendor dependencies, and governance obligations that standard privacy templates may not examine in enough detail.

Expanded Definition

An LLM Addendum is not a replacement privacy notice or a generic AI questionnaire. It is an assessment layer that expands a standard privacy review so security, legal, procurement, and data governance teams can examine risks introduced by large language model use. That includes prompts, outputs, training data, retrieval sources, model updates, human review paths, vendor dependencies, retention, and whether the system can expose personal data or regulated information through generated responses.

The term sits at the intersection of privacy governance and AI risk management. In practice, it helps teams capture issues that conventional templates often miss, such as prompt injection exposure, data minimisation concerns, output reliability, and secondary use of submitted content by a provider. Guidance is still evolving, so organisations should treat an LLM Addendum as a living control artifact rather than a fixed legal form. The closest formal reference point is the NIST AI 600-1 Generative AI Profile, which frames generative AI risks in governance terms rather than as a narrow technical checklist.

The most common misapplication is using an LLM Addendum as a one-time procurement attachment, which occurs when teams fail to update it after model changes, new connectors, or expanded data use.

Examples and Use Cases

Implementing an LLM Addendum rigorously often introduces review overhead and vendor negotiation friction, requiring organisations to weigh faster AI adoption against stronger control over data, prompts, and outputs.

  • A legal team adds questions about whether user prompts are stored, used for training, or exposed to subcontractors before approving a chatbot for employee support.
  • A privacy office requires a special assessment for a customer-facing assistant that may summarise case notes, ensuring personal data is not reproduced in uncontrolled outputs.
  • A procurement workflow includes clauses on model updates, logging, retention, and incident notification when a vendor provides a NIST AI Risk Management Framework-aligned service.
  • A security team reviews whether retrieval-augmented generation can pull from sensitive repositories and whether prompt injection could alter what the model reveals, a concern also reflected in the OWASP Agentic AI Top 10.
  • An internal governance board uses the addendum to decide when human approval is mandatory for model-generated HR or finance content.

Where the system includes autonomous tool use, the addendum should also reflect agentic behaviour and escalation paths, not just static text generation. The CSA MAESTRO agentic AI threat modeling framework is useful when those workflows can take actions beyond producing content.

Why It Matters for Security Teams

An LLM Addendum matters because generative AI changes the risk surface in ways that standard privacy reviews were never designed to capture. Security teams need a structured way to ask who can prompt the model, what the model can see, how outputs are validated, where content is stored, and which third parties may process that data. Without that clarity, organisations can end up with unreviewed data flows, weak accountability for vendor behaviour, and unclear incident response when a model leaks sensitive information.

This is especially relevant when LLMs are connected to identity, knowledge systems, or agentic workflows. A model that can access accounts, ticketing systems, or internal documents can become an operational control point, not just a content tool. That is why references such as the OWASP Top 10 for Agentic Applications 2026 and the MITRE ATLAS adversarial AI threat matrix are useful for broadening the review beyond privacy alone. Organisations typically encounter the real cost of an LLM Addendum only after a prompt leak, an unsafe output, or a vendor dispute, at which point the review becomes operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10, CSA MAESTRO and MITRE ATLAS address the attack and risk surface, while NIST AI RMF and NIST AI 600-1 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST AI RMF Defines AI governance risk processes that an LLM Addendum should extend.
NIST AI 600-1 Profiles generative AI risks and governance concerns directly relevant here.
OWASP Agentic AI Top 10 Covers agentic AI risks that emerge when LLMs can act through tools.
CSA MAESTRO Threat modeling for agentic AI supports addendum review of autonomous workflows.
MITRE ATLAS Maps adversarial AI techniques that can influence model behavior and outputs.

Document autonomous actions, escalation paths, and control boundaries for model-driven workflows.